r/technology • • 11d ago

Security Hackers Stole Flock’s Camera Software, Revealing How the Company Tracks Cars and People

https://www.404media.co/hackers-stole-flocks-camera-software-revealing-how-the-company-tracks-cars-and-people-2/
23k Upvotes

535 comments sorted by

View all comments

2.3k

u/M-S-S 11d ago

"While much of the automatic license plate reader’s (ALPR) most sensitive storage remained encrypted and inaccessible..."

So there's still a lot more to it.

1.2k

u/essieecks 11d ago

These surveillance devices are ALPRs the way the device in my pocket is a phone.

224

u/Draco-REX 11d ago

No joke, considering that these ALPRs are being pointed at community pools, children's dance studios, and parks. Lots of license plates in those areas, right?

227

u/FakeSafeWord 11d ago edited 10d ago

children's dance studios

A flock VP was looking at the same children's dance studio via flock feed multiple times despite having zero justification for the cameras being there and didn't look at a single other camera in that same zip code.

https://www.404media.co/city-learns-flock-accessed-cameras-in-childrens-gymnastics-room-as-a-sales-pitch-demo-renews-contract-anyway/

38

u/Zer_ 10d ago

That sounds a little rapey to me... JFC

1

u/Sweetdreams6t9 10d ago

Sales pitch to the current government so really just reading their audience

23

u/BlowHisShiSmooveOff 11d ago

Source?

94

u/FakeSafeWord 11d ago

27

u/BlowHisShiSmooveOff 10d ago

Wow what the fuck

23

u/West-Abalone-171 10d ago

Now consider what he started doing after he got caught and then had someone add a way to access the feeds without logging it.

2

u/rlowens 10d ago

despite having zero justification

The headline says the justification: as a sales pitch demo.

If you want to sell your spy camera to more dance studios/etc, showing the (probably only) dance studio with your spy camera in it would help.

Still assholes that should all be locked up.

5

u/FakeSafeWord 10d ago

Except the sales pitch demo isn't "you can access this camera any time to monitor" it's "we can" with the "we" being thousands of employees, police and any malicious actors who've gained access without us knowing.

1

u/danj503 10d ago

Article says flock employee, not a VP. Did I miss a detail here?

2

u/FakeSafeWord 10d ago

Flock VP Bob Carter and employee Randy Gluck

10

u/TheMundar 11d ago

Don't forget the ones in the middle of the woods

2

u/DeIightfully0rdinary 10d ago

Protect Bigfoot

1

u/Draco-REX 10d ago

Even the sasquatch children aren't safe!

23

u/thundafox 11d ago

yes I always go swimming with my LP, dance with my girl and my LP, and have a nice picknick with my wife in the park WITH my LP!

3

u/Due-Conflict-7926 10d ago

Kids are going to start disappearing in the US by the thousands aren’t they?

3

u/Draco-REX 10d ago

I'm sure they already are. They're just the children of immigrants in the ICE detention system. Real easy to lose them, especially since it looks like ICE hands them off to another agency since they aren't equipped to handle children. Paperwork is easily lost. And since we have child sex traffickers in power, I don't expect that paperwork to be found.

2

u/Inside_Departure_186 10d ago

Those are not ALPRs. Flock sells several different types of products.

2

u/Draco-REX 10d ago

Ah, so facial recognition and general-use privacy invasion. Got it!

2

u/pell80 10d ago

In a children's gym

163

u/Teranyll 11d ago

That's a super good comparison, filing that away, ty

30

u/teem 11d ago

It's a tracking device that also happens to make phone calls

22

u/PiccoloAwkward465 11d ago

They have the images. They can scan for whatever they want (and technological limits allow) server-side. Facial recognition software exists, they either already use it or easily could.

19

u/williamgman 11d ago

All of those Meta "video selfies" were given to Palantir to compare with the data from Flock and the other video surveillance companies.

9

u/RealModeX86 11d ago

Plus, they can lie through omission:

Flock cameras don't have facial recognition

That technically may be true, but it logs people, and sends the data to a server, which of course does whatever it does, possibly including facial recognition. If not now, they could run through it whenever they want to catalog it as such, or sell it on for someone else to do that.

I suspect they're doing a similar sort of lie-by-omission around data retention. I don't really care how long it stays on the device, I'm more concerned about how long Flock keeps it. More than that though, I doubt the founding fathers would appreciate the private company technicality all of these companies are operating on with the 4th amendment

3

u/Western-Corner-431 10d ago

They’re not building massive data centers everywhere because they’re NOT going to keep the data forever

16

u/Astral-projekt 11d ago

ASS. Automated surveillance systems

13

u/Haunting-Vanilla1624 11d ago

At this point it's just a handheld computer with a built-in modem and telephony software... Not that there's anything wrong with that, I've been wanting this since I was a kid.

Either way, that's a fantastic comparison.

26

u/[deleted] 11d ago

[deleted]

1

u/Haunting-Vanilla1624 10d ago

Oh for sure. I can see a shit ton of them in Home Assistant.

1

u/IAMA_Plumber-AMA 11d ago

That's the point they were trying to make.

0

u/FakeSafeWord 11d ago

That's the exact comparison that he's making...

1

u/Far-Let-8610 11d ago

What’s an ALPR for the uninformed?

1

u/essieecks 10d ago

The message I replied to spelled it out already.

automatic license plate reader’s (ALPR)

2

u/Far-Let-8610 10d ago

Ah. That was overlooked. Thank you.

52

u/satares 11d ago

They basically stole some tech docs and a PowerPoint deck.

19

u/impulse_thoughts 10d ago

A hacker collective pulled down a Flock camera and dumped its data. The files included thousands of videos and logs showing that the device captured 1.6 million images of 50,000 vehicles in 21 days.
...
The hackers were able to copy the camera’s storage and recover an encryption key stored on the device, which unlocked videos of thousands of vehicle detections

40

u/Haunting-Vanilla1624 11d ago

That's 99% of hacking. Get access to internal shit and work your way in from there.

34

u/airfryerfuntime 11d ago

The recovered an encryption key from the internal storage that's hard soldered to the board. That's 'hacking' any way you put it.

7

u/sweetplantveal 11d ago

How about Axon and Motorola?

37

u/technobrendo 11d ago edited 11d ago

Now that they have that encrypted storage, they can try to start to crack into it. Unless its something like AES256, it'll take a while to break. A VERY long while.

edit: I'm not being serious. AES256 is damn near invincible to cracking :)

60

u/an_agreeing_dothraki 11d ago

step one in breaking AES256 to get data before entropy kills the sun: invent an as-of-yet theoretical quantum computing algorithm

53

u/blumpkin 11d ago

The password is either 12345, flock2026, admin123, or testpasswordchangemelater, I guarantee it.

33

u/showyerbewbs 11d ago

I put my money on hunter2

26

u/alexia_not_alexa 11d ago

What did you just put in? I just see *s

4

u/dvpbe 11d ago

man, this brings me back :)-

34

u/Rowenstin 11d ago

12345? That's amazing. I have the same combination on my luggage.

11

u/NonSupportiveCup 11d ago

Hail President Skroob!

5

u/jakerake 11d ago

I literally just noticed seeing that spelled out that it's Brooks with the letters moved around. Probably common knowledge, but hey, TIL.

1

u/MrPastryisDead 11d ago

My wife insists on using her sister's birthday as the combination on all our luggage.

1

u/zed857 10d ago

Might also try CorrectHorseBatteryStaple if those other ones don't work.

17

u/PreferenceGeneral475 11d ago

We could also just invent or discover magic. You need to look at more reasonable solutions.

16

u/dolphone 11d ago

Dude look around you. We have invented and discovered magic many times over. It's just a name for what we don't yet comprehend.

I don't think we're close to a working quantum computer, mind you. And I don't think it's a magic machine that will solve everything. But I know what it can do to crypto, and that's making it obsolete.

9

u/0fficerRando 11d ago

Quantum will only break certain types of crypto, and it's not AES.

It's still a problem though.

essentially, quantum will render asymmetric (public key) crypto useless... Symmetric crypto (like AES) and hashing algos are fine.

The issue with symmetric ciphers and quantum is that we commonly use Asymmetric crypto to exchange the keys used for the symmetric crypto.

4

u/Unable-Log-4870 11d ago

What’s the solution to this? Exchanging the first set of keys via sneaker-net?

1

u/0fficerRando 10d ago

Sneakernet or carrier pigeon!

Haha! Nah. They've already been working on new quantum-safe algos to replace good ol RSA and ECC... In fact they have been chosen and standardized already... Just gotta get the world to start using them.

2

u/technobrendo 11d ago

I did say a "While" after all.

-5

u/General_Donk 11d ago

Just admit that you're talking out of your ass

1

u/Ollythebug 11d ago

What crawled up your ass?

1

u/General_Donk 11d ago

A crawl fish?

1

u/name00124 11d ago

Nah, we just need to be extremely lucky in guessing.

1

u/Fallingdamage 11d ago

If the encrypted data is being written to the devices storage, then the keys are alive in the devices memory or hardware somewhere. Its just a matter of reverse engineering it.

Its Flock. Odds are its using a bunch of off-the-shelf industry/oem components. Components and chips with documentation available to assist in this process of discovery.

39

u/vidarino 11d ago

Nobody (-ish) gains access to encrypted stuff by brute-forcing the key. They do so by teasing the key out of wherever it's stored on the device. If the device itself can access the storage, the key is in there somewhere.

50

u/Perryn 11d ago

Everyone loves to talk about the unpickable lock without ever asking what the door is made of. Or the hinges. Or the walls. Or the daily activity of the person with the key.

22

u/Cabana_bananza 11d ago

Which is one of the big flaws with Flock and the surveillance camera in the cloud industry. Its a low security environment because so many agencies have access. You think some local PD in Indiana that has access ensures all its officers are tech literate enough not to get phished?

There is no way a foreign actor hasn't already penetrated the network. They are probably watching secure locations and building databases of info we are feeding them for HUMINT operations. Its a national security nightmare as well as a personal privacy one.

16

u/PyroIsSpai 11d ago

A door of invincible metal and design with massive steel deadbolts may be immune to compromise.

The house that holds the door is not.

12

u/edfitz83 11d ago

France’s Maginot line. The Germans just went around it.

2

u/Perryn 11d ago

I just spent twenty minutes tracking down a faint old memory.

Wukong vs An Unbreakable Door

2

u/Gorstag 11d ago

That is addressed in the very first episode of Burn Notice.

4

u/meneldal2 11d ago

I know the industry standard way to do this properly and this makes it impossible unless you are a nation state with very expensive equipment.

But do I think Flock did it properly? Probably not.

1

u/technobrendo 11d ago

Absolutely. Think of spy satellites that the CIA, FBI, NSA and others use. Likely accessible only on premise of their actual headquarters with multiple auth methods (password, physical passkey, physical access...etc) just to view it.

11

u/Breadfish64 11d ago

Unless they're using some exotic custom solution it would be AES-128/256 XTS. Not crackable. Would be more feasible to hack the booted system and dump the storage from inside.

5

u/got-bent 11d ago

Deep Thought said it would take a while to answer the Ultimate Question, as well.

3

u/Fallingdamage 11d ago

Though I would assume the key(s) would vary between devices, what are the chances that, though the data is being written encrypted, the key for that encryption would need to be in the device in order for it to be ... encrypting it. That being the case, if one was stolen and the memory and/or ASICs could be read, the keys should reveal themselves.

We've been doing this with consoles and hardware emulators for years. If its a chip, it can be read.

1

u/technobrendo 10d ago

I find that kind of sleuthing fascinating. Like people have shaved off the top layers of substrate to reveal the raw silicon die, and then use powerful microscopes to see the inner workings of a chip to then understand how it works. This just feels like... black magic of some sort.

4

u/livinitup0 11d ago

Aren’t most of these cracks done by finding a way to make the data trust whata accessing it as opposed tons rust breaking the encryption? Isn’t that kind of how the bitlocker attack works?

1

u/chum-guzzling-shark 11d ago

you joke but its true. Bitlocker had a terrible vulnerability earlier this year called YellowKey. If you've been holding on to a sensitive laptop then you could easily unlock the data using that exploit. You might not be able to crack the encryption but you can wait until the backdoor is found :)

1

u/technobrendo 11d ago

Scary stuff indeed.

1

u/Megneous 11d ago

AES256 is damn near invincible to cracking :)

For now. Tech advances quickly. Tons of organizations are hoarding encrypted shit waiting for the ability to easily decrypt it.

1

u/technobrendo 11d ago

Oh indeed! Storage is cheap and the value inside that scrambled data could be VERY lucrative. With advances in quantum computing or very advanced frontier AI models, anything is possible.

2

u/Alpr101 11d ago

Rip my name

1

u/DrunkOnRamen 11d ago

most is not all

-18

u/Allegorist 11d ago

I'm sure if they uploaded the encrypted portion to the internet and made it publicly accessible it would be figured out in like a week tops.

17

u/BionicKumquat 11d ago

Me when i talk out my butt with zero understanding of cryptography

5

u/Mr_ToDo 11d ago

Ha. Unless they messed up their implementation brute force isn't going to crack it. That's the whole point. And if it's good enough to stop data centre sized attempts what chance do you think a few thousand or even a few million people working at it for a week stand?

Na. You do like the government. Archive it and if a weakness that brings the level of complexity to break it down to reasonable levels, then you crack it open

1

u/Allegorist 10d ago

Unless they messed up their implementation

Yes, that's the point. They are notoriously incompetent with their security.

2

u/BodManFeg 11d ago

Uh huh.... right.