news.mlab.sh
Back to the feed
vulnerability

Reverse-Engineering Flock Cameras

Medium
Summary

Hackers successfully reverse-engineered a Flock camera, discovering it not only tracks vehicles and license plates, but also actively identifies people and bicycles. The camera's software generates a massive amount of data, revealing concerning capabilities beyond basic surveillance, due to poor security practices.

A Flock camera was reverse-engineered, exposing significant capabilities beyond its stated function as a simple license plate reader. The analysis revealed that the camera’s software is capable of identifying people and bicycles in addition to tracking vehicles and license plates. The camera’s computer vision software was able to isolate details like bumper stickers and even an American flag patch on a motorcyclist’s saddlebag, demonstrating a level of detail and analysis exceeding typical surveillance equipment. The recovery of logs indicated the camera generated over a million images of passing vehicles. The vulnerability stemmed from a poorly designed security architecture, where an unencrypted partition contained the key to an otherwise encrypted partition, bypassing the intended security measures.

Read the full article at Schneier on Security