Flock Safety cameras exposed by hard-coded credentials
The short version: YouTuber Sanjay Ray says he found hard-coded credentials and shoddy security baked into Flock Safety's ALPR cameras, raising fresh doubts about who can actually access this surveillance data.
Our Take
Sanjay Ray's video digs into something we've been saying for a while: a nationwide network of license plate cameras is only as trustworthy as the security behind it. If his findings hold up — hard-coded credentials baked into the devices — that's not a minor bug. That's the kind of flaw that can let anyone with basic technical skills quietly tap into a system that's already vacuuming up your location history, plate number, and driving patterns, no warrant required.
Flock has built its business on convincing towns and cops that this technology is locked down tight and only accessible to "authorized" users. Hard-coded credentials undercut that pitch entirely — they suggest corners were cut in the rush to blanket the country with cameras. When the infrastructure of mass surveillance is this widespread, security isn't a nice-to-have, it's the whole ballgame. A breach doesn't just expose one person's data, it can expose the movements of everyone who's ever driven past one of these poles.
Credit to Sanjay Ray for putting real technical scrutiny on a company that mostly gets a pass from local governments. If you want to see how close this surveillance is to your own neighborhood, check our camera map, and if you're ready to push back on your city council or police department, our take-action guide is the place to start.
This is DeFlock The USA’s original commentary. The video above is the work of Sanjay Ray, published on YouTube — full credit to the creator.