It’s not even suitably encrypted on device?
Zero trust in anything Flock says.
It’s not even suitably encrypted on device?
Zero trust in anything Flock says.
I think I should add a "X'); DROP TABLE Cameras;--" bumper sticker to my car now.
Couldn't resist: https://github.com/EvanAnderson/whimsy/blob/main/Drop_Table_...
the Flock response has been 'it doesn't count if a Youtuber did it' lol: https://www.youtube.com/watch?v=0ADb-qQ5hMY
- Thomas Jefferson> The hackers said they were able to access the Android system on the camera, and found two partitions—sections of its hard-drive, essentially. A few of these were unencrypted, the hackers said, including one called “vendor” and another called “media.” The latter contained an encryption key that unlocked another part, which contained much of the media—think, the videos and stills—the camera took.
> In early 2025, security researcher Jon “GainSec” Gaines reverse engineered a Flock license-plate reader and documented flaws that could be used to gain root-level access. After Gaines disclosed his findings, the company acknowledged the findings but downplayed their severity, writing that the flaws required physical access to the device and that even someone who gained access to a camera “would still not be able to gain access to footage” because images remained on the device only briefly after being transmitted to the cloud.
Source: https://www.404media.co/hackers-stole-flocks-camera-software...
Encryption matters, even if I would divulge everything long before the wrench appeared.
At some point, the attackers are just going to have to give up and start hitting me with a wrench. Joke's on them though - I'm an Emacs user, I like pain.
I worry people will get the wrong idea about security: The application used for decryption doesn't need to be the same as the one used for encryption, at least not for any serious attacker. That would be 'security through obscurity'. They need the encrypted text; they don't need Emacs.
More importantly, no matter who you are, that you implemented the encryption yourself (?) is a major flaw - unless you have a cryptography team that has matured the implementation over a decade or so. Nobody is good enough to do that by themself. As the saying goes, anyone can create an encryption routine that they can't break.
It seems that some enterprising Jolly Roger could start running a public mesh net on top of them without Flock even noticing.
But think the real danger in Flock is the aggregate data, tracking between camaras. So if someone hacks a single camara, they probably don't get much, unless it is pointed right at someone, which is bad. Aren't they selling these as should be pointing at traffic? If they are pointing right at people, like at playgrounds, then they are being installed illegally to begin with ?
But there is some old rule about, even the best security can fail if the device is physically accessible.
The Android documentation has an example of how to use hardware keys, and a Chinese OEM (IIRC) was found using the example key provided by Android sample code - and yet that was more effort than Flock applied, since their ARM SoC support it.
They had not admitted before to tracking people, but their software is clearly submitting them. They had not admitted before to looking at bumper stickers, but turns out they do.
I wonder if they could find all cars with Bernie Sanders bumper stickers within X blocks of a polling place.. I can imagine that (or similar queries) might be very useful in the wrong hands.
Now they are in a position where they can sell new models with enhanced encryption and more features.
For example, passing a frame of video (YUV) into the peripheral which can resize the overall image, would fail if the system was busy with other DMA transfers. You could attempt to resize again, but there were no guarantee that it would complete successfully. Your options are to reduce overall DDR utilization or drop frames. In an application like Flock's, dropping frames is likely something they need to avoid.
The system in question is doing similar tasks, and I don't think that what I'm suggesting is out of the question.
And in any case. Passing compressed video streams or pictures through HW encryption engine will not saturate 1.5+ GiB/s or whatever even the lousiest 16-bit DDR3 at 400MHz would give you, not even close. It would be like a fraction of a percent of total bandwidth.
But, a question for you: even if it was the case that the hardware was the limitation, isn't that also an indictment of Flock? Selling something that cannot exist securely within the bounds of current technology? Or, at a minimum, bad chip selection leading to a compromised design?
All that data about ... license plates if you're willing to steal/damage private property. Seems like it would be a lot easier to setup your own ALPR.
Flock cameras capture the make, model, color, and body style of vehicles. They capture bumper stickers and other decals, as well as potentially identifying dents and scratches. They capture accessories like roof racks, bike racks, trailers, and toolboxes.
The OP story covers some of this. There's more at:
https://www.aclu.org/campaigns-initiatives/get-the-flock-out
https://www.nytimes.com/2026/08/10/us/flock-cameras-can-trac...
Also, there’s way more data on there than plate data.