Yep. Clown show.
> The hackers said they were able to access the Android system on the camera, and found two partitions—sections of its hard-drive, essentially. A few of these were unencrypted, the hackers said, including one called “vendor” and another called “media.” The latter contained an encryption key that unlocked another part, which contained much of the media—think, the videos and stills—the camera took.
> In early 2025, security researcher Jon “GainSec” Gaines reverse engineered a Flock license-plate reader and documented flaws that could be used to gain root-level access. After Gaines disclosed his findings, the company acknowledged the findings but downplayed their severity, writing that the flaws required physical access to the device and that even someone who gained access to a camera “would still not be able to gain access to footage” because images remained on the device only briefly after being transmitted to the cloud.
Source: https://www.404media.co/hackers-stole-flocks-camera-software...
How could anyone possibly physically access a device that is just sitting out in public?
YC's finest https://www.ycombinator.com/companies/flock-safety
Its impossible, I tell ya
TDIL my homebuilt Plex media server is more strongly encrypted than a Flock Camera
so is my all-passwords.txt file on my desktop
My passwords are in an encrypted block in a text file that can be unencrypted inline in an Emacs session with a keystroke sequence that looks like a cat just chased a mouse across the keyboard, and that's before entering the decryption password. To access it, an attacker would first have to learn Emacs. Pretty sure that's a post-quantum level of security.
They could use an LLM to lookup your HN posts and then to wrangle Emacs. Or just decrypt the text in another application - I doubt Emacs is the only platform for whatever crypto method you use. M-x rot13 ?
Oh, did I forget to mention the encryption is implemented in Emacs Lisp?
At some point, the attackers are just going to have to give up and start hitting me with a wrench. Joke's on them though - I'm an Emacs user, I like pain.
It's interesting and fun to implement this stuff; I totally agree. Emacs is amazing.
I worry people will get the wrong idea about security: The application used for decryption doesn't need to be the same as the one used for encryption, at least not for any serious attacker. That would be 'security through obscurity'. They need the encrypted text; they don't need Emacs.
More importantly, no matter who you are, that you implemented the encryption yourself (?) is a major flaw - unless you have a cryptography team that has matured the implementation over a decade or so. Nobody is good enough to do that by themself. As the saying goes, anyone can create an encryption routine that they can't break.
You do realize these are all jokes?
Maybe you do or did really believe those things - lots of people do. There's nothing wrong with it. Saying 'I was joking' is maybe true, maybe it's just using a very common tactic for covering.
emacs is not a joke emacs is life
https://youtu.be/urcL86UpqZc
Nefarious I like it
Obligatory relevant xkcd: https://xkcd.com/538/
It's a forever-fresh reminder about security versus your own government, but for malicious hackers and bots: the physical trip to visit you costs more than half their infrastructure.
Encryption matters, even if I would divulge everything long before the wrench appeared.
[dead]
Runs Android. Has (wireless?) internet access.
It seems that some enterprising Jolly Roger could start running a public mesh net on top of them without Flock even noticing.