AIO APEX

Hackers tore apart a Flock surveillance camera and found eight-year-old Android and a hardcoded master key

Micah Lee / Wired / 404 Media / Hackaday
Share:
Hackers tore apart a Flock surveillance camera and found eight-year-old Android and a hardcoded master key

A hacker collective calling itself stegan0gram physically removed a Flock Safety license-plate-reading camera from a pole in Wauwatosa, Wisconsin, tore it apart, and extracted its internal storage — revealing that the device tracking vehicles across thousands of American cities runs an Android operating system last patched in 2018, contains a hardcoded API key exposing data from any camera in the network, and stores its own encryption key unencrypted on the same partition it's supposed to protect.

Flock Safety's automatic license plate recognition cameras have become one of the most widely deployed surveillance systems in the United States, installed by police departments and homeowners' associations to photograph and log every vehicle passing a given point. The company has positioned the hardware as a modern policing tool. What stegan0gram found inside one, according to independent security researcher Micah Lee's analysis of the leaked filesystem, published through DDoSecrets and jointly investigated by Wired and 404 Media, is a device built on abandoned software: Android 8.1, a version Google stopped supporting in 2021, with a security patch level frozen at June 2018 and a Linux kernel more than nine years out of date.

That neglect isn't cosmetic. The outdated kernel carries at least two publicly documented, exploitable vulnerabilities: a Qualcomm GPU flaw (CVE-2021-1905) that allows an attacker to corrupt kernel memory and take full control of the device, and "WrongZone" (CVE-2018-9568), which lets a process escalate to root through an IPv6 socket handling error. Either would let an attacker who gains any foothold on a camera take it over completely — and these are vulnerabilities patched industry-wide years ago, left unaddressed on hardware actively logging the movements of the public.

The credential handling is worse. Researchers found a hardcoded API key — "HaJ3FgupAm8RrDJW3MHgT9X7Ft27eVaD" — embedded across 19 different Flock applications, which can be used to pull configuration data for any camera on the network simply by supplying its MAC address, no authentication beyond that key required. Separately, the camera's 18GB media storage partition, which holds encrypted vehicle photo archives, keeps its own decryption key sitting unencrypted on the same partition — the equivalent of locking a safe and taping the combination to the door. Extracted logs from the single camera showed 2,264 API calls and repeated GPS coordinates accurate to under 100 meters, alongside the device's serial number and exact street-level deployment location.

Flock Safety responded that it takes security "seriously" and maintains a vulnerability disclosure program, adding that it received no report through that channel and has "not enough detail to assess the claims being made" based on what's public so far. That response sidesteps the more uncomfortable fact for the company: the flaws weren't found through a cooperative disclosure process. They were found by someone who pulled a live camera off a pole in a Milwaukee suburb, popped it open, and read what was inside — a research method available to anyone with a ladder and the same access American drivers already involuntarily pass in front of every day.

The specifics matter beyond one company's embarrassment. ALPR networks like Flock's aggregate location data on ordinary vehicle owners with no court order and often no public disclosure of retention periods, and the technology has already been tied to documented cases of wrongful arrests from license plate misreads and officers misusing the system to track people they knew personally. A surveillance network with that scope running eight-year-old unpatched Android, a network-wide skeleton key hardcoded into its own apps, and an encryption scheme with the key taped to the lock isn't just a bug report — it's evidence that the security posture around mass vehicle surveillance in the US has not kept pace with how widely that surveillance has already been deployed.

Originally reported by Micah Lee / Wired / 404 Media / Hackaday. Read the original article for additional details.

View original source
Share: