Sunday, September 20, 2026

Now That I Know What They Look Like

I spot them now. A small dark box on a pole, angled at the road, above an intersection I have driven through for years. I never noticed it. Once you know the shape, you find them.

They are Flock Safety license plate readers, and a WIRED and 404 Media investigation now documents what one contains. A hacker collective calling itself stegan0gram removed a camera from above a roadway, made a near-complete copy of its storage, and shared the files with both outlets through Distributed Denial of Secrets. As an engineer, I read the technical findings first.

The device runs Android on a processor similar to those in midrange smartphones. About 20 Flock-built apps handle motion detection, image capture, object classification, uploads, and remote updates. When something moves into view, the camera takes a rapid series of photos. A typical vehicle generated about 28 images, and some generated more than 100. The camera varies exposure to capture both the plate and the wider scene, selects and crops useful frames, and sends them over the cellular network. Plate reading and identification of make, model, and color appear to happen on Flock servers.

The recovered logs cover about 21 days across several periods. In that time the camera photographed roughly 50,200 vehicles and generated about 1.6 million images. A typical day logged around 3,300 vehicles, with a high of 4,454. Older logs had been overwritten.

Flock describes the system as protected by on-device encryption. The hackers found two partitions that were unencrypted, named "vendor" and "media." The media partition held an encryption key that unlocked another part of the storage, including videos of thousands of vehicle detections. Much of the most sensitive storage stayed encrypted. In early 2025, researcher Jon Gaines documented root-level flaws in a Flock reader. Flock acknowledged them, said they required physical access, and said an attacker still could not reach footage because images remain on the device only briefly. The hackers had physical access. Flock says it received no report through its vulnerability disclosure process and lacks enough detail to assess their claims.

The software also detects people. It records where each person appears in the image and a confidence score. WIRED extracted the models and ran them against 27,321 stored clips, each one to two seconds long, 1,024 by 768 pixels, with no audio. The models found people in 11 clips, all of them motorcycle riders. The camera points down at traffic, so pedestrians rarely enter the frame. The plate detector also cropped bumper stickers, dealership frames, and an American flag patch on a saddlebag as if each were a plate. Investigators found no evidence of active face recognition, which matches Flock’s statement.

The logs show the hardware under strain: more than 27,000 "no space left on device" errors, plus tens of thousands of related errors, crashes, and reboots. A health check ran about every two minutes and logged "Who’s a good boy?!" more than 12,000 times.

I've taught embedded design courses, and the encryption finding fits a single lecture point. A key stored on the same device as the data it protects gives anyone with physical access a path to that data. A camera on a pole has physical access built in.

I drove past that pole for years without looking up. If it was a Flock unit, it took about 28 photos of my car on each pass. Now I look up at every intersection, and there are more than a few around.

I have a favorite saying for moments like this: let’s make like a bird and get the flock out of here. The camera will log the departure.


No comments: