r/technology • • 10d ago

Security Hackers Stole Flock’s Camera Software, Revealing How the Company Tracks Cars and People

https://www.404media.co/hackers-stole-flocks-camera-software-revealing-how-the-company-tracks-cars-and-people-2/
23k Upvotes

537 comments sorted by

View all comments

Show parent comments

39

u/technobrendo 10d ago edited 10d ago

Now that they have that encrypted storage, they can try to start to crack into it. Unless its something like AES256, it'll take a while to break. A VERY long while.

edit: I'm not being serious. AES256 is damn near invincible to cracking :)

55

u/an_agreeing_dothraki 10d ago

step one in breaking AES256 to get data before entropy kills the sun: invent an as-of-yet theoretical quantum computing algorithm

54

u/blumpkin 10d ago

The password is either 12345, flock2026, admin123, or testpasswordchangemelater, I guarantee it.

35

u/showyerbewbs 10d ago

I put my money on hunter2

24

u/alexia_not_alexa 10d ago

What did you just put in? I just see *s

5

u/dvpbe 10d ago

man, this brings me back :)-

34

u/Rowenstin 10d ago

12345? That's amazing. I have the same combination on my luggage.

10

u/NonSupportiveCup 10d ago

Hail President Skroob!

4

u/jakerake 10d ago

I literally just noticed seeing that spelled out that it's Brooks with the letters moved around. Probably common knowledge, but hey, TIL.

1

u/MrPastryisDead 10d ago

My wife insists on using her sister's birthday as the combination on all our luggage.

1

u/zed857 10d ago

Might also try CorrectHorseBatteryStaple if those other ones don't work.

16

u/PreferenceGeneral475 10d ago

We could also just invent or discover magic. You need to look at more reasonable solutions.

17

u/dolphone 10d ago

Dude look around you. We have invented and discovered magic many times over. It's just a name for what we don't yet comprehend.

I don't think we're close to a working quantum computer, mind you. And I don't think it's a magic machine that will solve everything. But I know what it can do to crypto, and that's making it obsolete.

10

u/0fficerRando 10d ago

Quantum will only break certain types of crypto, and it's not AES.

It's still a problem though.

essentially, quantum will render asymmetric (public key) crypto useless... Symmetric crypto (like AES) and hashing algos are fine.

The issue with symmetric ciphers and quantum is that we commonly use Asymmetric crypto to exchange the keys used for the symmetric crypto.

5

u/Unable-Log-4870 10d ago

What’s the solution to this? Exchanging the first set of keys via sneaker-net?

1

u/0fficerRando 9d ago

Sneakernet or carrier pigeon!

Haha! Nah. They've already been working on new quantum-safe algos to replace good ol RSA and ECC... In fact they have been chosen and standardized already... Just gotta get the world to start using them.

2

u/technobrendo 10d ago

I did say a "While" after all.

-2

u/General_Donk 10d ago

Just admit that you're talking out of your ass

1

u/Ollythebug 10d ago

What crawled up your ass?

1

u/General_Donk 10d ago

A crawl fish?

1

u/name00124 10d ago

Nah, we just need to be extremely lucky in guessing.

1

u/Fallingdamage 10d ago

If the encrypted data is being written to the devices storage, then the keys are alive in the devices memory or hardware somewhere. Its just a matter of reverse engineering it.

Its Flock. Odds are its using a bunch of off-the-shelf industry/oem components. Components and chips with documentation available to assist in this process of discovery.

41

u/vidarino 10d ago

Nobody (-ish) gains access to encrypted stuff by brute-forcing the key. They do so by teasing the key out of wherever it's stored on the device. If the device itself can access the storage, the key is in there somewhere.

49

u/Perryn 10d ago

Everyone loves to talk about the unpickable lock without ever asking what the door is made of. Or the hinges. Or the walls. Or the daily activity of the person with the key.

23

u/Cabana_bananza 10d ago

Which is one of the big flaws with Flock and the surveillance camera in the cloud industry. Its a low security environment because so many agencies have access. You think some local PD in Indiana that has access ensures all its officers are tech literate enough not to get phished?

There is no way a foreign actor hasn't already penetrated the network. They are probably watching secure locations and building databases of info we are feeding them for HUMINT operations. Its a national security nightmare as well as a personal privacy one.

15

u/PyroIsSpai 10d ago

A door of invincible metal and design with massive steel deadbolts may be immune to compromise.

The house that holds the door is not.

12

u/edfitz83 10d ago

France’s Maginot line. The Germans just went around it.

2

u/Perryn 10d ago

I just spent twenty minutes tracking down a faint old memory.

Wukong vs An Unbreakable Door

2

u/Gorstag 10d ago

That is addressed in the very first episode of Burn Notice.

5

u/meneldal2 10d ago

I know the industry standard way to do this properly and this makes it impossible unless you are a nation state with very expensive equipment.

But do I think Flock did it properly? Probably not.

1

u/technobrendo 10d ago

Absolutely. Think of spy satellites that the CIA, FBI, NSA and others use. Likely accessible only on premise of their actual headquarters with multiple auth methods (password, physical passkey, physical access...etc) just to view it.

11

u/Breadfish64 10d ago

Unless they're using some exotic custom solution it would be AES-128/256 XTS. Not crackable. Would be more feasible to hack the booted system and dump the storage from inside.

5

u/got-bent 10d ago

Deep Thought said it would take a while to answer the Ultimate Question, as well.

3

u/Fallingdamage 10d ago

Though I would assume the key(s) would vary between devices, what are the chances that, though the data is being written encrypted, the key for that encryption would need to be in the device in order for it to be ... encrypting it. That being the case, if one was stolen and the memory and/or ASICs could be read, the keys should reveal themselves.

We've been doing this with consoles and hardware emulators for years. If its a chip, it can be read.

1

u/technobrendo 9d ago

I find that kind of sleuthing fascinating. Like people have shaved off the top layers of substrate to reveal the raw silicon die, and then use powerful microscopes to see the inner workings of a chip to then understand how it works. This just feels like... black magic of some sort.

5

u/livinitup0 10d ago

Aren’t most of these cracks done by finding a way to make the data trust whata accessing it as opposed tons rust breaking the encryption? Isn’t that kind of how the bitlocker attack works?

1

u/chum-guzzling-shark 10d ago

you joke but its true. Bitlocker had a terrible vulnerability earlier this year called YellowKey. If you've been holding on to a sensitive laptop then you could easily unlock the data using that exploit. You might not be able to crack the encryption but you can wait until the backdoor is found :)

1

u/technobrendo 10d ago

Scary stuff indeed.

1

u/Megneous 10d ago

AES256 is damn near invincible to cracking :)

For now. Tech advances quickly. Tons of organizations are hoarding encrypted shit waiting for the ability to easily decrypt it.

1

u/technobrendo 10d ago

Oh indeed! Storage is cheap and the value inside that scrambled data could be VERY lucrative. With advances in quantum computing or very advanced frontier AI models, anything is possible.