Having hardcoded credentials is a sign of total incompetence. In this case at least it wasn't a password, but an API key which can be used to request credentials (stored in plaintext) which look like they'd get you access Flock's servers. Not quite as bad as a hardcoded admin password, and it's not clear what you'd be able to do if you did authenticate successfully as a camera, but its worrying enough. There have been enough vulnerabilities found in Flock's systems that it's pretty clear they aren't concerned about their security and it's plainly obvious that they don't care at all about our privacy or security.

Even if we decided that this level of mass surveillance on the American public was acceptable to us, Flock Safety/Flock Group as already demonstrated that they can't and shouldn't be trusted to implement it.

I too am appalled by the inefficiencies of the bureaucracy of the Gestapo. A serious threat to the state and the people could take days to reach the correct authorities. Only zhast month a smuggler escaped zhe guards, no doubt an agent of foreign intelligence.

I get the joke, but this is kind of why the security issue matters

Btw, Germans have no problem with pronouncing the letter L (before a vowel, anyway)

East Germans also wouldn't criticize the Statsi as a show of loyalty, and nobody would read about a security failure in the state news. So the story must be told by one of its characters. :-)

Exactly. The scary part isn't any single bug, it's the mismatch between the sensitivity of the system and the apparent security model

I for one welcome the incompetence. Godspeed to whoever is able to deploy a build to the whole device fleet that burns SoM boot protection fuses to an image that doesn't do anything hard bricking their entire network.

oversights like these are what eventually lead to situations like in 'Watch Dogs' and 'Cyberpunk' where you have these one click exploit that can break every tech and surveillance gadget in sight