Hackers physically removed a Flock Safety roadside camera, copied its storage, extracted an on-device encryption key, and recovered roughly 21 days of material that included about 1.6 million images tied to roughly 50,200 vehicle detections. The device’s software takes rapid bursts of photos (typically ~28 images per passing vehicle, sometimes 100+), detects people, vehicles, bicycles and license-plate-like regions, and crops frames for upload; tests of the recovered models confirmed person-detection (not face recognition) and showed the plate detector sometimes mistakes bumper stickers, frames or patches for plates. The camera itself appears not to perform OCR or vehicle make/model identification locally - those functions run on Flock’s servers - but the on-device files and short MP4 clips give a revealing view of what the sensor captures before cloud processing.
Technical analysis found the camera runs Android on a smartphone-class processor and about 20 vendor apps; some partitions were unencrypted, allowing recovery of media and keys. Logs show frequent “no space left on device” errors, crashes and reboots, alongside quirky messages, indicating storage and stability problems. Front-end police software reconstructed from leaked code shows how camera records can be combined with police files and commercial data to identify drivers, surface co-travel patterns, and search movements, underscoring surveillance risks. The breach, earlier researcher disclosures, and ensuing arrests and municipal pushback have intensified scrutiny over the cameras’ security and use; the vendor calls tampering illegal and points to its vulnerability-disclosure process.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.