‹ BackHN Continuity

Thread

Hackers Got Inside a Flock Camera

586 points · 270 comments · driverdan

  1. killbot5000 · · focus · HN ↗
    This is pure laziness aka “reduced time to market” on the part of Flock.

    It takes time and effort to think through proper secure boot architecture and to implement key management in a way that doesn’t kill developer productivity.

    Their product managers, though, should have realized that setting these up in unsecured public spaces means that their threat model really does include local physical access to everything.

    Using off the shelf hardware and software stacks all but guarantees attackers have tools at their fingertips to exploit said physical access.

    Given all the recent exploits hitting the kernel, there’s a good chance that there exists an exploitable over-the-air vulnerability present in their WiFi/bluetooth stack, too.

    1. krinchan · · focus · HN ↗
      My problem is that Claude kept screaming across several sessions that it echo'ed a default password for a local, ephemeral development container into a session across SEVERAL sessions.

      I get dinged continually for a vendor supplied container that writes an appropriately scoped access key to disk in plain text on startup (we are working to eliminate it but it requires migrating to an entirely new way of doing things the vendor only released earlier this year and I got derailed by other priorities).

      So like if established enterprises using off the shelf scanning software are breathing down my back about this...what the actual hell is happening inside flock that this was fine. Lol.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.