‹ BackHN Continuity

Thread

Hackers Got Inside a Flock Camera

586 points · 270 comments · driverdan

  1. killbot5000 · · focus · HN ↗
    This is pure laziness aka “reduced time to market” on the part of Flock.

    It takes time and effort to think through proper secure boot architecture and to implement key management in a way that doesn’t kill developer productivity.

    Their product managers, though, should have realized that setting these up in unsecured public spaces means that their threat model really does include local physical access to everything.

    Using off the shelf hardware and software stacks all but guarantees attackers have tools at their fingertips to exploit said physical access.

    Given all the recent exploits hitting the kernel, there’s a good chance that there exists an exploitable over-the-air vulnerability present in their WiFi/bluetooth stack, too.

    1. wat10000 · · focus · HN ↗
      The question is, why should they care at all? Will this hurt their business?
      1. NichoPaolucci · · focus · HN ↗
        Any breach of security on a system like this is a big flashing red-alert to me.

        If it could lead an attacker to get ANY of their data... Persons, places, events, etc is pretty damning stuff to be exfiltrated.

        Stalking/Domestic Violence, blackmail, timed robberies, you name it... That data shouldn't really be in anyone's hands in my opinion, but in anyone's hands (good guys / bad guys) it's pretty powerful.

        1. wat10000 · · focus · HN ↗
          That's why you or I would care, but that doesn't answer the question of why they would.

          Large companies tend to be amoral. Unless it affects them monetarily (possibly indirectly) they're not going to care. Given what they do to make money, I don't see any of these things hurting them.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.