583 points by driverdan 4 days ago | 271 comments | View on ycombinator
vayup 4 days ago |
autoexec 3 days ago |
Even if we decided that this level of mass surveillance on the American public was acceptable to us, Flock Safety/Flock Group as already demonstrated that they can't and shouldn't be trusted to implement it.
killbot5000 4 days ago |
It takes time and effort to think through proper secure boot architecture and to implement key management in a way that doesn’t kill developer productivity.
Their product managers, though, should have realized that setting these up in unsecured public spaces means that their threat model really does include local physical access to everything.
Using off the shelf hardware and software stacks all but guarantees attackers have tools at their fingertips to exploit said physical access.
Given all the recent exploits hitting the kernel, there’s a good chance that there exists an exploitable over-the-air vulnerability present in their WiFi/bluetooth stack, too.
driverdan 4 days ago |
Distributed Denial of Secrets has published the partition images: https://ddosecrets.org/article/flock-alpr-camera
drfloyd51 4 days ago |
It’s not even suitably encrypted on device?
Zero trust in anything Flock says.
petcat 4 days ago |
Has there been any report about which state this camera was recovered in? New Hampshire has a strict 3 minute rule for non-hit plate data before the captured images and records must be deleted [1].
[1] (N.H. Rev. Stat. § 261:75-b) requires ALPR systems to delete non-hit plate data within 3 minutes
crumpled 4 days ago |
I would absolutely assume that any system that sends your image to LE is part of a facial recognition system in practice. We know now that the cameras do recognize people and intentionally transmits images of them, for later identification.
writtenone 4 days ago |
smalltorch 4 days ago |
Grimeton 4 days ago |
That's why they don't give anything about the camera's security.
The images are all from a public place, so no privacy expectations and what's theworst that could happen? Someone uploads their cat images or the pr0n collection?
Ai figures that one out rather quickly.
wilburTheDog 4 days ago |
inanutshellus 4 days ago |
Seems like if I were a competitor of Flock I'd be pretty happy right now and all this negative press is making them artificially cheap to buyout right now.
Motorola/Vigilant, Rekor, Leonardo/ELSAG, and Axon are huge companies making mint off the same thing and no once in 20 years have I seen this level of attention... not on the overarching issue of surveillance-state-ing, but of one particular company.
iamnothere 4 days ago |
(The above should not be read as supporting Flock or discouraging further investigation.)
> The camera’s logs also show the camera struggling with storage. Its logs recorded more than 27,000 “no space left on device” errors while trying to save full-resolution images, along with tens of thousands of related errors, crashes, and reboots. At the same time, about every two minutes, code checked that the camera was still running and logged the message, “Who’s a good boy?!” More than 12,000 of those messages appear in the recovered logs.
Lol
client4 4 days ago |
jklinger410 4 days ago |
undefined 4 days ago |
deaux 4 days ago |
goolz 4 days ago |
aussieguy1234 3 days ago |
Right. So expect thousands of Flock cameras to be hacked soon.
Possible perps include foreign intelligence agencies (Khamenei in Iran was tracked down for his assassination using Iranian traffic cams), stalkers, domestic violence perps tracking their victims, the list goes on....
More than likely though, multiple of the above.
thangalin 4 days ago |
crumpled 4 days ago |
anguishe 4 days ago |
ohyoutravel 4 days ago |
Benefit of the doubt: Funding them for a community/city-owned traffic camera type thing seems like it would have been a much more reasonable proposition than funding Flock for their current use case of allowing police to stalk their ex girlfriends or mistresses.
4b11b4 4 days ago |
undefined 3 days ago |
imthatsteve 4 days ago |
We have all heard the argument that when corporations intentionally make the legal option worse it drives otherwise law abiding customers to pirate the content instead because piracy provides a better service than paying the corporation for their kneecapped product.
I dont see how the same thing doesnt apply to governments.
The people tell you over and over they dont want to live under a surveilance police state. So natually the corporations and government work together to create a fascist police state and they expect the people to be good little slaves and simply sell their souls to their government.
Especially in the day of ai when they could just fake those images incredibly easily to frame someone. They dont need a patsy the next time they jfk someone they just find some sucker with a weak alibi from a list of potential suckers and then fake some cctv images and cell phone data and they can put you where ever they want to.
The only real defence is to buy your own body cam and document every moment of your life so you can have competing evidence.
At this point im surprised damaging the cameras is the only thing these activists are doing.
I wouldnt be surprised to see flock employees and corrupt politicians finding bombs under their cars. Which will likely be used to justify more cameras which will only intensify the terrorist activity.
The tree of liberty is long overdue for a good watering.
realo 4 days ago |
I wonder what would happen if one of their customers asked for a 62443-4-2 certificate of compliance?
hk1337 4 days ago |
undefined 4 days ago |
LetsGetTechnicl 3 days ago |
phkahler 3 days ago |
Probably technically true. But since the cameras detect people that makes it easier for their backend system to do face recognition.
carefree-bob 3 days ago |
SlightlyLeftPad 3 days ago |
ck2 4 days ago |
as someone pointed out: let's make that "flock" name accurate
also make it identify bird song, I am sure there are microphones on there
KennyBlanken 3 days ago |
It's also really annoying me that police departments around the nation are petulantly implying they were "forced" to do this because of lawlessness and silly-villain karens...also claiming, without the press even remotely challenging them, that they're disappointed because "we believe they work."
There literally isn't a single fucking shred of evidence that Flock cameras do jack shit, that isn't from a study Flock paid for, which heavily cherry-picked communities, particularly ones with very low crime rates where a Flock camera happened to be involved and the crime rate which was already low dropped by a couple crimes a year and resulted in a "200% reduction in crime."
NuclearPM 3 days ago |
ErigmolCt 3 days ago |
coldbrewed 3 days ago |
* Privacy, civic trust, society if you get a chance!
This is the end product of tech leadership taking fat rips of disruption cocaine for the last 15 years. Flock Safety got VC money so that they could build a panopticon. There is nothing surprising about the fact that they did a hack job with terrible security; the fact that their service names are various types of alcohol is beyond parody.
Oh well, at least Flock Safety's IPO will be a critical cash infusion in the pursuit of building the torture nexus so that's cool.
zzzeek 4 days ago |
1. Take pictures
2. Send to a big server that all cops nationwide can log into whenever they want to stalk their exes
Did I miss something
fractal618 3 days ago |
br0ceph 2 days ago |
if the information does need to be protected from the public, then it must be private data and flock is an illegal system
catidegla 4 days ago |
blueoranges 4 days ago |
DarmokTanagra 3 days ago |
blacklimetea 4 days ago |
stackghost 4 days ago |
FlockisYC2 4 days ago |
blueoranges 4 days ago |
Jeremy1026 4 days ago |
ktm5j 4 days ago |
Ya know, I'm not on Flock's side here.. but be real, this is theft. You should be able to own that if you're going to do something like this.
They sincerely welcome your vulnerability disclosures, except in cases where you have to "interact" with the device/service or download its data. Other than that TINY carveout, everything is okay.
Oh, if the vuln about configuration and hardening "preferences" like SSL/TSL - Sorry, not interested.
And also, infrastructure vulnerabilities like DNS config - no no, try harder.
I know what you're thinking..ha ha...but we are good guys. You can still report vulnerabilities in the above categories, but the onus is on you to convince us that we should care about them. It is only fair.
https://www.flocksafety.com/legal/vulnerability-disclosure-p...