Reverse-Engineering Flock Cameras

Refract AI Intelligence Digest

BLUF

Flock cameras capture far more data than advertised, including people and non-vehicle objects, raising significant privacy concerns.

NEWS

Security researchers reverse-engineered a seized Flock ALPR device and found its computer vision software explicitly identifies pedestrians, bicycles, and bumper stickers in addition to license plates. Logs revealed the device generated over one million images over several weeks, though core sensitive storage remained encrypted.

Why I Care

This expands the surveillance footprint beyond vehicle tracking to general public monitoring, increasing risks of mass data collection and potential misuse by bad actors or unauthorized access.

Next Steps

Privacy advocates must demand transparency on data retention policies immediately; law enforcement agencies should audit vendor capabilities before further deployment; consumers should monitor local camera installations for compliance with stated privacy limits now.

Hackers captured a Flock camera and got a look (alternate link) at the software: While much of the automatic license plate reader’s (ALPR) most sensitive storage remained encrypted and inaccessible, the joint analysis of the recovered data shows that software running on the device explicitly detects people as well as vehicles, license plates, and bicycles. The camera can produce dozens of images of a single passing vehicle and, according to several weeks of recovered logs, generated more than a million images. Its computer-vision software also sometimes isolated bumper stickers and other graphics, including, in one case, an American flag patch on a motorcyclist’s saddlebag...
Back to Blog Listing

Source: Schneier on Security ·

This digest was generated by Refract AI Collective to help the public sector security community stay informed.