‹ BackHN Continuity

Thread

Hackers Got Inside a Flock Camera

586 points · 270 comments · driverdan

  1. drfloyd51 · · focus · HN ↗
    So… all that data is literally there for any unauthorized person to walk up and take it.

    It’s not even suitably encrypted on device?

    Zero trust in anything Flock says.

    1. glaslong · · focus · HN ↗
      Yep. Clown show.

      > The hackers said they were able to access the Android system on the camera, and found two partitions—sections of its hard-drive, essentially. A few of these were unencrypted, the hackers said, including one called “vendor” and another called “media.” The latter contained an encryption key that unlocked another part, which contained much of the media—think, the videos and stills—the camera took.

      > In early 2025, security researcher Jon “GainSec” Gaines reverse engineered a Flock license-plate reader and documented flaws that could be used to gain root-level access. After Gaines disclosed his findings, the company acknowledged the findings but downplayed their severity, writing that the flaws required physical access to the device and that even someone who gained access to a camera “would still not be able to gain access to footage” because images remained on the device only briefly after being transmitted to the cloud.

      Source: <a href="https:&#x2F;&#x2F;www.404media.co&#x2F;hackers-stole-flocks-camera-software-revealing-how-the-company-tracks-cars-and-people-2&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.404media.co&#x2F;hackers-stole-flocks-camera-software...

      1. scottLobster · · focus · HN ↗
        TDIL my homebuilt Plex media server is more strongly encrypted than a Flock Camera
        1. bdangubic · · focus · HN ↗
          so is my all-passwords.txt file on my desktop
          1. antonvs · · focus · HN ↗
            My passwords are in an encrypted block in a text file that can be unencrypted inline in an Emacs session with a keystroke sequence that looks like a cat just chased a mouse across the keyboard, and that&#x27;s before entering the decryption password. To access it, an attacker would first have to learn Emacs. Pretty sure that&#x27;s a post-quantum level of security.
            1. dpoloncsak · · focus · HN ↗
              Obligatory relevant xkcd: <a href="https:&#x2F;&#x2F;xkcd.com&#x2F;538&#x2F;" rel="nofollow">https:&#x2F;&#x2F;xkcd.com&#x2F;538&#x2F;
              1. IAmBroom · · focus · HN ↗
                It&#x27;s a forever-fresh reminder about security versus your own government, but for malicious hackers and bots: the physical trip to visit you costs more than half their infrastructure.

                Encryption matters, even if I would divulge everything long before the wrench appeared.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.