Hackers Stole a Flock Camera. What They Found Is More Interesting Than the Viral Video
One roadside camera captured 1.6 million images in 21 days.
A viral video making the rounds this week shows what appears to be a stolen Flock license-plate camera being subjected to an absurd experiment: thousands of license plates flashing past it at extreme speed.
The joke accompanying the video is that an American man âkidnappedâ the surveillance camera and forced it to process 23,040 license plates per second.
Thereâs just one problem.
That number doesnât appear to be real.
I couldnât find credible technical evidence that the camera processed 23,040 license plates per second. Reporting tracing the viral claim says the number originated in social-media framing and is inconsistent with how Flockâs system actually operates.
But hereâs the strange part:
The real story is arguably more interesting.
Security researchers actually did physically remove a Flock camera from above a roadway, copy its internal storage and reverse-engineer its software.
And what they discovered gives us one of the clearest looks yet inside Americaâs rapidly expanding license-plate surveillance infrastructure.
They Really Did Take Apart a Flock Camera
In September, the hacker collective stegan0gram physically removed a Flock Safety camera and made a near-complete copy of its internal storage.
The data was provided to journalists at WIRED and 404 Media, who analyzed the files along with the transparency organization Distributed Denial of Secrets.
This wasnât a remote compromise of Flockâs cloud.
The researchers had physical possession of the hardware.
Inside they found an Android-based computer running roughly 20 Flock applications responsible for functions including detecting movement, capturing images, classifying objects, uploading information and receiving updates.
Essentially:
Thereâs a small computer sitting on that pole watching traffic all day.
And the amount of information it generates is remarkable.
1.6 Million Images From One Camera
Recovered logs covered roughly 21 days of operation.
During those periods, that single camera encountered approximately:
50,200 vehicles.
And generated approximately:
1.6 million images.
A typical vehicle generated around 28 images, while some vehicles triggered more than 100.
That works out to roughly 76,000 generated images per day during the recovered period.
Not 23,040 license plates every second.
But still an enormous amount of visual information from one camera.
The camera wasnât simply snapping one picture of every license plate.
It rapidly captured multiple exposures as vehicles passed, allowing the system to find useful images of both the plate and the surrounding vehicle.
It then selected and cropped useful frames and transmitted information back to Flock over a cellular connection.
Thatâs an important distinction.
The Camera Doesnât Appear to Actually Read Your Plate
This is one of the most surprising technical details.
The roadside camera apparently performs some computer-vision work locally.
It detects objects.
Finds potential plates.
Captures images.
Crops useful regions.
But according to WIREDâs analysis, the actual license-plate recognition and identification of attributes such as vehicle make, model and color appear to happen on Flockâs servers, rather than entirely inside the roadside camera.
So think of the roadside unit as the eyes.
The cloud provides much of the brain.
That architecture matters.
Because once thousands of cameras feed observations into a centralized searchable system, the capability becomes much larger than any individual camera.
The surveillance power isnât the camera. Itâs the database behind it.
They Also Found 27,321 Video Clips
Flock cameras are generally discussed as license-plate readers capturing still images.
But investigators recovered 27,321 MP4 video clips from the device.
They were shortâroughly one to two seconds eachâand recorded at 1024Ă768 without audio.
They were separate from the higher-resolution bursts of still images generated as vehicles passed.
That does not mean a Flock ALPR is secretly recording continuous 24/7 surveillance video.
There is no evidence from this investigation establishing that.
But it demonstrates that the hardware can create and temporarily retain considerably more visual information than someone might imagine from the phrase:
License-plate reader.
Then Researchers Discovered It Could Detect People
This may be the most interesting discovery.
The software recovered from the camera explicitly contained models capable of detecting:
Vehicles.
License plates.
Bicycles.
And people.
When the software identifies a person, it can record where that person appears within the image and the confidence of the detection.
WIRED extracted the computer-vision models and tested them independently.
They successfully detected peopleâincluding a reporter in a test selfie.
Researchers then ran the model across the 27,321 recovered video clips.
People were detected in 11.
All were riding motorcycles.
That low number isnât especially surprising considering the camera had been mounted above a roadway and pointed primarily at vehicle traffic.
Importantly, investigators found no evidence that the device was performing facial recognition.
Detecting:
There is a person here
is technically very different from determining:
That person is John Smith.
But the distinction is worth understanding.
The Camera Sometimes Thought Other Things Were License Plates
Computer vision isnât perfect.
Researchers found examples where the system isolated objects that werenât actually license plates.
Bumper stickers could confuse it.
Other graphics could confuse it.
In one particularly interesting example, the system identified an American flag patch on a motorcyclistâs saddlebag as though it might be a license plate.
Thatâs not merely funny.
Itâs an important reminder about automated surveillance.
Humans tend to treat computer-generated classifications as objective.
But computer vision is making probabilistic judgments.
Sometimes it gets them wrong.
And those errors matter when the resulting information enters a law-enforcement system.
There have already been documented cases where erroneous license-plate-reader matches contributed to innocent drivers being detained.
Automation can make a mistake faster than a human ever could.
Then They Found the Encryption Key
This is where the story becomes a cybersecurity story.
Flock has described its system as using encryption to protect captured information.
Thatâs exactly what you would expect.
These cameras sit unattended on poles in publicly accessible locations.
You have to assume that eventually somebody will physically obtain one.
The researchers discovered an encryption key stored on an unencrypted portion of the deviceâs storage.
That key allowed them to decrypt some of the cameraâs recorded media.
Much of the cameraâs most sensitive storage remained encrypted and inaccessible, so this wasnât a complete defeat of every security mechanism.
But the architecture creates an obvious cybersecurity lesson.
Strong encryption is extraordinarily difficult to break.
But attackers often donât attack the encryption.
They look for the key.
Itâs the equivalent of installing an extremely expensive safe and then leaving information needed to open part of it nearby.
The cryptography can work perfectly.
The key management can still fail.
Physical Access Changes Everything
Cybersecurity professionals have an old rule:
If an attacker gains unrestricted physical access to a device, your security problem becomes substantially harder.
Roadside infrastructure makes that particularly challenging.
These devices arenât sitting inside locked data centers.
Theyâre deployed outdoors.
Thousands of them.
Often unattended.
Twenty-four hours a day.
That means manufacturers have to design them assuming someone eventually:
Steals one.
Opens one.
Copies the storage.
Analyzes the firmware.
Extracts the software.
Examines credentials.
Studies communications.
And tries to discover weaknesses.
The physical enclosure is only one layer.
You should design every device as though your attacker eventually owns one.
But Flock Cameras Have Genuine Public-Safety Uses
The privacy debate becomes difficult because this technology can also be extremely useful.
Flock cameras have helped police locate stolen vehicles, identify suspects and recover missing or kidnapped children.
For example, Kalamazoo public-safety officials say Flock data helped officers locate a kidnapped infant and stop the suspect within approximately 25 minutes.
In another case last year, a Flock camera in Arizona spotted a vehicle connected to the kidnapping of a one-year-old child in California, helping authorities locate the child safely after the vehicle crossed state lines.
Thatâs the strongest argument for these systems.
If police know the plate of a vehicle carrying an abducted child, a distributed camera network can potentially find that vehicle considerably faster than officers manually searching roads.
Thatâs enormously valuable.
The privacy question isnât whether that capability can do good.
Clearly it can.
The question is:
What else can that same capability do?
Because the Network Is Enormous
A single camera doesnât know where youâve been.
A network can.
Thatâs the fundamental difference.
According to a Washington Post investigation published in August, Flockâs system was operating across more than 6,000 communities and recording roughly 20 billion license plates per month.
Those observations can become searchable.
And once observations from many locations are connected, investigators can potentially reconstruct movement.
Where a vehicle appeared.
When it appeared.
Where it appeared next.
Repeated patterns.
Connections between locations.
Thatâs why describing Flock simply as a camera can miss the point.
One camera records a car. A network can record a life.
And That Power Has Already Been Misused
This isnât merely hypothetical.
The Washington Post documented allegations involving law-enforcement personnel using Flock systems for unauthorized surveillance.
In one case, a police chief allegedly searched Flock records involving his former girlfriend and her teenage daughterâs vehicles roughly 600 times, according to records compiled by Have I Been Flocked.
That doesnât mean most police officers misuse the system.
It demonstrates something more basic:
A powerful legitimate tool can also be abused by an authorized user.
Cybersecurity has a name for that problem:
Insider threat.
You donât solve insider threat by saying employees arenât supposed to misuse the system.
You build controls.
Strong authentication.
Least privilege.
Search justification.
Immutable audit logs.
Automated abuse detection.
Independent review.
Retention limits.
Alerts for unusual queries.
And consequences for misuse.
The same principles protecting a hospital database or corporate network should apply to surveillance infrastructure.
The Viral Number Distracts From the Real Story
The internet loves 23,040 plates per second because the number sounds insane.
But there is no good evidence that the stolen Flock camera actually demonstrated that processing capability.
And we donât need an exaggerated number to make this story interesting.
The verified findings are extraordinary enough:
One roadside camera.
About 21 days of recoverable logs.
Roughly 50,200 vehicles.
Approximately 1.6 million images.
27,321 short video clips.
Software capable of detecting people.
An encryption key recovered from the device.
And a cloud-connected infrastructure capable of turning individual roadside observations into searchable vehicle intelligence.
Thatâs the real story.
The Camera Isnât What Should Get Your Attention
Weâre entering a world filled with inexpensive sensors.
Cameras.
Doorbells.
Cars.
Phones.
Drones.
Access-control systems.
Retail cameras.
Traffic infrastructure.
The individual sensor isnât necessarily remarkable.
Whatâs remarkable is what happens when AI can continuously convert billions of observations into structured, searchable information.
A human could never watch millions of photographs every day.
Software can.
Thatâs what AI changes.
It turns surveillance from:
Someone might see you
into:
Someone can search for you later.
And thatâs why debates about systems like Flock shouldnât focus exclusively on whether cameras exist.
The important questions are:
Who can search the data?
What can they search for?
How long is it retained?
Who can share it?
Who audits those searches?
What happens when someone abuses access?
And what happens when somebody physically steals the hardware collecting it?
Because the most powerful part of modern surveillance isnât the camera watching the road.
Itâs the computer that remembers what the camera saw.
70% of all cyber attacks target small businesses, I can help protect yours.
#Cybersecurity #Privacy #FlockSafety #Surveillance #DataProtection
Someone really did steal a Flock surveillance camera and tear it apart. The viral â23,040 license plates per secondâ claim appears bogusâbut what researchers ACTUALLY found is crazier: 1.6 MILLION images from about 21 days, 27,321 video clips, software that detects people, and an encryption key stored on the device.