| ▲ | killbot5000 2 hours ago |
| This is pure laziness aka “reduced time to market” on the part of Flock. It takes time and effort to think through proper secure boot architecture and to implement key management in a way that doesn’t kill developer productivity. Their product managers, though, should have realized that setting these up in unsecured public spaces means that their threat model really does include local physical access to everything. Using off the shelf hardware and software stacks all but guarantees attackers have tools at their fingertips to exploit said physical access. Given all the recent exploits hitting the kernel, there’s a good chance that there exists an exploitable over-the-air vulnerability present in their WiFi/bluetooth stack, too. |
|
| ▲ | teraflop an hour ago | parent | next [-] |
| The flip side of this laziness is that now, when my elected representatives tell me "these are just license-plate readers that don't record video", I have evidence to show them that's false. If Flock had done a more competent job of securing their system, it would be harder to demonstrate this in a compelling way. To a technically-inclined person, it's obvious from the get-go that somewhere in Flock's pipeline, video is being recorded and archived, and is therefore vulnerable to misuse. But the more they're allowed to keep the implementation proprietary, the easier this is to sweep under the rug. |
|
| ▲ | dietr1ch an hour ago | parent | prev | next [-] |
| I really hate how Product Managers somehow get to take the reins of engineering teams instead of having to sell them product ideas. It's madness, they often lack the technical skills and "optimise away" requirements surfaced by eng teams they don't comprehend or just don't like having to deal with. |
| |
| ▲ | pixl97 39 minutes ago | parent [-] | | Because software engineering is not professional engineering. Now, this doesn't always stops management, but when you have to have an engineering signoff it does make things a bit more difficult. |
|
|
| ▲ | wat10000 2 hours ago | parent | prev [-] |
| The question is, why should they care at all? Will this hurt their business? |
| |
| ▲ | NichoPaolucci 2 hours ago | parent | next [-] | | Any breach of security on a system like this is a big flashing red-alert to me. If it could lead an attacker to get ANY of their data... Persons, places, events, etc is pretty damning stuff to be exfiltrated. Stalking/Domestic Violence, blackmail, timed robberies, you name it... That data shouldn't really be in anyone's hands in my opinion, but in anyone's hands (good guys / bad guys) it's pretty powerful. | | |
| ▲ | overfeed 30 minutes ago | parent | next [-] | | Getting persistent access to Flock's internal network is a high-priority item for every US adversary, that's just free intel collection on the movements of persons of interest. Knowing who the FBI and local cops are monitoring in is a cherry on top of the counter-counter-intelligence cake. Any entity with access to flock servers can virtually stake-out anyone/everyone driving past Flock camera to monitor their movements. In a hot war, this would provide actionable data to support assassination via road-side bomb/drone strikes. | |
| ▲ | wat10000 an hour ago | parent | prev | next [-] | | That's why you or I would care, but that doesn't answer the question of why they would. Large companies tend to be amoral. Unless it affects them monetarily (possibly indirectly) they're not going to care. Given what they do to make money, I don't see any of these things hurting them. | |
| ▲ | sixothree an hour ago | parent | prev | next [-] | | Apparently police are accessing the network via their personal devices. I highly doubt their security practices online are any better than this. I wouldn't be surprised either to see things that chinese manufacturers do such as intentional back doors. Overall this goes from disappointing to fairly repugnant. | | |
| ▲ | iAMkenough an hour ago | parent [-] | | Allegedly you can buy credentials on the darkweb to perform national searches. Might explain why some of the logged reasons for recent searches were “LMAO” | | |
| ▲ | DANmode an hour ago | parent [-] | | The normal explanation is plenty, unless you’ve never met, read about, or heard anyone talk about, law enforcement officers (who are human beings - for better and for worse). |
|
| |
| ▲ | fapjacks 27 minutes ago | parent | prev [-] | | Many moons ago, I was involved in the technical side of volunteer work for domestic violence victims escaping abusive relationships with e.g. law enforcement (cops), who even fifteen years ago had sweeping powers to track and stalk their victims. Things like actual anonymous burner phones and the ability to e.g. create new email accounts without government identification were critical to the process of getting these people out safely, or alive, without fear of retaliation. I can't even imagine how difficult this job must be nowadays, with bullshit like Flock spanning hundreds of police departments participating in their nationally-linked database. I have zero sources for what I'm about to say, but my instinct is that the political machines (expanding powers hidden behind "think of the children") behind how technology is evolving today has gotten people killed. |
| |
| ▲ | afavour 2 hours ago | parent | prev | next [-] | | Quite potentially, yes. Their name is already mud among many voters, if they're shown to be treating data insecurely then that's another reason why local governments might consider terminating contracts with them. | |
| ▲ | MattDaEskimo an hour ago | parent | prev | next [-] | | Feels like their purpose is to test the boundaries, take the hits, and eventually sell off | |
| ▲ | ryandrake 2 hours ago | parent | prev [-] | | Is there any recent example of a company getting breached and its data exfiltrated, where the business was actually hurt? I predict we'll get a standard boilerplate "We take security very seriously" press release, a narrative that blames the evil hackers entirely and not the company's negligence, and then that will be that. |
|