Distributed Denial of Secrets has published the partition images: https://ddosecrets.org/article/flock-alpr-camera
Linux version 3.18.71-perf-gaf770dc
i dont deal with that anymorrle, but last one I saw with 2.x was the pixel 6 pro.
Edited: I misunderstood what you mean, you were talking about the modem subsystem, sorry.
But you would have thought that by 2021 when Andreessen Horowitz funded them or at least by 2025 [1] when both further funded them, someone would have actually done some minor due diligence. Coincidentally too, 2025 was when the flock surveillance matrix went up all over the country almost immediately.
We constantly hear that the magic of tech funding lies in the people, not even the product/service. These types of things always seem to uncover that that is effectively just a lie to cover up the ulterior motives of setting up a tyrannical surveillance matrix all around you … to protect the children, of course.
[1] https://www.flocksafety.com/blog/flock-safety-secures-major-...
https://deepdelver.substack.com/p/delve-fake-compliance-as-a...
missing a d(gaf)
sorry, had to get that out!
as someone pointed out: let's make that "flock" name accurate
also make it identify bird song, I am sure there are microphones on there
(The above should not be read as supporting Flock or discouraging further investigation.)
> The camera’s logs also show the camera struggling with storage. Its logs recorded more than 27,000 “no space left on device” errors while trying to save full-resolution images, along with tens of thousands of related errors, crashes, and reboots. At the same time, about every two minutes, code checked that the camera was still running and logged the message, “Who’s a good boy?!” More than 12,000 of those messages appear in the recovered logs.
Lol
"Page 17" in the document shows a spicy little chip.
https://www.quectel.com/product/kg100s-amazon-sidewalk-modul...
Axon not only includes a cell modem... they're on Amazon Sidewalk, baby.
Communities are starting to pivot to the wider issue, but a reason that this issue found purpose is that Flock is a more evocative target than “ALPRs”. I think it wouldn’t be a bad thing if “Flock” becomes the generic name.
This log message probably indicates when they're resetting the watchdog timer.
Flock by contrast courts local PDs who will catch a package thief or two but they really just want to have the drag net at their finger tips so that when some more equal animal's cat gets stolen they can walk back in time and figure out the short list of who could've done it.
Fixed ALPRs aren't the only privacy problem, either. Many tow trucks have roving ALPRs that feed into big databases. The notion is that it helps them repossess cars that might be garaged at home. That data, however, is for sale to third parties.
That a good watchdog kick message NGL.
It’s not even suitably encrypted on device?
Zero trust in anything Flock says.
But think the real danger in Flock is the aggregate data, tracking between camaras. So if someone hacks a single camara, they probably don't get much, unless it is pointed right at someone, which is bad. Aren't they selling these as should be pointing at traffic? If they are pointing right at people, like at playgrounds, then they are being installed illegally to begin with ?
But there is some old rule about, even the best security can fail if the device is physically accessible.
The Android documentation has an example of how to use hardware keys, and a Chinese OEM (IIRC) was found using the example key provided by Android sample code - and yet that was more effort than Flock applied, since their ARM SoC support it.
They had not admitted before to tracking people, but their software is clearly submitting them. They had not admitted before to looking at bumper stickers, but turns out they do.
I wonder if they could find all cars with Bernie Sanders bumper stickers within X blocks of a polling place.. I can imagine that (or similar queries) might be very useful in the wrong hands.
Now they are in a position where they can sell new models with enhanced encryption and more features.
For example, passing a frame of video (YUV) into the peripheral which can resize the overall image, would fail if the system was busy with other DMA transfers. You could attempt to resize again, but there were no guarantee that it would complete successfully. Your options are to reduce overall DDR utilization or drop frames. In an application like Flock's, dropping frames is likely something they need to avoid.
The system in question is doing similar tasks, and I don't think that what I'm suggesting is out of the question.
And in any case. Passing compressed video streams or pictures through HW encryption engine will not saturate 1.5+ GiB/s or whatever even the lousiest 16-bit DDR3 at 400MHz would give you, not even close. It would be like a fraction of a percent of total bandwidth.
But, a question for you: even if it was the case that the hardware was the limitation, isn't that also an indictment of Flock? Selling something that cannot exist securely within the bounds of current technology? Or, at a minimum, bad chip selection leading to a compromised design?
> The hackers said they were able to access the Android system on the camera, and found two partitions—sections of its hard-drive, essentially. A few of these were unencrypted, the hackers said, including one called “vendor” and another called “media.” The latter contained an encryption key that unlocked another part, which contained much of the media—think, the videos and stills—the camera took.
> In early 2025, security researcher Jon “GainSec” Gaines reverse engineered a Flock license-plate reader and documented flaws that could be used to gain root-level access. After Gaines disclosed his findings, the company acknowledged the findings but downplayed their severity, writing that the flaws required physical access to the device and that even someone who gained access to a camera “would still not be able to gain access to footage” because images remained on the device only briefly after being transmitted to the cloud.
Source: https://www.404media.co/hackers-stole-flocks-camera-software...
Encryption matters, even if I would divulge everything long before the wrench appeared.
At some point, the attackers are just going to have to give up and start hitting me with a wrench. Joke's on them though - I'm an Emacs user, I like pain.
It seems that some enterprising Jolly Roger could start running a public mesh net on top of them without Flock even noticing.
the Flock response has been 'it doesn't count if a Youtuber did it' lol: https://www.youtube.com/watch?v=0ADb-qQ5hMY
All that data about ... license plates if you're willing to steal/damage private property. Seems like it would be a lot easier to setup your own ALPR.
Flock cameras capture the make, model, color, and body style of vehicles. They capture bumper stickers and other decals, as well as potentially identifying dents and scratches. They capture accessories like roof racks, bike racks, trailers, and toolboxes.
The OP story covers some of this. There's more at:
https://www.aclu.org/campaigns-initiatives/get-the-flock-out
https://www.nytimes.com/2026/08/10/us/flock-cameras-can-trac...
Also, there’s way more data on there than plate data.
I think I should add a "X'); DROP TABLE Cameras;--" bumper sticker to my car now.
Couldn't resist: https://github.com/EvanAnderson/whimsy/blob/main/Drop_Table_...
- Thomas JeffersonThat kind of stuff is around but maybe not evenly distributed or legible to large demographics.
Unfortunately, so is the rest of the vicious horrorshow, equally illegible and equally uneven in distribution.
I take your point; it makes sense.
"Regular folks" is doing a lot of work, though.
It may very well be the case that most of the material world which props up the idea of "regular folks" never was capital-R Real and insofar as the idea is a pleasant dream it is not a sustainable one.
Proximate to me, often "regular folks" entail white folks unproblematically living their lives around the norms of US hegemonic capital interests. When I hear Pat the Bunny sing "show me utopia, I will call it a jail" I understand the feeling. I was, afterall, raised by Christians who believed in David Byrne's picture of "Heaven" as a place where "nothing ever happens".
Those are the folks who have happily elected a few people to replace the Flock cameras here with Axon. Their vision of an ordered society is a bit chilling to me, despite the fact that they understand their project as both liberal and progressive.
As I understand it, deviations from those cultural norms are already "dystopic" to the "regular folks" I know- if we somehow lost our ability to transmute sand into computing power and dead plants into motive power and had to go back to living in the cliff side then we'd no longer really be human, despite the fact that their enchanted sand and holy oil is literally destroying the ecology of the entire planet.
This situation is, of course, already a distopia for the bands of Ute and Jicarilla Apache and Dine and Hopi and others living near me. And when I look at the kinds of technological survellience built into the material structures it feels easy enough to note that we already live in a dystopia. I have heard some specific dakota folks refer this situation to as post-apocalyptic and I am inclined to agree.
If we accept that we're already in a dystopia and, further, that much of the hegemonic culture's idea of a "utopia" has already been a holocaust for several other groups of people, then hoping for a "dystopia" in that sense might seem a bit more coherent.
Some people are just wired that way.
Benefit of the doubt: Funding them for a community/city-owned traffic camera type thing seems like it would have been a much more reasonable proposition than funding Flock for their current use case of allowing police to stalk their ex girlfriends or mistresses.
The front page then had "All the footage is yours. Your neighborhood 100% owns the data. Flock Safety will not share, sell, or access your data."
Unfortunately, flock has been excluded from wayback, so can't see other views of that page.
{insert Darth Vader: I'm altering the deal. Pray I don't alter it any further.}
(+45m edit) https://bestpitchdeck.com/flock-safety appears to be the pitch deck from 2020.
> ...
> In 2019, Flock signed their first police department deal with Jersey Village, Texas.
> The slides you see here are from Langley's pitch at a venture conference one month before closing a $47M Series C round in November 2020. The following July, Andreessen Horowitz led a $150M Series D investment in Flock as a cornerstone of their American Dynamism practice. Additional slides are included from keynote and sales presentations used in 2023.
> ...
10 years ago is no excuse.
It was all quite plain then. And the very heavy rhetoric made it very obvious which direction things would go.
Yes. Blame the pickaxe seller. Do not question the miners. Do not question the investors in the mining companies. Do not question the casual voter or internet commenter who thought all this was fine.
This isn't to say that flock not a scourge, but I think a lot of people (not saying you're one of them) could stand to look in the mirror here.
Back in ye olde dark ages of <checks notes> 2017, when YC was cutting Flock a check and when "big data" was the hot buzzword people of a certain bent couldn't get enough of this kind of stuff. Everyone was jacking off nonstop to the idea that we could just hoover up everyone's data ad then "efficiently" or "proactively" dispatch enforcement resources. People talked all sorts of big talk about stuff like cross referencing people's Home Depot spend with permit requirements, identifying small businesses that don't have healthy enough financials to be fully compliant, cross referencing invoices and delivery receipts to identify overloaded trucks, and generally finding all sorts of ways to fine the crap out of people for the pettiest of petty deviance. They considered this a noble goal.
Everyone's head was too far up their asses to look at the magic crystal ball called "history" and realize that a camera on every street corner watching who's going where all the damn time would be where it goes.
1. Take pictures
2. Send to a big server that all cops nationwide can log into whenever they want to stalk their exes
Did I miss something
Has there been any report about which state this camera was recovered in? New Hampshire has a strict 3 minute rule for non-hit plate data before the captured images and records must be deleted [1].
[1] (N.H. Rev. Stat. § 261:75-b) requires ALPR systems to delete non-hit plate data within 3 minutes
???
> VIII. Records of number plates read by each LPR shall not be recorded or transmitted anywhere and shall be purged from the system within 3 minutes of their capture [...]
But you're saying that these non-hit image captures were uploaded somewhere?
- Camera pre-checks the picture for quality and that there's something on there that they want
- Camera uploads picture to flock servers
- Camera deletes picture locally
- Rinse and repeat
I could actually see this being done by three jobs in parallel.
If there are a lot of images found on the camera then that's probably because the upload wasn't able to keep up with the amount of data that was created or they have a buffer of a few days or there's a cronjob that deletes these files every now and then...
Unless they actually use the camera also as the storage, which would be really stupid, but sometimes people to stupid things.
I wonder what can be done within 3 minutes?
Hints at unauthorized, illegal mass surveillance riding on top of authorized (but also possibly illegal) mass surveillance
Ya know, I'm not on Flock's side here.. but be real, this is theft. You should be able to own that if you're going to do something like this.
Also, is it really justified? Did we learn anything useful here that we didn't already know? There's more effective ways to push back against Flock, townships (like my own) are having plenty of success stories without stealing anything.
Um, are you saying the hackers should admit they broke the law? Or that Flock should righteously own the data they collect?
Either way, I d/c. Flock cameras are probably insecure, and their data is potentially dangerous.
Bad laws exist, and following them may be prudent at times, but the act of following them isn't a moral imperative.
It takes time and effort to think through proper secure boot architecture and to implement key management in a way that doesn’t kill developer productivity.
Their product managers, though, should have realized that setting these up in unsecured public spaces means that their threat model really does include local physical access to everything.
Using off the shelf hardware and software stacks all but guarantees attackers have tools at their fingertips to exploit said physical access.
Given all the recent exploits hitting the kernel, there’s a good chance that there exists an exploitable over-the-air vulnerability present in their WiFi/bluetooth stack, too.
If it could lead an attacker to get ANY of their data... Persons, places, events, etc is pretty damning stuff to be exfiltrated.
Stalking/Domestic Violence, blackmail, timed robberies, you name it... That data shouldn't really be in anyone's hands in my opinion, but in anyone's hands (good guys / bad guys) it's pretty powerful.
Overall this goes from disappointing to fairly repugnant.
Those that fail to meet standards should be fired to spare the taxpayers from the lawsuits coming from AI-assisted complainants.
It’s also too much for Flock’s YC-funded technology to implement a field filter that rejects “LMAO” as a valid request.
At the very least, your local staff’s nationwide stalking credentials being harvested by phishing and abused by others should carry criminal negligence penalties. Governments should pass that liability onto this YC-funded startup company.
Large companies tend to be amoral. Unless it affects them monetarily (possibly indirectly) they're not going to care. Given what they do to make money, I don't see any of these things hurting them.
Any entity with access to flock servers can virtually stake-out anyone/everyone driving past Flock camera to monitor their movements. In a hot war, this would provide actionable data to support assassination via road-side bomb/drone strikes.
https://edition.cnn.com/2026/08/26/us/flock-kentucky-police-...
A single cop can do it 2000 times it seems before they get caught
And it's not a lone case: https://www.washingtonpost.com/technology/2026/08/02/how-pol...
I can't even imagine how difficult this job must be nowadays, with bullshit like Flock spanning hundreds of police departments participating in their nationally-linked database. I have zero sources for what I'm about to say, but my instinct is that the political machines (expanding powers hidden behind "think of the children") behind how technology is evolving today has gotten people killed.
It's madness, they often lack the technical skills and "optimise away" requirements surfaced by eng teams they don't comprehend or just don't like having to deal with.
Now, this doesn't always stops management, but when you have to have an engineering signoff it does make things a bit more difficult.
Watch some engineers in other disciplines and you soon recognise that many of them have about the same responsibility as a software engineer. Design is design.
Or read about engineering failures like flight QF32 (mostly a success story):
A paperwork review showed that the required signatures were missing from 131 out of 138 retrospective concessions issued between 2009 and 2011
https://admiralcloudberg.medium.com/a-matter-of-millimeters-...Australian Quantas, with a UK Rolls Royce engine on an Airbus, with engines maintained in Aussie.
Safety is now often made up of interlocking: regulations, standards, quality systems, safety management systems, insurance, international legal contracts. Certified engineers and signatures are usually only a very small part of those systems.
Certification matters less than you might think across international borders.
Perhaps I'm a cynic, but beliefs in certification seem so irrational to me. What is it? Jealous desires for status? Desire to have guilds/gatekeepers? Complete misunderstanding of how safety occurs in "real" engineering?
I mean, you make my point. At no point did I say engineers are the only required component, but without the responsibility of an engineer signing off on its technical adequacy we have loads of historical proof that people end up dead far more often.
That is your belief, but I've never seen that belief backed by fact.
Most open source software disowns liability in CAPS in the license. Yet somehow FOSS like Linux gets used for safety critical infrastructure.
Microsoft would love certification requirements for engineers - that would kill open source to their conpetitive benefit.
Do you honestly think if we required Microsoft Certified Professionals to sign the internals of Microsoft OS then Windows would be more secure or reliable?
The bigger issue is that signatures and criminal consequences hardly matter across jurisdictions.
The capitalist issue is that businesses want scapegoats when things go wrong. That would be the outcome of signatures: engineers as fallboys for systemic failures across organisations.
Note how often pilots are blamed for accidents due to the design of planes.
It is just an idealistic belief based on feelies that software certification would achieve the goals you imagine it would.
Signatures are an anachronism: from an alien past.
International business uses different mechanisms for safety.
Our world is intertwined complexity. You somehow think that the buck should stop at engineers?
If engineers signed off on everything then we'd have no more disasters like New Orleans floods?
Who signed what for the Grenfell towers tragedy? Which engineers were reprimanded? Did they decide that more signatures would help prevent future disasters?
If Flock had done a more competent job of securing their system, it would be harder to demonstrate this in a compelling way. To a technically-inclined person, it's obvious from the get-go that somewhere in Flock's pipeline, video is being recorded and archived, and is therefore vulnerable to misuse. But the more they're allowed to keep the implementation proprietary, the easier this is to sweep under the rug.
They fought against datacenters. Now they are running for local offices - https://www.theguardian.com/us-news/2026/sep/15/datacenters-... - September 15th, 2026
https://news.ycombinator.com/item?id=49375000 (citations)
Local politics is where you understand how effective a handful of people can truly be.
Happy to read people are understanding the true power they have collectively instead of as individuals.
That is rapidly becoming Democratic party orthodoxy. At the very least there are a sizable number of Democrats who fit that.
Adding more weirdness, the details get worked out by each state.
My guess is they encrypted whatever is criminal justice information (license plate hotlists, etc) or protected by local laws (DMV data) and left the rest to make it easier to deploy and service. Remember pictures of you or your car taken in public are not protected or in scope.
Police tech is garbage and usually driven by federal grant spending. So it’s going to be interesting to see how Flock and Axon grow the business as it turns into a service model.
They sincerely welcome your vulnerability disclosures, except in cases where you have to "interact" with the device/service or download its data. Other than that TINY carveout, everything is okay.
Oh, if the vuln about configuration and hardening "preferences" like SSL/TSL - Sorry, not interested.
And also, infrastructure vulnerabilities like DNS config - no no, try harder.
I know what you're thinking..ha ha...but we are good guys. You can still report vulnerabilities in the above categories, but the onus is on you to convince us that we should care about them. It is only fair.
https://www.flocksafety.com/legal/vulnerability-disclosure-p...
The carveouts for stuff like configuration and DNS are entirely reasonable. Have you ever been behind a security@ email before? You get a lot of BS reports of that sort.
Content is not the same as configuration and they could get valuable information if they cared.
Testing against customers is also a common prohibition for obvious reasons.
> And also, infrastructure vulnerabilities like DNS config - no no, try harder.
It's understandable. If you have or manage a website you will receive daily emails (the kind that start with 'Hello sir') about automated scans finding low-hanging fruits like that, pretending a bounty payment.
Seems like if I were a competitor of Flock I'd be pretty happy right now and all this negative press is making them artificially cheap to buyout right now.
Motorola/Vigilant, Rekor, Leonardo/ELSAG, and Axon are huge companies making mint off the same thing and no once in 20 years have I seen this level of attention... not on the overarching issue of surveillance-state-ing, but of one particular company.
You've seen this level of attention on a market leader before: on Microsoft, on Adobe, and others.
2) The US Executive branch formed concentration camps and a private army, and started using this nationwide mass surveillance network to track down any brown people with a Spanish accent to lock them up in dangerous squalid conditions and/or deport them with no trial. This is an immediate, nation-wide harm being done to millions of Americans, and this new company is enabling it.
I would absolutely assume that any system that sends your image to LE is part of a facial recognition system in practice. We know now that the cameras do recognize people and intentionally transmits images of them, for later identification.
edit: And to be clear, the cameras specifically recognize and record people for a reason. This does not appear to be a fault in the system. One reason might be off-camera facial recognition.
It seems the inevitable next step would be post-processed facial recognition (checked against those ready-for-the-taking ID photos) in their OS Investigator platform.
I wonder what would happen if one of their customers asked for a 62443-4-2 certificate of compliance?
That's why they don't give anything about the camera's security.
The images are all from a public place, so no privacy expectations and what's theworst that could happen? Someone uploads their cat images or the pr0n collection?
Ai figures that one out rather quickly.
I almost guarantee you, if the camera even has a SIM-Card then it's pre-configured with all the necessary information to find and join the mobile core network via APN.
It turns on, joins the core network, gets handed an ip address and additional information like a servername/ip as its reporting endpoint, establishes the connection and starts taking pictures that it then sorts out and uploads.
That's pretty much it. No login credentials, no complicated protocols, nothing. The things is identified via IMEI, Mac or some other burned in "serial" and that's all that's necessary to make it happen.
So there are no credentials that could get lost, no technology that would be worth anything, access is being controlled on the network side and the images that are being taken are from a public place with no expectation for privacy.
The core system only has to be secure enough so that it doesn't get hacked via an open bluetooth tty or something and everything else is handled by the network it belongs to. That's why DNS manipulation and similar stuff doesn't get you anywhere.
Besides that, it has to be cheap and doesn't have to adhere to any security standards whatsoever. It's a pole with a mini camera and a solar cell that can just be vandalized by the next person that shows up.
We have all heard the argument that when corporations intentionally make the legal option worse it drives otherwise law abiding customers to pirate the content instead because piracy provides a better service than paying the corporation for their kneecapped product.
I dont see how the same thing doesnt apply to governments.
The people tell you over and over they dont want to live under a surveilance police state. So natually the corporations and government work together to create a fascist police state and they expect the people to be good little slaves and simply sell their souls to their government.
Especially in the day of ai when they could just fake those images incredibly easily to frame someone. They dont need a patsy the next time they jfk someone they just find some sucker with a weak alibi from a list of potential suckers and then fake some cctv images and cell phone data and they can put you where ever they want to.
The only real defence is to buy your own body cam and document every moment of your life so you can have competing evidence.
At this point im surprised damaging the cameras is the only thing these activists are doing.
I wouldnt be surprised to see flock employees and corrupt politicians finding bombs under their cars. Which will likely be used to justify more cameras which will only intensify the terrorist activity.
The tree of liberty is long overdue for a good watering.
If your solution is revolution you misunderstood the problem, and you'll make it worse
We still have vestiges of democratic institutions we can use to constrain and controll the state.
The blood letting, pain and suffering you are calling for is much worse than the private power's attack on privacy, and destroys the one effective tool (what remains of your Republic) that you have to fight them
Instead of fighting to destroy your republic, struggle to protect and restore it
Probably technically true. But since the cameras detect people that makes it easier for their backend system to do face recognition.
* Privacy, civic trust, society if you get a chance!
This is the end product of tech leadership taking fat rips of disruption cocaine for the last 15 years. Flock Safety got VC money so that they could build a panopticon. There is nothing surprising about the fact that they did a hack job with terrible security; the fact that their service names are various types of alcohol is beyond parody.
Oh well, at least Flock Safety's IPO will be a critical cash infusion in the pursuit of building the torture nexus so that's cool.
It's like they have no threat model in place.
Even if we decided that this level of mass surveillance on the American public was acceptable to us, Flock Safety/Flock Group as already demonstrated that they can't and shouldn't be trusted to implement it.
Right. So expect thousands of Flock cameras to be hacked soon.
Possible perps include foreign intelligence agencies (Khamenei in Iran was tracked down for his assassination using Iranian traffic cams), stalkers, domestic violence perps tracking their victims, the list goes on....
More than likely though, multiple of the above.
It's also really annoying me that police departments around the nation are petulantly implying they were "forced" to do this because of lawlessness and silly-villain karens...also claiming, without the press even remotely challenging them, that they're disappointed because "we believe they work."
There literally isn't a single fucking shred of evidence that Flock cameras do jack shit, that isn't from a study Flock paid for, which heavily cherry-picked communities, particularly ones with very low crime rates where a Flock camera happened to be involved and the crime rate which was already low dropped by a couple crimes a year and resulted in a "200% reduction in crime."