Hackers dump Flock ALPR camera firmware, exposing hardcoded creds and video capture
A hacker collective tore down a Flock traffic camera, copied its storage, and gave the data to journalists and DDoSecrets — revealing ancient software, hardcoded credentials, and that the devices photograph people as well as license plates.
What to know
- Leaked firmware shows Flock cameras capture and store video of people, not just license plates, contradicting company claims cited to lawmakers.
- The hacked camera ran Android 8.1 with an eight-year-old patch level and a nine-year-old Linux kernel, plus a hardcoded API key and plaintext credentials shared across Flock's own apps.
- Follow-up reporting says hackers extracted an encryption key and over 27,000 clips despite Flock's denials that such keys were stored on the device.
- Flock cameras are widely deployed by U.S. police departments, so the flaws raise mass-surveillance and security concerns beyond this single unit.
The dispute Some commenters ask why Flock specifically bears the brunt of criticism when competing ALPR makers deploy similar surveillance tech without comparable scrutiny. · positions read across 92 posts and comments
Flock's security engineering is negligent and amateurish, not a sophisticated hack.
-
“This is pure laziness aka "reduced time to market" on the part of Flock.”
killbot5000 · Hacker News ↗
The leak proves the cameras record video and identify people, contradicting official assurances they only read plates.
-
“The flip side of this laziness is that now, when my elected representatives tell me "these are just license-plate readers that don't record video", I have evidence to show them that's false.”
teraflop · Hacker News ↗
This reflects a deeper government-corporate push toward mass surveillance, not just one company's bug.
-
“Move fast and break things* * Privacy, civic trust, society if you get a chance!”
coldbrewed · Hacker News ↗
It's unclear why Flock alone draws this scrutiny when rival ALPR vendors run comparable systems.
-
“Motorola/Vigilant, Rekor, Leonardo/ELSAG, and Axon are huge companies making mint off the same thing and no once in 20 years have I seen this level of attention... not on the overarching issue of surveillance-state-ing, but of one…”
inanutshellus · Hacker News ↗
“We liberated hardware in the field, disarmed them, and proceeded with reverse engineering of the cameras and associated solar equipment.”
stegan0gram, hacker collective · 404 Media / WIRED, via micahflee.com ↗ · Sep 15
stegan0gram Hacker collectiveMicah Flee Independent security researcherFlock Safety Manufacturer of the ALPR camera404 Media / WIRED Journalists who broke the joint investigationDDoSecrets Data leak publisher
How it unfolded 6 developments, newest first · click a bar or a number to jump articlespostscomments
-
6
Outlets detail 27,321 extracted clips despite Flock's denials
Tom's Hardware and Techspot reported that stegan0gram used an on-device encryption key to extract more than 27,000 video clips and 1.6 million images, contradicting Flock's denials that such keys were stored on the hardware.
-
3 outlets first by Tom's Hardware, 7d ago · also TechRepublic, Schneier · read ↗
-
D
the flock camera data dump is a shower of comedy gold https:// micahflee.com/flock-cameras-ar e-riddled-with-security-vulnerabilities-and-hard-coded-credentials/
2 more of the top 3 · 25 posts in this stretch
-
I would be very curious to know if this invalidates their use in court, since the chain of custody is now hypothetically compromised. Then again, I hope that I, personally, never have to find out
-
if this data is public information, then why does it need encrypted secrecy, paywalls, or any kind of gatekeeping?if the information does need to be protected from the public, then it must be private data and flock is an illegal system
-
-
5
Ars Technica confirms cameras detect people, not just cars
Follow-up reporting corroborated that the hacked camera's software identifies pedestrians in addition to vehicles, broadening the scope of what Flock's system is shown to capture.
-
first by New Republic, 7d ago · also Wired, Beehaw, Straight Arrow
3 more headlines
- Hackers Got Inside a Flock Camera. Its Data Shows How the System Really Works Wired · 7d ago
- Hackers stole a Flock camera. Here's what they found inside Straight Arrow · 7d ago
- Hacked Data Shows What Flock Cameras Really Record—and It's Terrifying New Republic · 7d ago
-
first by Mastodon, 6d ago
-
C
RE: https:// infosec.exchange/@micahflee/11 7282688510612709 *Jabba the Hut laugh* ho ho ho ho Flock API key = НаJ3FgupAm8RrDJW3МНgT9X7Ft27eVaD https:// ddosecrets.org/article/flock-a lpr-camera
2 more of the top 3 · 10 posts in this stretch
-
Code is often commented in a way that naturally tells the developer what it's doing. Many devs prefer clear and concise comments to document their work, their comments are quite literal: 'This creates thus and such structure' 'this passes a variable from that structure.' 'this destroys that structure after variable has been passed'. Other coders…
-
> Oh, if the vuln about configuration and hardening "preferences" like SSL/TSL - Sorry, not interested.> And also, infrastructure vulnerabilities like DNS config - no no, try harder.It's understandable. If you have or manage a website you will receive daily emails (the kind that start with 'Hello sir') about automated scans finding low-hanging…
-
-
4
Researcher finds hardcoded credentials and ancient software stack
Independent security researcher Micah Flee's teardown of the leaked firmware found the camera running Android 8.1 with an eight-year-old patch level and a nine-year-old Linux kernel, plus a hardcoded API key and plaintext Auth0 credentials shared across Flock's apps.
“This camera is missing Android security updates for the last eight years.”
— Micah Flee -
first by Mastodon, 7d ago · also HN Frontpage, micahflee
1 more headline
- Flock cameras are riddled with security vulnerabilities and hardcoded creds HN Frontpage · 7d ago
-
S
I’m posting this again , specifically so I can say: LOL . LMFAO . # privacy # flock # infosec https:// micahflee.com/flock-cameras-ar e-riddled-with-security-vulnerabilities-and-hard-coded-credentials/
2 more of the top 3 · 21 posts in this stretch
-
Tyranny of government invites terrorism from its constituents.We have all heard the argument that when corporations intentionally make the legal option worse it drives otherwise law abiding customers to pirate the content instead because piracy provides a better service than paying the corporation for their kneecapped product.I dont see how the…
-
C
Amazing analysis of the flock firmware by @ micahflee https:// micahflee.com/flock-cameras-ar e-riddled-with-security-vulnerabilities-and-hard-coded-credentials/
-
-
3
Commenters say leak disproves Flock's 'no video' claims
On Hacker News, commenters argued the dump undercuts official assurances that Flock systems only read license plates without recording video, and criticized the company's vulnerability disclosure policy and overall security posture.
“The flip side of this laziness is that now, when my elected representatives tell me "these are just license-plate readers that don't record video", I have evidence to show them that's false.”
— teraflop -
A
👀 "...Hackers ripped down a Flock camera above a roadway, made a near-complete copy of the data stored inside it, and shared the files with 404 Media and WIRED, revealing in new detail how exactly Flock Safety’s cameras track the movements of both vehicles and people. The hackers say they are also publishing details on how they managed to obtain…
2 more of the top 3 · 22 posts in this stretch
-
Yep. Clown show.> The hackers said they were able to access the Android system on the camera, and found two partitions—sections of its hard-drive, essentially. A few of these were unencrypted, the hackers said, including one called “vendor” and another called “media.” The latter contained an encryption key that unlocked another part, which…
-
L
BREAKING: Hackers dump Flock camera code (Android!) and successfully decrypt
-
-
2
Leaked logs show camera imaged 50,000 vehicles in 21 days
Analysis of the extracted logs found the device photographed roughly 50,200 vehicles and generated about 1.6 million images over 21 days, and that it could also detect pedestrians, not just plates.
-
D
Flock ALPR camera (28.55 GB) Filesystem images of the partitions on an in-use Flock ALPR camera, including custom Android APK files installed on the device, as well as its recorded media. The data reveals how the devices track both vehicles and people, and demonstrates the fundamental security problem with privacy invading devices like those…
2 more of the top 3 · 10 posts in this stretch
-
This reporting was done in collaboration with 404media. Here's the discussion for 404's article: https://news.ycombinator.com/item?id=49726577Distributed Denial of Secrets has published the partition images:
-
NEW: Hackers cut down a Flock camera, dumped its internal storage, and shared the files. It includes thousands of videos and logs showing how the device took images of 50,000 vehicles in days It reveals in new detail how Flock tracks vehicles and people.
-
-
1
Hackers publish stolen data from a Flock traffic camera
The hacker collective stegan0gram removed a Flock ALPR camera from above a roadway, made a near-complete copy of its stored data, and shared the files with 404 Media and WIRED; DDoSecrets published the filesystem partition images the same morning.
“Why just destroy [Flock cameras] when we can reverse engineer them and find the secrets of those spying on us?”
— stegan0gram -
4 outlets Flock ALPR camera
first by Distributed Denial of Secrets Recently …, 8d ago · also 404 Media, HN Best, HN Frontpage
3 more headlines
- Hacker collective stegan0gram dismantles a Flock camera, recovering an encryption key and showing it runs ~20 apps on a midrange smartphone-grade processor 404 Media · 8d ago
- Hackers Got Inside a Flock Camera HN Best · 8d ago
- Hackers Got Inside a Flock Camera. Its Data Shows How the System Works HN Frontpage · 8d ago
-
first by NewsMax.com, 7d ago · also 404 Media
1 more headline
-
4
NEW: Hackers ripped down a Flock camera above a roadway, made a near-complete copy of the data stored inside it, and shared the files with 404 Media and @wired.com, revealing in new detail how exactly Flock Safety’s cameras track the movements of both vehicles and people.
2 more of the top 3 · 4 posts in this stretch
-
C
Surveillance society https://www. wired.com/story/hackers-flock- camera-data-shows-how-system-works/
-
What, i say trump isn't a nazi and you think I'm a bot? Just read some history, I think trump is awful, but it is just a lazy comparison
-
What people are saying 11 voices from 4 sites · best of 92 · verbatim
- Which state was this specific camera deployed in, given some states' strict data-retention limits for non-hit plates?
- Are the leaked Auth0 credentials still live and usable to authenticate as other cameras?
- Sep 18
-
Is anybody else also as irritated as me by the 'Flock' brand name? It sounds very condescending, not like a security system for citizens, but one to manage lifestock. Or is this my non-native English striking again and a perfectly normal term in this context? I sure expect someone will make use of the information provided with these leaks, maybe…
-
Benn Jordan posited this line of argument in his videos finding a similar number of severe security flaws in these surveillance devices, including R/W access to the video archive I believe. *Personally*, I think it's a good argument, but I'm not sure how it would hold up in court. I'm not sure if there's any prior cases that demonstrate if secure…
-
[Crt.sh](https://crt.sh/?q=%25.flocksafety.com) also lists a lot of services for them. I wonder how many of those accept the same credentials.
-
that's amazing. these things suck. That is some vintage android. Kind of fun that with software that old, you just have your pick of exploits, like from a catalogue. Do these cameras get OTA updates? Because if not, and they use those hardcoded API creds, and now the whole world has them...
- Sep 17
-
to have that much data means each camera got at least 1 terrabyte drive on it. Next time you cut one down fish out those drives, good money. Don't tell your local homeless about it
-
Except the sales pitch demo isn't "you can access this camera any time to monitor" it's "we can" with the "we" being thousands of employees, police and any malicious actors who've gained access without us knowing.
-
“404 Media also revealed that a cop in Texas searched Flock cameras nationwide for a woman who self-administered an abortion.” Well that’s some evil christofascist abuse of power shit right there.
- Sep 16
-
Having hardcoded credentials is a sign of total incompetence. In this case at least it wasn't a password, but an API key which can be used to request credentials (stored in plaintext) which look like they'd get you access Flock's servers. Not quite as bad as a hardcoded admin password, and it's not clear what you'd be able to do if you did…
-
If you want to know what a "Vulnerability Disclosure Policy" (VDP) would look like if its main purpose is to claim we have VDP and create an appearance of responsible security posture, but not really to learn about vulnerabilities - read Flock's VDP.They sincerely welcome your vulnerability disclosures, except in cases where you have to "interact"…
-
This is pure laziness aka “reduced time to market” on the part of Flock.It takes time and effort to think through proper secure boot architecture and to implement key management in a way that doesn’t kill developer productivity.Their product managers, though, should have realized that setting these up in unsecured public spaces means that their…
-
NEW: When @dmehro.bsky.social at @wired.com and @josephcox.bsky.social at @404media.co both got handed the full contents of a Flock camera, we worked together to figure out what it revealed. (WIRED's below, 404's version here: