conv.

All stories
SecurityQuiet 2d · day 8

Hackers dump Flock ALPR camera firmware, exposing hardcoded creds and video capture

A hacker collective tore down a Flock traffic camera, copied its storage, and gave the data to journalists and DDoSecrets — revealing ancient software, hardcoded credentials, and that the devices photograph people as well as license plates.

What to know

  • Leaked firmware shows Flock cameras capture and store video of people, not just license plates, contradicting company claims cited to lawmakers.
  • The hacked camera ran Android 8.1 with an eight-year-old patch level and a nine-year-old Linux kernel, plus a hardcoded API key and plaintext credentials shared across Flock's own apps.
  • Follow-up reporting says hackers extracted an encryption key and over 27,000 clips despite Flock's denials that such keys were stored on the device.
  • Flock cameras are widely deployed by U.S. police departments, so the flaws raise mass-surveillance and security concerns beyond this single unit.

The dispute Some commenters ask why Flock specifically bears the brunt of criticism when competing ALPR makers deploy similar surveillance tech without comparable scrutiny. · positions read across 92 posts and comments

most voices

Flock's security engineering is negligent and amateurish, not a sophisticated hack.

  • “This is pure laziness aka "reduced time to market" on the part of Flock.”

    killbot5000 · Hacker News ↗
many voices

The leak proves the cameras record video and identify people, contradicting official assurances they only read plates.

  • “The flip side of this laziness is that now, when my elected representatives tell me "these are just license-plate readers that don't record video", I have evidence to show them that's false.”

    teraflop · Hacker News ↗
some voices

This reflects a deeper government-corporate push toward mass surveillance, not just one company's bug.

  • “Move fast and break things* * Privacy, civic trust, society if you get a chance!”

    coldbrewed · Hacker News ↗
some voices

It's unclear why Flock alone draws this scrutiny when rival ALPR vendors run comparable systems.

  • “Motorola/Vigilant, Rekor, Leonardo/ELSAG, and Axon are huge companies making mint off the same thing and no once in 20 years have I seen this level of attention... not on the overarching issue of surveillance-state-ing, but of one…”

    inanutshellus · Hacker News ↗

“We liberated hardware in the field, disarmed them, and proceeded with reverse engineering of the cameras and associated solar equipment.”

stegan0gram, hacker collective · 404 Media / WIRED, via micahflee.com ↗ · Sep 15

stegan0gram Hacker collectiveMicah Flee Independent security researcherFlock Safety Manufacturer of the ALPR camera404 Media / WIRED Journalists who broke the joint investigationDDoSecrets Data leak publisher

Hackers dump Flock ALPR camera firmware, exposing hardcoded creds and video capture
404media.co

How it unfolded 6 developments, newest first · click a bar or a number to jump articlespostscomments

Peak 25 pieces in two hours at Sep 16, 7 AM; 162 pieces over 8 days (34 articles · 78 posts · 50 comments) Sep 16, 5 AM — 13 pieces · 4 articles · 7 posts · 2 comments — Mastodon 7, Reddit 3, Newswires 2, +1 moreSep 16, 7 AM — 25 pieces · 11 articles · 12 posts · 2 comments — Newswires 11, Mastodon 7, Hacker News 4, +2 moreSep 16, 9 AM — 16 pieces · 1 article · 6 posts · 9 comments — Hacker News 9, Mastodon 6, Newswires 1Sep 16, 11 AM — 21 pieces · 9 articles · 3 posts · 9 comments — Hacker News 9, Newswires 9, Mastodon 3Sep 16, 1 PM — 10 pieces · 1 article · 5 posts · 4 comments — Hacker News 4, Mastodon 3, Reddit 2, +1 moreSep 16, 3 PM — 4 pieces · 1 article · 2 posts · 1 comment — Mastodon 3, Hacker News 1Sep 16, 5 PM — 10 pieces · 1 article · 6 posts · 3 comments — Mastodon 5, Hacker News 4, Newswires 1Sep 16, 7 PM — 5 pieces · 5 posts — Mastodon 5Sep 16, 9 PM — 5 pieces · 3 posts · 2 comments — Mastodon 2, Hacker News 2, Reddit 1Sep 16, 11 PM — 3 pieces · 2 posts · 1 comment — Mastodon 2, Reddit 1Sep 17, 1 AM — 4 pieces · 1 post · 3 comments — Hacker News 3, Mastodon 1Sep 17, 3 AM — 8 pieces · 2 articles · 5 posts · 1 comment — Mastodon 6, Reddit 1, Newswires 1Sep 17, 5 AM — 6 pieces · 1 article · 4 posts · 1 comment — Mastodon 4, Reddit 1, Newswires 1Sep 17, 7 AM — 1 piece · 1 post — Bluesky 1Sep 17, 9 AM — 1 piece · 1 post — Reddit 1Sep 17, 11 AM — 3 pieces · 1 post · 2 comments — Reddit 2, Mastodon 1Sep 17, 1 PM — 5 pieces · 1 article · 3 posts · 1 comment — Bluesky 2, Mastodon 1, Reddit 1, +1 moreSep 17, 3 PM — 1 piece · 1 post — Lobsters 1Sep 17, 5 PM — quietSep 17, 7 PM — quietSep 17, 9 PM — 1 piece · 1 comment — Lobsters 1Sep 17, 11 PM — 1 piece · 1 comment — Lobsters 1Sep 18, 1 AM — 4 pieces · 3 posts · 1 comment — Mastodon 2, Bluesky 1, Lobsters 1Sep 18, 3 AM — quietSep 18, 5 AM — quietSep 18, 7 AM — 1 piece · 1 comment — Lobsters 1Sep 18, 9 AM — quietSep 18, 11 AM — quietSep 18, 1 PM — 2 pieces · 1 post · 1 comment — Bluesky 1, Lobsters 1Sep 18, 3 PM — 2 pieces · 1 article · 1 comment — Lobsters 1, Newswires 1Sep 18, 5 PM — 2 pieces · 2 comments — Lobsters 2Sep 18, 7 PM — quietSep 18, 9 PM — quietSep 18, 11 PM — quietSep 19, 1 AM — quietSep 19, 3 AM — quietSep 19, 5 AM — quietSep 19, 7 AM — quietSep 19, 9 AM — 1 piece · 1 comment — Lobsters 1Sep 19, 11 AM — quietSep 19, 1 PM — quietSep 19, 3 PM — quietSep 19, 5 PM — quietSep 19, 7 PM — quietSep 19, 9 PM — quietSep 19, 11 PM — quietSep 20, 1 AM — quietSep 20, 3 AM — quietSep 20, 5 AM — quietSep 20, 7 AM — quietSep 20, 9 AM — quietSep 20, 11 AM — 1 piece · 1 post — Mastodon 1Sep 20, 1 PM — quietSep 20, 3 PM — quietSep 20, 5 PM — quietSep 20, 7 PM — quietSep 20, 9 PM — quietSep 20, 11 PM — quietSep 21, 1 AM — quietSep 21, 3 AM — quietSep 21, 5 AM — quietSep 21, 7 AM — quietSep 21, 9 AM — 1 piece · 1 article — Newswires 1Sep 21, 11 AM — quietSep 21, 1 PM — 2 pieces · 2 posts — Mastodon 2Sep 21, 3 PM — 1 piece · 1 post — Mastodon 1Sep 21, 5 PM — quietSep 21, 7 PM — quietSep 21, 9 PM — quietSep 21, 11 PM — quietSep 22, 1 AM — 1 piece · 1 post — Mastodon 1Sep 22, 3 AM — quietSep 22, 5 AM — quietSep 22, 7 AM — 1 piece · 1 post — Mastodon 1Sep 22, 9 AM — quietSep 22, 11 AM — quietSep 22, 1 PM — quietSep 22, 3 PM — quietSep 22, 5 PM — quietSep 22, 7 PM — quietSep 22, 9 PM — quietSep 22, 11 PM — quietYesterday, 1 AM — quietYesterday, 3 AM — quietYesterday, 5 AM — quietYesterday, 7 AM — quietYesterday, 9 AM — quietYesterday, 11 AM — quietYesterday, 1 PM — quietYesterday, 3 PM — quietYesterday, 5 PM — quietYesterday, 7 PM — quietYesterday, 9 PM — quietYesterday, 11 PM — quietToday, 1 AM — quietToday, 3 AM — quietToday, 5 AM — quietToday, 7 AM — quietToday, 9 AM — quiet 1–345–6
Sep 17Sep 18Sep 19Sep 20Sep 21Sep 22yesterdaynow · 11:54 AM ET
  1. 6

    Outlets detail 27,321 extracted clips despite Flock's denials

    Tom's Hardware and Techspot reported that stegan0gram used an on-device encryption key to extract more than 27,000 video clips and 1.6 million images, contradicting Flock's denials that such keys were stored on the hardware.

    1. 3 outlets first by Tom's Hardware, 7d ago · also TechRepublic, Schneier · read ↗

    • davidgerard@circumstances.run

      the flock camera data dump is a shower of comedy gold https:// micahflee.com/flock-cameras-ar e-riddled-with-security-vulnerabilities-and-hard-coded-credentials/

      davidgerard@circumstances.runMastodon7d ago227▲view on Mastodon ↗
    2 more of the top 3 · 25 posts in this stretch
    • I would be very curious to know if this invalidates their use in court, since the chain of custody is now hypothetically compromised. Then again, I hope that I, personally, never have to find out

      mdanielreversing,security6d ago29▲view on Lobsters ↗
    • if this data is public information, then why does it need encrypted secrecy, paywalls, or any kind of gatekeeping?if the information does need to be protected from the public, then it must be private data and flock is an illegal system

      br0cephHacker News6d agoview on Hacker News ↗
    all of them →
  2. 5

    Ars Technica confirms cameras detect people, not just cars

    Follow-up reporting corroborated that the hacked camera's software identifies pedestrians in addition to vehicles, broadening the scope of what Flock's system is shown to capture.

    1. first by New Republic, 8d ago · also Wired, Beehaw, Straight Arrow

      3 more headlines
    2. first by Mastodon, 6d ago

    1 more claim →
    • catsalad@infosec.exchange

      RE: https:// infosec.exchange/@micahflee/11 7282688510612709 *Jabba the Hut laugh* ho ho ho ho Flock API key = НаJ3FgupAm8RrDJW3МНgT9X7Ft27eVaD https:// ddosecrets.org/article/flock-a lpr-camera

      catsalad@infosec.exchangeMastodon7d ago105▲view on Mastodon ↗
    2 more of the top 3 · 10 posts in this stretch
    • Code is often commented in a way that naturally tells the developer what it's doing. Many devs prefer clear and concise comments to document their work, their comments are quite literal: 'This creates thus and such structure' 'this passes a variable from that structure.' 'this destroys that structure after variable has been passed'. Other coders…

      DiamondHandsToUranusr/technology7d agoview on r/technology ↗
    • > Oh, if the vuln about configuration and hardening "preferences" like SSL/TSL - Sorry, not interested.> And also, infrastructure vulnerabilities like DNS config - no no, try harder.It's understandable. If you have or manage a website you will receive daily emails (the kind that start with 'Hello sir') about automated scans finding low-hanging…

      scouttHacker News7d agoview on Hacker News ↗
    all of them →
  3. 4

    Researcher finds hardcoded credentials and ancient software stack

    Independent security researcher Micah Flee's teardown of the leaked firmware found the camera running Android 8.1 with an eight-year-old patch level and a nine-year-old Linux kernel, plus a hardcoded API key and plaintext Auth0 credentials shared across Flock's apps.

    “This camera is missing Android security updates for the last eight years.”
    — Micah Flee
    1. first by Mastodon, 7d ago · also HN Frontpage, micahflee

      1 more headline
    • scottwilson@infosec.exchange

      I’m posting this again , specifically so I can say: LOL . LMFAO . # privacy # flock # infosec https:// micahflee.com/flock-cameras-ar e-riddled-with-security-vulnerabilities-and-hard-coded-credentials/

      scottwilson@infosec.exchangeMastodon7d ago43▲view on Mastodon ↗
    2 more of the top 3 · 21 posts in this stretch
    • Tyranny of government invites terrorism from its constituents.We have all heard the argument that when corporations intentionally make the legal option worse it drives otherwise law abiding customers to pirate the content instead because piracy provides a better service than paying the corporation for their kneecapped product.I dont see how the…

      imthatsteveHacker News7d agoview on Hacker News ↗
    • cooperq@masto.hackers.town

      Amazing analysis of the flock firmware by @ micahflee https:// micahflee.com/flock-cameras-ar e-riddled-with-security-vulnerabilities-and-hard-coded-credentials/

      cooperq@masto.hackers.townMastodon7d ago22▲view on Mastodon ↗
    all of them →
  4. 3

    Commenters say leak disproves Flock's 'no video' claims

    On Hacker News, commenters argued the dump undercuts official assurances that Flock systems only read license plates without recording video, and criticized the company's vulnerability disclosure policy and overall security posture.

    “The flip side of this laziness is that now, when my elected representatives tell me "these are just license-plate readers that don't record video", I have evidence to show them that's false.”
    — teraflop
    • ai6yr@m.ai6yr.org

      👀 "...Hackers ripped down a Flock camera above a roadway, made a near-complete copy of the data stored inside it, and shared the files with 404 Media and WIRED, revealing in new detail how exactly Flock Safety’s cameras track the movements of both vehicles and people. The hackers say they are also publishing details on how they managed to obtain…

      ai6yr@m.ai6yr.orgMastodon8d ago81▲view on Mastodon ↗
    2 more of the top 3 · 22 posts in this stretch
    • Yep. Clown show.> The hackers said they were able to access the Android system on the camera, and found two partitions—sections of its hard-drive, essentially. A few of these were unencrypted, the hackers said, including one called “vendor” and another called “media.” The latter contained an encryption key that unlocked another part, which…

      glaslongHacker News8d agoview on Hacker News ↗
    • lauren@mastodon.laurenweinstein.org

      BREAKING: Hackers dump Flock camera code (Android!) and successfully decrypt

      lauren@mastodon.laurenweinstein.orgMastodon8d ago25▲view on Mastodon ↗
    all of them →
  5. 2

    Leaked logs show camera imaged 50,000 vehicles in 21 days

    Analysis of the extracted logs found the device photographed roughly 50,200 vehicles and generated about 1.6 million images over 21 days, and that it could also detect pedestrians, not just plates.

    • ddosecrets@kolektiva.social

      Flock ALPR camera (28.55 GB) Filesystem images of the partitions on an in-use Flock ALPR camera, including custom Android APK files installed on the device, as well as its recorded media. The data reveals how the devices track both vehicles and people, and demonstrates the fundamental security problem with privacy invading devices like those…

      ddosecrets@kolektiva.socialMastodon8d ago309▲view on Mastodon ↗
    2 more of the top 3 · 10 posts in this stretch
    • This reporting was done in collaboration with 404media. Here's the discussion for 404's article: https://news.ycombinator.com/item?id=49726577Distributed Denial of Secrets has published the partition images:

      driverdanHacker News8d agoview on Hacker News ↗
    • NEW: Hackers cut down a Flock camera, dumped its internal storage, and shared the files. It includes thousands of videos and logs showing how the device took images of 50,000 vehicles in days It reveals in new detail how Flock tracks vehicles and people.

      @dmehroX8d agoview on X ↗
    all of them →
  6. 1

    Hackers publish stolen data from a Flock traffic camera

    The hacker collective stegan0gram removed a Flock ALPR camera from above a roadway, made a near-complete copy of its stored data, and shared the files with 404 Media and WIRED; DDoSecrets published the filesystem partition images the same morning.

    “Why just destroy [Flock cameras] when we can reverse engineer them and find the secrets of those spying on us?”
    — stegan0gram
    1. 4 outlets Flock ALPR camera

      first by Distributed Denial of Secrets Recently …, 8d ago · also 404 Media, HN Best, HN Frontpage

      3 more headlines
    2. first by NewsMax.com, 7d ago · also 404 Media

      1 more headline
    2 more claims →
    • 404media.co

      NEW: Hackers ripped down a Flock camera above a roadway, made a near-complete copy of the data stored inside it, and shared the files with 404 Media and @wired.com, revealing in new detail how exactly Flock Safety’s cameras track the movements of both vehicles and people.

      404media.coBluesky8d ago7.7k▲view on Bluesky ↗
    2 more of the top 3 · 4 posts in this stretch
    • cigitalgem@sigmoid.social

      Surveillance society https://www. wired.com/story/hackers-flock- camera-data-shows-how-system-works/

      cigitalgem@sigmoid.socialMastodon8d ago1▲view on Mastodon ↗
    • What, i say trump isn't a nazi and you think I'm a bot? Just read some history, I think trump is awful, but it is just a lazy comparison

      mighthaveabitlaterr/technology8d agoview on r/technology ↗
    all of them →

What people are saying 11 voices from 4 sites · best of 92 · verbatim

Still unanswered
  • Which state was this specific camera deployed in, given some states' strict data-retention limits for non-hit plates?
  • Are the leaked Auth0 credentials still live and usable to authenticate as other cameras?