deniz.in

Markets

Weather

Loading weather

· via Hacker News – Front Page (native)

Flock Camera Breach Exposes How License Plate Readers Track Cars and People

Hackers copied the storage of a roadside Flock Safety camera and shared it with WIRED and 404 Media, revealing built-in people detection, 1.6 million images, and an encryption key stored on the device itself.

Flock Camera Breach Exposes How License Plate Readers Track Cars and People

Hackers calling themselves stegan0gram physically pulled a Flock Safety camera from its mount above a roadway, copied nearly its entire internal storage, and passed the files to 404 Media and the transparency nonprofit Distributed Denial of Secrets, which shared them with WIRED. The resulting joint investigation by the two outlets offers the most detailed public account yet of what the company's automatic license plate readers actually capture — and people are part of it, not just plates.

What was inside

According to the WIRED and 404 Media analysis, the device runs Android on a processor comparable to a midrange smartphone, with roughly 20 Flock-built apps handling motion detection, image capture, object classification, uploads over the cellular network and remote updates.

Flock has described its cameras as protected by on-device encryption, and the hackers confirmed that some of the most sensitive storage remained locked. But several disk partitions were unencrypted, including one holding recorded media, and that partition also contained an encryption key. With it, the group unlocked videos covering thousands of vehicle detections.

That sits awkwardly next to Flock's earlier response to security researcher Jon "GainSec" Gaines, who in early 2025 documented flaws allowing root-level access. The company acknowledged his findings but minimised them, arguing that even an attacker with physical access "would still not be able to gain access to footage" because images leave the device shortly after upload.

What the camera sees

Recovered logs spanning about 21 days show the camera photographed roughly 50,200 vehicles and generated about 1.6 million images, averaging around 3,300 vehicles per day with a peak of 4,454. A single passing car typically produced 28 images, sometimes more than 100, shot at multiple exposures so that both the plate and the wider scene stay legible.

The camera itself apparently does not read plates or identify a vehicle's make, model and colour; the analysis indicates that happens on Flock's servers. The device scans its bursts, crops the useful frames and transmits them onward.

The more consequential finding is that the on-device software explicitly detects people, alongside vehicles, plates and bicycles, logging where a person appears in the frame and how confident the model is. To test this, WIRED extracted the vision models from the camera's files and ran them against 27,321 short video clips stored on the device. People turned up in only 11 clips — all motorcyclists — likely because the camera hangs above a road aimed at traffic. The models also detected a person in a reporter's selfie during testing.

The plate detector proved loose in what it accepted: bumper stickers, dealership frames and other graphics were sometimes cropped as though they were plates, including an American flag patch on a motorcyclist's saddlebag. The investigators found no active face-recognition capability beyond dormant defaults shipped with Android, consistent with Flock's public position.

A national web of access

Images and metadata flow to Flock's servers, where time-stamped records become searchable by the local agency that owns each camera — and, in many cases, by departments far away through the company's national network. In Alpharetta, Georgia, WIRED found records accessible to more than 2,000 agencies, spanning police, colleges, airports and, oddly, the General Services Administration's inspector general.

That reach has drawn scrutiny before. 404 Media previously reported that local officers ran searches on behalf of Immigration and Customs Enforcement, including in jurisdictions that ban such cooperation, and that a Texas officer queried cameras nationwide for a woman who had self-administered an abortion.

Rising resistance

The theft marks an escalation in opposition to the hardware. People across the US have been arrested for allegedly tampering with or sabotaging Flock cameras, some towns have said they will stop using them, and one police department 3D-printed a dummy camera housing to lure vandals. "Why just destroy them when we can reverse engineer them and find the secrets of those spying on us?" a stegan0gram member said. The group says it will publish how it obtained the software, inviting others to follow suit.

Why it matters

Flock's pitch rests on two claims: the hardware is hardened, and it reads plates rather than people. This breach dents both. An encryption key recoverable from an unencrypted partition on the device means physical access can yield footage, and the recovered software shows person detection is a built-in function, not an incidental one. Combined with a network that exposes one town's records to thousands of agencies, the findings hand communities and regulators concrete evidence for an ongoing debate over license plate readers — and with the hackers' method due for publication, Flock faces the prospect of repeat extraction attempts.

  • #flock-safety
  • #surveillance
  • #privacy
  • #license-plate-readers
  • #security

Related posts