Hackers dismantle Flock camera to see what makes it tick

Share This Post

A Flock camera is mounted to a pole

As anti-surveillance activists around the country have taken to physically tearing down Flock cameras and automatic license-plate readers, one hacking group decided destruction wasn’t enough.

According to reporting by 404 Media and WIRED, a hacker collective calling itself stegan0gram removed a Flock camera above a roadway, copied nearly all the data stored inside it, and turned the files over to journalists for analysis in a joint investigation between the two outlets.

The breach cracked open a system Flock has long described as secured by on-device encryption.

404 Media and WIRED reported that the hackers found two unencrypted partitions on the camera’s internal storage — one holding vendor files, the other holding media — and that the media partition contained an encryption key that unlocked most of the footage the device had recorded. The material was also shared with the transparency nonprofit Distributed Denial of Secrets, which passed it to WIRED for the joint review.

What’s inside a Flock camera?

Once inside, the outlets found that the camera runs on a processor comparable to a midrange smartphone and operates around 20 Flock-built applications handling everything from motion detection to image classification and remote updates, according to the joint analysis.

Contrary to some assumptions about the system, the software on the camera itself doesn’t read license plates or identify a vehicle’s make, model, or color — that processing happens later, on Flock’s own servers, after the device transmits its photos, WIRED and 404 reported. The outlets also reported that the camera’s recovered logs covered roughly three weeks of activity, which showed the camera photographing over 50,000 vehicles and producing 1.6 million images.

Perhaps most notably, the analysis confirmed the camera’s software explicitly detects people, not just cars and plates — logging where a person appears in frame along with a confidence score, a capability 404 Media described as largely absent from public discussion of the devices.

A Flock spokesperson told 404 Media that removing and tampering with its cameras is illegal, and said the company had received no vulnerability report through its official disclosure process, leaving it unable to fully evaluate the hackers’ claims. Flock maintains its cameras don’t perform facial recognition, and the outlets said they found no evidence of active facial-recognition capability beyond features built into the Android operating system by default, which did not appear to be enabled.

The individual camera is only part of the picture. As reported by WIRED, Flock’s system routes captured data to a searchable national database, allowing records from a single city’s cameras to be accessed by thousands of outside agencies — police departments, universities, and airports, among them.

404 Media has previously reported that this network was used by local police to run searches on behalf of ICE and, in one case, to help track down a woman who had self-administered an abortion, controversies that have fueled the broader backlash against the cameras.

Subscribe The Newsletter

Get updates and learn from the best

More To Explore

Do You Want To Stay Connected?

drop a line and keep in touch