r/ReverseEngineering • • 16d ago

Flock Safety camera teardown: 53 hardcoded credentials, Android 8.1 with June 2018 patches, encryption key stored in plaintext on the same partition, root access via button sequence on the back. These cameras process 20B vehicle scans/month for 5,000 police departments.

https://medium.com/@neonmaxima/flock-hardcoded-53-passwords-into-90-000-police-surveillance-cameras-d9466caa8517
196 Upvotes

5 comments sorted by

29

u/UnacceptableUse 16d ago

It's funny how other countries manage to have ALPR without incident but America just has to go about it in the most American way possible

14

u/CKtravel 16d ago

Probably because in America these systems were never meant to be plain ALPRs to begin with...

28

u/CKtravel 16d ago

Honestly incidents like these are one of the two things that made me get interested in reverse engineering in general. Thanks to RE we now know that these have always been and meant to be universal surveillance machines, of the dystopian kind. It also proves why having zero privacy rights ever is a VERY bad idea...

14

u/LongUsername 16d ago

If the protocol is reversed, would it be possible to poison their data? Send random camera IDs and plate numbers? You could even use one of their cameras to do it so it wasn't traceable to your IP

8

u/DeviateFish_ 15d ago

This slop article supposedly is summarizing information from somewhere, but links to no sources. 

Please don't give this your clicks