Flock Safety’s security cameras have become the focus of privacy debates. As concerns grow in communities where the cameras have been installed, examples have also emerged of law enforcement officers abusing access. The contents of one camera’s disk were leaked; Micah Lee’s investigation showed that the system contained serious security vulnerabilities. Instead of a specially hardened operating system, the devices use Android 8.1, released in 2017 and no longer supported. The relationship between this choice and Flock Safety’s founding in 2017 is unclear; known vulnerabilities remain unpatched. The more serious issue is a hard-coded, widely accessible API key that can be used to obtain information from any Flock camera using its MAC address. It is not known whether this can be fixed through software. Further findings are expected as investigations continue.
Why it matters
The findings show that the debate concerns not only the presence of cameras in public spaces, but also how access to these systems is restricted. An unsupported operating system and known vulnerabilities that have not been patched mean that while the cameras are being used for security purposes, they may remain vulnerable in terms of their own infrastructure. The widely accessible hard-coded API key means the problem is not limited to a single device; the ability to obtain information through the MAC address of any Flock camera directly affects communities and law enforcement access. However, it is not yet clear whether the vulnerability can be addressed through software, how extensive the abuse is, or whether further findings will emerge from the investigations.