A rare technical investigation of a Flock Safety camera reveals how much data a single device can collect in just a few weeks. Researchers found tens of thousands of vehicle records, more than a million images, thousands of short video clips, object-detection software capable of recognizing vehicles, bicycles and people, and locally stored data that could be accessed after the camera was physically removed. The findings offer a detailed look at how Flock’s system works — and raise new questions about privacy, data security and the growing use of automated surveillance technology.
A new technical investigation is providing one of the clearest looks yet at what happens inside a Flock Safety automated license plate reader after a vehicle passes in front of it.
A hacker collective calling itself stegan0gram physically removed a Flock camera installed above a roadway, copied nearly all of the data stored on the device and shared the material with journalists at WIRED and 404 Media. The two outlets analyzed the files, software, logs and video recovered from the camera.
The findings show that a single camera can generate a much larger amount of imagery than the simple phrase “license plate reader” might suggest.
About 50,200 vehicles in 21 days
The recovered logs contained approximately 21 days of usable activity spread across several periods.
During that time, the camera recorded about 50,200 vehicle encounters and generated approximately 1.6 million images. On a typical day, the device logged around 3,300 vehicles, while the busiest day represented in the recovered records included 4,454 vehicles.
Those figures should not be interpreted as what every Flock camera records. Traffic volume depends heavily on where an individual camera is located. The investigators also noted that the camera had almost certainly been operating outside the recovered periods, but older logs had already been overwritten or were no longer recoverable.
One passing vehicle can produce dozens of photographs
The investigation found that the camera does not simply take one photograph each time a license plate passes.
According to the recovered software, when motion enters the camera’s view, the system takes a rapid sequence of photographs using different exposures.
A typical vehicle encounter produced approximately 28 images. Some vehicles generated more than 100 imagesduring a single pass.
The different exposures help capture both the license plate and the wider scene. Software running on the device then analyzes the images, selects useful frames, crops portions of them and sends selected information to Flock through a cellular connection.
That provides important context for the figure of 1.6 million images: it does not mean 1.6 million different vehicles were recorded. Many images were generated from repeated shots of the same passing vehicle.
The camera itself does part of the analysis
The recovered device contained a processor similar to those used in midrange smartphones and ran roughly 20 applications developed by Flock.
According to WIRED’s analysis, those applications performed functions including motion detection, taking photographs, classifying objects, preparing data for upload and receiving software updates.
The physical camera appears to perform part of the computer-vision work locally, but investigators found that more advanced processing — such as reading the actual plate and determining a vehicle’s make, model and color — appears to occur on Flock’s servers rather than entirely inside the roadside device.
The software can detect people — not only cars
One of the more significant findings concerned what the computer-vision software was designed to recognize.
The recovered software contained models capable of detecting:
vehicles, license plates, bicycles and people.
When the software detects a person, according to WIRED, it records the person’s position within the image along with a confidence score indicating how certain the model is that the object is human.
Investigators extracted the computer-vision models from the camera and tested them separately. The models successfully detected people in test photographs, including a photograph of one of the reporters.
However, this particular camera was positioned above a roadway rather than a pedestrian area, so very few people appeared in the recovered footage.
More than 27,000 short video clips were stored
Investigators found 27,321 short video clips on the camera.
The clips were approximately one to two seconds long, had a resolution of 1,024 × 768 pixels, and contained no audio. They were separate from the higher-resolution bursts of still photographs taken when vehicles passed.
When WIRED ran the recovered detection models across those 27,321 clips, the software identified people in 11 clips. All of the detected people were riding motorcycles.
The investigators said the low number was probably explained by the location and angle of this particular camera rather than an inability of the software to recognize people.
It sometimes mistook other objects for license plates
The investigation also revealed limitations in the detection system.
In some cases, the software interpreted bumper stickers, dealership frames and other graphics as possible license plates and cropped them as though they were plates.
In one example described by WIRED, the detector identified an American flag patch on a motorcycle saddlebag as though it might be a license plate.
That does not mean the system ultimately classified those objects as valid plate numbers. It shows what the first-stage detection software may select for further analysis.
Investigators found no active facial-recognition system
The finding that the camera can detect a person is different from facial recognition.
WIRED and 404 Media reported that they found no evidence that Flock’s software on this camera was performing facial recognition. Some face-related functionality existed as part of the underlying Android operating system, but investigators found no indication that it was enabled or being actively used by Flock’s camera software.
So the distinction is important: the recovered software could recognize that an object was a person, but investigators did not find evidence that the camera was identifying who that person was by their face.
An encryption key was stored on the camera
The security findings may be just as important as the surveillance findings.
Flock has previously described its cameras as using on-device encryption. But after physically obtaining this camera, the hackers said they were able to access its Android operating system and examine different sections of its storage.
Some storage remained encrypted and inaccessible.
But investigators reported that other partitions were not encrypted. One of those areas contained an encryption key that could be used to unlock another section containing a substantial amount of the camera’s photographs and video.
This does not mean someone could remotely obtain all Flock camera data simply by connecting to the system. The researchers had physical possession of the device. That distinction is crucial.
But the discovery raises questions about what data can remain accessible if someone physically obtains one of the cameras.
The camera also experienced storage problems
The internal logs showed that the device was not operating without technical problems.
Investigators found more than 27,000 “no space left on device” errors generated while the camera was attempting to save full-resolution images.
The logs also contained tens of thousands of other error messages, crashes and reboots.
Those records provide a rare glimpse at the amount of data the camera was processing locally before information was transferred elsewhere.
What happens to the data after the camera captures it?
Flock cameras photograph vehicles and transmit selected images and associated information through a cellular network to the company’s infrastructure.
According to WIRED’s technical analysis, the roadside camera performs initial processing, but Flock’s servers appear to carry out additional analysis such as reading license plates and identifying characteristics including a vehicle’s make, model and color.
Those records can then become searchable by the law-enforcement agency operating the camera and, depending on that agency’s sharing settings and agreements, potentially by other agencies within the Flock network.
Previous WIRED reporting found, for example, that records from Flock cameras in Alpharetta, Georgia, were accessible to more than 2,000 agencies and institutions. That finding concerns that particular network configuration and should not be assumed to represent the access settings of every city or police department using Flock.
What Flock Safety says
Flock Safety disputed the circumstances under which the information was obtained rather than providing an immediate technical confirmation of all of the findings.
The company told WIRED that unauthorized removal and tampering with a Flock camera is illegal.
Regarding the encryption-key finding, Flock said it maintains a public vulnerability disclosure process for security researchers and had not received a report about these findings through that system. The company said it did not have enough information to independently assess the researchers’ claims and encouraged anyone who discovered legitimate vulnerabilities to submit the technical details for review.
What the investigation does — and does not — prove
The investigation is based on one physically obtained Flock camera, so the recovered numbers should not automatically be applied to every Flock device in the country.
It does establish something more specific: this particular operational camera retained enough software, logs, images and video for researchers to reconstruct in considerable detail how it processed traffic during the recovered period.
And the scale was substantial: approximately 50,200 vehicle encounters, 1.6 million images and 27,321 short video clips, from roughly three weeks of recoverable activity on one roadside device.
The findings also show why the national discussion around automated license plate readers has expanded beyond license plates themselves. The technology involves rapid image capture, object detection, local processing, cloud analysis and potentially large searchable networks of vehicle-location records.
At the same time, the investigation did not find evidence that this camera was actively performing facial recognition, and because researchers physically possessed the device, the findings should not be described as proof that outsiders can remotely retrieve the same information from any Flock camera.
Sources: WIRED — Hackers Got Inside a Flock Camera. Its Data Shows How the System Really Works;
by Aziza Smailović

