News: 0180604682

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

What Happened After Security Researchers Found 60 Flock Cameras Livestreaming to the Internet (youtube.com)

(Saturday January 17, 2026 @05:41PM (EditorDavid) from the I'll-be-seeing-you dept.)


A couple months ago, YouTuber Benn Jordan "found vulnerabilities in some of Flock's license plate reader cameras," [1]reports 404 Media's Jason Koebler . "He reached out to me to tell me he had learned that some of Flock's Condor cameras were left live-streaming to the open internet."

This led to a remarkable article where Koebler [2]confirmed the breach by visiting a Flock surveillance camera mounted on a California traffic signal. ("On my phone, I am watching myself in real time as the camera records and livestreams me — without any password or login — to the open internet... Hundreds of miles away, my colleagues are remotely watching me too through the exposed feed.")

> Flock left livestreams and administrator control panels for at least 60 of its AI-enabled Condor cameras around the country exposed to the open internet, where anyone could watch them, download 30 days worth of video archive, and change settings, see log files, and run diagnostics. Unlike many of Flock's cameras, which are designed to capture license plates as people drive by, Flock's Condor cameras are pan-tilt-zoom (PTZ) cameras designed to record and track people, not vehicles. Condor cameras can be set to automatically zoom in on people's faces... The exposure was initially discovered by YouTuber and technologist Benn Jordan and was shared with security researcher Jon "GainSec" Gaines, who [3]recently found numerous vulnerabilities in several other models of Flock's automated license plate reader (ALPR) cameras.

Jordan appeared this week as a guest [4]on Koebler's own YouTube channel , while Jordan released a video of his own about the experience. titled " [5]We Hacked Flock Safety Cameras in under 30 Seconds ." (Thanks to Slashdot reader [6]beadon for sharing the link.) But together Jordan and 404 Media also created another video three weeks ago titled " [7]The Flock Camera Leak is Like Netflix for Stalkers " which includes footage he says was "completely accessible at the time Flock Safety was telling cities that the devices are secure after they're deployed."

The video decries cities "too lazy to conduct their own security audit or research the efficacy versus risk," but also calls weak security "an industry-wide problem." Jordan explains in the video how he "very easily found the administration interfaces for dozens of Flock safety cameras..." — but also what happened next:

> None of the data or video footage was encrypted. There was no username or password required. These were all completely public-facing, for the world to see.... Making any modification to the cameras is illegal, so I didn't do this. But I had the ability to delete any of the video footage or evidence by simply pressing a button. I could see the paths where all of the evidence files were located on the file system...

>

> During and after the process of conducting that research and making that video, I was visited by the police and had what I believed to be private investigators outside my home photographing me and my property and bothering my neighbors. John Gaines or [8]GainSec , the brains behind most of this research, lost employment within 48 hours of the video being released. And the sad reality is that I don't view these things as consequences or punishment for researching security vulnerabilities. I view these as consequences and punishment for doing it ethically and transparently.

>

> I've been contacted by people on or communicating with civic councils who found my videos concerning, and they shared Flock Safety's response with me. The company claimed that the devices in my video did not reflect the security standards of the ones being publicly deployed. The CEO even posted on LinkedIn and boasted about Flock Safety's security policies. So, I formally and publicly offered to personally fund security research into Flock Safety's deployed ecosystem. But the law prevents me from touching their live devices. So, all I needed was their permission so I wouldn't get arrested. And I was even willing to let them supervise this research.

>

> I got no response.

So instead, he read Flock's official response to a security/surveillance industry research group — while standing in front of one of their security cameras, streaming his reading to the public internet.

"Might as well. It's my tax dollars that paid for it."

" 'Flock is committed to continuously improving security...'"



[1] https://www.404media.co/how-benn-jordan-discovered-flocks-cameras-were-left-streaming-to-the-internet/

[2] https://www.404media.co/flock-exposed-its-ai-powered-cameras-to-the-internet-we-tracked-ourselves/

[3] https://www.youtube.com/watch?v=uB0gr7Fh6lY

[4] https://www.youtube.com/watch?v=tSd0nXolnIs

[5] https://www.youtube.com/watch?v=uB0gr7Fh6lY

[6] https://www.slashdot.org/~beadon

[7] https://www.youtube.com/watch?v=vU1-uiUlHTo

[8] https://gainsec.com/whoami/



work with a city (Score:3)

by Registered Coward v2 ( 447531 )

Get a city to demand Flock let them do a security check with their own reserach and make the results public. If tehy are secure, I'm sure Flock will say OK, no problem...

So? (Score:1, Flamebait)

by johnnys ( 592333 )

So a bunch of cameras are streaming live video of a public space on the Internet.

So what? It's a public space with no expectation of privacy. Does a camera have to point to a coffeepot to be acceptable?

Re:So? (Score:5, Informative)

by gardyloo ( 512791 )

Maybe you didn't mean to react to the security researcher's quotes, but too bad. It was there, in the public posting space. So I'm going to drop part of it here:

"I had the ability to delete any of the video footage or evidence by simply pressing a button. I could see the paths where all of the evidence files were located on the file system..."

That's part of the "so what?".

Re: (Score:2)

by PPH ( 736903 )

> I had the ability to delete any of the video footage or evidence by simply pressing a button.

Please don't change any of this, Flock. You have already created reasonable doubt that any criminal with more than a room temperature IQ defense attorney can use for acquittal. Even fixing this _now_ will require documented security measures plus ongoing compliance testing. Or Flock evidence will never be worth a fluck.

Re: (Score:2)

by jacks smirking reven ( 909048 )

These cameras are being used by law enforcement is the problem, IE, they are being used to track your movements and report to the police so their security procedures matter. This isn't a wildlife cam or a retail store with some cameras pointed outside.

Re: (Score:3)

by jacks smirking reven ( 909048 )

Is that it? That's your argument for why Flock has lax security, they should be allowed? Do you even understand the criticism here or are you just a crime slopper?

I mean Flock also lead to this situation so you know, it's not all good!

[1]Officer who used Flock cameras to falsely accuse Denver woman of theft will face unspecified disciplinary action [coloradosun.com]

Watch the video and look just *how sure* he is only to have gotten it completely wrong.

On the other hand maybe your straw-man argument should actually be my positio

[1] https://coloradosun.com/2025/11/11/columbine-valley-police-officer-flock-disciplinary-action/

Re: (Score:1)

by johnnys ( 592333 )

It's a shame you don't understand police work. Evidence is actually needed: Public video is very valuable, as is citizen-posted cell phone video and reports, provided they are not "edited" for malicious purpose.

Look at what happened in Minnesota: Lots of video of the murder of the woman in the SUV has been very helpful in keeping that horror from being swept under the rug. (Note: I don't consider ICE as "police": They are racist and untrained brownshirts.)

And your Denver situation is far more a straw man ar

Re: (Score:2)

by jacks smirking reven ( 909048 )

You're arguing against phantoms.

Do you understand the criticism. Nowhere did I make the argument "Police shouldn't use cameras" but the people running those cameras since it is used to literally prosecute people should be sure and follow the laws. Do you not agree to that?

If the video in Minnesota was captured by Flock cameras (was any of it?) and police or civilians were able to break in and delete or replace those videos is that good for anyone?

Do you understand or just want to make up positions to argue

Re: (Score:2)

by Pitawg ( 85077 )

It is a shame you do not understand police work. The only evidence is You being added to the suspect-to-annoy list for every crime Flock records you face, car, or relative nearby within a range of time near each crime near a camera.

Being a suspect used to mean something. Now it means you were within a mile of something.

Evidence is not what you think it is. (Nor them for that matter.)

Re: (Score:2)

by Bahbus ( 1180627 )

> Evidence is actually needed: Public video is very valuable

Sure, but public video with ALPR that *anyone* can access and *anyone* can view/modify/delete the contents is not needed. And it doesn't bode well for the security on the rest of them.

> Look at what happened in Minnesota

Sure, but those, ultimately, are videos being taken by regular people. The police/city government doesn't own those. Flock cameras are only owned by police/city and the police will lie if, and whenever, able. ICE can access Flock (and Ring) cameras.

> And your Denver situation is far more a straw man argument (Or "argue by exception") than mine.

It's not. Cop uses exact same technology to be bad. Researcher claims security

Re: (Score:2)

by Kernel Kurtz ( 182424 )

> It's a shame you don't understand police work. Evidence is actually needed: Public video is very valuable, as is citizen-posted cell phone video and reports, provided they are not "edited" for malicious purpose.

Indeed. Unlike these cameras which are apparently publicly and anonymously editable.

Re: (Score:2)

by Calydor ( 739835 )

They're also Pan, Tilt, Zoom cameras. If you have full access to their settings it'd be easy to turn the camera into a private area.

Re: (Score:1)

by sirbreyer ( 10503225 )

I think the point isn't as much the product (which I am sure supports authentication and encryption) but the reaction. OK, some partner installed it in the laziest way possible and said 'pay me'. The reaction is a common one nowadays - deny or even retaliate. Not even going into the lack of verification during/after handoff.

Live streaming toilet cam? (Score:1)

by klipclop ( 6724090 )

That's what I was expecting. He found some misconfigured cameras streaming people's personal spaces to the Internet.. Instead he discovered weather and traffic cameras in public spaces live streaming to the Internet? There are a lot of government websites that purposely do this. Causing lots of drama over a small mistake is a very unprofessional thing to do if you want to be taken seriously as a "reporter"

Re: (Score:1)

by Chungus ( 10502837 )

I can tell you have a good heart, and good intentions. Now pretend you're a serial killer with nefarious intentions.

"We hacked... in under 30 seconds"? (Score:2)

by 93 Escort Wagon ( 326346 )

I realize that language is fluid, and the meaning of words can change based on popular usage. But using "hacked" to mean "we visited a web portal that was left open to the internet"? Come on...

I guess slashdot.org gets hacked millions of times a year! And my department's website gets hacked hundreds of times a day!

We need an award (Score:4, Funny)

by david.emery ( 127135 )

"Best response to a security vulnerability"

> So instead, he read Flock's official response to a security/surveillance industry research group — while standing in front of one of their security cameras, streaming his reading to the public internet.

> "Might as well. It's my tax dollars that paid for it."

> " 'Flock is committed to continuously improving security...'"

Nothing (Score:2, Informative)

by rsilvergun ( 571051 )

Nothing happened. The people who are better than you, you're betters, want this and you are too busy freaking out about whatever they're telling you to freak out about this week that has no bearing on your civil rights or the economy to do anything about it.

And if by some miracle you've realized this is a bad idea and you're looking for a way to stop it your Fox News loving Grandpa is going to fuck shit up at the elections.

What amazes me is that this is all happening out in the open right where we c

Re: (Score:2)

by PPH ( 736903 )

> stop using "us" and "we" in your posts

Maybe rsilvergun has a mouse in his pocket.

Find Your Nearest Camera (Score:4, Informative)

by SlashbotAgent ( 6477336 )

Find your nearest cameras on [1]Deflock's map [deflock.me].

It's actually pretty jarring to see how many installed cameras there are.

The absurdity of statements from Flock's CEO, PR, and legal departments are pretty disturbing as well.

I'd noticed them around my town recently. But, I hadn't given them much thought. But, after watching Jordan's video and seeing the map... Yikes! Panopticon in 4, 3, 2...

[1] https://deflock.me/

Re: (Score:1)

by mrbester ( 200927 )

Seems like there need to be some "Blade Runners" taking these cameras down.

To those who say there is no expectation of privacy, there is also no expectation of blanket covert surveillance.

"Oh, but it isn't covert. You can clearly see the cameras" They are supposed to be monitoring t vehicles. Who do you approach to FOIA the footage taken of you?

More interesting, or disturbing ... (Score:3)

by fahrbot-bot ( 874524 )

> What Happened After Security Researchers Found 60 Flock Cameras Livestreaming to the Internet

They were filming in a "V" pattern and heading South for the winter.

Avoidence makes me happy. (Score:2)

by Pitawg ( 85077 )

Every time I am not caught on a camera, while not committing a crime, is another happy moment realizing my own or my loved ones' pets will not be shot at home by a panicky LEO asking if I saw anything through a wall, or jumped out of my car walked climbed over the wall and committed the carjacking, I was reportedly near within the hour time span I was stuck in traffic, between times I was recorded between multiple cameras.

Nothing ever becomes real until it is experienced.
-- John Keats