Captured Flock Camera Had Encryption Key on an Unencrypted Partition
The short version: A teardown by The Kernel Panic Brief reportedly found a Flock camera's encryption key sitting on an unencrypted partition, undercutting Flock's security claims while confirming the devices classify people, vehicles, and bikes.
Our Take
If this teardown holds up, it's a pretty damning find. Flock has spent years telling cities, police departments, and the public that its network of plate readers is a tightly secured system handling sensitive location data responsibly. The Kernel Panic Brief's hardware analysis suggests otherwise — a security misstep as basic as leaving an encryption key on an unencrypted partition isn't a theoretical vulnerability, it's the kind of thing that undermines the entire chain-of-custody argument these companies lean on when they ask the public to trust them with millions of data points on where we drive, when, and how often.
It also confirms something we've said for a while: these cameras aren't just reading plates. The software reportedly flags people, vehicles, license plates, and bicycles — meaning the footprint of this surveillance net is broader than the marketing suggests. When a vendor says 'we only track cars,' recovered firmware doing object detection on pedestrians and bikes tells a different story about what's actually being built and stored.
Credit to The Kernel Panic Brief for doing the unglamorous work of pulling this system apart instead of taking the spec sheet at face value. This is exactly the kind of independent verification that mass surveillance infrastructure depends on nobody doing. Check our camera map to see what's been documented near you, and if you want to push back on a local deployment, our take-action page has concrete next steps.
This is DeFlock The USA’s original commentary. The video above is the work of The Kernel Panic Brief, published on YouTube — full credit to the creator.