this post was submitted on 17 Sep 2026
202 points (99.5% liked)

Cybersecurity

10604 readers
143 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 3 years ago
MODERATORS
 
HaJ3FgupAm8RrDJW3MHgT9X7Ft27eVaD
top 37 comments
sorted by: hot top controversial new old
[–] faebudo@infosec.pub 50 points 1 week ago* (last edited 1 week ago)

They are always very specific when saying that Flock cameras do not do face recognition. Because stated like this it's true. The face recognition doesn't happen on the camera (also not license plate reading etc.) instead photos are sent to central servers where they do the license plate reading and face recognition.

[–] Redvenom@retrolemmy.com 33 points 1 week ago (1 children)

Just a random string of characters:

HaJ3FgupAm8RrDJW3MHgT9X7Ft27eVaD

[–] victorz@lemmy.world 12 points 1 week ago* (last edited 1 week ago)

Is that the token?

Ah yes, yes it is.

[–] markstos@lemmy.world 25 points 1 week ago (2 children)

We are soon to find out if Flock blindly onboards random MAC addresses as new cameras.

If so, it seems anyone with the hardcoded key can authenticate with Flock ask if they were a new camera.

[–] muusemuuse@sh.itjust.works 9 points 1 week ago

I wonder if that means you could “claim” a bunch of MAC addresses so you can block deployment of new or replacement flock cameras.

[–] p03locke@lemmy.dbzer0.com 8 points 1 week ago (1 children)

And it doesn't have to be a camera. It can just be a random set of images.

[–] yakko@feddit.uk 7 points 1 week ago (1 children)

It can be

Gasp

Can it pretend to be information about me, but then instead it's all butt holes?

[–] Quexotic@sh.itjust.works 5 points 1 week ago (1 children)
[–] yakko@feddit.uk 5 points 1 week ago (1 children)

Because mine is secretive 😶

[–] Quexotic@sh.itjust.works 4 points 1 week ago

OMG that user handle.

[–] ilovededyoupiggy@sh.itjust.works 24 points 1 week ago (4 children)

I'm going to go as a functional Flock camera for Halloween.

[–] adarza@lemmy.ca 6 points 1 week ago

don't look surprised when someone in a hockey mask cuts your legs off at the knees with a chainsaw.

🎶 When you get knocked down, don't you get up again. We're all trying to keep you down.

[–] mp3@lemmy.ca 4 points 1 week ago

damn that's good

[–] modus@lemmy.world 3 points 1 week ago

So you're wearing Meta glasses?

[–] wyldrstallyns@lemmy.dbzer0.com 22 points 1 week ago

Get it, freedom fighters! 🤘🏼✊🏼

[–] Quexotic@sh.itjust.works 21 points 1 week ago (1 children)

If you think for about two seconds about the national security implications about this, this is extremely, extremely bad.

[–] Cethin@lemmy.zip 6 points 1 week ago* (last edited 1 week ago) (1 children)

You're right, but Flock (and all of these cameras) is bad for the liberty of the people, so this is good. Any time a national security threat is found, it shakes the trust in these systems, so they're less likely to be trusted again.

[–] Quexotic@sh.itjust.works 5 points 1 week ago (1 children)

The worst thing is that this isn't exactly new. The house heard about the vulnerabilities of this system in May.

https://www.youtube.com/watch?v=VKSjlZ6xyDo

Unfortunately, we're in such a state of plutocracy and regulatory capture that even stating how big of a national security risk they are did not make any movement until now.

[–] p03locke@lemmy.dbzer0.com 2 points 1 week ago (1 children)

In other words, it only makes movement when the general public finds out and starts sabotaging their cameras?

[–] Quexotic@sh.itjust.works 1 points 4 days ago

The damage really just amounts to insignificant outliers. There's so many cameras that the vandalized ones only make up a statistically insignificant portion.

At the moment, I believe the actual movement is coming from the ground up, grassroots movements that are going to their town halls and telling their representatives that they want these cameras the fuck out of their cities, and it seems to be working, at least somewhat.

I'd be lying though if I didn't feel some kind of justice and satisfaction every time I see that one dude in Florida carrying around a camera.

[–] derry@midwest.social 16 points 1 week ago

Keeps getting better

[–] jtrek@startrek.website 16 points 1 week ago (1 children)

I wonder if this was a form of sabotage by an engineer, or regular incompetence

[–] leftzero@lemmy.dbzer0.com 7 points 1 week ago

Hanlon's razor:

Never attribute to malice that which is adequately explained by stupidity.

But, also, Grey's law:

Any sufficiently advanced incompetence is indistinguishable from malice.

Why are you linking to bluesky instead of his article?

[–] lka1988@sh.itjust.works 5 points 1 week ago
[–] victorz@lemmy.world 3 points 1 week ago* (last edited 1 week ago) (4 children)

Quick question: what would be the correct way to handle this, security wise? How should they acquire their token if it isn't present on-device?

I mean, each device could have its own token, but you could still sniff it, maybe? I dunno.

How should Flock have gone about this if working to their own self-interest?

[–] dejected_warp_core@lemmy.world 17 points 1 week ago (1 children)

Ethically? Expire the token since it's compromised, and offer to refurbish all units in the field since flock screwed up, a now all customer data could be poisoned/suspect now.

Realistically? Keep going like nothing happened an make it a customer support problem while pushing new hardened cameras that cost more. Because the product alone loudly flags Flock as a bunch of amoral greedy fuckwits.

I won't suggest ways to actually make their product bulletproof because I care and we don't need to make this problem worse for everyone. It is a tantilizing problem space but there are never any perfect answers in security, only relatively better/worse ones.

[–] victorz@lemmy.world 7 points 1 week ago (1 children)

Oh, I don't mean afterwards. I meant before it even happened.

[–] msage@programming.dev 3 points 1 week ago

You give each camera its own token, and validate it with hardware ID.

Even better, give them hardware token, that can sign, but does not leak its keys.

In either way, you can ID the device, and block unsold and confirmed stolen/damaged ones. And never accept traffic from anything else.

[–] mp3@lemmy.ca 12 points 1 week ago* (last edited 1 week ago)

One way would be to generate a unique private key on the secure element / TPM and its public key stored on the server for validation. Each API request would need to be signed with a relatively short expiration time. That way the code never contains sensitive content such as an API key, an exploited device only holds in RAM a signed certificate that is valid for a short period of time, and the certificate can be revoked/blocklisted on the server if compromised.

[–] kibiz0r@midwest.social 7 points 1 week ago (1 children)

Unique private key per device, pre-provisioned certificate at manufacturing time, hardware-level separation of crypto operations so sensitive creds are never in memory.

It’s a bit more expensive to manufacture, in terms of BOM and logistics. And then you have a lot more complexity to your production system too.

[–] victorz@lemmy.world 1 points 1 week ago (1 children)

Is it possible to have several private keys per singleton public key?

[–] multiplemigs@sh.itjust.works -1 points 1 week ago (1 children)

y'all just givin the work away huh? don't answer this unless you are getting paid.

[–] victorz@lemmy.world 2 points 1 week ago (1 children)

O... Kay, I'm just trying to expand my knowledge about this particular case. I'm mostly a web dev but I'm trying to expand into security a little bit as well because I think that's important for my field. It just wasn't a part of my curriculum at uni 10–20 years ago.

[–] multiplemigs@sh.itjust.works 2 points 1 week ago

i was mostly joking 🙃 sorry if it came across as rude