Forgot your password?
typodupeerror
Privacy Security

Hackers Stole Flock's Camera Software, Revealing How the Company Tracks Cars and People (404media.co) 97

"Hackers ripped down a Flock camera above a roadway, made a near-complete copy of the data stored inside it, and shared the files with 404 Media and WIRED," according to an article published on both sites.

Though Flock has described its system as protected by on-device encryption, "The hackers were able to copy the camera's storage and recover an encryption key stored on the device, which unlocked videos of thousands of vehicle detections." The hackers shared the material with 404 Media and the transparency nonprofit Distributed Denial of Secrets, which shared the data with WIRED. 404 Media and WIRED then analyzed those files as part of a joint investigation... [T]he joint analysis of the recovered data shows that software running on the device explicitly detects people as well as vehicles, license plates, and bicycles. The camera can produce dozens of images of a single passing vehicle and, according to several weeks of recovered logs, generated more than a million images. Its computer-vision software also sometimes isolated bumper stickers and other graphics, including, in one case, an American flag patch on a motorcyclist's saddlebag...

According to our analysis, the camera's logs recorded about 21 days of activity across several periods. During those windows, the device photographed roughly 50,200 vehicles and generated about 1.6 million images. On a typical day, it logged around 3,300 vehicles, with a high of 4,454... The software running on the camera explicitly detects people, something which is typically overlooked in discussions around Flock cameras. When it spots a person, it records where they appear in the image and how confident it is in the detection.

It was a collective calling itself stegan0gram that breached the cameras, according to the interview they did with Wired and 404 Media. "Why just destroy them when we can reverse engineer them and find the secrets of those spying on us?"

Hackers Stole Flock's Camera Software, Revealing How the Company Tracks Cars and People

Comments Filter:
  • and deported if caught

  • Aside from giving us solid data on how badly Flock is behaving vs what they claim, there's one extremely useful detail this dump reveals: Flock sucks at correctly identifying the interesting parts of its targets.

    Time to absolutely wallpaper the front and back of our cars with bumper stickers that look like faces and license plates. Let 'em burn police time chasing down "8008135" stickers to the point nobody even checks the alerts anymore.
    • by omnichad ( 1198475 ) on Thursday September 17, 2026 @01:17PM (#66341248) Homepage

      I don't think that's what this means, though I'm not creating an account to read the full article. It identifies marks like bumper stickers in *addition* to the license plate. So even if you miss the plates (or the suspect changes plates), you can identify it by other means. This would be like identifying a person by tattoos when you can't get a good photo of their face.

      • by ThomasBHardy ( 827616 ) on Thursday September 17, 2026 @01:30PM (#66341272)

        Automated detection of political identify through bumper stickers?

      • by pla ( 258480 )
        I'm not suggesting that as a way to specifically avoid detection; rather, as a way to poison the data with 99% irrelevant matches. We all know the relevant XKCD [xkcd.com], but there's more options than a sawzall to fight back.

        As an aside, the full Wired article is freely available. I can't say if there's any additional information in the 404 Media version (because I'm also not signing up), but the Wired writeup is pretty solid.
        • Re: (Score:3, Funny)

          by apparently ( 756613 )

          I'm not suggesting that as a way to specifically avoid detection; rather, as a way to poison the data with 99% irrelevant matches.

          Your plan to "absolutely wallpaper the front and back of our cars with bumper stickers that look like faces and license plates" just makes your car even more uniquely identifiable. You're a complete fucking idiot.

          • by pla ( 258480 )
            Do you understand people are being pulled over at gunpoint for false matches on Flock?

            To repeat myself for the hard of thinking, "I'm not suggesting that as a way to specifically avoid detection". There's no practical and legal way to really "hide" while driving a car you own on public roads. I have no interest, positive or negative, in whether or not Flock helps catch actual criminals - That detail is completely irrelevant to the fact it's a blatant end-run around the fourth amendment.

            Sure, the local p
        • Back in the '90s I was chatting with a skript-kliddie who actually had an AOL logon like that. He figured that none of the CS drones could type it in right to nuke his account. You should have seen his face when I said the magic words: "copy and paste."
        • It won't help in any way because the pictures are sent home for more processing.

          • by pla ( 258480 )
            From the Wired article, "A typical passing vehicle generated about 28 images, though some produced more than 100. The camera uses different exposures to capture both the license plate and the wider scene, then scans the images, selects and crops useful frames, and sends them with other data to Flock over the cellular network."

            If Flock wants to pay for the bandwidth and tokens to upload every image, who am I to stop my enemy from burning money?

            As for doing it locally as some have suggested, there's a mu
            • by pla ( 258480 )
              Apologies: I have no idea where 333312 came from. The real number is 10752 - But that's still three orders of magnitude higher than what any on-device AI is going to be capable of anytime in the near future.
              • Apologies: I have no idea where 333312 came from.

                I just hope it didn't cost you any tokens.

                • by pla ( 258480 )
                  I will not ever pass off something written by AI as my own (yes, I really do use hyphens, oxford commas, and negative parallelism and have done so for decades before evil AI was anything more than a SciFi trope, as easily verified by my comment history prior to 2022). I check any non-trivial stats against primary sources. I don't even bother asking AI to calculate something for me, because it really really sucks at math.

                  In this case, though, I apparently also sucked at math and readily admit I and I alone
    • Honestly, AI technology has gotten good enough that those types of things won't fool it anymore. Captchas take longer for a human than it does for an AI model with vision, and the human is more likely to make a mistake.

      The point is, sure, their system may suck right now, but if adversarial patterns became common, they're a model update away from fixing it. Might need better hardware on the device, so at most you'll cost them some money, but it won't get us our privacy back.

    • by awwshit ( 6214476 ) on Thursday September 17, 2026 @02:31PM (#66341344)

      I think you'd want panel on your car that are like e-ink screens. While you can't change your license plate, what if you could change the color of your car? What if you car had different bumper stickers in different locations for each Flock camera? Constantly evolving patterns, and maybe patterns shared between vehicles, seems like a good adversarial approach. Attack their assumptions.

    • by allo ( 1728082 )

      Don't. Even when adversarial patterns work against one algorithm right now, they won't work against the next, but make you more recognizable. Each adversarial attack in neural networks is tailored to one specific network and does not affect others. Most the time it is also not simple to combine two attacks so both work, but you still won't fool a third iteration of the detection network anyway. So do you want to be the only person with five fake license plates? You become so easy to recognize even when your

    • by Gilmoure ( 18428 )

      Bob Dobbs returns to the chat.

  • by Tarlus ( 1000874 ) on Thursday September 17, 2026 @01:01PM (#66341236)

    The software running on the camera explicitly detects people, something which is typically overlooked in discussions around Flock cameras.

    Membership required to read the linked article, no thank you.

    While it sounds like it's not necessarily facial recognition, how long until they start normalizing CCP / Minority Report level facial recognition and identity tracking?

    I'm glad there's some political and cultural pushback but it still smells like boiling frogs.

  • Anti-Flock patch. A small electronic screen patch that plus into your tail lights and attaches to your trunk.

    Each day it randomly picks one of 900 different images to display. It includes things like bumper stickers, dents, grafiti, etc.

    Every car that gets the device comes with the same 900 images, but it can receive updates so if Flock begins to recognize the images, they can change to a different set of 900 images.

    • by organgtool ( 966989 ) on Thursday September 17, 2026 @02:30PM (#66341342)
      That would be a temporary solution, but competitors of Flock are already using fingerprints from your car based on Bluetooth from infotainment, built-in modem for updates and telematics, and even your TPMS sensors which broadcast unique IDs. In addition to that the fingerprints can contain info from your phone (Wifi, Bluetooth, RFID, cellular modem) and other wireless devices such as headphones and AirTags. Apparently this is already available in a product known as Leonardo. Looks like it's time to build a Faraday Cage around my vehicle.
      • That would be a temporary solution, but competitors of Flock are already using fingerprints from your car based on Bluetooth from infotainment, built-in modem for updates and telematics, and even your TPMS sensors which broadcast unique IDs. In addition to that the fingerprints can contain info from your phone (Wifi, Bluetooth, RFID, cellular modem) and other wireless devices such as headphones and AirTags. Apparently this is already available in a product known as Leonardo. Looks like it's time to build a Faraday Cage around my vehicle.

        Sounds like th epublic needs an OSS version of Leonardo to even th eplaying field and track police and elected officials...

      • Sounds like a good argument for putting the second amendment to use.

      • by Gilmoure ( 18428 )

        Who knew TPMS reports would evolve into snitches?!!

  • It seems to me every business level security camera has these AI features now. Everyone focuses on just Flock while overlooking what the entire industry is doing. Cyberpunk is slowly becoming reality.
  • by fahrbot-bot ( 874524 ) on Thursday September 17, 2026 @02:05PM (#66341316)

    "Hackers ripped down a Flock camera above a roadway, ...

    Flock will install camera cameras to watch their traffic cameras.

  • Security LOL !!! (Score:5, Insightful)

    by sentiblue ( 3535839 ) on Thursday September 17, 2026 @02:26PM (#66341332)
    It's funny that the camera protects data on device by encryption, but also keeps a copy of the private key there. You only need the public key to encrypt. The private key is supposed to be kept in their infrastructure for decryption when needed. I guess they've never heard of physical security.
    • I got the impression they were only using a single key, not dual key encryption.

      • by znrt ( 2424692 )

        which would be even worse. the first case could be a programmer mistake that somehow was missed by security audits. incredibly gross, but still, stuff like that can happen. the second case would imply that the gadget's security was designed by a total nutcase.

  • The Flock hardware requirements stood out to me. The hackers said that Flock software could run on a mid-range phone. This suggests that malware with Flock capabilities (and a little better data discipline) could hide on a high-end phone. Flock-like malware could easily hide on a modern laptop.
    • Someone told me once that the hardware in there is this mediocre Android dev board [lantronix.com] with a little additional panopticon gear bolted onto it. So yeah, definitely in the "Free phones handed out in front of Walgreens" territory.

      Not sure what would be the utility of running that sort of software on an individual endpoint machine, there's already much better malware intended to run on those. But it does point out the ease with which a sufficiently motivated actor can roll out an impressive surveillance grid wit

  • With the key recoverable on the device?

    Fucking amateur hour!

    • Did we really expect more from the company that also left a lot of its devices searching for WiFi APs with predictable SSIDs and passwords, then offering an ADB port? Or, for those that weren't actively connectable, requiring pushing the exposed power button on the back with a stick to make them connectable?

      Startup culture, move fast, break things -- preferably someone else's things.

  • by usedtobestine ( 7476084 ) on Thursday September 17, 2026 @03:02PM (#66341378)

    Did they try to inject image data? Wouldn't it be funning to insert images of Putin, Kim, Washington, and Lincoln?

  • roads (Score:3, Funny)

    by bugs2squash ( 1132591 ) on Thursday September 17, 2026 @03:35PM (#66341412)
    They are pointed at roads - so the responsible thing to do is to drive across peoples' back yards
  • Well now, Flock is back in my good graces. We've got to wipe all those Pee-Wee Hermans off the face of the planet.

  • by Mirnotoriety ( 10462951 ) on Thursday September 17, 2026 @03:47PM (#66341428)
    Hackers Got Inside a Flock Camera. Its Data Shows How the System Really Works [justpaste.it]

    Wired [wired.com]: “The hackers said they were able to access the Android system on the camera and found two partitions—sections of its hard drive, essentially. A few of these were unencrypted, the hackers said, including one called “vendor” and another called “media.” The latter contained an encryption key that unlocked another part, which contained much of the media—the videos and stills—the camera took.”

    “In early 2025, security researcher Jon “GainSec” Gaines reverse engineered a Flock license-plate reader and documented flaws that could be used to gain root-level access. After Gaines disclosed his findings, the company acknowledged the findings but downplayed their severity, writing that the flaws required physical access to the device and that even someone who gained access to a camera “would still not be able to gain access to footage,” because images remained on the device only briefly after being transmitted to the cloud.”
  • Those systems may reveal more about the endpoints used by the cameras to upload the data, as well as the IP addresses being used by the street-cameras. Those remote endpoints (likely in a cloud) can be better analyzed/targeted than a single flock instance.
  • by Shakes Fist ( 10502847 ) on Thursday September 17, 2026 @06:50PM (#66341652)
    Here is the true USA, "Land of the Free" - spying on everyone outside their homes and, with smart TV's, inside their homes too.
    Wake the fuck up.
    • Incoming doublethink: You hate constant surveillance? Why do you hate America? Don't you know we're at war? Constant surveillance - ConSev - is the only thing keeping us safe from Eastasia! Freedom!!

You must realize that the computer has it in for you. The irrefutable proof of this is that the computer always does what you tell it to do.

Working...