One camera. Roughly 50,200 vehicles photographed. About 1.6 million images generated. And thatās just 21 days of activity that happened to survive on the deviceās storage before older logs got overwritten.
A group of hackers ripped down a Flock camera mounted above a roadway, made a near-complete copy of the data stored inside it, and handed the files over for analysis. What came out of that dump is the clearest look anyone outside the company has gotten at how Flock Safetyās automatic license plate readers see the world.
The short version: the software on the camera explicitly detects people, not just cars. That detail tends to get lost in the public argument over these devices, which usually centers on plates and vehicles.
The encryption Flock talks about has a key sitting on the device
Flock has described its cameras as protected by on-device encryption. The hackers copied the cameraās storage and recovered an encryption key stored on the device itself, which unlocked videos of thousands of vehicle detections.
They said they found the Android system running on the camera and two partitions, sections of the hard drive. A few were unencrypted, including one called āvendorā and another called āmedia.ā The media partition held the encryption key that unlocked another partition containing much of the video and stills the camera captured.
Plenty of the most sensitive storage stayed encrypted and out of reach. But enough came loose to reconstruct how the thing works.
The hackers say theyāre also publishing details on how they obtained the software, hoping other people copy them. The material went to the transparency nonprofit Distributed Denial of Secrets.
āWhy just destroy them when we can reverse engineer them and find the secrets of those spying on us?ā one of the hackers, from a collective calling itself stegan0gram, said in an interview. āWe liberated hardware in the field, disarmed them, and proceeded with reverse engineering of the cameras and associated solar equipment.ā
What the models actually detect when you run them yourself
The models got extracted from the cameraās files and run against test images and footage recovered from the device. They readily detected people, including a selfie of a reporter.
Then came the bulk test: 27,321 short videoclips stored on the camera. MP4 files, each about one to two seconds long, recorded at 1,024 by 768 pixels, no audio. These are separate from the rapid bursts of higher-resolution stills the camera fires off as vehicles pass.
The models found people in 11 of those clips. All of them were riding motorcycles.
Thatās a small number, and the likely reason is boring rather than reassuring: this particular camera sat above a roadway pointed down at traffic, where pedestrians werenāt going to show up. Move the same hardware and the same software somewhere with foot traffic and the math changes.
When the software spots a person, it records where they appear in the image and how confident it is in the detection.
The plate detector cropped an American flag patch as if it were a plate
Hereās where the computer vision gets loose. In some cases the license plate detector mistook bumper stickers, dealership frames and other graphics for plates and cropped them out as if they were the real thing.
In one video of a passing motorcycle, the detector cropped an American flag patch on the riderās saddlebag as if it were a license plate.
Thatās not a scandal on its own. Itās a detector doing what detectors do with rectangular graphics. But it tells you something about how much interpretation is happening before a human ever looks at a record.
On face recognition, the finding cuts the other way. Flock insists its cameras donāt perform it, and the analysis turned up no evidence of face-recognition capability in the cameraās software beyond what ships by default in Android. Those capabilities didnāt appear to be enabled or in active use.
Twenty-eight photos of your car, and the reading happens elsewhere
The deviceās processor is similar to what youād find in a midrange smartphone. It runs about 20 Flock-built apps handling motion detection, photo capture, object classification, uploads and remote updates.
According to the code, when something moves into view, the camera fires a rapid series of photos. A typical passing vehicle generated about 28 images. Some produced more than 100.
The camera varies exposure to capture both the plate and the wider scene, scans the images, selects and crops useful frames, then sends them with other data to Flock over cellular.
What it doesnāt appear to do is read the plate or identify make, model and color. That happens on Flockās servers, which then make time-stamped records searchable by whichever local agency owns or has access to the cameras.
On a typical day, this camera logged around 3,300 vehicles, with a high of 4,454. Those numbers swing hard depending on placement and traffic volume.
Who can search your carās record is the part that keeps blowing up
Flockās national network lets police departments across the country query cameras they donāt own. Itās a selling point and a recurring controversy.
In Alpharetta, Georgia, records from the cityās Flock cameras were accessible to more than 2,000 agencies. Police departments, colleges, airports and, inexplicably, the Office of Inspector General for the federal General Services Administration.
Local cops have performed lookups in the national network on behalf of Immigration and Customs Enforcement, including in areas that banned working with immigration authorities or transferring license plate data out of state. A cop in Texas searched Flock cameras nationwide for a woman who self-administered an abortion.
Those cases are what turned this into a national argument about whether communities want these cameras at all.
This isnāt the first time someone took one apart
In early 2025, security researcher Jon āGainSecā Gaines reverse-engineered a Flock license-plate reader and documented flaws that could be used to gain root-level access.
Flock acknowledged the findings but downplayed their severity, writing that the flaws required physical access and that even someone who gained access to a camera āwould still not be able to gain access to footage,ā because images remained on the device only briefly after being transmitted to the cloud.
The current dump complicates that position, given the thousands of vehicle detections recovered from the device.
In August, frontend code for Flockās police software, now called OS Investigate and previously known as Nightshift, surfaced and portions of the tool were reconstructed. That software showed how Flock combines camera records with police files and commercial data to identify drivers, surface vehicles that repeatedly travel together and search for people based on movement patterns. The camera dump is the other end of that same pipe.
Flockās response, and a former copās warning
A Flock spokesperson said in a statement: āThe unauthorized removal and tampering of a Flock camera is illegal.ā
Asked specifically about the encryption key stored on the camera, the company added, āFlock takes security seriously and maintains a public Vulnerability Disclosure Policy for security researchers to report potential vulnerabilities directly to us. We received no report through that process, and based on the limited information provided, we do not have enough detail to assess the claims being made. If the individuals identified legitimate vulnerabilities, we encourage them to submit their technical findings through our vulnerability reporting process so our security team can review them and take any appropriate action.ā
One of the hackers said, āBeing investigated is a legit concern and something we are trying to avoid. Iām sure our actions have attracted some attention as it is, but we are careful and try to keep a low profile.ā
Multiple people around the country have been arrested for allegedly tampering with or sabotaging Flock cameras. Some towns have announced theyāll stop using them. One police department built a fake 3D-printed Flock camera case to bait vandals.
Noel Pichardo, a former Pawtucket, Rhode Island, police officer who became an outspoken critic of Flock after challenging his departmentās use of the cameras, says he understands the activistsā frustration but worries sabotage could strengthen the case for the devices.
āI think that type of vigilantism will only crystallize the police and the state at large in their belief that this tool is necessary,ā Pichardo says. āThe longer the state continues to ignore the groanings of their constituents who are against this type of surveillance, the more this will happen.ā
The logs are a mess, and somebody had fun writing them
For all the sophistication in the detection stack, the camera kept choking on storage. Its logs recorded more than 27,000 āno space left on deviceā errors while trying to save full-resolution images, plus tens of thousands of related errors, crashes and reboots.
And roughly every two minutes, a watchdog process checked that the camera was still running and logged a message: āWhoās a good boy?!ā More than 12,000 of those appear in the recovered logs.
When the camera did restart, another service signed off with āA reboot was requested! Ā”Adiós, Amigos!ā
If you want to know what one of these cameras has on you, thatās the practical takeaway buried in the noise. The device is a smartphone-class computer stapled to a pole, running out of disk, cheerfully logging dog jokes, while it cuts your car into 28 frames and ships them to a server that 2,000 agencies might be able to query.