frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Flock Exposed Its AI-Powered Cameras to the Internet. We Tracked Ourselves

https://www.404media.co/flock-exposed-its-ai-powered-cameras-to-the-internet-we-tracked-ourselves/
76•chaps•3h ago
https://archive.ph/IWMKe

Comments

dvtkrlbs•2h ago
I just watched the Benn Jordan's video on this. Even if this is just configuration error on some of their cameras this is terrifying and I think they should be held accountable for this and their previous myriad of CVEs.
chaps•2h ago
Here's the video for interested folk:

https://www.youtube.com/watch?v=vU1-uiUlHTo

tencentshill•2h ago
It's amazing that any vendor, let alone a CJIS vendor even allows unsecured deployments of their software in 2025.
edot•2h ago
Flock or their defenders will lock in on the excuse that “oh these are misconfigured” or “yeah hacking is illegal, only cops should have this data”. The issue is neither of the above. The issue is the collection and collation of this footage in the first place! I don’t want hackers watching me all the time, sure, but I DEFINITELY don’t trust the state or megacorps to watch me all the time. Hackers concern me less, actually. I’m glad that Benn Jordan and others are giving this the airtime it needs, but they’re focusing the messaging on security vulnerabilities and not state surveillance. Thus Flock can go “ok we will do better about security” and the bureaucrats, average suburbanites, and law enforcement agencies will go “ok good they fixed the vulnerabilities I’m happy now”
dvtkrlbs•2h ago
Yes and the biggest problem with this kind of ALPRs are they bypass the due process. Most of the time police can just pull up data without any warrant and there has been instances where this was abused (I think some cops used this for stalking their exes [1]) and also the most worrying Flock seems to really okay with giving ICE unlimited access to this data [2] [3] (which I speculate for loose regulations).

[1]: https://lookout.co/georgia-police-chief-arrested-for-using-f... [2]: https://www.404media.co/emails-reveal-the-casual-surveillanc... [3]: https://www.404media.co/ice-taps-into-nationwide-ai-enabled-...

throwway120385•1h ago
When you give access to any system that collects the personal information including location data for people in the US to the police, a percentage of the police will always use those systems for stalking their exes.
hugo1789•1h ago
What is not only true for police but for every sufficiently big group of people.
SamInTheShell•1h ago
Nothing will be done until one of the investors of the tech end up embarrassed from weaponization of the tech against themselves. These people have no clue how creepy some of their technologic betters can be. I once witnessed a coworker surveilling his own network to ensure his girlfriend wasn't cheating on him (this was a time before massive SSL adoption). The guy just got a role doing networking at my company and thankfully he wasn't there for very long after that.
tracker1•1h ago
I think more importantly people need to recognize that cops are people, flawed and fallible as is the flock system in general. It should never be the whole solution and be used as evidence alone.
bromuk•2h ago
Really great investigation, what's the URL of the "vibe coded" site with the access links?
eightysixfour•1h ago
I don't want these cameras to exist but, if they're going to, might we be better off if they are openly accessible? At the very least, that would make the power they grant more diffuse and people would be more cognizant of their existence and capabilities.
hrimfaxi•1h ago
Is it more symmetrical? I know in theory we all can continuously download and datamine these video feeds but can everyone really?
eightysixfour•1h ago
No, but the same argument could be made for things like open source software. We assume/hope that someone more aligned with our outcomes is actively looking.

Or, at the very least, that we can go back and look later.

hrimfaxi•1h ago
I don't think they are similar. Public feeds would enable someone to document and sell people's whereabouts in real time. The fact that I could do the same or go back and look later is no defense.
eightysixfour•1h ago
This is a different argument than what I was responding to.

> I know in theory we all can continuously download and datamine these video feeds but can everyone really?

To which my response is "this is like OSS." What I mean by that is that, in theory, people audit and review code submitted to OSS software, in reality most people trust that there are other people who do it.

> Public feeds would enable someone to document and sell people's whereabouts in real time. The fact that I could do the same or go back and look later is no defense.

This is a different argument to me and one that I'm still torn about. I think that if the feeds exist and the government and private entities have access to them, the trade-offs may be better if everyone has access to them. In my mind this results in a few things:

1. Diffusion of power - You said public feeds would "enable someone to document and sell people's whereabouts in real time." Well, private feeds allow this too. I'd rather have everyone know about some misdeed than Flock or the local PD blackmail someone with it.

2. Second guessing deployment - I think if the people making the decisions know that the data will be publicly available, they're more likely to second guess deploying it in the first place.

3. Awareness - if you can just open an app on your phone and look at the feed from a camera then you become aware of the amount of surveillance you are subject to. I think being aware of it is better than not.

There's trade-offs to this. The cameras become less effective if everyone knows where they are. It doesn't help with the location selection bias - if they're only installed in areas of town where decision makers don't live and don't go, the power is asymmetric again. Plenty of other reasons it is bad. None of them worse than the original sin of installing them in the first place.

kgwxd•38m ago
They don't grant power, they enhance it. Not helpful for those without don't have any actual power.
lubujackson•33m ago
Did you see the other post about this where the guys showed a Flock camera pointed at a playground, so any pedo can see when kids are there and not attended?

Or how it has become increasingly trivial to identify by face or license plate such that combining tools reaches "movie Interpol" levels, without any warrant or security credentials?

If Big Brother surveillance is unavoidable I don't think "everyone has access" is the solution. The best defense is actually the glut of data and the fact nobody is actively watching you picking your nose in the elevator. If everyone can utilize any camera and its history for any reason then expect fractal chaos and internet shaming.

eddyg•1h ago
Yes, they should be secured so they can only be accessed by law enforcement.

But if your spouse/SO/sister/mother/girlfriend/whatever was assaulted while jogging in a park that had Flock cameras, and it allowed law enforcement to quickly identify, track, apprehend and charge the criminal, you'd absolutely be grateful for the technology. There's nothing worse than being told "we don't have any leads" when someone you care about has been attacked.

estimator7292•1h ago
What about when ICE uses this data to abduct and deport your spouse and family members? Will you be grateful then?
gs17•54m ago
They should also require a warrant at least, especially for any data sharing. With "they can only be accessed by law enforcement", we've already had plenty of police harassing their exes. If they couldn't convince a judge to let them use the camera, there's really no hope of the case going anywhere.

> There's nothing worse than being told "we don't have any leads" when someone you care about is attacked.

I'd argue worse is "we know exactly who did it and we're not going to do anything about it (but we would do something if you try to do something about it yourself)".

fzeroracer•50m ago
What if your spouse/SO/whatever was wrongfully arrested because they were on a Flock camera and conveniently matched what the police were looking for? Or if they ran whatever dogshit AI algorithm over it looking for suspects?

We can make up situations all day where it can or can not be validated but the reality is that this is a defacto surveillance state. If every move you make can be monitored, you should assume that the state can and will abuse it to hurt innocent people in the name of politics or whatever.

gs17•24m ago
Or if they were simply being harassed because their ex was a cop who decided to use the cameras to stalk them, where there's not even an excuse.
kgwxd•46m ago
What's the point of making a statement like that? Is it like a Snapple cap thing, or do you expect people to actually give up on talking about the blatant government overreach?

And what a dumb way to frame it. "Think of the woman" is the same argument as "think of the children". Why not just say if you were attacked you'd want it to be on camera? Afraid it'll make you sound weak? Well, so does bootlicking.

dexwiz•46m ago
Until your spouse/SO/sister/mother/girlfriend spurns a LEO, and then the LEO uses it to stalk and harass them. Talk to any LEO, they constantly misuse their data access to look up friends/family/neighbors to find dirt. Most of the time its relatively harmless gossip, but it can easily be used to harass people.
tediousgraffit1•33m ago
"Those who would give up essential Liberty, to purchase a little temporary Safety, deserve neither Liberty nor Safety."
542354234235•26m ago
Maybe I’m crazy, but I don’t want laws to be written to the level of my emotional individual reaction to a singular crime. I want laws to reflect the ideals and values of society, and to work at scale when balancing individual freedom, societal safety, and protection from government abuse.

“It is better, so the Fourth Amendment teaches us, that the guilty sometimes go free than the citizens be subject to easy arrest.” - Former Supreme Court Justice William O. Douglas

everdrive•1h ago
It's getting pretty crazy out there. What's your recourse for this? Avoid most populated areas?
murderingmurloc•1h ago
I live in a town of 6,000 and we have 5 Flock cameras
potato3732842•1h ago
It's a quality of people problem not a quantity of people problem.
potzemizer•33m ago
I mean. There are solutions...

https://www.bbc.com/news/world-europe-46822472

neogodless•1h ago
Related:

https://news.ycombinator.com/item?id=46356182 Benn Jordan – This Flock Camera Leak Is Like Netflix for Stalkers [video] (youtube.com)

ChrisArchitect•33m ago
Associated Benn Jordan video post: https://www.youtube.com/watch?v=vU1-uiUlHTo
fusslo•26m ago
I wonder what our founders would think about tools like Flock.

From what I understand these systems are legal because there is no expectation of privacy in public. Therefore any time you go in public you cannot expect NOT to be tracked, photographed, and entered into a database (which may now outlive us).

I think the argument comes from the 1st amendment.

Weaponizing the Bill of Rights (BoR) for the government against the people does not seem to align with my understanding of why the Bill of Rights was cemented into our constitution in the first place.

I wonder what Adams or Madison would make of it. I wonder if Benjamin Franklin would be appalled.

I wonder if they'd consider every license plate reading a violation of the 4th amendment.

GaryBluto•10m ago
I'm not sure if it's better or worse to have it publicly accessible or only accessible to an elite group.

The Illustrated Transformer

https://jalammar.github.io/illustrated-transformer/
16•auraham•23m ago•3 comments

US 'demolishing its scientific leadership with a wrecking ball'

https://sciencebusiness.net/news/horizon-europe/us-demolishing-its-scientific-leadership-wrecking...
7•xqcgrek2•7m ago•0 comments

Scaling LLMs to Larger Codebases

https://blog.kierangill.xyz/oversight-and-guidance
145•kierangill•4h ago•67 comments

Claude Code gets native LSP support

https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md
127•JamesSwift•3h ago•63 comments

Let's write a toy UI library

https://nakst.gitlab.io/tutorial/ui-part-1.html
41•birdculture•6d ago•2 comments

NIST was 5 μs off UTC after last week's power cut

https://www.jeffgeerling.com/blog/2025/nist-was-5-μs-utc-after-last-weeks-power-cut
35•jtokoph•2h ago•19 comments

Your Supabase Is Public

https://skilldeliver.com/your-supabase-is-public
37•skilldeliver•3h ago•19 comments

The biggest CRT ever made: Sony's PVM-4300

https://dfarq.homeip.net/the-biggest-crt-ever-made-sonys-pvm-4300/
178•giuliomagnifico•6h ago•116 comments

Jimmy Lai Is a Martyr for Freedom

https://reason.com/2025/12/19/jimmy-lai-is-a-martyr-for-freedom/
181•mooreds•2h ago•78 comments

Benn Jordan – This Flock Camera Leak Is Like Netflix for Stalkers [video]

https://www.youtube.com/watch?v=vU1-uiUlHTo
228•SamInTheShell•2h ago•134 comments

Uplane (YC F25) Is Hiring Founding Engineers (Full-Stack and AI)

https://www.useparallel.com/uplane1/careers
1•MarvinStarter•2h ago

Henge Finder

https://hengefinder.rcdis.co/#learn
19•recursecenter•2h ago•4 comments

The ancient monuments saluting the winter solstice

https://www.bbc.com/culture/article/20251219-the-ancient-monuments-saluting-the-winter-solstice
145•1659447091•10h ago•82 comments

Microsoft will kill obsolete cipher that has wreaked decades of havoc

https://arstechnica.com/security/2025/12/microsoft-will-finally-kill-obsolete-cipher-that-has-wre...
111•signa11•6d ago•63 comments

A year of vibes

https://lucumr.pocoo.org/2025/12/22/a-year-of-vibes/
149•lumpa•9h ago•82 comments

Debian's Git Transition

https://diziet.dreamwidth.org/20436.html
139•all-along•11h ago•38 comments

There's no such thing as a fake feather [video]

https://www.youtube.com/watch?v=N5yV1Q9O6r4
50•surprisetalk•4d ago•15 comments

Programming languages used for music

https://timthompson.com/plum/cgi/showlist.cgi?sort=name&concise=yes
197•ofalkaed•2d ago•78 comments

Show HN: Netrinos – A keep it simple Mesh VPN for small teams

https://netrinos.com
70•pcarroll•2d ago•35 comments

The Rise of SQL:the second programming language everyone needs to know

https://spectrum.ieee.org/the-rise-of-sql
5•b-man•4d ago•0 comments

Flock Exposed Its AI-Powered Cameras to the Internet. We Tracked Ourselves

https://www.404media.co/flock-exposed-its-ai-powered-cameras-to-the-internet-we-tracked-ourselves/
82•chaps•3h ago•34 comments

Show HN: An easy way of broadcasting radio around you (looking for feedback)

https://github.com/dpipstudio/botwave
18•douxx•4d ago•1 comments

How I protect my Forgejo instance from AI web crawlers

https://her.esy.fun/posts/0031-how-i-protect-my-forgejo-instance-from-ai-web-crawlers/index.html
123•todsacerdoti•1d ago•70 comments

Deliberate Internet Shutdowns

https://www.schneier.com/blog/archives/2025/12/deliberate-internet-shutdowns.html
282•WaitWaitWha•4d ago•143 comments

If you don't design your career, someone else will (2014)

https://gregmckeown.com/if-you-dont-design-your-career-someone-else-will/
336•TheAlchemist•9h ago•182 comments

Disney Imagineering Debuts Next-Generation Robotic Character, Olaf

https://disneyparksblog.com/disney-experiences/robotic-olaf-marks-new-era-of-disney-innovation/
265•ChrisArchitect•21h ago•113 comments

Decompiling the Synergy: Human–LLM Teaming in Reverse Engineering [pdf]

https://www.zionbasque.com/files/papers/dec-synergy-study.pdf
33•matt_d•5d ago•1 comments

Webb observes exoplanet that may have an exotic helium and carbon atmosphere

https://science.nasa.gov/missions/webb/nasas-webb-observes-exoplanet-whose-composition-defies-exp...
119•taubek•3d ago•32 comments

Aliasing

https://xania.org/202512/15-aliasing-in-general
84•ibobev•6d ago•24 comments

Functional Flocking Quadtree in ClojureScript

https://www.lbjgruppen.com/en/posts/flocking-quadtrees
100•lbj•6d ago•10 comments