Flock cameras are riddled with security vulnerabilities and hardcoded creds
The Flock ALPR cameras have been found to contain significant security vulnerabilities, including hardcoded credentials and outdated software. Hackers from stegan0gram have reverse engineered these cameras to expose these flaws. The cameras are running a modified version of Android 8.1, which was released in 2017 and stopped receiving security updates in 2021.
The Linux kernel version on the camera is also over nine years out-of-date. The camera is missing critical security patches and is vulnerable to various hacks. The camera's firmware includes 20 separate apps, all sharing a library with a hard-coded API key. This key can be used to obtain credentials for any Flock camera by making an API request to a specific server.
These credentials can then be used to interact with Flock's backend servers. The camera's location data has been found in the logs, revealing its physical whereabouts. Despite Flock claiming to take security seriously, they have not responded to reports of these vulnerabilities.
Written by urgent.news from Hacker News's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.