A hacker collective physically removed a Flock Safety automatic license plate reader camera, extracted its storage, and recovered an unencrypted encryption key that unlocked video data. Analysis of the dumped files shows the device captured 1.6 million images of roughly 50,000 vehicles over 21 days, with each vehicle generating ~28 photos on average. Critically, the software explicitly detects people (not just plates), isolates graphics like bumper stickers and flag patches as false positives, and runs ~20 Flock-built apps on Android. The device itself doesn't read plates—that happens server-side. The breach undercuts Flock's claims about on-device encryption protection; the hackers bypassed it by finding unencrypted partitions ("vendor" and "media") where a key sat in plain view. The source notes this is one camera; scale varies by installation. Flock disputes the severity and declined detailed technical comment, pointing to their vulnerability disclosure policy instead. This is genuinely about the *physical* attack surface and what happens when threat models assume devices stay mounted and untouched.
reply