Surveillance Camera Security? It’s Completely Flocked!

Surveillance cameras from Flock Safety have become a controversial privacy battleground, as the communities in which they are installed wake up to their sinister potential, and stories roll in of law enforcement professionals abusing their access. One has had its disk contents dumped, and we’ve been treated to some insights courtesy of [Micah Lee]. In short: their approach to security is deeply flawed.

It’s interesting to find that instead of a custom hardened OS, these devices run Android. Not just Android, but Android 8.1, a long out of support version originally released in 2017. This is is the year Flock Safety was founded, which may or may not be coincidental. Like any old version of a widely used operating system it has a host of known vulnerabilities, none of which are patched on this version.

The Android version is small beer compared to the revelation that they contain a hard-coded and very open-access API key that can be used by any mildly curious miscreant to reveal information from any Flock camera using its MAC address. One would hope that a product marketed for use by law enforcement might have paid attention to such a basic lapse, but it seems not. Whether or not this can be corrected by a software upgrade and the leaked key deactivated without turning off the network depends on whether thy can do upgrades tailored to specific devices, but either way we wouldn’t like to be the team tasked with fixing that one.

In a way it’s reassuring that the surveillance apparatus when it came was so incompetently managed, and we hope that these vulnerabilities will have moderated its effect. We’re sure more tasty discoveries will emerge as investigations proceed, and we’ve got the popcorn ready.

Image: Tony Webster, CC BY 2.0.

61 thoughts on “Surveillance Camera Security? It’s Completely Flocked!”

  1. So, does that mean there is a way to cause the cameras to ‘self destruct’ by just accessing them remotely and gaining control?

    An OTA command to nuke the OS, and maybe boot partitions?

    That’s definitely not something anyone with the knowhow should ever attempt…..

    1. Before you heavy blame a company like that. I’ve already experienced multiple times where a company asked for a quick prototype. Then we made a quick prototype with the very large warning “NOT FIT FOR PRODUCTION”. And then, they took it to production, and surprise, there are issues. You quote what it would take to do it proper, but they don’t want to spend that. And thus hire a different firm to do some changes.

      And lying to your customers is cheaper then doing proper engineering. So just fix the immediate issues that pop up and say very loudly that you take security seriously.

      1. ^ this, getting an MVP working for a tech demo / initial testing is 1/10th the work of building the fully secure and proper version but once the customer has the MVP and decides to just sell it you’re basically done.

        1. MVP means Minimum Viable Product. Sadly, Marketing and Sales–and the C-suite–too often tale that as another way of saying “Ready To Ship”. Let’s face it, here’s a fundamental disconnect between Engineering, who often take MVP to mean something that they can use as their product development launch point, and Marketing and Sales, who meant something they would sell. Of course, M&S’s job is to make people buy what-it’s-claimed-to-be.

      2. The greedy bastards never learn, only quick money matters for them. They sent all knowhow to China because it was cheaper to make stuff there, and now China is kicking their behinds and taking their market share. Classic.

  2. I’m from Europe and was under the impression that in the US there are quite strict cyber security regulations in place when you want to sell your products.
    If the security of these cameras is so bad what keeps a bad actor (like an adverserial state actor) from accessing the camera network and track all the important persons?

    1. If your company sells products to the U.S. government, you are required to comply with the minimum cybersecurity standards set by 52.204-21 Basic Safeguarding of Covered Contractor Information Systems. If your company produces products used by the Department of Defense (DoD), you may be required to comply with the minimum cybersecurity standards set by DFARS if those products aren’t commercially available off-the-shelf (COTS).
      I think you may be confusing the rules for selling to the federal government with products generally, which also can vary from state to state. I’m suppressing a cynical smirk, and won’t ask where you got your impression. Caveat Emptor, “buyer beware”, is doctrine in U.S., part of Common Law. So I guess as a European you can feel free to sell cheap crap here!

  3. Unrelated to this but I’m enjoying the recent flurry of DIY youtube videos on the most effective portable power tools for rapidly cutting through any annoying metal poles on your own property.

  4. I really don’t see a problem with having these cameras. There aren’t enough police officer’s to go around. And the ones we have, almost always arrive well after the crime. They take any witness statements, file a report. These cameras may help them. Most criminals will keep committing similar crimes until caught or killed. I’d prefer not to be the next victim. We’ve had cameras everywhere for decades. Most retail have them inside and out. Whole lot of home have them covering most of their property, some get the streets, even neighboring properties. Doorbell cameras. Not to mention most phones have cameras. Do we really expect privacy in public spaces? Seems like it’s the liberals protesting Flock cameras the most. But, they’ll protest most anything. Hate them until you need them.
    It is concerning that these could be accessed wirelessly by most anyone, once the How-to is put online. But, it’s also nice to know that they kept the price down, since we all are paying for them, and the replacements. Protestors mainly physically damage them. Personally, I’m not doing anything in public, that should be of concern to anyone. If I was ever accused, a Flock camera might be a friendly witness.

      1. No doubt you are. How much are you paid to be a “protestor” ?

        Everything stated is accurate & factual.

        Seems absurd to complain about it when an average smart phone with it’s OS, is 100% collecting data. Not to mention voice prompted, on 24 x 7 listening devices that send reams of data to – gasp ! – a “data center”.

        The majority of people are fools.
        If they weren’t, they’d be fiscally independent thinkers not easily influenced
        by – tik tok “influencers”, and mass mob think (instigated by organizations that
        have a stake in sowing disharmony among the peasants).

        1. And you think we aren’t just as upset at the data collection happing in other modern spaces? That’s not the case. I’ve gone to great lengths to cut out google and other’s data mining systems from my life. I don’t personally think bulk data collection on others is ethical, especially when it’s use to profile and influence them.

          Comparing flock cameras to a random person’s personal camera though is extremely disingenuous. One is hooked up to a national servalence network with far too little oversight and a track record of abuse; the other is not.

          Same difference between a store running their own cameras and just holding onto the footage from the last month in case they need to reference it. For a long time that’s all security cameras were. Now they’re becoming tracking and profiling tools.

          It’s not so much the physical camera itself I have a problem with. It’s the system it feeds that data too. That’s why flock has been getting so much attention lately.

    1. @Harvey. You have profound privilege of never being the ire of someone in power.

      Congratulations.

      Flock cameras (or any privacy eroding tool) are “wonderful”, until they are misused. And we all know nothing EVER gets misused.

      1. Guess what, I have everything to hide, absolutely everything: my personal data and my life are my own business and nobody else’s. If that makes me a criminal, a terrorist or whatever, please let your own government (or mine for that matter) waste taxpayers money to track me together with millions of people fed up with being spied upon. I hereby give permission to HAD to give my IP and time of connection to any law enforcement organization requesting it, no need for a gag order, just give it to them. Home contract, public IP, no VPN used.
        Enough of that “if you have nothing to hide” nonsense, really.

    2. This is ridiculous to see such an obvious paid shill on here defending their orwellian nightmare as “it’s liberals problems”. Yes, I have an expectation to privacy, to not be tracked across state lines by whoever finds it convenient to do so for whatever reason without my control and permanent holding of my data doing so, it’s people like you who are destroying society for a buck for everyone, get off of this site. I don’t want to see what happened to Slashdot happen to Hackaday.

    3. It’s not just liberal-leaning people, but, even if it was, they’re right. And ” it’s also nice to know that they kept the price down”… I don’t know about you, but, I’d call $3k/each a bit excessive.

      1. Yeah, the use of “liberal-leaning” got me to wondering if I know what liberal means. I would have expected the opposite to be true if there were actually a bias among the “anti” crowd. In a (US) political context, I would buy “Liberterian-leaning” for sure.

    4. If I was ever accused, a Flock camera might be a friendly witness.

      A Flock “witness” led to false murder charges against a woman in Florida, who spent 13 days in jail.
      A Flock “witness” led to false fraud charges against a woman from Tennessee, who spent 6 months in jail.
      A Flock “witness” led to false theft charges against a woman from Colorado.
      On more than one occasion, Flock “witnesses” have identified journalists driving vehicles loaned to them by their manufacturer as having stolen the vehicles because the license plates were misread. At least one of them was arrested at gunpoint.

      All of the above had the normal presumption of innocence turned upside down, forcing them to prove their innocence.

      Not to mention the over 50 police officers so far who have been caught using Flock to stalk their exes.

      These and other egregious incidents are why Sen. Josh Hawley – a Republican – has opened a Senate investigation into Flock.

      1. Yep. Opposing dragnet level mass survalance is not and should not be a partisian issue. I’ve seen people from many different backgrounds, left and right, express great frustration with this direction our nation is moving.

        Unless your party is “authoritarian” that is

    5. How much are they paying for posts like this?
      If they aren’t paying, please read a bit more on this subject.
      If you do and still think this, please seek help.

      There is more than one report of cops using this to stalk women. That by itself shows that this sort of thing can’t be allowed.

      Combine that with our right to some level of privacy even in public as the Supreme Court has ruled and this sort of thing cannot be allowed to exist.

    6. If you don’t want to be a victim of criminals, learn to protect yourself. You don’t get to snoop on everyone else’s business just because you’re unfit, untrained, and a coward. And yes, now that you mention it, I do expect privacy in public spaces. I would support laws forbidding public photography of human beings, which is something I never had the need to think about before.

    7. It was the grocer’s apostrophe that told me a lot about this commenter.

      Yes, there is no reasonable expectation of privacy in a public space, the corollary of “a man’s home is his castle” and the need for warrants, ie probable cause, to search it. But the daily stories of abuse by “police officer’s” stalking their exes or whatever isn’t something only liberals should be concerned about.

      As noted elsewhere in comments, false positives by these systems — the woman who was extradited and held in North Dakota, where she had never been, for bank fraud based on a poor photo match, is the most recent one I saw — suggests “police officer’s” are relying on them in place of the diligence the commenter seems to give them credit for.

      Would the commenter be willing to sit on a street corner and note all the cars that passed and photograph all the faces? Would he be willing to have someone else visibly doing that? Is that better or worse than a video feed going into a black box system that no one oversees?

  5. Well, without the security flaws we might not know how this data collection works, how it is abused. Unless you’re in a “I was happily oblivious, I wish Flock would have been more competent.” state.

    All of this data collecting needs more transparency, and not in an EU telephone book sized pop up, that nobody can read. There has to be some accounting, “Your data was used X times and made someone Y money.” Clearly it’s worth something to someone, but they’re not telling.

    After “we” understand this, maybe there can be some laws that work. But with these weak governments (strong on talking points or non voter bashing does not count), that’ll not happen.

    1. I don’t think there’s money changing hands in a way that even IS accountable. What I’ve read about is about bad actors in law enforcement, who would skirt “Your data was used X times” no matter how phrased in a regulation. And I shudder to think of what you mean by “weak gov’ts”. In the US we have this whole system of state vs federal jurisdiction that purposefully weakens both. We kinda like a “weak government,” and not just conservative ideologues. Our basic outlook is to never give such power to the police or political actors(elected or appointed) in the first place -nor military, although that has been breaking down since 9/11. I don’t really think “transparency” is even possible! I’m not opposed to letting the law demand access to recordings by private companies, I realize how useful this can be to police and the courts to prosecute criminals. But I will never trust police or governments(local esp, but state and federal too) to use footage from cameras in public places. Never, never, never.

  6. unfortunately every human endeavor is always operating at the frontier trouble. as long as no one is exploiting it, they can leave the doors open. once exploits are popular, they will fix them, or their competitors will eat their business. the fact that flock’s engineers are stupid or lazy is only a very brief advantage.

  7. Android 8.1? Whoa.

    That means it’s likely a QC APQ 8009 CPU. Hugely popular back in the day.

    Why? That’s when Qualcomm went all-in for IoT and cameras prices plummeted to why we have so many door bell/amzn/netst/ring/flock/clones, etc.. today. That also means there likely a Bluetooth stack and even wake word processing available on those cameras.

    source: used to program on those APQ8009s…

    1. There definately is a Bluetooth stack. And a WiFi stack. They use it to log the transmit IDs of every device they see and create a map of where specific people have been. Even if the camera never ‘sees’ you; just walking past them on a sidewalk is enough.

  8. Honestly, the thing that worries me the most about this is the idea of somebody hacking these cameras and silently modifying evidence to implicate innocent people in crimes they did not commit.

    Data from the camera would be pretty hard to disprove in court. Could be quite scary.

    1. Yep.

      One thing these cameras do is log the presence of cellphones nearby by listening to wireless signals. Most phones happily emit their Mac address over WiFi or Bluetooth here and there.

      You could easily frame a specific person as being somewhere at a certain time.

    2. RE: Data from the camera would be pretty hard to disprove in court.

      Not in all states. Delaware is one of the few states that has a law that stipulates that, unless given a specific permission by the person, data collected cannot be used as evidence in court.

      That’s why Delaware courts have so many out-of-courtroom settlements, sometimes entities/companies cannot prove themselves collecting relevant data legally, and average Sam can also counter-sue them for the invasion of privacy (and likely to win, btw, but, of course, it may take few years of average Sam’s life proving that he is right, and companies also never ever forget who sued them and won; companies’ legal memory easily outlasts 100+ years in total and they can wait for Sam to die of old age, while technicalities are being spelled out in smallest legal nanodetails possible under the sun and the galaxies and all the visible stars combined).

      Meaning, things like non-authorized recordings without consent are likely to be dismissed in court – given one is quite sure he is not breaking any laws (too much – don’t forget gazillion unenforceable laws/regulations lurking everywhere undetected – unless suddenly needed). I do not like this being a double-edged sword, ie, all kinds of entities/ppl regularly abuse the mentioned law, but it gives ordinary Sam at least some leverage against faceless.

Leave a Reply

Please be kind and respectful to help make the comments section excellent. (Comment Policy)

This site uses Akismet to reduce spam. Learn how your comment data is processed.