‹ BackHN Continuity

Thread

Flock cameras are riddled with security vulnerabilities and hardcoded creds

35 points · 4 comments · micahflee

Loading the complete thread in the background. This saved snapshot is available now. Refresh

  1. zeech · · focus · HN ↗
    Discussion about the article this post is talking about: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49726586">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49726586
    1. dang · · focus · HN ↗
      Comments moved thither. Thanks!

      I&#x27;ve added <a href="https:&#x2F;&#x2F;micahflee.com&#x2F;flock-cameras-are-riddled-with-security-vulnerabilities-and-hard-coded-credentials&#x2F;" rel="nofollow">https:&#x2F;&#x2F;micahflee.com&#x2F;flock-cameras-are-riddled-with-securit... to the toptext there.

      1. FlockIsYC · · focus · HN ↗

        [dead]

  2. NuclearPM · · focus · HN ↗
    1984 but stupid-mode.
    1. toomuchtodo · · focus · HN ↗
      We should be so lucky these people are so incompetent.
  3. coldbrewed · · focus · HN ↗
    Move fast and break things*

    * Privacy, civic trust, society if you get a chance!

    This is the end product of tech leadership taking fat rips of disruption cocaine for the last 15 years. Flock Safety got VC money so that they could build a panopticon. There is nothing surprising about the fact that they did a hack job with terrible security; the fact that their service names are various types of alcohol is beyond parity.

    Oh well, at least Flock Safety&#x27;s IPO will be a critical cash infusion in the pursuit of building the torture nexus so that&#x27;s cool.

  4. asveikau · · focus · HN ↗
    tldr from my skim, the two worst things:

    * Probably vulnerable to CVEs that were patched in 2018 and 2021.

    * Generates API key to phone home based only on its own MAC address.

  5. autoexec · · focus · HN ↗
    Having hardcoded credentials is a sign of total incompetence. In this case at least it wasn&#x27;t a password, but an API key which can be used to request credentials (stored in plaintext) which look like they&#x27;d get you access Flock&#x27;s servers. Not quite as bad as a hardcoded admin password, and it&#x27;s not clear what you&#x27;d be able to do if you did authenticate successfully as a camera, but its worrying enough. There have been enough vulnerabilities found in Flock&#x27;s systems that it&#x27;s pretty clear they aren&#x27;t concerned about security and it&#x27;s plainly obvious that they don&#x27;t care at all about our privacy.

    Even if we decided that this level of mass surveillance on the American public was acceptable to us, Flock Safety&#x2F;Flock Group as already demonstrated that they can&#x27;t and shouldn&#x27;t be trusted to implement it.

    1. asveikau · · focus · HN ↗
      I don&#x27;t think having credentials stored on the device is all that fatal. The device has to read them back, after all. What they did, however, is much worse: the credentials come from the MAC address. So they&#x27;re literally broadcasted on every network packet.
      1. throwaway89201 · · focus · HN ↗
        The device runs Android, which makes it very simple to use the Keystore system and to store a device specific private key within the TEE or SE where it can&#x27;t be very easily extracted. If you really don&#x27;t want to provision in the factory, you could use secure boot measurements to do it remotely. Of course this isn&#x27;t completely watertight either against a physical attacker, but it would survive a filesystem dump attack and is the least you can do to appear competent.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.