same, but i'm not sure how that's related to my comment. workarounds or alternate articles without significant new information are typically posted within the same submission, not separate ones.
3.18.71-perf-gaf770dc is a Qualcomm Android vendor kernel from roughly late 2017. The 3.18 branch went fully EOL in 2019, so nothing after that was ever backported to it.
2017 was also the year Flock was funded and founded and went through the YConbinator cohort.
But you would have thought that by 2021 when Andreessen Horowitz funded them or at least by 2025 [1] when both further funded them, someone would have actually done some minor due diligence. Coincidentally too, 2025 was when the flock surveillance matrix went up all over the country almost immediately.
We constantly hear that the magic of tech funding lies in the people, not even the product/service. These types of things always seem to uncover that that is effectively just a lie to cover up the ulterior motives of setting up a tyrannical surveillance matrix all around you … to protect the children, of course.
In an ideal world they'd have people whose job it is to monitor upstream activity in the components used in the firmware and maintain this. Sounds like they did not have that.
I think I should start posting a reminder in Flock threads that Axon is a Flock competitor, is also evil, and is possibly even worse, but there’s rarely any mention of it. Journalists need to do some digging there. This shouldn’t just be a Flock story, or Flock will just get bought up or something and everyone will move on.
> The camera’s logs also show the camera struggling with storage. Its logs recorded more than 27,000 “no space left on device” errors while trying to save full-resolution images, along with tens of thousands of related errors, crashes, and reboots. At the same time, about every two minutes, code checked that the camera was still running and logged the message, “Who’s a good boy?!” More than 12,000 of those messages appear in the recovered logs.
"Axon is Flock but worse" will be the next big fight as police departments are pulling a fast one and saying "we got rid of Flock" by switching to Axon.
Axon (among others) has operations hubs for data fusion centers and other platforms for police like Evidence.com, so it’s an easy sell to departments.
Communities are starting to pivot to the wider issue, but a reason that this issue found purpose is that Flock is a more evocative target than “ALPRs”. I think it wouldn’t be a bad thing if “Flock” becomes the generic name.
For those unaware, embedded devices usually have a "watchdog" timer that needs to be periodically reset ("fed"/"pet"/"kicked") when everything is operating correctly or else the device will reboot as a fail-safe.
This log message probably indicates when they're resetting the watchdog timer.
While Axon's system should be under the microscope too I don't think they have the nation wide cloud that Flock is doing and requires specific agreements to share data. Maybe that is getting abused to form a national database but I imagine it was designed so say a county sheriff department and local city PDs could share resources. I don't think most people are that concerned about things like that (though they should be), it is the nation wide surveillance that creeps people out. That and the stalking of course and both systems can be used for that.
Axon and Motorola also do a lot more to court state agencies who have grand plans of monitoring some highway corridor so their buddies at DEA/CPB/SMD/whatever can tip them off and their "drug task force" can make a newsworthy bust.
Flock by contrast courts local PDs who will catch a package thief or two but they really just want to have the drag net at their finger tips so that when some more equal animal's cat gets stolen they can walk back in time and figure out the short list of who could've done it.
Also, a reminder that ALPR abuse predates Flock. Flock has just made it more visible. About a decade ago I personally heard a cop let it slip that he had plate-stalked someone for the crime of saying mean things about his department on Twitter. The difference today is that more departments have access to these kinds of tools.
Fixed ALPRs aren't the only privacy problem, either. Many tow trucks have roving ALPRs that feed into big databases available to third parties. The notion is that it helps them repossess cars that might be garaged at home. That data, however, is for sale to third parties.
But think the real danger in Flock is the aggregate data, tracking between camaras. So if someone hacks a single camara, they probably don't get much, unless it is pointed right at someone, which is bad. Aren't they selling these as should be pointing at traffic? If they are pointing right at people, like at playgrounds, then they are being installed illegally to begin with ?
A network connected device that can be hacked is a small step away from being the first foothold into its server. The fact that on-device security is this atrocious suggests that their server is not any better quality, which means hacking it would probably not take much effort.
There are levels to defending against physical attacks, and Flock half-assed theirs by leaving the encryption key right on the file system, according to the reporting. Those more serious about security like Apple, store keys in an "enclave" chip so it can't be easily extracted by an attacker doing the bare minimum
Apple did that… eventually. Early iPhones weren’t very secure. Apple only got serious after they dominated the market and reducing the theft value of iPhones became a priority.
Even the cheapest commodity encryption chips have had this capability for well over a decade now, Unlike Apple, Flock are not a hardware pioneer by a long shot.
The Android documentation has an example of how to use hardware keys, and a Chinese OEM (IIRC) was found using the example key provided by Android sample code - and yet that was more effort than Flock applied, since their ARM SoC support it.
i think this is actually good, because there are differences between the images they found, and security settings that the company claimed.
They had not admitted before to tracking people, but their software is clearly submitting them. They had not admitted before to looking at bumper stickers, but turns out they do.
I wonder if they could find all cars with Bernie Sanders bumper stickers within X blocks of a polling place.. I can imagine that (or similar queries) might be very useful in the wrong hands.
Is this an older model? I could see them turning off or using weak encryption on media if the hardware couldn't keep up with the amount of data they were writing.
As another commenter pointed out, any cheapo ARM core from the last 10 years could do the job Flock needs it to do, as long as it has a (very cheap and common) crypto engine strapped to it.
But, a question for you: even if it was the case that the hardware was the limitation, isn't that also an indictment of Flock? Selling something that cannot exist securely within the bounds of current technology? Or, at a minimum, bad chip selection leading to a compromised design?
> The hackers said they were able to access the Android system on the camera, and found two partitions—sections of its hard-drive, essentially. A few of these were unencrypted, the hackers said, including one called “vendor” and another called “media.” The latter contained an encryption key that unlocked another part, which contained much of the media—think, the videos and stills—the camera took.
> In early 2025, security researcher Jon “GainSec” Gaines reverse engineered a Flock license-plate reader and documented flaws that could be used to gain root-level access. After Gaines disclosed his findings, the company acknowledged the findings but downplayed their severity, writing that the flaws required physical access to the device and that even someone who gained access to a camera “would still not be able to gain access to footage” because images remained on the device only briefly after being transmitted to the cloud.
My passwords are in an encrypted block in a text file that can be unencrypted inline in an Emacs session with a keystroke sequence that looks like a cat just chased a mouse across the keyboard, and that's before entering the decryption password. To access it, an attacker would first have to learn Emacs. Pretty sure that's a post-quantum level of security.
It's a forever-fresh reminder about security versus your own government, but for malicious hackers and bots: the physical trip to visit you costs more than half their infrastructure.
Encryption matters, even if I would divulge everything long before the wrench appeared.
They could use an LLM to lookup your HN posts and then to wrangle Emacs. Or just decrypt the text in another application - I doubt Emacs is the only platform for whatever crypto method you use. M-x rot13 ?
Oh, did I forget to mention the encryption is implemented in Emacs Lisp?
At some point, the attackers are just going to have to give up and start hitting me with a wrench. Joke's on them though - I'm an Emacs user, I like pain.
has been for a long time - there's a sound engineer who developed quite a following (and is fairly involved with local movement hackerspaces) who demo'd how easy it was to hack Flock cameras nearly a year ago: https://www.youtube.com/watch?v=uB0gr7Fh6lY
You don't think that because it's called a "license plate reader," that it only captures license plates, do you?
Flock cameras capture the make, model, color, and body style of vehicles. They capture bumper stickers and other decals, as well as potentially identifying dents and scratches. They capture accessories like roof racks, bike racks, trailers, and toolboxes.
The OP story covers some of this. There's more at:
My working assumption based on what I hear out of Flock is that they have a public feature set (mass license plate surveillance for LEO) and a covert feature set (even more mass surveillance, beyond license plates and privacy agreements, for intelligence communities).
The devices are entirely open for all practical purposes - but worrying about individual cameras is silly, because they have no meaningful security at all around the API's to access all the cloud data - you can buy law enforcement credentials dirt cheap in dark web marketplaces to log in and track anyone/anywhere you want and access all footage.
I remember walking over a hill into a rave in the Utah desert that we'd set up and thinking that it actually was the cyberpunk dystopia that I had been hoping for.
That kind of stuff is around but maybe not evenly distributed or legible to large demographics.
Unfortunately, so is the rest of the vicious horrorshow, equally illegible and equally uneven in distribution.
Interesting that you frame it as "hoping" for a dystopia. Like even in our wildest imaginations we can't envision a future where society works for regular folks.
I'm sympathetic to the problem that folks like Mark Fisher have laid out, in which (to paraphrase) "it is easier to imagine the end of the world than the end of capitalism", and that indeed might be one way to understand my feeling.
I take your point; it makes sense.
"Regular folks" is doing a lot of work, though.
It may very well be the case that most of the material world which props up the idea of "regular folks" never was capital-R Real and insofar as the idea is a pleasant dream it is not a sustainable one.
Proximate to me, often "regular folks" entail white folks unproblematically living their lives around the norms of US hegemonic capital interests. When I hear Pat the Bunny sing "show me utopia, I will call it a jail" I understand the feeling. I was, afterall, raised by Christians who believed in David Byrne's picture of "Heaven" as a place where "nothing ever happens".
Those are the folks who have happily elected a few people to replace the Flock cameras here with Axon. Their vision of an ordered society is a bit chilling to me, despite the fact that they understand their project as both liberal and progressive.
As I understand it, deviations from those cultural norms are already "dystopic" to the "regular folks" I know- if we somehow lost our ability to transmute sand into computing power and dead plants into motive power and had to go back to living in the cliff side then we'd no longer really be human, despite the fact that their enchanted sand and holy oil is literally destroying the ecology of the entire planet.
This situation is, of course, already a distopia for the bands of Ute and Jicarilla Apache and Dine and Hopi and others living near me. And when I look at the kinds of technological survellience built into the material structures it feels easy enough to note that we already live in a dystopia. I have heard some specific dakota folks refer this situation to as post-apocalyptic and I am inclined to agree.
If we accept that we're already in a dystopia and, further, that much of the hegemonic culture's idea of a "utopia" has already been a holocaust for several other groups of people, then hoping for a "dystopia" in that sense might seem a bit more coherent.
I feel like most of this was already known when someone here in Dallas figured out they had wifi connectivity you could connect and get access. I may not have the details exactly correct but I think someone got access then.
Flock is a scourge on democracy. Flock is YC. But looks like they did YC nearly ten years ago. Who knows what their pitch deck looked like? If they pivoted since then to their current sinister incarnation? I don’t see any evidence that YC is still actively supporting them.
Benefit of the doubt: Funding them for a community/city-owned traffic camera type thing seems like it would have been a much more reasonable proposition than funding Flock for their current use case of allowing police to stalk their ex girlfriends or mistresses.
They just had a Superbowl ad like two years ago (ok, it was for Ring, but partnering with Flock) that said it was all about finding lost dogs around the neighborhood...and, that was it.
It’s not like this stuff wasn’t known to be a problem 10 years ago. We were already in Trump’s first term, it’s not like it was part of the early post 9/11 “secure everything” push. It was WAY after that.
It’s not an excuse, but gives some luxury of distance. We have a lot more hindsight now on how rotten things can become, so with that hindsight it’s easy to say that companies like Flock shouldn’t exist, or shouldn’t be invested in. Ten years ago required some more leaps in foresight that some people were making, I was, but even I didn’t think it would get as evil as it has.
The NSA spying scandal happened under Obama even! IMO that was the defining moment for electronic privacy as a real political issue; before that we were very much in post-9/11 state of exception mode.
Yes. Blame the pickaxe seller. Do not question the miners. Do not question the investors in the mining companies. Do not question the casual member population who thinks that all this is fine.
This isn't to say that flock not a scourge, but I think a lot of people (not saying you're one of them) could stand to look in the mirror here.
Back in ye olde dark ages of <checks notes> 2017, when YC was cutting Flock a check and when "big data" was the hot buzzword people of a certain bent couldn't get enough of this kind of stuff. Everyone was jacking off nonstop to the idea that we could just hoover up everyone's data ad then "efficiently" or "proactively" dispatch enforcement resources. People talked all sorts of big talk about stuff like cross referencing people's Home Depot spend with permit requirements, identifying small businesses that don't have healthy enough financials to be fully compliant, cross referencing invoices and delivery receipts to identify overloaded trucks, and generally finding all sorts of ways to fine the crap out of people for the pettiest of petty deviance. They considered this a noble goal.
Everyone's head was too far up their asses to look at the magic crystal ball called "history" and realize that a camera on every street corner watching who's going where all the damn time would be where it goes.
> According to our analysis, the camera’s logs recorded about 21 days of activity across several periods. During those windows, the device photographed roughly 50,200 vehicles and generated about 1.6 million images. On a typical day, it logged around 3,300 vehicles, with a high of 4,454.
Has there been any report about which state this camera was recovered in? New Hampshire has a strict 3 minute rule for non-hit plate data before the captured images and records must be deleted [1].
[1] (N.H. Rev. Stat. § 261:75-b) requires ALPR systems to delete non-hit plate data within 3 minutes
Yes, only the unaccountable extra-judicial, legally immune low education, high domestic violence/divorce “law enforcement officers” should have access. It’s not like they would use it to stalk and surveil people … likes they have been caught doing all over and then get away with performative slaps on the wrist and get hired in the next jurisdiction down.
K. And cops also have guns, tear gas, the right to pull people over, arrest them, etc. etc. If they cannot be trusted with a licence plate database, then they can't really be trusted with those either.
Are you advocating to just abolish police so that whoever is willing to use the most force can be in charge of everything? Like Mexico, but with less policing!
Or to just remove all their weapons and legal powers so that they can just ask people to 'please stop doing crime'?
Or just that we should only allow high-IQ college graduates to be cops? It sure doesn't seem like there are enough of those interested in that line of work. As it is, it already pays well, and yet I can hardly think of anyone I know who has even considered being a cop.
I'm not trying to be obtuse here, but just asserting "police bad" doesn't seem like it even comes close to trying to solve any problems.
"And cops also have guns, tear gas, the right to pull people over, arrest them, etc. etc. If they cannot be trusted with a licence plate database, then they can't really be trusted with those either."
now you're getting it.
"cops are the only reason we don't all have delicious cartel boots (or their bullets) in our mouths already"
citation needed.
And since you're looking for some solutions to these problems, here are a few: end qualified immunity, make peace officers obtain licensure and insurance so when the shitheads fuck up they are personally liable for their corruption, dissole internal affairs and move the investigations to a third party. In terms of reducing crime: tax the ever loving fuck out of anyone worth more than a million, dump those taxes into public services like education and healthcare so people aren't forced into deviance (further reading: https://www.simplypsychology.org/mertons-strain-theory-devia...)
> tax the ever loving fuck out of anyone worth more than a million, dump those taxes into public services like education and healthcare
Have you met California? That's literally the exact thing we do here. Yet our crime is terrible. And if you think throwing money at schools will translate automatically into better outcomes, it really isn't that simple. Schools with 50% more money hire more administrators and consultants and build way nicer facilities, but they don't just automatically turn out kids who are 50% more moral.
Healthcare is a similar joke. We spend more on healthcare than any nation! Yet we're not the most healthy. Why should we run up the score even more on how much tax money we spend on that when we've already proven it to be inefficient?
> people aren't forced into deviance
With respect, I do not believe that anyone is forced into deviance. People will always come from a diversity of levels of privilege (unless we convert to an economy like North Korea where the leader and their friends live well and everyone else is in poverty). Those who start out with the least will always have a choice to try to get ahead through crime or by honest means, just like everyone else does.
Wouldn't you say the rich aren't any more likely to actually follow the law as the poor? Why do they have agency, but poor criminals were predestined for crime?
> licensure and insurance
This doesn't seem like a serious idea to me. Licensure is no magic wand. The effect of malpractice insurance in medicine has arguably brought most of society very little benefit (other than attorneys).
A nationwide standard on censuring officers proportionally (up to and including suspension or ban from serving as a peace officer anywhere) for offenses of misuse of power makes sense and could be good policy. Most of the rest of this just sounds like unserious wishing that will never go anywhere.
I know several police officers and none of them fit this description. I'm sure there are officers that do; I have Youtube too. But this is a pretty gross way to refer to about 1,000,000 people doing an extraordinarily difficult job.
The images were deleted the moment they were uploaded. But the record in the log files persisted. The camera doesn't have enough memory to store that many data.
> The images were deleted the moment they were uploaded.
???
> VIII. Records of number plates read by each LPR shall not be recorded or transmitted anywhere and shall be purged from the system within 3 minutes of their capture [...]
But you're saying that these non-hit image captures where uploaded somewhere?
- Camera pre-checks the picture for quality and that there's something on there that they want
- Camera uploads picture to flock servers
- Camera deletes picture locally
- Rinse and repeat
I could actually see this being done by three jobs in parallel.
If there are a lot of images found on the camera then that's probably because the upload wasn't able to keep up with the amount of data that was created or they have a buffer of a few days or there's a cronjob that deletes these files every now and then...
Unless they actually use the camera also as the storage, which would be really stupid, but sometimes people to stupid things.
That's also the biggest plot-hole in the first Star Wars movie. Princess Leia is supposed to be this righteous noble of the moral resistance and yet she STEALS the Death Star plans!
Then why bother using that language? Why not just "we took".
Also, is it really justified? Did we learn anything useful here that we didn't already know? There's more effective ways to push back against Flock, townships (like my own) are having plenty of success stories without stealing anything.
“I kept trying to explain in between haymakers that we were better than this and on top of that it wasn’t likely to be ruled on favorably as far as the courts.”
- Luke O’Neil https://flaminghydra.com/the-end-and-after-2/
You don't think maybe it's just a little bit tongue-in-cheek? Maybe a reference to how the US Military sometimes goes into foreign countries saying we'll be greeted as liberators?
This is pure laziness aka “reduced time to market” on the part of Flock.
It takes time and effort to think through proper secure boot architecture and to implement key management in a way that doesn’t kill developer productivity.
Their product managers, though, should have realized that setting these up in unsecured public spaces means that their threat model really does include local physical access to everything.
Using off the shelf hardware and software stacks all but guarantees attackers have tools at their fingertips to exploit said physical access.
Given all the recent exploits hitting the kernel, there’s a good chance that there exists an exploitable over-the-air vulnerability present in their WiFi/bluetooth stack, too.
Quite potentially, yes. Their name is already mud among many voters, if they're shown to be treating data insecurely then that's another reason why local governments might consider terminating contracts with them.
Any breach of security on a system like this is a big flashing red-alert to me.
If it could lead an attacker to get ANY of their data... Persons, places, events, etc is pretty damning stuff to be exfiltrated.
Stalking/Domestic Violence, blackmail, timed robberies, you name it... That data shouldn't really be in anyone's hands in my opinion, but in anyone's hands (good guys / bad guys) it's pretty powerful.
Apparently police are accessing the network via their personal devices. I highly doubt their security practices online are any better than this. I wouldn't be surprised either to see things that chinese manufacturers do such as intentional back doors.
Overall this goes from disappointing to fairly repugnant.
Allegedly you can buy credentials on the darkweb to perform national searches. Might explain why some of the logged reasons for recent searches were “LMAO”
The normal explanation is plenty, unless you’ve never met, read about, or heard anyone talk about, law enforcement officers (who are human beings - for better and for worse).
How many of us have had coworkers who put something like that into a commit message? And that's a message that's at least notionally supposed to be helpful to you or your coworkers, rather than existing purely for the purposes of oversight you don't want in the first place.
I would expect law enforcement coworkers to understand the law, department procedure, and public requests for their data. That’s expecting too much from the academy, I guess.
Those that fail to meet standards should be fired to spare the taxpayers from the lawsuits coming from AI-assisted complainants.
It’s also too much for Flock’s YC-funded technology to implement a field filter that rejects “LMAO” as a valid request.
At the very least, your local staff’s nationwide stalking credentials being harvested by phishing and abused by others should carry criminal negligence penalties. Governments should pass that liability onto this YC-funded startup company.
That's why you or I would care, but that doesn't answer the question of why they would.
Large companies tend to be amoral. Unless it affects them monetarily (possibly indirectly) they're not going to care. Given what they do to make money, I don't see any of these things hurting them.
Getting persistent access to Flock's internal network is a high-priority item for every US adversary, that's just free intel collection on the movements of persons of interest. Knowing who the FBI and local cops are monitoring in is a cherry on top of the counter-counter-intelligence cake.
Any entity with access to flock servers can virtually stake-out anyone/everyone driving past Flock camera to monitor their movements. In a hot war, this would provide actionable data to support assassination via road-side bomb/drone strikes.
Many moons ago, I was involved in the technical side of volunteer work for domestic violence victims escaping abusive relationships with e.g. law enforcement (cops), who even fifteen years ago had sweeping powers to track and stalk their victims. Things like actual anonymous burner phones and the ability to e.g. create new email accounts without government identification were critical to the process of getting these people out safely, or alive, without fear of retaliation.
I can't even imagine how difficult this job must be nowadays, with bullshit like Flock spanning hundreds of police departments participating in their nationally-linked database. I have zero sources for what I'm about to say, but my instinct is that the political machines (expanding powers hidden behind "think of the children") behind how technology is evolving today has gotten people killed.
It's a red-alert to you and me, but Flock won't care. People already don't want these cameras in their cities, but police departments buy them anyway. What does it matter if there's one more reason you don't want them?
They want the good, bad and ugly to flock to them as it were and vaporize them so Axon and Motorola Solutions can just pick up right where they left off. And people will just ignore or forget it because it's not the same company.
I really hate how Product Managers somehow get to take the reins of engineering teams instead of having to sell them product ideas.
It's madness, they often lack the technical skills and "optimise away" requirements surfaced by eng teams they don't comprehend or just don't like having to deal with.
Do you feel like an inadiquate imposter or something? I'm assuming you work in software.
Watch some engineers in other disciplines and you soon recognise that many of them have about the same responsibility as a software engineer. Design is design.
Or read about engineering failures like flight QF32 (mostly a success story):
A paperwork review showed that the required signatures were missing from 131 out of 138 retrospective concessions issued between 2009 and 2011
Australian Quantas, with a UK Rolls Royce engine on an Airbus, with engines maintained in Aussie.
Safety is now often made up of interlocking: regulations, standards, quality systems, safety management systems, insurance, international legal contracts. Certified engineers and signatures are usually only a very small part of those systems.
Certification matters less than you might think across international borders.
Perhaps I'm a cynic, but beliefs in certification seem so irrational to me. What is it? Jealous desires for status? Desire to have guilds/gatekeepers? Complete misunderstanding of how safety occurs in "real" engineering?
Your conclusion seems at odds with your evidence: the quote you reference indicates that a professional engineer was meant to examine the 'retrospective concessions' and did not. The result was that no qualified engineer was taking responsibility for their quality. Fixing the process meant getting credentialed engineers to assess and incur liability for the solutions, which is how the professional engineering licensure system is supposed to work.
That’s because computers are Turing complete anything is technically possible and comes down to the time quality cost triangle. Most management thinks they can optimize that triangle by squeezing the living bejesus out of their teams.
The flip side of this laziness is that now, when my elected representatives tell me "these are just license-plate readers that don't record video", I have evidence to show them that's false.
If Flock had done a more competent job of securing their system, it would be harder to demonstrate this in a compelling way. To a technically-inclined person, it's obvious from the get-go that somewhere in Flock's pipeline, video is being recorded and archived, and is therefore vulnerable to misuse. But the more they're allowed to keep the implementation proprietary, the easier this is to sweep under the rug.
Don't know why you're getting downvoted, but hackernews is very anti-democratic in nature. One thing politicians quickly realize, especially local ones, is that you do have to be accountable to voters at the end of the day. One or two bad stories is enough to sink a local race too, or at minimum require a massive spend to overcome the negativity.
Local politics is where you understand how effective a handful of people can truly be.
Happy to read people are understanding the true power they have collectively instead of as individuals.
Exactly. It helps they also control who can even run for office in any meaningful way. Nobody fights the left harder than Democrats. Good luck finding a representative that is against data centers, flock, Israel, congressional stock bans and pausing and regulating AI, views overwhelming popular with the majority of the actual American public.
It’s not laziness, it’s hyper focus on compliance. CJIS is the policy maintained by the FBI that handles information security, which is derived from standards built around paper.
Adding more weirdness, the details get worked out by each state.
My guess is they encrypted whatever is criminal justice information (license plate hotlists, etc) or protected by local laws (DMV data) and left the rest to make it easier to deploy and service. Remember pictures of you or your car taken in public are not protected or in scope.
Police tech is garbage and usually driven by federal grant spending. So it’s going to be interesting to see how Flock and Axon grow the business as it turns into a service model.
Yeah, you could potentially MITM them with a rogue cell tower, I suppose.
I'm curious about the researchers still having the device. They could also see all the cloud endpoints that were being accessed. Are they secure?
If you want to know what a "Vulnerability Disclosure Policy" (VDP) would look like if its main purpose is to claim we have VDP and create an appearance of responsible security posture, but not really to learn about vulnerabilities - read Flock's VDP.
They sincerely welcome your vulnerability disclosures, except in cases where you have to "interact" with the device/service or download its data. Other than that TINY carveout, everything is okay.
Oh, if the vuln about configuration and hardening "preferences" like SSL/TSL - Sorry, not interested.
And also, infrastructure vulnerabilities like DNS config - no no, try harder.
I know what you're thinking..ha ha...but we are good guys. You can still report vulnerabilities in the above categories, but the onus is on you to convince us that we should care about them. It is only fair.
It'd be interesting to know how much of that they put second to "Americans seem to like using our hardware as targets for firearms, reciprocating saws, spray paint, and garbage bags" in their list of corporate concerns.
This looks like a pretty reasonable policy to me all things considered. And no, I'm no fan of Flock. But they do run security cameras for the cops, they can't just say go ahead, go wild on all our customers' cameras. The lawyers would throw a fit.
The carveouts for stuff like configuration and DNS are entirely reasonable. Have you ever been behind a security@ email before? You get a lot of BS reports of that sort.
The TLS/SSL and DNS carveouts are pretty normal. There are a million security options for those services and enabling them all would often mean denying access to anyone running a browser/client more than a few weeks old. Documenting them all would be a PITA so most policies simply prohibit them entirely.
Testing against customers is also a common prohibition for obvious reasons.
Hm... not normal in my experience. Not enabling a config is not a vulnerability in itself. If not enabling something means a security guarantee is broken (Eg: videos are accessible) then it is a vulnerability, and typically included in VDP, atleast VDPs that are in good faith.
The article understates how bad it is. For months people have been able to walk up next to these these cameras and obtain root immediately and access all the video footage, redirect it to their own servers, etc. The cameras include self-signed certs, credentials, update scripts that can execute anything you want as root, and much more.
Dark web is also filled with inexpensive law enforcement credentials to log into all the systems and track anyone you want at any time.
The quality of the software here is what you'd expect from an 8 hour middle-school hackathon.
203 comments
[ 0.25 ms ] story [ 10.2 ms ] threadDistributed Denial of Secrets has published the partition images: https://ddosecrets.org/article/flock-alpr-camera
Linux version 3.18.71-perf-gaf770dc
But you would have thought that by 2021 when Andreessen Horowitz funded them or at least by 2025 [1] when both further funded them, someone would have actually done some minor due diligence. Coincidentally too, 2025 was when the flock surveillance matrix went up all over the country almost immediately.
We constantly hear that the magic of tech funding lies in the people, not even the product/service. These types of things always seem to uncover that that is effectively just a lie to cover up the ulterior motives of setting up a tyrannical surveillance matrix all around you … to protect the children, of course.
[1] https://www.flocksafety.com/blog/flock-safety-secures-major-...
https://deepdelver.substack.com/p/delve-fake-compliance-as-a...
missing a d(gaf)
sorry, had to get that out!
as someone pointed out: let's make that "flock" name accurate
also make it identify bird song, I am sure there are microphones on there
We'll call it Cock Safety and help our community with patented JimmyHat technology to keep you safe and covered.
> The camera’s logs also show the camera struggling with storage. Its logs recorded more than 27,000 “no space left on device” errors while trying to save full-resolution images, along with tens of thousands of related errors, crashes, and reboots. At the same time, about every two minutes, code checked that the camera was still running and logged the message, “Who’s a good boy?!” More than 12,000 of those messages appear in the recovered logs.
Lol
"Page 17" in the document shows a spicy little chip.
https://www.quectel.com/product/kg100s-amazon-sidewalk-modul...
Axon not only includes a cell modem... they're on Amazon Sidewalk, baby.
https://coverage.sidewalk.amazon/
Communities are starting to pivot to the wider issue, but a reason that this issue found purpose is that Flock is a more evocative target than “ALPRs”. I think it wouldn’t be a bad thing if “Flock” becomes the generic name.
This log message probably indicates when they're resetting the watchdog timer.
Flock by contrast courts local PDs who will catch a package thief or two but they really just want to have the drag net at their finger tips so that when some more equal animal's cat gets stolen they can walk back in time and figure out the short list of who could've done it.
Fixed ALPRs aren't the only privacy problem, either. Many tow trucks have roving ALPRs that feed into big databases available to third parties. The notion is that it helps them repossess cars that might be garaged at home. That data, however, is for sale to third parties.
It’s not even suitably encrypted on device?
Zero trust in anything Flock says.
But think the real danger in Flock is the aggregate data, tracking between camaras. So if someone hacks a single camara, they probably don't get much, unless it is pointed right at someone, which is bad. Aren't they selling these as should be pointing at traffic? If they are pointing right at people, like at playgrounds, then they are being installed illegally to begin with ?
But there is some old rule about, even the best security can fail if the device is physically accessible.
The Android documentation has an example of how to use hardware keys, and a Chinese OEM (IIRC) was found using the example key provided by Android sample code - and yet that was more effort than Flock applied, since their ARM SoC support it.
They had not admitted before to tracking people, but their software is clearly submitting them. They had not admitted before to looking at bumper stickers, but turns out they do.
I wonder if they could find all cars with Bernie Sanders bumper stickers within X blocks of a polling place.. I can imagine that (or similar queries) might be very useful in the wrong hands.
But, a question for you: even if it was the case that the hardware was the limitation, isn't that also an indictment of Flock? Selling something that cannot exist securely within the bounds of current technology? Or, at a minimum, bad chip selection leading to a compromised design?
> The hackers said they were able to access the Android system on the camera, and found two partitions—sections of its hard-drive, essentially. A few of these were unencrypted, the hackers said, including one called “vendor” and another called “media.” The latter contained an encryption key that unlocked another part, which contained much of the media—think, the videos and stills—the camera took.
> In early 2025, security researcher Jon “GainSec” Gaines reverse engineered a Flock license-plate reader and documented flaws that could be used to gain root-level access. After Gaines disclosed his findings, the company acknowledged the findings but downplayed their severity, writing that the flaws required physical access to the device and that even someone who gained access to a camera “would still not be able to gain access to footage” because images remained on the device only briefly after being transmitted to the cloud.
Source: https://www.404media.co/hackers-stole-flocks-camera-software...
Encryption matters, even if I would divulge everything long before the wrench appeared.
At some point, the attackers are just going to have to give up and start hitting me with a wrench. Joke's on them though - I'm an Emacs user, I like pain.
It seems that some enterprising Jolly Roger could start running a public mesh net on top of them without Flock even noticing.
the Flock response has been 'it doesn't count if a Youtuber did it' lol: https://www.youtube.com/watch?v=0ADb-qQ5hMY
All that data about ... license plates if you're willing to steal/damage private property. Seems like it would be a lot easier to setup your own ALPR.
Flock cameras capture the make, model, color, and body style of vehicles. They capture bumper stickers and other decals, as well as potentially identifying dents and scratches. They capture accessories like roof racks, bike racks, trailers, and toolboxes.
The OP story covers some of this. There's more at:
https://www.aclu.org/campaigns-initiatives/get-the-flock-out
https://www.nytimes.com/2026/08/10/us/flock-cameras-can-trac...
I think I should add a "X'); DROP TABLE Cameras;--" bumper sticker to my car now.
That kind of stuff is around but maybe not evenly distributed or legible to large demographics.
Unfortunately, so is the rest of the vicious horrorshow, equally illegible and equally uneven in distribution.
I take your point; it makes sense.
"Regular folks" is doing a lot of work, though.
It may very well be the case that most of the material world which props up the idea of "regular folks" never was capital-R Real and insofar as the idea is a pleasant dream it is not a sustainable one.
Proximate to me, often "regular folks" entail white folks unproblematically living their lives around the norms of US hegemonic capital interests. When I hear Pat the Bunny sing "show me utopia, I will call it a jail" I understand the feeling. I was, afterall, raised by Christians who believed in David Byrne's picture of "Heaven" as a place where "nothing ever happens".
Those are the folks who have happily elected a few people to replace the Flock cameras here with Axon. Their vision of an ordered society is a bit chilling to me, despite the fact that they understand their project as both liberal and progressive.
As I understand it, deviations from those cultural norms are already "dystopic" to the "regular folks" I know- if we somehow lost our ability to transmute sand into computing power and dead plants into motive power and had to go back to living in the cliff side then we'd no longer really be human, despite the fact that their enchanted sand and holy oil is literally destroying the ecology of the entire planet.
This situation is, of course, already a distopia for the bands of Ute and Jicarilla Apache and Dine and Hopi and others living near me. And when I look at the kinds of technological survellience built into the material structures it feels easy enough to note that we already live in a dystopia. I have heard some specific dakota folks refer this situation to as post-apocalyptic and I am inclined to agree.
If we accept that we're already in a dystopia and, further, that much of the hegemonic culture's idea of a "utopia" has already been a holocaust for several other groups of people, then hoping for a "dystopia" in that sense might seem a bit more coherent.
Benefit of the doubt: Funding them for a community/city-owned traffic camera type thing seems like it would have been a much more reasonable proposition than funding Flock for their current use case of allowing police to stalk their ex girlfriends or mistresses.
The front page then had "All the footage is yours. Your neighborhood 100% owns the data. Flock Safety will not share, sell, or access your data."
Unfortunately, flock has been excluded from wayback, so can't see other views of that page.
{insert Darth Vader: I'm altering the deal. Pray I don't alter it any further.}
Is hacker news anti-dog now ?
10 years ago is no excuse.
It was all quite plain then. And the very heavy rhetoric made it very obvious which direction things would go.
Yes. Blame the pickaxe seller. Do not question the miners. Do not question the investors in the mining companies. Do not question the casual member population who thinks that all this is fine.
This isn't to say that flock not a scourge, but I think a lot of people (not saying you're one of them) could stand to look in the mirror here.
Back in ye olde dark ages of <checks notes> 2017, when YC was cutting Flock a check and when "big data" was the hot buzzword people of a certain bent couldn't get enough of this kind of stuff. Everyone was jacking off nonstop to the idea that we could just hoover up everyone's data ad then "efficiently" or "proactively" dispatch enforcement resources. People talked all sorts of big talk about stuff like cross referencing people's Home Depot spend with permit requirements, identifying small businesses that don't have healthy enough financials to be fully compliant, cross referencing invoices and delivery receipts to identify overloaded trucks, and generally finding all sorts of ways to fine the crap out of people for the pettiest of petty deviance. They considered this a noble goal.
Everyone's head was too far up their asses to look at the magic crystal ball called "history" and realize that a camera on every street corner watching who's going where all the damn time would be where it goes.
1. Take pictures
2. Send to a big server that all cops nationwide can log into whenever they want to stalk their exes
Did I miss something
Has there been any report about which state this camera was recovered in? New Hampshire has a strict 3 minute rule for non-hit plate data before the captured images and records must be deleted [1].
[1] (N.H. Rev. Stat. § 261:75-b) requires ALPR systems to delete non-hit plate data within 3 minutes
Are you advocating to just abolish police so that whoever is willing to use the most force can be in charge of everything? Like Mexico, but with less policing!
Or to just remove all their weapons and legal powers so that they can just ask people to 'please stop doing crime'?
Or just that we should only allow high-IQ college graduates to be cops? It sure doesn't seem like there are enough of those interested in that line of work. As it is, it already pays well, and yet I can hardly think of anyone I know who has even considered being a cop.
I'm not trying to be obtuse here, but just asserting "police bad" doesn't seem like it even comes close to trying to solve any problems.
now you're getting it.
"cops are the only reason we don't all have delicious cartel boots (or their bullets) in our mouths already"
citation needed.
And since you're looking for some solutions to these problems, here are a few: end qualified immunity, make peace officers obtain licensure and insurance so when the shitheads fuck up they are personally liable for their corruption, dissole internal affairs and move the investigations to a third party. In terms of reducing crime: tax the ever loving fuck out of anyone worth more than a million, dump those taxes into public services like education and healthcare so people aren't forced into deviance (further reading: https://www.simplypsychology.org/mertons-strain-theory-devia...)
Have you met California? That's literally the exact thing we do here. Yet our crime is terrible. And if you think throwing money at schools will translate automatically into better outcomes, it really isn't that simple. Schools with 50% more money hire more administrators and consultants and build way nicer facilities, but they don't just automatically turn out kids who are 50% more moral.
Healthcare is a similar joke. We spend more on healthcare than any nation! Yet we're not the most healthy. Why should we run up the score even more on how much tax money we spend on that when we've already proven it to be inefficient?
> people aren't forced into deviance
With respect, I do not believe that anyone is forced into deviance. People will always come from a diversity of levels of privilege (unless we convert to an economy like North Korea where the leader and their friends live well and everyone else is in poverty). Those who start out with the least will always have a choice to try to get ahead through crime or by honest means, just like everyone else does.
Wouldn't you say the rich aren't any more likely to actually follow the law as the poor? Why do they have agency, but poor criminals were predestined for crime?
> licensure and insurance
This doesn't seem like a serious idea to me. Licensure is no magic wand. The effect of malpractice insurance in medicine has arguably brought most of society very little benefit (other than attorneys).
A nationwide standard on censuring officers proportionally (up to and including suspension or ban from serving as a peace officer anywhere) for offenses of misuse of power makes sense and could be good policy. Most of the rest of this just sounds like unserious wishing that will never go anywhere.
https://ij.org/the-ij-database-of-alpr-abuse/
???
> VIII. Records of number plates read by each LPR shall not be recorded or transmitted anywhere and shall be purged from the system within 3 minutes of their capture [...]
But you're saying that these non-hit image captures where uploaded somewhere?
- Camera pre-checks the picture for quality and that there's something on there that they want
- Camera uploads picture to flock servers
- Camera deletes picture locally
- Rinse and repeat
I could actually see this being done by three jobs in parallel.
If there are a lot of images found on the camera then that's probably because the upload wasn't able to keep up with the amount of data that was created or they have a buffer of a few days or there's a cronjob that deletes these files every now and then...
Unless they actually use the camera also as the storage, which would be really stupid, but sometimes people to stupid things.
Hints at unauthorized, illegal mass surveillance riding on top of authorized (but also possibly illegal) mass surveillance
Ya know, I'm not on Flock's side here.. but be real, this is theft. You should be able to own that if you're going to do something like this.
Also, is it really justified? Did we learn anything useful here that we didn't already know? There's more effective ways to push back against Flock, townships (like my own) are having plenty of success stories without stealing anything.
Um, are you saying the hackers should admit they broke the law? Or that Flock should righteously own the data they collect?
Either way, I d/c. Flock cameras are probably insecure, and their data is potentially dangerous.
Bad laws exist, and following them may be prudent at times, but the act of following them isn't a moral imperative.
See also: https://dave.autonoma.ca/blog/2019/06/06/web-of-knowledge/
It takes time and effort to think through proper secure boot architecture and to implement key management in a way that doesn’t kill developer productivity.
Their product managers, though, should have realized that setting these up in unsecured public spaces means that their threat model really does include local physical access to everything.
Using off the shelf hardware and software stacks all but guarantees attackers have tools at their fingertips to exploit said physical access.
Given all the recent exploits hitting the kernel, there’s a good chance that there exists an exploitable over-the-air vulnerability present in their WiFi/bluetooth stack, too.
If it could lead an attacker to get ANY of their data... Persons, places, events, etc is pretty damning stuff to be exfiltrated.
Stalking/Domestic Violence, blackmail, timed robberies, you name it... That data shouldn't really be in anyone's hands in my opinion, but in anyone's hands (good guys / bad guys) it's pretty powerful.
Overall this goes from disappointing to fairly repugnant.
Those that fail to meet standards should be fired to spare the taxpayers from the lawsuits coming from AI-assisted complainants.
It’s also too much for Flock’s YC-funded technology to implement a field filter that rejects “LMAO” as a valid request.
At the very least, your local staff’s nationwide stalking credentials being harvested by phishing and abused by others should carry criminal negligence penalties. Governments should pass that liability onto this YC-funded startup company.
Large companies tend to be amoral. Unless it affects them monetarily (possibly indirectly) they're not going to care. Given what they do to make money, I don't see any of these things hurting them.
Any entity with access to flock servers can virtually stake-out anyone/everyone driving past Flock camera to monitor their movements. In a hot war, this would provide actionable data to support assassination via road-side bomb/drone strikes.
I can't even imagine how difficult this job must be nowadays, with bullshit like Flock spanning hundreds of police departments participating in their nationally-linked database. I have zero sources for what I'm about to say, but my instinct is that the political machines (expanding powers hidden behind "think of the children") behind how technology is evolving today has gotten people killed.
It's madness, they often lack the technical skills and "optimise away" requirements surfaced by eng teams they don't comprehend or just don't like having to deal with.
Now, this doesn't always stops management, but when you have to have an engineering signoff it does make things a bit more difficult.
Watch some engineers in other disciplines and you soon recognise that many of them have about the same responsibility as a software engineer. Design is design.
Or read about engineering failures like flight QF32 (mostly a success story):
https://admiralcloudberg.medium.com/a-matter-of-millimeters-...Australian Quantas, with a UK Rolls Royce engine on an Airbus, with engines maintained in Aussie.
Safety is now often made up of interlocking: regulations, standards, quality systems, safety management systems, insurance, international legal contracts. Certified engineers and signatures are usually only a very small part of those systems.
Certification matters less than you might think across international borders.
Perhaps I'm a cynic, but beliefs in certification seem so irrational to me. What is it? Jealous desires for status? Desire to have guilds/gatekeepers? Complete misunderstanding of how safety occurs in "real" engineering?
If Flock had done a more competent job of securing their system, it would be harder to demonstrate this in a compelling way. To a technically-inclined person, it's obvious from the get-go that somewhere in Flock's pipeline, video is being recorded and archived, and is therefore vulnerable to misuse. But the more they're allowed to keep the implementation proprietary, the easier this is to sweep under the rug.
Local politics is where you understand how effective a handful of people can truly be.
Happy to read people are understanding the true power they have collectively instead of as individuals.
Adding more weirdness, the details get worked out by each state.
My guess is they encrypted whatever is criminal justice information (license plate hotlists, etc) or protected by local laws (DMV data) and left the rest to make it easier to deploy and service. Remember pictures of you or your car taken in public are not protected or in scope.
Police tech is garbage and usually driven by federal grant spending. So it’s going to be interesting to see how Flock and Axon grow the business as it turns into a service model.
They sincerely welcome your vulnerability disclosures, except in cases where you have to "interact" with the device/service or download its data. Other than that TINY carveout, everything is okay.
Oh, if the vuln about configuration and hardening "preferences" like SSL/TSL - Sorry, not interested.
And also, infrastructure vulnerabilities like DNS config - no no, try harder.
I know what you're thinking..ha ha...but we are good guys. You can still report vulnerabilities in the above categories, but the onus is on you to convince us that we should care about them. It is only fair.
https://www.flocksafety.com/legal/vulnerability-disclosure-p...
The carveouts for stuff like configuration and DNS are entirely reasonable. Have you ever been behind a security@ email before? You get a lot of BS reports of that sort.
Testing against customers is also a common prohibition for obvious reasons.
Dark web is also filled with inexpensive law enforcement credentials to log into all the systems and track anyone you want at any time.
The quality of the software here is what you'd expect from an 8 hour middle-school hackathon.