Product1 publisher3 min readPublished
Pull a Flock camera off a pole and the decryption key comes with it
A hacker group calling itself stegan0gram took a unit down, copied its storage and handed the files to 404 Media and WIRED, who found the key to most of the recorded footage on an unencrypted partition.
The Product Desk · Product desk

What happened
- A hacker collective calling itself stegan0gram removed a Flock camera from above a roadway, copied nearly all the data stored inside it and handed the files to 404 Media and WIRED for a joint review.
- The two outlets found two unencrypted partitions on the camera's internal storage, and the one holding media also held an encryption key that unlocked most of the footage the device had recorded.
- Flock told 404 Media that removing and tampering with its cameras is illegal and that it had received no vulnerability report through its official disclosure process, leaving it unable to fully evaluate the claims.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- exposure Every installed unit carries its own key, so the security line in a city's contract holds only for as long as nobody with a ladder wants the footage.
- decision A buyer who accepted "on-device encryption" as a control now has a different question to put at renewal: where the key sits relative to the data, and who verified it by opening a camera.
- constraint Since the recognition runs on Flock's servers, a city cannot narrow what gets collected by changing what the box does; the images have to leave the pole to be read at all.
- contradiction The same review that undercuts the encryption claim backs Flock on facial recognition, so a council reading it gets one finding to act on and one to set aside.
Whether on-device encryption protects anything depends on where the key sits. The stored files on this unit were encrypted; the key that opened most of them was on the same device, on a partition that was not, according to the joint analysis by 404 Media and WIRED [4].
A vendor saying footage is encrypted on the camera implies that a stolen camera is a brick. The two outlets got about three weeks of images out of this one, plus the means to read them [8][4]. Flock has long described the system as secured by on-device encryption [3], and the copied files also went to the transparency nonprofit Distributed Denial of Secrets, which passed them to WIRED [5].
Over roughly three weeks, the logs from this single pole show the camera photographed more than 50,000 vehicles and produced 1.6 million images [8]. Divide the images by the vehicles and you get about 32 frames per vehicle, and because the vehicle count is a reported floor the real figure is somewhat lower [1]. Spread across 21 days, that comes to roughly 76,000 images a day from one location [2].
The device sold to read license plates does not read them: the photos go to Flock's servers, and the plate, make, model and color are worked out there [7]. On the camera sit about 20 Flock-built applications handling motion detection, image classification and remote updates, on a processor comparable to a midrange smartphone [6]. One of those functions detects people and logs where a person appears in the frame along with a confidence score, a capability 404 Media said has been largely absent from public discussion of the devices [9].
WIRED reported that Flock routes captured data to a searchable national database, where records from one city's cameras can be reached by thousands of outside agencies, among them police departments, universities and airports [12]. 404 Media has previously reported that local police used the network to run searches on behalf of ICE, and in one case to help track down a woman who had self-administered an abortion [13].
A Flock spokesperson told 404 Media that removing and tampering with its cameras is illegal, and said the company had received no vulnerability report through its official disclosure process, which left it unable to fully evaluate the hackers' claims [10]. On facial recognition, the review supports the company. The outlets reported no evidence of active facial-recognition capability beyond features built into Android by default, and those did not appear to be enabled [11].
For anyone who has to answer for one of these installations, the useful exercise is narrow. Each security sentence in the contract needs the test that would prove it false, and a name attached to whoever ran that test. A claim that footage is encrypted on the device fails if the key is on the device, and someone has to open one to find that out. The second question, which the recovered files answer for this unit, is what the box does that the product description never mentions. Activists around the country have been physically tearing these cameras down [1].
What to watch
- Whether Flock moves the decryption key off the device, and whether it examines the recovered files and responds to the findings.
- Whether any city with a Flock contract asks for an independent physical test of the on-device encryption claim before renewing.
- Whether person detection with confidence scores appears in Flock's product documentation or contract language now that it is public.