Read as article
Hackers Rip Down Flock Camera and Dump Its Software
By @sharedot · · 6 pages
A hacker collective pulled a Flock camera from a roadway and copied its files, revealing person detection, an on-device encryption key and more.
What the hackers did
The collective stegan0gram says it "liberated hardware in the field, disarmed them, and proceeded with reverse engineering of the cameras and associated solar equipment," then shared the extracted files with 404 Media and WIRED. The hackers say they gained access to the camera's Android system and found two partitions — one called "vendor" and another called "media" — that were unencrypted, with the media partition containing an encryption key that unlocked much of the device's stored media. The material was passed to 404 Media, WIRED and Distributed Denial of Secrets for joint analysis. Flock said in a statement that removal and tampering with a camera is illegal, and that it received no report through its Vulnerability Disclosure Program. The company said that if the individuals identified legitimate vulnerabilities, it encourages them to submit technical findings through its reporting process so its security team can review them.
The surprising detail: people detection
The most unexpected finding is that the camera's computer-vision software explicitly detects people, not just vehicles, license plates and bicycles — recording where a person appears in an image and how confident the model is. WIRED extracted the models from the camera's files and ran them against test images and footage, readily detecting people including a selfie of a reporter. The outlet then ran the models across 27,321 short video clips stored on the camera, detecting people in 11 clips, all motorcycle riders. WIRED also reports the plate detector was surprisingly loose, mistaking bumper stickers, dealership frames and an American flag patch on a motorcyclist's saddlebag for license plates. No evidence of face-recognition capability was found beyond default, unused Android features.
Scale and storage strain
According to WIRED's analysis, the camera's logs recorded about 21 days of activity, photographing roughly 50,200 vehicles and generating about 1.6 million images — around 3,300 vehicles on a typical day, peaking at 4,454. A typical passing vehicle generated about 28 images, sometimes more than 100, with different exposures capturing both the plate and the wider scene before uploading over cellular. The device runs about 20 Flock-built apps on a smartphone-class processor. The logs also show the hardware struggling: WIRED counted more than 27,000 "no space left on device" errors alongside crashes and reboots — and a health-check routine logging "Who's a good boy?!" every two minutes.
Why it matters and what's next
The extraction undercuts earlier downplaying of the device's security. According to 404 Media, security researcher Jon "GainSec" Gaines documented flaws allowing root-level access in early 2025, and Flock responded that even someone with physical access "would still not be able to gain access to footage." The recovered key unlocked videos of thousands of vehicle detections. The findings also land amid broader controversy over Flock's national network — 404 Media has previously revealed local cops running lookups on behalf of ICE and a Texas cop searching for a woman who self-administered an abortion. Some towns are now dropping Flock cameras, while critics like former Pawtucket officer Noel Pichardo worry sabotage may only harden police support for the tools.