frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Flock Exposed Its AI-Powered Cameras to the Internet. We Tracked Ourselves

https://www.404media.co/flock-exposed-its-ai-powered-cameras-to-the-internet-we-tracked-ourselves/
51•chaps•2h ago
https://archive.ph/IWMKe

Comments

dvtkrlbs•2h ago
I just watched the Benn Jordan's video on this. Even if this is just configuration error on some of their cameras this is terrifying and I think they should be held accountable for this and their previous myriad of CVEs.
chaps•1h ago
Here's the video for interested folk:

https://www.youtube.com/watch?v=vU1-uiUlHTo

tencentshill•1h ago
It's amazing that any vendor, let alone a CJIS vendor even allows unsecured deployments of their software in 2025.
edot•1h ago
Flock or their defenders will lock in on the excuse that “oh these are misconfigured” or “yeah hacking is illegal, only cops should have this data”. The issue is neither of the above. The issue is the collection and collation of this footage in the first place! I don’t want hackers watching me all the time, sure, but I DEFINITELY don’t trust the state or megacorps to watch me all the time. Hackers concern me less, actually. I’m glad that Benn Jordan and others are giving this the airtime it needs, but they’re focusing the messaging on security vulnerabilities and not state surveillance. Thus Flock can go “ok we will do better about security” and the bureaucrats, average suburbanites, and law enforcement agencies will go “ok good they fixed the vulnerabilities I’m happy now”
dvtkrlbs•1h ago
Yes and the biggest problem with this kind of ALPRs are they bypass the due process. Most of the time police can just pull up data without any warrant and there has been instances where this was abused (I think some cops used this for stalking their exes [1]) and also the most worrying Flock seems to really okay with giving ICE unlimited access to this data [2] [3] (which I speculate for loose regulations).

[1]: https://lookout.co/georgia-police-chief-arrested-for-using-f... [2]: https://www.404media.co/emails-reveal-the-casual-surveillanc... [3]: https://www.404media.co/ice-taps-into-nationwide-ai-enabled-...

throwway120385•1h ago
When you give access to any system that collects the personal information including location data for people in the US to the police, a percentage of the police will always use those systems for stalking their exes.
hugo1789•11m ago
What is not only true for police but for every sufficiently big group of people.
SamInTheShell•1h ago
Nothing will be done until one of the investors of the tech end up embarrassed from weaponization of the tech against themselves. These people have no clue how creepy some of their technologic betters can be. I once witnessed a coworker surveilling his own network to ensure his girlfriend wasn't cheating on him (this was a time before massive SSL adoption). The guy just got a role doing networking at my company and thankfully he wasn't there for very long after that.
tracker1•58m ago
I think more importantly people need to recognize that cops are people, flawed and fallible as is the flock system in general. It should never be the whole solution and be used as evidence alone.
bromuk•1h ago
Really great investigation, what's the URL of the "vibe coded" site with the access links?
eightysixfour•1h ago
I don't want these cameras to exist but, if they're going to, might we be better off if they are openly accessible? At the very least, that would make the power they grant more diffuse and people would be more cognizant of their existence and capabilities.
hrimfaxi•59m ago
Is it more symmetrical? I know in theory we all can continuously download and datamine these video feeds but can everyone really?
eightysixfour•56m ago
No, but the same argument could be made for things like open source software. We assume/hope that someone more aligned with our outcomes is actively looking.

Or, at the very least, that we can go back and look later.

hrimfaxi•52m ago
I don't think they are similar. Public feeds would enable someone to document and sell people's whereabouts in real time. The fact that I could do the same or go back and look later is no defense.
eightysixfour•9m ago
This is a different argument than what I was responding to.

> I know in theory we all can continuously download and datamine these video feeds but can everyone really?

To which my response is "this is like OSS." What I mean by that is that, in theory, people audit and review code submitted to OSS software, in reality most people trust that there are other people who do it.

> Public feeds would enable someone to document and sell people's whereabouts in real time. The fact that I could do the same or go back and look later is no defense.

This is a different argument to me and one that I'm still torn about. I think that if the feeds exist and the government and private entities have access to them, the trade-offs may be better if everyone has access to them. In my mind this results in a few things:

1. Diffusion of power - You said public feeds would "enable someone to document and sell people's whereabouts in real time." Well, private feeds allow this too. I'd rather have everyone know about some misdeed than Flock or the local PD blackmail someone with it.

2. Second guessing deployment - I think if the people making the decisions know that the data will be publicly available, they're more likely to second guess deploying it in the first place.

3. Awareness - if you can just open an app on your phone and look at the feed from a camera then you become aware of the amount of surveillance you are subject to. I think being aware of it is better than not.

There's trade-offs to this. The cameras become less effective if everyone knows where they are. It doesn't help with the location selection bias - if they're only installed in areas of town where decision makers don't live and don't go, the power is asymmetric again. Plenty of other reasons it is bad. None of them worse than the original sin of installing them in the first place.

eddyg•25m ago
Yes, they should be secured so they can only be accessed by law enforcement.

But if your spouse/SO/sister/mother/girlfriend/whatever was assaulted while jogging in a park that had Flock cameras, and it allowed law enforcement to quickly identify, track, apprehend and charge the criminal, you'd absolutely be grateful for the technology. There's nothing worse than being told "we don't have any leads" when someone you care about is attacked.

estimator7292•21m ago
What about when ICE uses this data to abduct and deport your spouse and family members? Will you be grateful then?
kernal•14m ago
If they committed a crime by entering the country illegally then yes. Are you grateful for all of the crimes committed by illegal aliens?
everdrive•18m ago
It's getting pretty crazy out there. What's your recourse for this? Avoid most populated areas?
murderingmurloc•12m ago
I live in a town of 6,000 and we have 5 Flock cameras
potato3732842•11m ago
It's a quality of people problem not a quantity of people problem.
neogodless•8m ago
Related:

https://news.ycombinator.com/item?id=46356182 Benn Jordan – This Flock Camera Leak Is Like Netflix for Stalkers [video] (youtube.com)

Where to see free Christmas light displays in California

https://californiachristmaslights.com/
1•nvader•1m ago•0 comments

Towards a secure peer-to-peer app platform for Clan

https://clan.lol/blog/towards-app-platform-vmtech/
1•todsacerdoti•1m ago•0 comments

Why is CSS the way it is?

https://increment.com/frontend/ask-an-expert-why-is-css-the-way-it-is/
1•fanf2•1m ago•0 comments

People Have Died in Crashes Where Tesla Doors Wouldn't Open

https://www.bloomberg.com/news/features/2025-12-22/tesla-door-safety-tied-to-at-least-15-auto-acc...
2•MBCook•2m ago•0 comments

AI Docs Generator

https://github.com/BinarCode/aidocs-cli
1•eduardlupacescu•2m ago•1 comments

Detecting Goroutine Leaks with DTrace

https://gaultier.github.io/blog/detecting_goroutine_leaks_with_dtrace.html
1•broken_broken_•2m ago•0 comments

Corporate Lawyers and Fat Envelope America

https://www.thebignewsletter.com/p/monopoly-round-up-corporate-lawyers
1•connor11528•3m ago•0 comments

YouTube Playables Builder Beta

https://www.youtube.com/playablesbuilder/
1•mcargian•4m ago•0 comments

I know you didn't write this

https://ammil.industries/i-know-you-didnt-write-this/
2•cjlm•4m ago•0 comments

Technology Supports and Undermines Democracy

https://hls.harvard.edu/today/how-technology-supports-and-undermines-democracy/
1•mooreds•4m ago•0 comments

Every CSS Named Color Organized by Palette

https://austingil.com/every-css-named-color-organized-by-palette/
1•speckx•4m ago•0 comments

The Politics of Superintelligence

https://www.noemamag.com/the-politics-of-superintelligence/
1•polotics•4m ago•0 comments

Can Americans learn to love tiny, cheap kei cars?

https://www.npr.org/2025/12/22/nx-s1-5644937/kei-cars-tiny-vehicles
1•neuralkoi•5m ago•0 comments

Intent: An LLM-Powered Reranker Library That Explains Itself

https://bits.logic.inc/p/open-sourcing-intent-an-llm-powered
1•sgk284•9m ago•0 comments

Model FaceOff – real world prompt comparison between models

https://www.modelfaceoff.com
1•eibrahim•10m ago•0 comments

AI Is Killing Our Online Interaction

https://ertu.dev/posts/ai-is-killing-our-online-interaction/
2•ertucetin•10m ago•0 comments

Estates of Being

https://thinkhuman.com/estates-of-being/
1•jamesgill•10m ago•0 comments

Freshwater and hydrogen generation using ion concentration polarization

https://www.nature.com/articles/s43246-025-01001-z
1•PaulHoule•13m ago•0 comments

Nonviolent Communication(NVC) at Workplace

https://ankit-maverick.github.io/nvc-workplace-infographic/
1•ankmav•16m ago•0 comments

Tools for Successful Documentation Projects

https://lwn.net/SubscriberLink/1049976/3a1fd436e92a5661/
1•mroche•16m ago•0 comments

Can Claude teach me to make coffee?

https://www.lesswrong.com/posts/aZYr5MBhxEbPQSt5N/can-claude-teach-me-to-make-coffee
1•paulpauper•17m ago•0 comments

We Put Claude Code in Rollercoaster Tycoon

https://labs.ramp.com/rct
2•ramplabs•17m ago•0 comments

Dervos 2025 Keynote: Solar Pill the World with Jesse Peltan

https://www.dertaskforce.com/p/dervos-2025-keynote-solar-pill-the
1•paulpauper•17m ago•0 comments

Against Against Boomers

https://www.astralcodexten.com/p/against-against-boomers
1•paulpauper•18m ago•0 comments

Christmas Songs That Do Too Much

https://danverbraganza.com/writings/christmas-songs-that-do-too-much
1•nvader•21m ago•0 comments

Hubble Tension Resolution via Temporal Spacetime Compression

https://github.com/Jordan-Townsend/hubble-tension-resolution
1•Subtextofficial•26m ago•1 comments

Emergency Autoland deployed when pilot becomes Incapacitated

https://www.flightradar24.com/blog/aviation-news/aviation-safety/garmin-emergency-autoland-deploy...
1•strangattractor•26m ago•1 comments

Brand as Code via brand.json / brand.txt

https://www.braingrid.ai/brand.json
1•acossta•26m ago•1 comments

Rivian's AI pivot is about more than chasing Tesla

https://www.theverge.com/transportation/846783/rivian-ai-autonomy-day-self-driving-lidar-chip-tesla
2•ianrahman•27m ago•0 comments

Analysing Screenshots from 10k Steam Games [video]

https://www.youtube.com/watch?v=FyhVJUJrvoM
1•chunkles•28m ago•0 comments