After gaining physical access to a Flock Safety security camera, hackers were able to extract its software and data. They were also able to retrieve an encryption key stored on the camera, enabling them to access videos and additional data.
Key takeaways
- Edge deployments fail when encryption keys and sensitive logs reside unencrypted in local memory.
- Massive surveillance apparatuses carry severe liability when physical tampering uncovers systemic data collection practices.
- Defenders must enforce hardware key isolation, distinct device credentials, and immediate data ephemeralization across all remote nodes.
- Exposing mass surveillance through hardware reverse engineering proves once again that security by obscurity fails every time it meets a screwdriver.
Why It Matters
The Flock camera teardown highlights the risks of physical device security in edge deployments. The recovery team made a near-complete copy of the drive, pulled an encryption key stored on the device, and unlocked thousands of roadside clips and still bursts. This incident underscores the importance of securing physical devices, as any hacker with access to the hardware can potentially expose sensitive data.
Physical Device Security
The Flock camera was bolted to public poles and roadway arms, often around 8 to 12 feet high. This makes it easily accessible to attackers with a ladder. The physical threat is higher than for rack-mounted gear in a locked facility. When the decryption key is stored on that same publicly reachable box, every successful pull becomes a bulk export of neighbor travel history.
Security by Obscurity
The Flock camera runs a modified Android 8.1, an OS released in 2017 that Google stopped supporting in 2021, with a security patch level of June 2018. The Linux kernel is 3.18.71, a 2017 release from a kernel series that itself went end-of-life in 2019. This highlights the issue of using outdated software and hardware in edge deployments.
Hardware Key Isolation
The camera's encryption key was stored on the same partition it protected, making it vulnerable to extraction. This is a critical flaw that allows attackers to access sensitive data. The hard-coded API key ships in a shared library bundled into 19 separate on-device apps, and that key appears to let a caller request credentials for a camera by MAC address.
Threat Modeling
The Flock camera teardown shows the importance of threat modeling for physical possession. The build on the device was compiled in June 2025, indicating recent software built on an ancient base. This points at a platform decision rather than a patching lapse. The issue is not unique to Flock but is a common problem in the IoT industry.
Regulatory Compliance
Regulators are starting to demand that companies know what's actually in their firmware before it ships, threat model for physical possession, and commit to a software lifecycle that outlives the BSP the chip vendor handed them. This is sound engineering and not just a checklist requirement.
