Hacker collective stegan0gram dismantles a Flock camera, recovering an encryption key and showing it runs ~20 apps on a midrange smartphone-grade processor
While people around the U.S. are tearing down Flock cameras, one group of hackers went a step further: extracting the camera's software too.
The recovered device software and encryption key move scrutiny from Flock’s web-facing products to the camera itself. Public posts about the extracted material characterize the device as detecting people, vehicles, plates, and bicycles; those are observers’ interpretations of the disclosed files, not independently established product claims.
First-order effects
Flock’s camera software and on-device encryption implementation are open to independent inspection after stegan0gram recovered a key and copied the device’s contents.
Police departments using Flock cameras face more specific questions about what the devices capture and process than license-plate-reading descriptions alone answer.
Second-order effects
Flock must defend the security of deployed hardware as well as the governance of its investigative platform, since device-level disclosure supplies material for outside technical review.
Agencies weighing Flock’s network and OS Investigate integrations gain a new basis to demand clarity on collection at the capture layer before records enter broader investigative workflows.
Third-order effects
If device extraction becomes a repeatable form of oversight, surveillance-camera vendors will face pressure to make the capture layer auditable rather than treating it as a sealed appliance.
The episode points to a surveillance stack in which debates over data provenance extend from backend databases to the edge devices that create the records.
The trend: Networked public-surveillance systems are becoming contestable at the device layer as their camera feeds are connected to broader investigative databases.
Analysis of the data “shows that software running on the device explicitly detects people as well as vehicles, license plates, and bicycles. The camera can produce dozens of images of a single passing vehicle and, according to several weeks of recovered logs, generated more than…
“Hackers ripped down a Flock camera above a roadway, made a near-complete copy of the data stored inside it, and shared the files with 404 Media and WIRED, revealing in new detail how exactly Flock Safety's cameras track the movements of both vehicles and people.”
NEW: When @dmehro.bsky.social at @wired.com and @josephcox.bsky.social at @404media.co both got handed the full contents of a Flock camera, we worked together to figure out what it revealed. (WIRED's below, 404's version here: www.404media.co/hackers-stol...)
@dmehro The best part of this story is that the files were encrypted, and the key to unencrypt them was also found inside the camera. This is like having a bank vault door with the key duct taped to the front of it. COMPLETE INEPTITUDE
Flock is not a license plate recorder, despite what defenders claim. It is a midrange Android taking millions of pictures & sending a lot of them to Flock. Makes you wonder: what else is Flock doing with those photos?
Still coming to terms with the fact that Flock is a badly secured Android on a pole chanting “Who's a good boy?!” to itself while spying on the world..
NEW: Hackers cut down a Flock camera, dumped its internal storage, and shared the files. It includes thousands of videos and logs showing how the device took images of 50,000 vehicles in days It reveals in new detail how Flock tracks vehicles and people. https://www.wired.com/...
I've got a lot of work to do today but I'm getting absolutely nerdsniped by the new Flock dataset. You can download it here. It's all of the Android partitions extracted from a Flock device ddosecrets.org/article/floc... [embedded post]