This reporting was done in collaboration with 404media. Here's the discussion for 404's article: https://news.ycombinator.com/item?id=49726577

Distributed Denial of Secrets has published the partition images: https://ddosecrets.org/article/flock-alpr-camera

I poked around in the boot partition. The kernel is ancient!

Linux version 3.18.71-perf-gaf770dc

3.18.71-perf-gaf770dc is a Qualcomm Android vendor kernel from roughly late 2017. The 3.18 branch went fully EOL in 2019, so nothing after that was ever backported to it.

2017 was also the year Flock was funded and founded and went through the YConbinator cohort.

But you would have thought that by 2021 when Andreessen Horowitz funded them or at least by 2025 [1] when both further funded them, someone would have actually done some minor due diligence. Coincidentally too, 2025 was when the flock surveillance matrix went up all over the country almost immediately.

We constantly hear that the magic of tech funding lies in the people, not even the product/service. These types of things always seem to uncover that that is effectively just a lie to cover up the ulterior motives of setting up a tyrannical surveillance matrix all around you … to protect the children, of course.

[1] https://www.flocksafety.com/blog/flock-safety-secures-major-...

In an ideal world they'd have people whose job it is to monitor upstream activity in the components used in the firmware and maintain this. Sounds like they did not have that.

[deleted]

It's almost as if they paid a contractor to design the hardware back in 2017 and put all the funding into marketing(bribes) since then. Shocker.

"It's only a problem if your definition of done makes it one".

Interesting that they are a YC Company. Does yC do any ethics vetting of saying "No, let's stop fascism before it spreads?"

YC does no meaningful vetting at all. You can steal another YC entrant’s product and still get funded.

https://deepdelver.substack.com/p/delve-fake-compliance-as-a...

many cases already public of rejected founders having their idea pushed on accepted founders with bad ideas.

TIL but not surprising.

I would recommend reading "The Nerd Reich" by Gil Duran for context on this question.

It’s in my list, but has been deprioritized because I am familiar with the primary sources.

I don’t think you are catching on. Why would tyrants do ethics vetting? You assume God intentions?

I’m not a fan of the sloppy use of fascism in lieu of the more suitable term, tyranny (which I believe is intentional distraction, because that’s what I would have done), however, if you understand the mechanism of a YC and its total reliance on the money printing fraud, you would understand that YC is the closest thing to “fascism” there actually is, the federal government’s money printing fraud fueling and life blood of the Monopoly money they print to defraud you of value, in order to run their own little con job of how impressive and futuristic and modern these companies are that rely on extracting of value and exploiting vulnerabilities, not actually creating value.

Flock by a guy named Langley is at the very best a rather poetic example of that. I doubt they’re sophisticated enough to have worked this out, but they’re exploiting the vulnerability of people wanting and needing to feel safe in a system that maintains deliberate danger as a social engineering mechanism to control and dominate and even up until recently, deliberately degrade the populace.

What better way to get to more “fascist” fraudulent Monopoly money than to promise the people who’s lives you’ve made insecure that you can protect them through 24/7 surveillance of all of their activities and thoughts.

It’s not really a new thing; the “Patriot” Act was the first major act that simply shoved the American Revolution aside, but Flock by Langley is just the first instance of it being apparent through its ham fisted swashbuckling YC “beak things fast” clown approach that has unfortunately made many people extremely rich, and thus we got more of it.

Security through obsolescence!

That's how we got Chinese APT in our phone systems that we are apparently going to do nothing about. Seriously, can be fixed, AT&T et all just won't

The oldest supported kernel is 5.10 and that loses support in December. That's wild they are using a 3.X kernel

You'd be surprised how many things you use daily that people still backport the bare minimum to clig to 2.4.x forever

I really hope those don't have access to any networks.

good chance the linux running in your high end phone's modem runs 2.x kernel.

i dont deal with that anymorrle, but last one I saw with 2.x was the pixel 6 pro.

Just check, my 2YO phone runs kernel 6.6, not latest but i think good enough for production.

Edited: I misunderstood what you mean, you were talking about the modem subsystem, sorry.

I don't think you misunderstood, I think they're talking out their arse. Modems don't run Linux, they run RTOS operating systems. ShannonOS in the case of the Pixel 6 with a exynos modem

The pixel 6 pro runs ShannonOS an RTOS system, it's an exynos modem

Yeah I've seen plenty of kernels that start with a 2 with no forward path possible due to "we don't know how to get our driver working anymore"

To be fair if you could SLTS support by CIP (which is designed for things like this) you have 4.19 at least still maintained. 4.4 might still be too but I'd have to check

>gaf770dc

missing a d(gaf)

sorry, had to get that out!

[deleted]

do the articles have significantly different information/coverage to warrant two submissions?

No, they're the same article. I had only read 404's when I submitted them and I assumed they'd both be submitted regardless.

I can't read the Wired article because I'm only allowed three excerpts and 15 ads a day at Wired.com

same, but i'm not sure how that's related to my comment. workarounds or alternate articles without significant new information are typically posted within the same submission, not separate ones.