Flock Cameras Run 8-Year-Old Android and Ship Hardcoded API Keys

Flock cameras are riddled with security vulnerabilities and hardcoded creds

Flock Cameras Run 8-Year-Old Android and Ship Hardcoded API Keys

Security researchers from the stegan0gram collective obtained filesystem images of a Flock ALPR camera and found it running Android 8.1 with a 2018 security patch level, plus a Linux 3.18.71 kernel from 2017. The firmware contains a hardcoded API key that can retrieve Auth0 credentials for any camera by MAC address, and those credentials are stored in plaintext. Flock says it received no vulnerability report and disputes the findings.

Presumably, you can use this hard-coded API key to obtain credentials for any Flock camera, based on its MAC address.
  1. zeech

    Discussion about the article this post is talking about: https://news.ycombinator.com/item?id=49726586

  2. autoexec

    Having hardcoded credentials is a sign of total incompetence. In this case at least it wasn't a password, but an API key which can be used to request credentials (stored in plaintext) which look like they'd get you access Flock's servers. Not quite as bad as a hardcoded admin password, and it's not clear what you'd be able to do if you did authenticate successfully as a camera, but its worrying enough. There have been enough vulnerabilities found in Flock's systems that it's pretty clear they aren't concerned about their security and it's plainly obvious that they don't care at all about our privacy or security.

    Even if we decided that this level of mass surveillance on the American public was acceptable to us, Flock Safety/Flock Group as already demonstrated that they can't and shouldn't be trusted to implement it.

  3. asveikau

    tldr from my skim, the two worst things:

    * Probably vulnerable to CVEs that were patched in 2018 and 2021.

    * Generates API key to phone home based only on its own MAC address.

More from this day

2026-09-16