Hackers pulled the software and the encryption key out of a Flock camera: one unit shot 1.6 million frames in 21 days and flags people, not just plates
A group of hackers took a Flock Safety licence-plate camera down from its pole, copied almost everything stored inside it and found, sitting unencrypted on one of its partitions, the key that unlocks the camera's video archive. They passed the copy to 404 Media and to the transparency archive Distributed Denial of Secrets, which shared it with WIRED; the two outlets published a joint analysis on 16 September. Flock has told cities for years that footage is protected by on-device encryption and that even someone with physical access "would still not be able to gain access to footage". The recovered logs show one camera on one road photographing about 50,200 vehicles and generating 1.6 million images in 21 days, roughly 28 frames per car, and the software on board explicitly classifying people as well as plates. Those records feed a national network that, in one Georgia suburb, was searchable by more than 2,000 agencies.
In brief
- The collective, which calls itself stegan0gram, gained access to the camera's Android system, found unencrypted "vendor" and "media" partitions, and on the second recovered a key that decrypted the stored videos and detections. The most sensitive storage remained locked.
- The device runs about 20 Flock-built apps on a mid-range smartphone processor. On motion it fires a burst of photos at different exposures, crops useful frames and uploads them over cellular; plate reading and make, model and colour identification happen on Flock's servers.
- Logs covering 21 days show about 3,300 vehicles a day, a peak of 4,454, and 1.6 million images. WIRED ran the extracted models on 27,321 stored clips and confirmed they detect people; the plate detector also cropped bumper stickers and an American-flag patch as if they were plates.
- Flock says removing a camera is illegal and that it received no report through its vulnerability-disclosure process. The same company's data has already reached ICE via local police lookups, the pattern behind the class action over Motorola's plate-data sharing.
What was inside the camera
The hackers describe the job in the language of a field operation: they "liberated hardware in the field, disarmed them", then reverse-engineered the camera and its solar power kit, and they say they are publishing the method so others can repeat it. "Why just destroy them when we can reverse engineer them and find the secrets of those spying on us?" one member told 404 Media. The camera runs Android. Two partitions were unencrypted, one named vendor, one named media, and the media partition held the encryption key for another volume containing the videos and stills the camera had taken. That is the detail that undercuts Flock's public position. In early 2025 the researcher Jon "GainSec" Gaines documented flaws in a Flock reader that gave root access; Flock acknowledged them, said they needed physical access, and argued that footage stays on the device only briefly after upload, so an attacker would get nothing. The 27,321 short clips WIRED found on this unit, each one to two seconds at 1024 by 768 without audio, say otherwise, as do the 1.6 million images the logs record. The logs also show a device under strain: more than 27,000 "no space left on device" errors while saving full-resolution frames, tens of thousands of crashes and reboots, a health check every two minutes that writes "Who's a good boy?!" to the log, and a farewell line on each restart, "A reboot was requested! ¡Adios Amigos!"
What the software is looking for
The public conversation about Flock has been about number plates, and the company's marketing keeps it there. The code does not. When something enters the frame the camera takes a rapid series of photos, uses different exposures to capture the plate and the wider scene, then runs classifiers that label vehicles, plates, bicycles and people, recording where a person appears in the image and how confident the model is. WIRED extracted those models and ran them against test images, including a reporter's selfie, which they detected without difficulty; across the 27,321 clips they found people in 11, all motorcyclists, a low count explained by the camera's placement above a road rather than by any limit in the software. The plate detector proved eager: dealership frames, bumper stickers and, in one clip, a flag patch on a rider's saddlebag were cropped and stored as if they were plates. Neither outlet found face-recognition code beyond what Android ships by default, and that was not enabled. What the camera does not do on board is also informative: it does not read the plate or identify make, model and colour. That happens on Flock's servers, which means the raw bursts, dozens of frames of every car and whoever is in or near it, leave the roadside and enter a searchable national store. In August WIRED reconstructed part of Flock's police tool, OS Investigate, formerly Nightshift, and showed the other end of that pipeline: searches for vehicles that travel together, drivers identified from patterns of movement, camera records joined to police files and commercial data. Clearview's face-to-dossier product does the same join starting from a photograph; Flock starts from a plate.
Why one camera's diary matters
Multiply the numbers. One roadside unit, 3,300 cars a day, 28 frames each; thousands of such units in a city, tens of thousands nationally, all uploading to one company's servers where the plate becomes a name and the frames become a timeline. That is a location history built without a phone, a warrant or the driver's knowledge, and it is held by a vendor rather than by the agency that installed the camera, so the town that bought it is often not the only one searching it. 404 Media's earlier reporting found local officers running national lookups for ICE in jurisdictions that had banned cooperation, and a Texas officer searching cameras nationwide for a woman who had ended her own pregnancy. The Supreme Court decided in June that a person's location history requires a warrant when police want it from a phone company; the same history assembled from a plate-reader network has no such rule yet, and a camera that also flags people, bicycles and stickers is not collecting less. The stegan0gram dump does not change the law. It changes what can be said with a straight face about encryption, about what the cameras see and about how long the footage stays where it was taken.