Hackers Got Inside a Flock Camera. Its Data Shows How the System Works
3 hours ago
- Hackers removed a Flock camera, copied its data, and shared the files, revealing detailed tracking of vehicles and people.
- The breach exposed on-device encryption weaknesses; hackers recovered an encryption key and thousands of vehicle detection videos.
- Camera software detects people as well as vehicles, license plates, and bicycles, generating over a million images in weeks.
- The hackers aimed to reverse engineer and expose Flock's secrets rather than just destroy cameras, calling themselves stegan0gram.
- Flock's national network allows over 2,000 agencies to search camera records, raising privacy and legal concerns.
- Controversies include cops using Flock data for immigration enforcement and abortion-related searches, fueling public opposition.
- Camera runs Android with two partitions; hackers found unencrypted sections containing an encryption key to access media.
- Security researcher Jon Gaines had previously documented similar flaws, but Flock downplayed risks involving physical access.
- Analysis showed cameras take rapid photo bursts (e.g., 28 images per vehicle) and rely on server-side plate reading.
- Person-detection software was tested and identified people in clips, though false positives occurred with non-plate objects.
- WIRED reconstructed Flock's police software, showing how records combine with other data to track drivers.
- Critics argue sabotage may backfire, strengthening police support for surveillance tools rather than reducing them.
- Camera logs revealed frequent storage errors and crashes, with over 27,000 'no space left' errors and periodic reboot messages.