Skip to content

Product1 publisher3 min readPublished

Hackers found the key to a Flock camera's video inside the camera

Hackers pulled a Flock camera off a roadway and copied its storage. The key to the encrypted media sat on an unencrypted partition, and the recovered logs show the device detects people and bicycles as well as plates.

The Product Desk · Product desk

Photograph accompanying Hackers found the key to a Flock camera's video inside the camera
Photo: flocksafety.com

What happened

  • Hackers pulled a Flock camera down from above a roadway, copied nearly everything stored inside it and handed the files to 404 Media and Distributed Denial of Secrets, which passed them to WIRED.
  • Several weeks of recovered logs record more than a million images from the one camera, which can produce dozens of frames of a single passing vehicle.
  • WIRED found that records from Alpharetta, Georgia's Flock cameras were reachable by more than 2,000 agencies, among them colleges, airports and the GSA's Office of Inspector General.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • constraint On-device encryption stops being a control once the device is in someone else's hands, so a buyer cannot settle the question from a spec sheet. It takes a board on a bench and someone willing to look for the key.
  • decision An agency renewing a plate-reader contract now has to decide whether it is buying plate reads or a person detector, because the class list sits in the software whatever the policy document says.
  • exposure The people walking and cycling past these cameras signed nothing and can check nothing; the searches that reach their records are run by agencies elsewhere, and the local department answers for them.
  • precedent With the teardown method published, the next set of evidence about Flock's edge security is likelier to come off a pole than out of the vendor's documentation.

The hackers said they reached the Android system on the camera and found its storage split into partitions, a few of them unencrypted, including one called "vendor" and one called "media" [5]. The media partition held an encryption key. That key opened the partition with most of the videos and stills on it [5]. Much of the reader's most sensitive storage stayed encrypted and out of reach, according to the joint analysis by 404 Media and WIRED [6].

A camera bolted to a pole has to boot with nobody there to type a passphrase, so its key has to live somewhere on the hardware. Where it sits and what guards it is the whole of the claim. Flock has described its system as protected by on-device encryption [3]; in this unit the key was a file on a partition the hackers could read [5].

"Why just destroy them when we can reverse engineer them and find the secrets of those spying on us?" one of the hackers, from a collective calling itself stegan0gram, said in an interview [10]. The group said it is also publishing details of how it obtained the software, hoping others copy the method [12]. Multiple people around the country have been arrested for allegedly tampering with Flock cameras, and one police department built a fake 3D-printed camera case to bait vandals [17].

The product is sold as a license plate reader. The software on the device explicitly detects people and bicycles as well as vehicles and plates [7], and its computer vision sometimes isolated bumper stickers and other graphics, in one case an American flag patch on a motorcyclist's saddlebag [9]. The joint analysis does not say what happens to the person detections after they leave the camera; WIRED's account says Flock's servers presumably read the plate and can identify characteristics such as color, make and model [19].

Several weeks of recovered logs record more than a million images, and one passing vehicle can produce dozens of them [8]. Take several weeks as two to four: a million images over 14 days is about 71,000 a day, and over 28 days about 36,000 a day, from a single device [18].

What a city signs for and what the search box does are separate questions. 404 Media reported that local police ran lookups in Flock's national network on behalf of Immigration and Customs Enforcement, including in places that had banned working with immigration authorities or moving plate data out of state [14], and that an officer in Texas searched Flock cameras nationwide for a woman who self-administered an abortion [15].

For anyone buying edge hardware with encryption on the spec sheet, two questions have checkable answers. Where is the key when the device is in someone else's hands, and what protects it there? And what is the detector's full class list, including the classes the product is not sold on? A vendor can put both in writing, and both can be compared against a board on a bench. The cost of asking is that the honest answer may be the one the recovered data gave here: the key was stored on the same device as the video it unlocked [4].

Flock has heard about this class of problem before. In early 2025 the security researcher Jon "GainSec" Gaines reverse engineered a Flock license plate reader and documented flaws that could be used to gain root-level access; WIRED reports that the company acknowledged the findings but downplayed their severity [16].

What to watch

  • Whether Flock disputes the joint analysis or moves device keys off readable partitions in a firmware update.
  • Whether the published teardown method produces copycat dumps from other cameras, and more tampering arrests.
  • Whether any agency renewing a Flock contract asks for the detector's full class list in writing.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories