A hacker collective stole a Flock camera and accessed its internal data, revealing new details on how the company’s automatic license plate readers track not only vehicles but people as well.
The collective, which refers to itself as stegan0gram, provided a copy of the data to 404 Media , Wired and the nonprofit leak archiver Distributed Denial of Secrets , known as DDoSecrets. They made the data public on Wednesday.
Download the Straight Arrow app today to get the stories that matter free from manipulation, bias or agenda.™
Point phone camera here
While much of the data was properly encrypted and inaccessible, stegan0gram was able to copy the camera’s storage and locate an encryption key that unlocked thousands of videos and still images of vehicles. Straight Arrow viewed some of the images leaked by the hackers.
An investigation into the exposed data by 404 Media and Wired found software designed to detect vehicles and license plates as well as people and other modes of transportation such as bicycles. Images and logs on the device showed that the camera captured more than 1.6 million images of 50,000 vehicles over 21 days.
“The hack and leak of one of Flock Safety’s ALPR devices demonstrates a fundamental problem with mass surveillance technology, which is not only catnip for abusers and incompatible with personal privacy, but also inescapably vulnerable to physical or electronic interference and intrusion,” DDoSecrets co-founder Emma Best told Straight Arrow.
The new insight into the inner workings of Flock’s cameras comes amid a growing backlash against the surveillance technology. Grassroots protests have led to cities and towns across the country canceling their contracts with the company. Cases of vandalism against the cameras have also become commonplace.
One hacker from stegan0gram argued, however, that those with the technical know-how should learn how the cameras work instead of destroying them.
“Why just destroy them when we can reverse engineer them and find the secrets of those spying on us?” the hacker told Wired. “We liberated hardware in the field, disarmed them, and proceeded with reverse engineering of the cameras and associated solar equipment.”
The hackers found that Flock’s cameras run an Android system. The hard drive inside the camera contained unencrypted sections, including one labeled “media,” where the encryption key granting access to the videos and images was located.
Analysis of the code by 404 Media and Wired found 20 Flock-built apps, including ones that detect motion and take pictures and others that classify objects, upload data and receive remote updates
Although none of the analyzed images and or videos showed pedestrians, likely due to the camera’s location above a busy roadway, the code confirmed that when a person enters into view, “it records where they appear in the image and how confident it is in the detection.
Both 404 Media and Wired said they found no evidence that Flock’s cameras use facial recognition.
‘Flock takes security seriously’
In a statement to the outlets, a Flock spokesperson said that “the unauthorized removal and tampering of a Flock camera is illegal.”
When asked the exposed encryption key, the spokesperson said that “Flock takes security seriously” and directed security researchers to disclose any vulnerabilities to the company.
The hackers, who declined to inform Flock of the security issues they found, appear more concerned with flying under the radar
“Being investigated is a legit concern and something we are trying to avoid,” one hacker told Wired. “I’m sure our actions have attracted some attention as it is, but we are careful and try to keep a low profile.”
Round out your reading
All your questions napping , answered.
Trump’s $5,000 promise echoes past payouts that never materialized .
Inside the effort to make data centers pay their of electricity costs.
Why did the Feds seize the ’ largest Martian meteorite on Earth ’?
Photos and video show exactly where and when Trump visited Ground Zero after 9/11 .
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
