Skip to content

Security1 publisher2 min readPublished

Hackers unlocked thousands of Flock detections with a key found on the camera itself

A joint 404 Media and WIRED investigation says the recovered Flock unit also ran software that detects people, and Washington DC's police union says Internal Affairs used the same plate feed to follow officers under investigation.

The Watch · Security desk

Photograph accompanying Hackers unlocked thousands of Flock detections with a key found on the camera itself
Photo: malwarebytes.com

What happened

  • The DC Police Union says it learned in July that MPD Internal Affairs investigators had used Flock plate data to track sworn officers under investigation without telling them.
  • MPD says its position is that using plate-reader data in the misconduct investigation was appropriate, and that the labor dispute is going to arbitration.
  • WIRED found that plate records from Alpharetta, Georgia were accessible to more than 2,000 agencies, among them colleges, airports and a federal inspector general's office.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • capability With person detection already running on the device, closing the distance between a plate history and a person history is a question of configuration and access.
  • exposure A city that joins a Flock sharing pool exports its own governance: Alpharetta's records were reachable by more than 2,000 agencies whose search justification and audit practices it does not set.
  • decision Buyers now have to specify tamper resistance and key custody in the contract, because a vendor claim of on-device encryption did not survive one camera being unbolted.
  • precedent Arbitration will decide whether Internal Affairs needed separate authorization for those queries, and the party that got a formal channel to contest a Flock search is a police union.

The key was on the camera. A group of hackers reportedly pulled a Flock unit off a roadway and copied its storage. From that same storage they recovered an encryption key, and it opened video of thousands of vehicle detections that Flock says on-device encryption protects [3][4]. Flock said it could not assess the claims without more detail [5]. Anyone who can reach a pole and remove a unit inherits what the unit stored, and the finding turns on that physical access [12].

The recovered files also carried software models that detect people, alongside vehicles, bicycles and license plates, according to the joint 404 Media and WIRED investigation [2]. The researchers found no evidence that face-recognition features were actively used [6]. So what the files show is a person class in an object detector, running on hardware sold to police for finding stolen cars and wanted suspects [1]. The retention schedules and search-audit language for these systems were written around plate reads.

In Washington, the argument is about who gets searched. The DC Police Union says it learned in July that Metropolitan Police Department Internal Affairs investigators had used Flock plate-reader data to track sworn officers under investigation without their knowledge [8]. The union filed a complaint and asked the department to stop, arguing that MPD lacked adequate controls for a system with that much surveillance capability [9]. The dates of the searches have not been reported. MPD defended the use, saying its position is that the use of plate-reader data in the misconduct investigation was appropriate, and said the labor dispute is headed to arbitration [10].

WIRED found that records from the city of Alpharetta, Georgia "were accessible to more than 2,000 agencies, including police departments, colleges, airports, and, inexplicably, the Office of Inspector General for the federal General Services Administration" [7]. So Alpharetta writes the retention, justification and audit rules, and more than 2,000 agencies can query the records those rules cover.

The hacker account reaches the public through the investigation and Flock has not confirmed it [5]. Nor does the reporting show the person-detection models being used to assemble histories of named individuals. The recorded harm alleged so far is the DC case, where the tracking was done with plate data by the officers' own department [8].

Malwarebytes, which wrote up both reports, argues that a network recording repeated sightings can expose where someone lives, works, worships or seeks healthcare. Match a person to a vehicle, it says, and vehicle tracking becomes person tracking in practice [13]. Its recommended controls include documented investigative justification before a search and independent security assessments covering key management [11].

What to watch

  • Whether Flock confirms or disputes the key-recovery account, and whether it changes where camera keys are stored.
  • The arbitration outcome in the MPD dispute, and whether it produces written rules for Internal Affairs plate queries.
  • Whether any Flock customer city publishes an audit showing which of the 2,000-plus agencies actually queried its records.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories