One roadside camera. Twenty-one days. 1.6 million images, 27,321 video clips, and an encryption key stored in the last place it should ever be: an unencrypted partition on the device itself. That is what a joint investigation by 404 Media, WIRED, and transparency nonprofit Distributed Denial of Secrets found after a hacker collective called stegan0gram physically removed a Flock Safety camera from above a roadway, cloned its storage, and handed the contents to journalists for analysis.
What Flock Promised and What Investigators Found
Flock told police departments and city governments that strong on-device encryption protects footage even if someone gains physical access to a unit. The investigators found something different.
That protection, the company claimed, held even if someone gained physical access to a unit. Flock’s public messaging also suggested that images are only briefly retained locally before being forwarded to the cloud, minimizing exposure risk from a stolen or tampered device. This investigation is the first public technical teardown to directly test those claims.
Inside the Device
The camera runs an Android-based operating system with multiple storage partitions, including two unencrypted areas labeled “vendor” and “media.”
Investigators recovered the encryption key from the unencrypted “media” partition. That key then unlocked a separate encrypted partition holding the video and image cache. Strong encryption protects nothing when the key sits on the same unencrypted shelf as the lock; the cryptography itself was not the failure, the key storage was.
The Scale of What One Camera Captures
The 21-day dataset from a single location documented approximately 50,200 vehicles, averaging roughly 28 images per vehicle.
The 27,321 MP4 clips run one to two seconds each, at 1,024 by 768 resolution, with no audio. Logs from that same period also recorded 11 person detections, a reminder that the camera’s edge AI capabilities extend beyond vehicles. The camera was secretly tracking users more than license plates.
Flock’s Response
Flock said it takes security seriously, maintains a public vulnerability disclosure policy, and stated it received no formal report through that channel about this issue.
The company added that it lacked sufficient detail to fully assess the claims, according to reporting by Cybernews. Set that response against what investigators recovered: a functioning encryption key, three weeks of stored footage, and access to data that Flock’s own messaging indicated would not be meaningfully exposed by physical compromise of a unit.
A Pattern of Concerns
This incident does not arrive in isolation; Flock’s systems have been linked to documented misuse and municipal contract cancellations.
Officers have used Flock’s platform to track romantic partners. A separate erroneous plate entry triggered an aggressive stop of a car reviewer whose vehicle was misidentified. Some cities have terminated Flock contracts over privacy concerns, and some frustrated residents have attempted to damage or disable cameras outright. Former Pawtucket, Rhode Island police officer Noel Pichardo argues that approach is counterproductive: “I think that type of vigilantism will only crystallize the police and the state at large in their belief that this tool is necessary.”
What Comes Next
For any community where Flock cameras are deployed, this investigation raises questions that now require concrete answers.
How long is footage actually retained on-device, and does that window match what vendors state publicly? How is on-device person detection governed and audited? Independent technical verification of vendor security claims is the practical standard this case makes unavoidable; self-reported assurances are not sufficient. If your city contracts with Flock, those are reasonable questions to bring to the next council meeting.




























