This is pure laziness aka “reduced time to market” on the part of Flock.
It takes time and effort to think through proper secure boot architecture and to implement key management in a way that doesn’t kill developer productivity.
Their product managers, though, should have realized that setting these up in unsecured public spaces means that their threat model really does include local physical access to everything.
Using off the shelf hardware and software stacks all but guarantees attackers have tools at their fingertips to exploit said physical access.
Given all the recent exploits hitting the kernel, there’s a good chance that there exists an exploitable over-the-air vulnerability present in their WiFi/bluetooth stack, too.
The flip side of this laziness is that now, when my elected representatives tell me "these are just license-plate readers that don't record video", I have evidence to show them that's false.
If Flock had done a more competent job of securing their system, it would be harder to demonstrate this in a compelling way. To a technically-inclined person, it's obvious from the get-go that somewhere in Flock's pipeline, video is being recorded and archived, and is therefore vulnerable to misuse. But the more they're allowed to keep the implementation proprietary, the easier this is to sweep under the rug.
They can be recalled and/or replaced, as many have who voted for data centers.
They fought against datacenters. Now they are running for local offices - <a href="https://www.theguardian.com/us-news/2026/sep/15/datacenters-local-elections" rel="nofollow">https://www.theguardian.com/us-news/2026/sep/15/datacenters-... - September 15th, 2026
killbot5000 · · focus · HN ↗
It takes time and effort to think through proper secure boot architecture and to implement key management in a way that doesn’t kill developer productivity.
Their product managers, though, should have realized that setting these up in unsecured public spaces means that their threat model really does include local physical access to everything.
Using off the shelf hardware and software stacks all but guarantees attackers have tools at their fingertips to exploit said physical access.
Given all the recent exploits hitting the kernel, there’s a good chance that there exists an exploitable over-the-air vulnerability present in their WiFi/bluetooth stack, too.
teraflop · · focus · HN ↗
If Flock had done a more competent job of securing their system, it would be harder to demonstrate this in a compelling way. To a technically-inclined person, it's obvious from the get-go that somewhere in Flock's pipeline, video is being recorded and archived, and is therefore vulnerable to misuse. But the more they're allowed to keep the implementation proprietary, the easier this is to sweep under the rug.
QuiEgo · · focus · HN ↗
toomuchtodo · · focus · HN ↗
They fought against datacenters. Now they are running for local offices - <a href="https://www.theguardian.com/us-news/2026/sep/15/datacenters-local-elections" rel="nofollow">https://www.theguardian.com/us-news/2026/sep/15/datacenters-... - September 15th, 2026
<a href="https://news.ycombinator.com/item?id=49375000">https://news.ycombinator.com/item?id=49375000 (citations)
astura · · focus · HN ↗
toomuchtodo · · focus · HN ↗