209 points driverdan 2 hours ago 94 comments
driverdan 2 hours ago | parent
Distributed Denial of Secrets has published the partition images: https://ddosecrets.org/article/flock-alpr-camera
john_strinlai 2 hours ago | parent
incee 1 hour ago | parent
john_strinlai 1 hour ago | parent
driverdan 1 hour ago | parent
fullstop 2 hours ago | parent
Linux version 3.18.71-perf-gaf770dc
datakan 1 hour ago | parent
incee 1 hour ago | parent
tyrabound 32 minutes ago | parent
But you would have thought that by 2021 when Andreessen Horowitz funded them or at least by 2025 [1] when both further funded them, someone would have actually done some minor due diligence. Coincidentally too, 2025 was when the flock surveillance matrix went up all over the country almost immediately.
We constantly hear that the magic of tech funding lies in the people, not even the product/service. These types of things always seem to uncover that that is effectively just a lie to cover up the ulterior motives of setting up a tyrannical surveillance matrix all around you … to protect the children, of course.
[1] https://www.flocksafety.com/blog/flock-safety-secures-major-...
Arrowmaster 15 minutes ago | parent
samudrijan 30 minutes ago | parent
Barbing 1 hour ago | parent
client4 2 hours ago | parent
ck2 2 hours ago | parent
as someone pointed out: let's make that "flock" name accurate
also make it identify bird song, I am sure there are microphones on there
kotaKat 1 hour ago | parent
We'll call it Cock Safety and help our community with patented JimmyHat technology to keep you safe and covered.
smalltorch 2 hours ago | parent
iamnothere 2 hours ago | parent
(The above should not be read as supporting Flock or discouraging further investigation.)
> The camera’s logs also show the camera struggling with storage. Its logs recorded more than 27,000 “no space left on device” errors while trying to save full-resolution images, along with tens of thousands of related errors, crashes, and reboots. At the same time, about every two minutes, code checked that the camera was still running and logged the message, “Who’s a good boy?!” More than 12,000 of those messages appear in the recovered logs.
Lol
jordanb 2 hours ago | parent
ofcrpls 1 hour ago | parent
kotaKat 1 hour ago | parent
"Page 17" in the document shows a spicy little chip.
https://www.quectel.com/product/kg100s-amazon-sidewalk-modul...
Axon not only includes a cell modem... they're on Amazon Sidewalk, baby.
jkestner 1 hour ago | parent
Communities are starting to pivot to the wider issue, but a reason that this issue found purpose is that Flock is a more evocative target than “ALPRs”. I think it wouldn’t be a bad thing if “Flock” becomes the generic name.
scarecrowbob 37 minutes ago | parent
tomwheeler 19 minutes ago | parent
CoopaTroopa 1 hour ago | parent
wl 1 hour ago | parent
This log message probably indicates when they're resetting the watchdog timer.
cuvinny 1 hour ago | parent
cucumber3732842 1 hour ago | parent
Flock by contrast courts local PDs who will catch a package thief or two but they really just want to have the drag net at their finger tips so that when some more equal animal's cat gets stolen they can walk back in time and figure out the short list of who could've done it.
wl 1 hour ago | parent
Fixed ALPRs aren't the only privacy problem, either. Many tow trucks have roving ALPRs that feed into big databases. The notion is that it helps them repossess cars that might be garaged at home. That data, however, is for sale to third parties.
cucumber3732842 1 hour ago | parent
jkestner 1 hour ago | parent
stackghost 2 hours ago | parent
drfloyd51 2 hours ago | parent
It’s not even suitably encrypted on device?
Zero trust in anything Flock says.
FrustratedMonky 1 hour ago | parent
But think the real danger in Flock is the aggregate data, tracking between camaras. So if someone hacks a single camara, they probably don't get much, unless it is pointed right at someone, which is bad. Aren't they selling these as should be pointing at traffic? If they are pointing right at people, like at playgrounds, then they are being installed illegally to begin with ?
voakbasda 1 hour ago | parent
FrustratedMonky 58 minutes ago | parent
But there is some old rule about, even the best security can fail if the device is physically accessible.
fullstop 1 hour ago | parent
ohyoutravel 1 hour ago | parent
fullstop 1 hour ago | parent
samudrijan 32 minutes ago | parent
criddell 19 minutes ago | parent
fullstop 8 minutes ago | parent
Now they are in a position where they can sell new models with enhanced encryption and more features.
megous 1 hour ago | parent
fullstop 1 hour ago | parent
For example, passing a frame of video (YUV) into the peripheral which can resize the overall image, would fail if the system was busy with other DMA transfers. You could attempt to resize again, but there were no guarantee that it would complete successfully. Your options are to reduce overall DDR utilization or drop frames. In an application like Flock's, dropping frames is likely something they need to avoid.
The system in question is doing similar tasks, and I don't think that what I'm suggesting is out of the question.
megous 14 minutes ago | parent
And in any case. Passing compressed video streams or pictures through HW encryption engine will not saturate 1.5+ GiB/s or whatever even the lousiest 16-bit DDR3 at 400MHz would give you, not even close. It would be like a fraction of a percent of total bandwidth.
fullstop 7 minutes ago | parent
ryukoposting 45 minutes ago | parent
But, a question for you: even if it was the case that the hardware was the limitation, isn't that also an indictment of Flock? Selling something that cannot exist securely within the bounds of current technology? Or, at a minimum, bad chip selection leading to a compromised design?
glaslong 1 hour ago | parent
> The hackers said they were able to access the Android system on the camera, and found two partitions—sections of its hard-drive, essentially. A few of these were unencrypted, the hackers said, including one called “vendor” and another called “media.” The latter contained an encryption key that unlocked another part, which contained much of the media—think, the videos and stills—the camera took.
> In early 2025, security researcher Jon “GainSec” Gaines reverse engineered a Flock license-plate reader and documented flaws that could be used to gain root-level access. After Gaines disclosed his findings, the company acknowledged the findings but downplayed their severity, writing that the flaws required physical access to the device and that even someone who gained access to a camera “would still not be able to gain access to footage” because images remained on the device only briefly after being transmitted to the cloud.
Source: https://www.404media.co/hackers-stole-flocks-camera-software...
scottLobster 1 hour ago | parent
bdangubic 44 minutes ago | parent
antonvs 16 minutes ago | parent
dpoloncsak 5 minutes ago | parent
paimapi 1 hour ago | parent
the Flock response has been 'it doesn't count if a Youtuber did it' lol: https://www.youtube.com/watch?v=0ADb-qQ5hMY
xnx 51 minutes ago | parent
All that data about ... license plates if you're willing to steal/damage private property. Seems like it would be a lot easier to setup your own ALPR.
antonvs 8 minutes ago | parent
Flock cameras capture the make, model, color, and body style of vehicles. They capture bumper stickers and other decals, as well as potentially identifying dents and scratches. They capture accessories like roof racks, bike racks, trailers, and toolboxes.
The OP story covers some of this. There's more at:
https://www.aclu.org/campaigns-initiatives/get-the-flock-out
https://www.nytimes.com/2026/08/10/us/flock-cameras-can-trac...
EvanAnderson 35 minutes ago | parent
I think I should add a "X'); DROP TABLE Cameras;--" bumper sticker to my car now.
runjake 10 minutes ago | parent
goolz 2 hours ago | parent
apercu 1 hour ago | parent
calgoo 1 hour ago | parent
scarecrowbob 38 minutes ago | parent
That kind of stuff is around but maybe not evenly distributed or legible to large demographics.
Unfortunately, so is the rest of the vicious horrorshow, equally illegible and equally uneven in distribution.
deaux 1 hour ago | parent
SecretDreams 1 hour ago | parent
Teever 1 hour ago | parent
Some people are just wired that way.
chrystalkey 18 minutes ago | parent
hk1337 1 hour ago | parent
ohyoutravel 1 hour ago | parent
Benefit of the doubt: Funding them for a community/city-owned traffic camera type thing seems like it would have been a much more reasonable proposition than funding Flock for their current use case of allowing police to stalk their ex girlfriends or mistresses.
shagie 1 hour ago | parent
The front page then had "All the footage is yours. Your neighborhood 100% owns the data. Flock Safety will not share, sell, or access your data."
Unfortunately, flock has been excluded from wayback, so can't see other views of that page.
{insert Darth Vader: I'm altering the deal. Pray I don't alter it any further.}
(+45m edit) https://bestpitchdeck.com/flock-safety appears to be the pitch deck from 2020.
> ...
> In 2019, Flock signed their first police department deal with Jersey Village, Texas.
> The slides you see here are from Langley's pitch at a venture conference one month before closing a $47M Series C round in November 2020. The following July, Andreessen Horowitz led a $150M Series D investment in Flock as a cornerstone of their American Dynamism practice. Additional slides are included from keynote and sales presentations used in 2023.
> ...
MBCook 1 hour ago | parent
10 years ago is no excuse.
ohyoutravel 1 hour ago | parent
cucumber3732842 1 hour ago | parent
Yes. Blame the pickaxe seller. Do not question the miners. Do not question the investors in the mining companies. Do not question the casual voter or internet commenter who thought all this was fine.
This isn't to say that flock not a scourge, but I think a lot of people (not saying you're one of them) could stand to look in the mirror here.
Back in ye olde dark ages of <checks notes> 2017, when YC was cutting Flock a check and when "big data" was the hot buzzword people of a certain bent couldn't get enough of this kind of stuff. Everyone was jacking off nonstop to the idea that we could just hoover up everyone's data ad then "efficiently" or "proactively" dispatch enforcement resources. People talked all sorts of big talk about stuff like cross referencing people's Home Depot spend with permit requirements, identifying small businesses that don't have healthy enough financials to be fully compliant, cross referencing invoices and delivery receipts to identify overloaded trucks, and generally finding all sorts of ways to fine the crap out of people for the pettiest of petty deviance. They considered this a noble goal.
Everyone's head was too far up their asses to look at the magic crystal ball called "history" and realize that a camera on every street corner watching who's going where all the damn time would be where it goes.
zzzeek 1 hour ago | parent
1. Take pictures
2. Send to a big server that all cops nationwide can log into whenever they want to stalk their exes
Did I miss something
nullable_bool 1 hour ago | parent
petcat 1 hour ago | parent
Has there been any report about which state this camera was recovered in? New Hampshire has a strict 3 minute rule for non-hit plate data before the captured images and records must be deleted [1].
[1] (N.H. Rev. Stat. § 261:75-b) requires ALPR systems to delete non-hit plate data within 3 minutes
hellon3wheels 1 hour ago | parent
tyrabound 41 minutes ago | parent
anonymars 35 minutes ago | parent
writtenone 1 hour ago | parent
mring33621 13 minutes ago | parent
Hints at unauthorized, illegal mass surveillance riding on top of authorized (but also possibly illegal) mass surveillance
ktm5j 1 hour ago | parent
Ya know, I'm not on Flock's side here.. but be real, this is theft. You should be able to own that if you're going to do something like this.
outside1234 1 hour ago | parent
intrasight 1 hour ago | parent
overtone1000 1 hour ago | parent
0b4a1f8caa8b2a 37 minutes ago | parent
micromacrofoot 25 minutes ago | parent
thangalin 1 hour ago | parent
killbot5000 13 minutes ago | parent
It takes time and effort to think through proper secure boot architecture and to implement key management in a way that doesn’t kill developer productivity.
Their product managers, though, should have realized that setting these up in unsecured public spaces means that their threat model really does include local physical access to everything.
Using off the shelf hardware and software stacks all but guarantees attackers have tools at their fingertips to exploit said physical access.
Given all the recent exploits hitting the kernel, there’s a good chance that there exists an exploitable over-the-air vulnerability present in their WiFi/bluetooth stack, too.
wilburTheDog 5 minutes ago | parent