A single camera. Somewhere in the neighborhood of 50,200 vehicles photographed. Roughly 1.6 million images produced. And all of that covers a mere 21 days — the stretch of activity that happened to still be sitting on the device’s storage before older logs were overwritten.
A group of hackers pulled a Flock camera down from its mount above a roadway, cloned nearly everything held inside it, and passed the files along for analysis. What surfaced from that dump is the most detailed view anyone outside the company has gotten of how Flock Safety’s automatic license plate readers perceive the world.
Boiled down: the software running on the camera is explicitly looking for people, not only cars. That fact tends to disappear in the public fight over these devices, which normally revolves around plates and vehicles.
Flock touts on-device encryption — the key was sitting right there
Flock has publicly framed its cameras as safeguarded by on-device encryption. The hackers imaged the camera’s storage and pulled an encryption key that was stored on the device itself, which in turn unlocked video of thousands of vehicle detections.
By their account, the camera runs Android, and they turned up two partitions — sections of the hard drive. A handful were left unencrypted, among them one labeled “vendor” and another labeled “media.” It was the media partition that contained the encryption key opening another partition packed with much of the video and stills the camera had captured.
A good deal of the most sensitive storage remained encrypted and inaccessible. Even so, enough shook loose to piece together how the device operates.
The hackers say they intend to publish their method for obtaining the software as well, in the hope that others will follow suit. The material was handed to the transparency nonprofit Distributed Denial of Secrets.
“Why just destroy them when we can reverse engineer them and find the secrets of those spying on us?” said one of the hackers, part of a collective going by stegan0gram, in an interview. “We liberated hardware in the field, disarmed them, and proceeded with reverse engineering of the cameras and associated solar equipment.”
Run the models yourself and here’s what they flag
The models were extracted from the camera’s files and then run against test imagery and footage recovered off the device. They picked out people without difficulty, including in a reporter’s selfie.
Next came the volume test: 27,321 brief videoclips sitting on the camera. Each was an MP4 running roughly one to two seconds, captured at 1,024 by 768 pixels, with no audio. They are distinct from the fast bursts of higher-resolution stills the camera takes as vehicles go by.
Out of all those clips, the models identified people in 11. Every one of them was on a motorcycle.
It’s a low count, and the explanation is mundane rather than comforting: this specific camera was perched above a roadway aiming down at traffic, a spot where pedestrians simply weren’t going to appear. Put identical hardware and identical software somewhere with foot traffic and the arithmetic looks very different.
Whenever the software identifies a person, it logs their position within the image along with its confidence in the detection.
An American flag patch got cropped like it was a license plate
This is where the computer vision starts to wobble. The license plate detector at times confused bumper stickers, dealership frames and assorted graphics for plates, cropping them out as though they were genuine.
In footage of one motorcycle going past, the detector cropped an American flag patch stitched to the rider’s saddlebag as if it were a license plate.
By itself that isn’t a scandal — it’s a detector behaving the way detectors behave around rectangular graphics. What it does reveal is how much interpretation takes place before any human being lays eyes on a record.
The face recognition finding points in the opposite direction. Flock maintains its cameras don’t do it, and the analysis surfaced no evidence of face-recognition capability in the camera’s software apart from what Android ships with by default. Those capabilities appeared to be neither enabled nor actively used.
Twenty-eight shots of your car — and the reading happens somewhere else
The device’s processor resembles something you’d find in a midrange smartphone. On top of it sit roughly 20 Flock-built apps covering motion detection, photo capture, object classification, uploads and remote updates.
The code shows that once something enters the frame, the camera rattles off a quick sequence of photos. An ordinary passing vehicle yielded about 28 images. Some triggered more than 100.
Exposure is varied so the camera can grab both the plate and the broader scene; it scans the images, picks and crops the useful frames, then pushes them along with other data to Flock over cellular.
What it apparently does not do is read the plate or work out make, model and color. That processing lives on Flock’s servers, which turn the results into time-stamped records searchable by whatever local agency owns the cameras or has access to them.
On a normal day, this camera tallied somewhere around 3,300 vehicles, peaking at 4,454. Those figures shift dramatically depending on where a camera sits and how heavy the traffic is.
The real flashpoint is who gets to search your car’s record
Flock’s national network allows police departments anywhere in the country to query cameras they have no ownership stake in. That’s simultaneously a sales pitch and a repeating controversy.
In Alpharetta, Georgia, more than 2,000 agencies could reach records from the city’s Flock cameras — police departments, colleges, airports and, for reasons nobody can explain, the Office of Inspector General for the federal General Services Administration.
Local officers have run national-network lookups on behalf of Immigration and Customs Enforcement, including in places that had barred cooperation with immigration authorities or the transfer of license plate data across state lines. In Texas, an officer searched Flock cameras nationwide looking for a woman who had self-administered an abortion.
Episodes like those are what escalated this into a nationwide argument over whether communities want the cameras in the first place.

Someone has cracked one open before
Back in early 2025, security researcher Jon “GainSec” Gaines reverse-engineered a Flock license-plate reader and wrote up flaws that could be leveraged for root-level access.
Flock conceded the findings while playing down how serious they were, arguing that exploiting the flaws required physical access and that anyone who did break into a camera “would still not be able to gain access to footage,” since images lingered on the device only momentarily after being sent to the cloud.
The thousands of vehicle detections pulled off this device make that argument considerably harder to sustain.
Then in August, frontend code for Flock’s police software — branded OS Investigate today, formerly Nightshift — came to light, and chunks of the tool were rebuilt from it. That software demonstrated how Flock fuses camera records with police files and commercial data to pin down drivers, flag vehicles that habitually travel in tandem and hunt for people using movement patterns. The camera dump is the opposite end of that same pipe.
What Flock says, and a warning from a former officer
In a statement, a Flock spokesperson said: “The unauthorized removal and tampering of a Flock camera is illegal.”
Pressed on the encryption key kept on the camera, the company said, “Flock takes security seriously and maintains a public Vulnerability Disclosure Policy for security researchers to report potential vulnerabilities directly to us. We received no report through that process, and based on the limited information provided, we do not have enough detail to assess the claims being made. If the individuals identified legitimate vulnerabilities, we encourage them to submit their technical findings through our vulnerability reporting process so our security team can review them and take any appropriate action.”
One of the hackers put it this way: “Being investigated is a legit concern and something we are trying to avoid. I’m sure our actions have attracted some attention as it is, but we are careful and try to keep a low profile.”
Arrests over alleged tampering with or sabotage of Flock cameras have piled up around the country. A number of towns have said they’re dropping the devices. One police department went so far as to 3D-print a decoy Flock camera case to lure vandals.
Noel Pichardo, once a police officer in Pawtucket, Rhode Island, became a vocal Flock critic after pushing back on his own department’s use of the cameras. He says the activists’ anger makes sense to him, but he worries that sabotage may end up bolstering the argument for the technology.
“I think that type of vigilantism will only crystallize the police and the state at large in their belief that this tool is necessary,” Pichardo says. “The longer the state continues to ignore the groanings of their constituents who are against this type of surveillance, the more this will happen.”
The logs are chaos, and whoever wrote them was enjoying themselves
However sophisticated the detection stack may be, the camera kept gagging on storage. Its logs captured upward of 27,000 “no space left on device” errors during attempts to write full-resolution images, alongside tens of thousands of associated errors, crashes and reboots.
And about every two minutes, a watchdog process confirmed the camera was still alive and wrote a message to the log: “Who’s a good boy?!” The recovered logs contain more than 12,000 of them.
Whenever the camera actually did reboot, a different service bowed out with “A reboot was requested! ¡Adiós, Amigos!”
If you’re wondering what one of these cameras knows about you, that’s the practical lesson hiding in all the noise. It’s a smartphone-grade computer bolted to a pole, perpetually running out of disk, merrily logging dog jokes, while it slices your car into 28 frames and ships them off to a server that 2,000 agencies might be able to query.













STAY ALWAYS UP TO DATE