Flock Camera Hack Exposed an Encryption Key in Plain Sight

Researchers who cloned a stolen Flock Safety camera found its encryption key stored unprotected on the same device, exposing 1.6 million images

Al Landes Avatar
Al Landes Avatar

By

Image: Wikimedia Commons

Key Takeaways

Key Takeaways

  • Investigators recovered a Flock camera encryption key stored on an unencrypted partition.
  • One cloned camera held 1.6 million images and 27,321 video clips spanning 21 days.
  • Flock’s security assurances conflict with findings, prompting calls for independent vendor audits.

One roadside camera. Twenty-one days. 1.6 million images, 27,321 video clips, and an encryption key stored in the last place it should ever be: an unencrypted partition on the device itself. That is what a joint investigation by 404 Media, WIRED, and transparency nonprofit Distributed Denial of Secrets found after a hacker collective called stegan0gram physically removed a Flock Safety camera from above a roadway, cloned its storage, and handed the contents to journalists for analysis.

What Flock Promised and What Investigators Found

Flock told police departments and city governments that strong on-device encryption protects footage even if someone gains physical access to a unit. The investigators found something different.

That protection, the company claimed, held even if someone gained physical access to a unit. Flock’s public messaging also suggested that images are only briefly retained locally before being forwarded to the cloud, minimizing exposure risk from a stolen or tampered device. This investigation is the first public technical teardown to directly test those claims.

Inside the Device

The camera runs an Android-based operating system with multiple storage partitions, including two unencrypted areas labeled “vendor” and “media.”

Investigators recovered the encryption key from the unencrypted “media” partition. That key then unlocked a separate encrypted partition holding the video and image cache. Strong encryption protects nothing when the key sits on the same unencrypted shelf as the lock; the cryptography itself was not the failure, the key storage was.

The Scale of What One Camera Captures

The 21-day dataset from a single location documented approximately 50,200 vehicles, averaging roughly 28 images per vehicle.

The 27,321 MP4 clips run one to two seconds each, at 1,024 by 768 resolution, with no audio. Logs from that same period also recorded 11 person detections, a reminder that the camera’s edge AI capabilities extend beyond vehicles. The camera was secretly tracking users more than license plates.

Flock’s Response

Flock said it takes security seriously, maintains a public vulnerability disclosure policy, and stated it received no formal report through that channel about this issue.

The company added that it lacked sufficient detail to fully assess the claims, according to reporting by Cybernews. Set that response against what investigators recovered: a functioning encryption key, three weeks of stored footage, and access to data that Flock’s own messaging indicated would not be meaningfully exposed by physical compromise of a unit.

A Pattern of Concerns

This incident does not arrive in isolation; Flock’s systems have been linked to documented misuse and municipal contract cancellations.

Officers have used Flock’s platform to track romantic partners. A separate erroneous plate entry triggered an aggressive stop of a car reviewer whose vehicle was misidentified. Some cities have terminated Flock contracts over privacy concerns, and some frustrated residents have attempted to damage or disable cameras outright. Former Pawtucket, Rhode Island police officer Noel Pichardo argues that approach is counterproductive: “I think that type of vigilantism will only crystallize the police and the state at large in their belief that this tool is necessary.”

What Comes Next

For any community where Flock cameras are deployed, this investigation raises questions that now require concrete answers.

How long is footage actually retained on-device, and does that window match what vendors state publicly? How is on-device person detection governed and audited? Independent technical verification of vendor security claims is the practical standard this case makes unavoidable; self-reported assurances are not sufficient. If your city contracts with Flock, those are reasonable questions to bring to the next council meeting.

Share this

At Gadget Review, our guides, reviews, and news are driven by thorough human expertise and use our Trust Rating system and the True Score. AI assists in refining our editorial process, ensuring that every article is engaging, clear and succinct. See how we write our content here →