Full Breakdown
Flock Safety Camera’s Encryption Key Exposed in Plain Text
By Drooid · · How we work
Core Event: Physical Breach Reveals Critical Security Flaw
A hacker collective called stegan0gram removed a Flock Safety automatic license-plate reader (ALPR) mounted above a U.S. roadway, copied its internal storage, and disclosed the data to 404 Media and DDoSecrets. The dump, shared with WIRED, was investigated in a joint report published on September 16 2026. It showed two unencrypted partitions—“vendor” and “media”—with the “media” partition containing the encryption key that protects the encrypted video and image recordings.
Background & Context
Flock Safety sells ALPR cameras to police departments and local governments. More than 120,000 cameras operate in roughly 6,000 U.S. cities, recording license plates, pedestrians, bicycles and visual details such as bumper stickers or flag patches. The devices run Android 8.1, an OS that no longer receives security updates.
Data & Statistics
- Storage period: 21 days on the examined camera.
- Vehicles recorded: ~50,200.
- Images captured: 1.6 million.
- Video clips: 27,321 short clips.
- Error logs: Over 27,000 “no space left on device” messages.
- Vulnerabilities identified: CVE-2021-1905 and CVE-2018-9568.
- Embedded credential: An API key stored in plain form enables anyone with a camera’s MAC address to query Flock’s servers for authentication credentials.
Official Statements & Responses
- Flock Safety said unauthorized removal and tampering are illegal, noted its public Vulnerability Disclosure Policy, and said it has received no reports through that channel.
- Congressional action: Democrats and Republicans introduced the No FLOCK Act, sponsored by Rep. Raja Krishnamoorthi (IL) and Rep. Michael Cloud (TX). The bill would allow the Secretary of Transportation to withhold 10 % of federal highway funds from states that do not limit Flock camera data use to tolls, stolen-vehicle recovery, missing or endangered persons, and serious crimes.
- Local government response: The city of Boston announced it will discontinue use of Flock’s services over data-sharing concerns, while retaining other license-plate camera systems.
Why It Matters / Impact
The exposure shows that on-device encryption fails when the key is stored on the same medium. Anyone with physical access can retrieve raw footage and metadata, including detailed images of pedestrians and objects beyond license plates. The unpatched Android OS and known vulnerabilities lower the barrier for remote exploitation via the embedded API key. These weaknesses intersect with ongoing public scrutiny of ALPR deployments.
On-the-Ground Observations
Extracted logs show continuous operation despite storage saturation and record detections of pedestrians and bicycles alongside vehicles. The software isolates visual details such as bumper stickers and flag patches, confirming capabilities beyond simple license-plate reading.
What’s Next
The No FLOCK Act is moving through Congress and could affect federal highway-fund allocations. Municipalities like Boston are reevaluating contracts with Flock Safety. No further scheduled disclosures or remediation timelines have been announced by the company.
