Hackers reveal how Flock cameras really track cars and people
Ars Technica Dhruv Mehrotra, Joseph Cox, wired.com ● Covered by 3 sources
Hackers copied a Flock camera’s storage and found it tracks more than plates. The files show it also flags people, bikes, and even tiny details like stickers.
Based on reporting by Ars Technica, Dhruv Mehrotra, Joseph Cox, wired.com — read the original for the full story.
Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error
Hackers tore a Flock camera off a roadway, copied almost everything stored inside it, and then handed the material to 404 Media and WIRED. The result is a rare peek at a system Flock has said is protected by on-device encryption — and a much clearer picture of what the cameras actually record and infer.
The most striking part is how much the device itself still knew once the hackers got to it. They were able to recover an encryption key stored on the camera, unlock videos tied to thousands of vehicle detections, and share the data with the transparency nonprofit Distributed Denial of Secrets, which passed it along to WIRED. Much of the license-plate-reader’s most sensitive storage stayed locked away, but not all of it did.
According to the joint analysis by 404 Media and WIRED, the software on the camera explicitly detects people, vehicles, license plates, and bicycles. That matters because this isn’t just a system that spots cars and logs tags. It is also making judgments about human presence.
The recovered logs also show the camera can spit out dozens of images of a single passing vehicle, and over several weeks it generated more than a million images. In some cases, its computer-vision software picked out small visual details too, including bumper stickers and other graphics. One example: an American flag patch on a motorcyclist’s saddlebag.
The hackers say they plan to publish how they got the software as well, hoping others will repeat the process. That turns this from a one-off breach into a template, which is the part anyone running or defending this kind of system should be losing sleep over.
My take — AI-written commentary, not fact-checked reporting
This is the sort of privacy story that keeps proving the same point: once a company sells “safety” cameras, the software quietly grows legs. The real trick isn’t spotting a car; it’s how quickly plate readers turn into people readers with a very expensive vocabulary. That’s the old surveillance business model in a fresh coat of paint.
Read more about this at: Ars Technica