For most people, a Flock camera is a gray box on a pole that you drive past without registering. It photographs your license plate, logs the make and color of your car, records where and when, and sends that upstream. The company has spent years insisting the box is narrower than its critics claim: plates and vehicles, not people, with encryption protecting whatever sits on the device.
A group calling itself stegan0gram decided to check by taking one down and opening it.
What they found inside has been analyzed by 404 Media, the transparency nonprofit Distributed Denial of Secrets and WIRED, and it complicates two of the company’s central claims at once. The footage on the device was protected by encryption. The key to that encryption was also on the device, sitting in a partition that was not encrypted at all.
The short version
- A hacker collective physically removed a Flock automated license plate reader and copied nearly all of its stored data
- The files went to 404 Media and Distributed Denial of Secrets, and were analyzed alongside WIRED
- Analysts found unencrypted partitions on the camera’s internal storage. One of them held an encryption key that unlocked stored video and images
- Software on the device explicitly detects people, logging where a person appears in frame and a confidence score
- WIRED pulled the computer vision models off the device and ran them independently. They detected people, including a reporter’s selfie
- Over a 21 day window, this single camera photographed about 50,200 vehicles and produced roughly 1.6 million images
- Flock’s response: removing and tampering with a camera is illegal, and researchers should use its vulnerability disclosure program
The encryption claim, and what was actually on the drive
Physical security is the hard case for any device left unattended outdoors. Flock’s position has been that it is handled: even if someone gets hold of a camera, on-device encryption keeps the stored footage out of reach.
That argument only works if the key lives somewhere the attacker cannot get to. On this unit it did not. Analysts reported two unencrypted sections on the camera’s internal storage, and one of them, labeled media, contained a key that opened the encrypted store of vehicle detection images and video.
Encryption where the key ships alongside the ciphertext is not a small implementation detail. It means the protection holds against someone who steals the drive and nothing else, and fails against anyone who takes the whole device, which is the scenario the claim was supposed to cover.
This is not the first time the gap between Flock’s security posture and its deployed hardware has been the story. Last month the company was explaining why a batch of its cameras were streaming to the open internet, an incident the chief executive attributed to a bad run of SIM cards.
The people detection question
The more consequential finding is about what the software on the camera is looking for.
Flock’s public position has been consistent and carefully worded: the system does not use facial recognition and does not collect biometric information. Both of those statements can be true at the same time as the finding here, which is why the distinction matters.
The software running on the device detects people as a category. When a person enters the frame, it records their position in the image and a confidence score for the detection. WIRED extracted the vision models from the camera and ran them on its own material, where they identified people successfully, including a selfie taken by one of its reporters.
Detecting that a human being is present is not the same as identifying which human being it is. Nobody has shown that Flock is running face matching. But “we do not do facial recognition” and “our roadside cameras do not process people at all” are different promises, and only the first one has actually been made.
| What people assume | What the teardown indicates |
|---|---|
| The camera only reads license plates | On-device software detects vehicles, plates, bicycles and people, with a confidence score per detection |
| Stored footage is safe if the unit is stolen | An unencrypted partition on the device held a key that decrypted the stored media |
| It snaps one photo per passing car | Roughly 32 images per vehicle, based on the 21 day sample |
| A single camera sees a modest amount of traffic | About 2,390 vehicles a day from one unit, on one road |
| People detection implies facial recognition | Not demonstrated. Detecting a person is a separate capability from identifying one |
One camera, three weeks
The volume numbers are the part that tends to reframe the conversation, because they come from a single device on a single stretch of road.
Around 32 images per passing car is the number worth sitting with. The mental model most people carry is a speed camera: one trigger, one photo, one plate. A device generating dozens of frames per vehicle is building something closer to a short clip of every car that goes by, which is a materially different kind of record to hold and to request.
Flock’s response, and the part it does not address
The company’s reply was narrow. A spokesperson said the unauthorized removal and tampering of a Flock camera is illegal, and pointed researchers toward its vulnerability disclosure program.
Both points are fair as far as they go. Pulling hardware off a pole is not a sanctioned research method, and a disclosure program is the route a security researcher is supposed to take. What the statement does not do is contest any of the technical findings, which is the thing most readers actually wanted addressed.
The hackers, for their part, framed the exercise as a deliberate alternative to vandalism. Cameras have been physically destroyed in a number of places over the past year, and this group’s argument was that destruction wastes an opportunity.
“Why just destroy them when we can reverse engineer them and find the secrets of those spying on us?” one member told 404 Media. The group described having “liberated hardware in the field” before working through the cameras and their solar equipment.
Whatever you make of the method, the collective has said it intends to publish how it extracted the software, which means this is unlikely to be a single event. That is the practical consequence for Flock: the findings are now reproducible by anyone willing to take the same legal risk.
The context this lands in
This is not a company having its first difficult month. The Institute for Justice has documented multiple cases of police personnel using Flock’s system to look up current partners, former partners and strangers who caught their attention in public. Those were not breaches. They were authorized users, doing what the system allowed them to do.
Chief executive Garrett Langley has since conceded the company moved too slowly, telling the BBC that employees and communities expected Flock to take a stronger position and that he had resisted because he did not want the responsibility. The company is now shortening how long recordings are retained.
Why retention is the variable that matters
Shorter retention is a real concession, and it is aimed at the correct problem.
A single photograph of a car at an intersection is close to meaningless. The power of a network like this comes from persistence and coverage. Once you have months of records from hundreds of cameras, a plate number stops being a snapshot and becomes a movement history: where a vehicle goes, when, how often, and which other locations it correlates with.
That is the capability that made misuse by individual officers possible, and it is the capability that shrinks when the retention window shrinks. Cutting storage time does more to limit what the system can be abused for than any policy document, because it removes the raw material rather than restricting access to it.
It is also the argument that has been winning locally. A pair of Republican governors ordered Flock cameras pulled down in their states earlier this month, and city councils around the country have been voting contracts down. The pressure on this company has not been coming from one direction.
What to watch
- Whether Flock disputes the technical findings. So far it has addressed the method, not the substance. A point by point response would tell you a lot
- Whether the key handling gets fixed, and how fast. This is a firmware problem with a known solution. The timeline is the tell
- Whether people detection gets documented publicly. The capability may be benign. Finding out about it through a teardown is the part that erodes trust
- Whether the method spreads. If the extraction process is published and repeated, the company is dealing with an ongoing condition rather than an incident
Surveillance systems ask the public to accept a set of claims about what they do and do not capture, because the hardware is sealed and the software is not inspectable. That bargain works while the claims hold up.
Somebody opened the box. The encryption story did not survive contact with the inside of the device, and the description of what the camera watches turned out to be narrower than the camera itself. Those are both fixable. The harder thing to repair is the reason people went looking in the first place.

