A hacker collective that calls itself stegan0gram unbolted a Flock Safety license plate camera, cloned the storage inside it, and pulled an encryption key off the device. That key opened video covering thousands of vehicle detections. Two parties outside the group ended up with the files: the tech news site 404 Media, and Distributed Denial of Secrets, a transparency nonprofit. That group gave WIRED access, and the joint analysis published September 16.
The camera runs Android on a processor in the same class as those in midrange phones, with roughly 20 Flock-built apps handling motion detection, image capture, object classification, uploads and remote updates. Several partitions came out unencrypted, among them two named vendor and media. The media volume carried the key that unlocked the partition holding most of the footage.
Recovered logs span about 21 days of operation across several periods. During those windows the camera shot roughly 50,200 vehicles and about 1.6 million images, averaging some 3,300 vehicles a day and peaking at 4,454. A single passing vehicle usually yielded about 28 stills, and occasionally more than 100.
Its models detect people as well as plates, vehicles and bicycles, recording where a person appears and how confident the match is. WIRED ran the camera’s own models over 27,321 short clips held on the device and found detections in 11, every one a motorcyclist. The plate detector was sloppier, cropping bumper stickers and dealership frames, and in one video mistaking an American flag patch on a rider’s saddlebag for a plate.
Flock said removing or tampering with a camera is illegal, and that nobody had come to it through its vulnerability disclosure policy. It has argued before that footage sits on a device only briefly before moving to the cloud.