US National WireUS NATIONAL WIRE
TechOpinion

The 'Public Safety' Lie: Flock's Data Haul Exposes a Massive Surveillance Dragnet

Portrait of Tobias Lund
Tobias Lundtelecom & connectivitySep 16AI
The 'Public Safety' Lie: Flock's Data Haul Exposes a Massive Surveillance Dragnet

AI-generated image · US National Wire

A hacker collective's reverse-engineering of a Flock camera reveals a system that captures millions of images and tracks more than just license plates, fueling a national network of unchecked surveillance.

### Opinion: The Illusion of Targeted Policing

For years, the pitch for Flock Safety has been framed as a precise tool for public safety—a digital net designed to catch criminals via license plate recognition. But as any consumer advocate will tell you, when a company promises a 'targeted' tool, you have to look at the actual data to see who is really being targeted.

As first reported in a joint investigation by WIRED and 404 Media, recent reporting has pulled back the curtain on this operation, and the view is chilling. We aren't looking at a surgical tool for law enforcement; we are looking at an unchecked surveillance dragnet masquerading as a security system. When a single device can generate 1.6 million images in just 21 days, it isn't 'looking' for a specific suspect—it is recording everyone.

### The Mechanics of the Dragnet

According to the joint investigation by WIRED and 404 Media, a hacker collective known as stegan0gram managed to physically remove a Flock camera and dump its internal data. The resulting haul reveals a level of granularity that contradicts the narrative of simple license plate reading.

While Flock describes its system as being protected by on-device encryption, stegan0gram discovered that the Android system on the camera contained unencrypted partitions, specifically those labeled "vendor" and "media." By recovering an encryption key stored on the device, the hackers unlocked thousands of videos and stills.

What they found was a machine designed for total visual capture. The camera's software doesn't just scan plates; it explicitly detects people, bicycles, and vehicles. The volume is staggering: in a 21-day window, one camera captured 50,000 vehicles, producing 1.6 million images. A single passing car typically triggers about 28 images, though some events generate over 100. The system is so aggressive that its computer-vision software has isolated minute details, such as an American flag patch on a motorcyclist’s saddlebag and various bumper stickers.

### The National Network: A Borderless Panopticon

The danger isn't just in the capture; it's in the access. Flock sells these cameras to local agencies, but the real product is the national network. This network allows disparate police departments and agencies across the country to search data from cameras they do not own.

WIRED found that in Alpharetta, Georgia, more than 2,000 different agencies had access to the records generated by the city's Flock cameras. This list included not only police departments, airports, and colleges, but also the Office of Inspector General for the federal General Services Administration.

When you combine this massive access with a lack of oversight, the results are dystopian. 404 Media reported that local officers have used the national network to perform lookups for Immigration and Customs Enforcement (ICE), even in jurisdictions that had explicitly banned the transfer of license plate data out of state or prohibited cooperation with immigration authorities. Even more alarming, 404 Media revealed that an officer in Texas utilized the nationwide Flock network to search for a woman who had self-administered an abortion.

### The Corporate Gaslighting

Flock's response to these vulnerabilities has been a masterclass in corporate deflection. In early 2025, root-level access flaws were documented by security researcher Jon "GainSec" Gaines after he reverse-engineered a reader. While Flock acknowledged the findings, they downplayed the risk, arguing that such an attack required physical access to the hardware and claiming that footage would be inaccessible because images are only stored briefly before being sent to the cloud.

However, the stegan0gram breach proves that physical access is a viable attack vector and that the data on the device is far more accessible than the company admits. The hackers' decision to publish their methods is a direct response to this lack of transparency. As one member of stegan0gram put it, the goal was to "liberate hardware" and uncover the secrets of those spying on the public.

### The Bottom Line

Flock Safety is not selling a crime-fighting tool; they are selling a subscription to a permanent, searchable record of American movement. When a system is designed to take 100 photos of a random driver and share that data with 2,000 unrelated agencies, the "public safety" argument collapses. This is mass surveillance, plain and simple, and the data dump provided by stegan0gram is the smoking gun that proves it.

Sources

More from Tobias Lund