Logo

One Camera Was Taken Apart — What Hackers Found Inside Is Raising Bigger Questions About Flock

Preview

WASHINGTON — A physically removed Flock Safety surveillance camera has given researchers an unusually detailed look inside a system designed to monitor vehicles, revealing that the technology can detect people and retain far more data than many users may realize.

The Camera That Revealed the System

In September, a hacker collective calling itself stegan0gram physically removed a Flock camera positioned above a roadway and copied much of its internal storage.

The material was then provided to WIRED and 404 Media, which analyzed the device's software, logs, videos and images as part of a joint investigation. 

The episode is significant because it did not involve a remote break-in to Flock's cloud platform.

Instead, the hackers obtained physical access to one camera, reverse-engineered its hardware and recovered data stored locally on the device.

Millions of Images From One Camera

The recovered logs showed that the camera recorded approximately 50,200 vehicles and generated roughly 1.6 million images during about 21 days of activity.

A typical passing vehicle generated around 28 images, while some vehicles produced more than 100 separate images as they moved through the camera's field of view. 

The device also contained 27,321 short video clips, giving researchers an unusually detailed picture of what happens before information is transmitted to Flock's servers.

The numbers would vary depending on traffic and camera placement, but the findings demonstrate how quickly a roadside surveillance device can accumulate visual records.

People Were Part of the Picture

One of the investigation's most notable findings concerned the camera's computer-vision software.

Although Flock's technology is primarily marketed as an automated license-plate reader, the software recovered from the camera explicitly included a detector for people, as well as vehicles, bicycles and license plates. 

When the system detected a person, it recorded the person's location within an image and a confidence score indicating how likely the software considered the detection.

WIRED also tested the recovered models against images and thousands of video clips stored on the camera, confirming that the software could detect people under certain conditions. 

That Does Not Mean Facial Recognition

The findings require an important distinction.

WIRED and 404 Media reported finding no evidence that the camera's software was actively using facial-recognition technology. Flock has also said its cameras do not perform face recognition. 

Instead, the concern involves the broader ability to identify and analyze objects and movements captured within the camera's field of view.

The investigation found that the system could sometimes isolate bumper stickers and other graphics, even mistakenly treating an American flag patch on a motorcycle as if it were a license plate. 

The Encryption Discovery

The most consequential security finding involved encryption.

Flock has said its cameras use on-device encryption to protect locally stored footage. However, investigators found that the hackers recovered an encryption key from the camera itself. 

That key allowed them to unlock thousands of stored video clips.

The discovery does not establish that Flock's cloud network was remotely breached or that attackers gained access to the company's entire customer database.

Instead, it demonstrates that physical access to an individual camera could expose locally stored material.

How the Tracking System Works

The investigation also provided a clearer picture of the technology's architecture.

The camera captures multiple images of passing vehicles, selects useful frames and transmits the information through a cellular connection to Flock's servers.

According to the analysis, the camera itself does not appear to perform all of the sophisticated identification work. Vehicle characteristics and license-plate processing appear to occur on Flock's backend systems. 

The resulting records can then become searchable by law-enforcement agencies participating in Flock's network.

A Nationwide Network

Flock's technology operates on a much larger scale than a single roadside camera.

The Washington Post reported in August that Flock had more than 120,000 cameras across more than 6,000 communities, creating an extensive network of automated vehicle surveillance. 

In one example examined by WIRED, records from cameras in Alpharetta, Georgia, were accessible to more than 2,000 agencies participating in the broader network.

That network effect is central to the company's appeal to law enforcement — but it is also a major source of privacy concerns.

From License Plates to Movement Patterns

Earlier WIRED reporting found that Flock's newer investigative software can analyze camera records to identify vehicles that repeatedly travel together or search for vehicles based on movement patterns. 

The system can also combine camera information with police records and commercial databases, potentially connecting vehicle observations with names, addresses and other identifying information.

Flock says some of these newer capabilities are still being developed and tested with selected law-enforcement partners. 

Misuse Has Become Another Problem

The security revelations arrive amid a separate controversy involving how officers have used Flock's surveillance network.

The Washington Post reported that dozens of law-enforcement officers had allegedly misused license-plate readers to monitor romantic partners, former partners and acquaintances.

In September, five Indianapolis police officers were criminally charged following allegations involving improper use of Flock's system. 

Flock has responded by introducing stricter oversight measures, including requirements intended to make searches easier to audit.

Communities Are Reconsidering the Technology

The controversy has also prompted some local governments to reconsider their contracts.

On October 1, the El Paso County sheriff in Colorado announced that his department would stop using Flock cameras, citing concerns about the technology's future and anticipated legal changes. 

San Francisco officials have also proposed tighter restrictions on access to automated license-plate data, including shorter retention periods and additional approval requirements for older records. 

Meanwhile, lawmakers from both parties have proposed legislation addressing warrants, data access and restrictions surrounding Flock surveillance.

Flock's Response

Flock has disputed descriptions suggesting that its cloud infrastructure was hacked.

The company previously stated that its cloud platform had not been compromised and that it had not experienced an incident involving attackers accessing or exfiltrating customer data. 

Following the camera investigation, Flock said unauthorized removal and tampering with cameras is illegal and pointed researchers toward its vulnerability-disclosure process.

The company also maintains that it takes security seriously and encourages researchers who discover vulnerabilities to report them directly. 

The Bigger Question

The latest investigation therefore does not show that hackers remotely broke into Flock's entire surveillance network.

What it does show is that a single physically compromised camera contained substantially more information than the public-facing description of a simple license-plate reader might suggest.

The discovery also highlights a difficult distinction between what surveillance technology is designed to identify and everything its sensors can technically observe.

What Happens Next?

Flock says it continues to strengthen security, while law-enforcement agencies and lawmakers are debating how surveillance data should be collected, shared and retained.

The company's own security-advisory page, last updated September 15, says it has not yet published a security advisory under its vulnerability-disclosure policy. 

For privacy advocates, the camera investigation provides new evidence for tighter controls. For law enforcement, the technology remains a tool for locating vehicles and investigating crimes.

The striking part of the story is not simply that hackers got inside one camera — it is that opening a single device revealed just how much information can accumulate behind a system built to watch the road.

 

Comments (0)

Loading comments...