UpTrajectory Review
A team of hackers got physical access to a Flock automated license plate reader camera, cracked it open, and walked away with an encryption key, roughly 27,000 video clips, and 1.6 million images — all generated by that single unit in just 21 days. That is the entire substance of the TechRepublic item, and it is thin even by news-brief standards. But the numbers alone carry the story: one camera, three weeks, and a data haul large enough to reconstruct the movements of thousands of drivers. Flock Safety has built a business installing these cameras in neighborhoods, on commercial properties, and along roadways across the country, marketing them as a crime-fighting tool. This incident suggests the hardware protecting that data may not be as hardened as the pitch implies.
For a small-business operator, this is not an abstract security story. Plenty of SMBs have installed Flock cameras in their parking lots, loading docks, and gated entrances — often at the urging of insurers, landlords, or local police partnerships — on the assumption that the vendor handles the hard security work. This breach says otherwise. If you operate a camera system that collects footage of customers, employees, or passersby, you own the liability when that footage leaks, regardless of whose logo is on the housing. State privacy laws in California, Texas, Virginia, and elsewhere increasingly treat biometric and location data as protected categories, and 'the vendor got hacked' is not a defense regulators accept.
What is genuinely notable here is the physical vector. Most SMB security anxiety centers on remote attacks — phishing, ransomware, credential stuffing. This was someone literally opening the device. That raises a harder question: how many of the cameras bolted to poles and walls across your property could be cracked open in minutes by anyone with a ladder and a screwdriver? We are somewhat skeptical of drawing sweeping conclusions from a single unit, and the brief gives no detail on which camera model was involved or whether Flock has since patched the vulnerability. But the fact that a stored encryption key was retrievable at all points to a design failure that is difficult to dismiss as an edge case.
The downstream effects ripple in a few directions. If you share Flock data with law enforcement through a formal partnership, a breach like this could taint the evidentiary chain for cases built on that footage. If you are a property manager with cameras across multiple sites, you now face a decision about whether to audit, replace, or disconnect hardware you already paid for. And if you are a business in a neighborhood where Flock cameras are municipally deployed, your employees' and customers' movements may already sit in a dataset that third parties can extract. None of those outcomes shows up on the vendor's invoice, but all of them land on your plate.
Watch for Flock's formal response — whether it acknowledges the specific vulnerability, pushes a firmware update, or downplays the finding as a lab exercise with no real-world exposure. Also watch whether any state attorneys general or privacy regulators open inquiries; a 1.6-million-image breach is the kind of number that gets attention. In the meantime, if you have Flock cameras on your property, ask your vendor contact three questions in writing: Is the encryption key stored on-device or in a secure enclave? Has the firmware on your units been updated since this disclosure? And what contractual liability does Flock accept if footage from your location is breached? Get the answers on record before you need them.
“Hackers physically compromised a Flock camera and found an encryption key, 27,000 clips, and 1.6 million images generated in 21 days.” — TechRepublic
Takeaway: Audit any vendor-owned cameras on your property now — ask where encryption keys are stored, whether firmware is patched, and who bears liability if footage leaks.
Excerpt from the original — TechRepublic
Hackers physically compromised a Flock camera and found an encryption key, 27,000 clips, and 1.6 million images generated in 21 days.
The post Hackers Crack Flock Camera, Expose 1.6M Images in 21 Days appeared first on TechRepublic.