Researcher finds hardcoded credentials and ancient software stack
4 Sep 16 4:48 PM · 7d ago · 2 articles · 22 posts · 9 comments · 4 sources · development 4 of 6
Independent security researcher Micah Flee's teardown of the leaked firmware found the camera running Android 8.1 with an eight-year-old patch level and a nine-year-old Linux kernel, plus a hardcoded API key and plaintext Auth0 credentials shared across Flock's apps.
“This camera is missing Android security updates for the last eight years.”
Micah Fleestegan0gram Hacker collectiveMicah Flee Independent security researcherFlock Safety Manufacturer of the ALPR camera404 Media / WIRED Journalists who broke the joint investigationDDoSecrets Data leak publisher
The whole story articlespostscomments the bright band is this development · numbered dots are the others · click one to jump
What was reported 1 claim about this development
-
first by Mastodon, 7d ago · also HN Frontpage, micahflee
1 more headline
- Flock cameras are riddled with security vulnerabilities and hardcoded creds HN Frontpage · 7d ago
What people said 21 voices · verbatim
-
S
I’m posting this again , specifically so I can say: LOL . LMFAO . # privacy # flock # infosec https:// micahflee.com/flock-cameras-ar e-riddled-with-security-vulnerabilities-and-hard-coded-credentials/
-
Tyranny of government invites terrorism from its constituents.We have all heard the argument that when corporations intentionally make the legal option worse it drives otherwise law abiding customers to pirate the content instead because piracy provides a better service than paying the corporation for their kneecapped product.I dont see how the…
-
C
Amazing analysis of the flock firmware by @ micahflee https:// micahflee.com/flock-cameras-ar e-riddled-with-security-vulnerabilities-and-hard-coded-credentials/
-
Having hardcoded credentials is a sign of total incompetence. In this case at least it wasn't a password, but an API key which can be used to request credentials (stored in plaintext) which look like they'd get you access Flock's servers. Not quite as bad as a hardcoded admin password, and it's not clear what you'd be able to do if you did…
-
N
Oh, Flock cameras, you magnificent mess! 🎥🔓 Who knew that your idea of "security" involved hardcoded passwords and a welcome mat for hackers? It's like leaving the keys under the doormat and being shocked when someone lets themselves in! 🤦♂️🔐 https:// micahflee.com/flock-cameras-ar…
-
Move fast and break things** Privacy, civic trust, society if you get a chance!This is the end product of tech leadership taking fat rips of disruption cocaine for the last 15 years. Flock Safety got VC money so that they could build a panopticon. There is nothing surprising about the fact that they did a hack job with terrible security; the fact…
-
R
"Hackers ripped down a Flock camera above a roadway, made a near-complete copy of the data stored inside it, and shared the files with 404 Media and WIRED, revealing in new detail how exactly Flock Safety’s cameras track the movements of both vehicles and people. The hackers say they are also publishing details on how they managed to obtain the…
-
This looks like a pretty reasonable policy to me all things considered. And no, I'm no fan of Flock. But they do run security cameras for the cops, they can't just say go ahead, go wild on all our customers' cameras. The lawyers would throw a fit.The carveouts for stuff like configuration and DNS are entirely reasonable. Have you ever been behind…
-
R
"Flock cameras run on a modified version of Android. The specific build that this Flock camera was running at the point in time the firmware was extracted was from June 5, 2025. Despite being a relatively recent build, the Flock camera was running Android 8.1. This version of Android was released in 2017, and officially stopped getting support…
-
The TLS/SSL and DNS carveouts are pretty normal. There are a million security options for those services and enabling them all would often mean denying access to anyone running a browser/client more than a few weeks old. Documenting them all would be a PITA so most policies simply prohibit them entirely.Testing against customers is also a common…
-
A
In more relevant Hot Shit news came out today, Flock surveillance cameras have been hacked and their full capabilities analyzed. Hoo boy is it bad. Top takeaways - the software is past end-of-life Linux kernel running past end-of-life Android, so a shit-ton of easy to use documented exploits work on them. - BONUS! Hard-coded credentials. - Bigtime…
-
It'd be interesting to know how much of that they put second to "Americans seem to like using our hardware as targets for firearms, reciprocating saws, spray paint, and garbage bags" in their list of corporate concerns.
-
I
Alcuni hacker sono riusciti a penetrare in una telecamera di sorveglianza Flock. I dati raccolti mostrano come funziona realmente il sistema. Un collettivo di hacker ha smantellato una telecamera Flock e ne ha scaricato i dati. I file includevano migliaia di video e registri che mostravano come il dispositivo avesse catturato 1,6 milioni di…
-
>> Flock insists its cameras do not perform face recognition.Probably technically true. But since the cameras detect people that makes it easier for their backend system to do face recognition.
-
A
I suspect that someone with sufficient skills, knowledge, inclination, (and residency in a country that doesn't have an extradition treaty with the US) could find a way to brick every single Flock camera in the country. https:// micahflee.com/flock-cameras-ar e-riddled-with-security-vulnerabilities-and-hard-coded-credentials/
-
This is SOP for IOT devices. I am beginning to think we need to regulate this stuff, because it is ubiquitous. The device manufacturers do not have a culture of security.
-
H
# flock https:// wpde.com/news/nation-world/hac kers-breach-flock-camera-data-share-findings-with-media-surveillance-system-vehicle Hackers breach Flock camera data, share findings with media https:// wpde.com/news/nation-world/hac kers-breach-flock-camera-data-share-findings-with-media-surveillance-system-vehicle
-
I too am appalled by the inefficiencies of the bureaucracy of the Gestapo. A serious threat to the state and the people could take days to reach the correct authorities.
-
On one hand: the neo-Confederate Eyes of Sauron might be trivial to shut down remotely. On the other hand: this also means they might be trivial to access by any attacker. Even more of a reason to shut them down and fast, I say. micahflee.com/flock-cameras-ar… # Flock
-
M
PSA: "Encrypted" means very little if your key management is bad. # infosec https://www. wired.com/story/hackers-flock- camera-data-shows-how-system-works/
-
P
https://www. 404media.co/hackers-stole-floc ks-camera-software-revealing-how-the-company-tracks-cars-and-people-2/
All 6 developments of Hackers dump Flock ALPR camera firmware, exposing hardcoded… →
NewswiresMastodonRedditBlueskyHacker NewsXLobsters