Public Safety
The Encryption Key Was on the Flock Camera
A recovered Flock ALPR held its encryption key on the device, computer-vision models that detect people, and 21 days of logs covering about 1.6 million images. That is a procurement fact, not a hacking story.
September 16, 2026 · 8 min read

A collective calling itself stegan0gram took a Flock Safety automatic license plate reader off a pole, copied what was on it, and handed the files to 404 Media and WIRED. I am not going to cheer that. Pulling a camera that is not yours is a crime, and Flock said so in its statement. I am going to treat the recovered files the way I would treat any other piece of field evidence: what was actually on the box, and what that means for the next agency that signs a contract.
What matters is what the hardware still held after Flock told customers that physical access would not yield footage.
What was actually on the device
WIRED and 404 Media analyzed the dump together. The camera is built like a midrange Android phone and runs about 20 Flock-built apps for motion, capture, classification, cellular upload, and remote updates. Motion triggers a burst of stills. A typical passing vehicle produced about 28 images. Some produced more than 100. The camera crops useful frames and ships them over cellular. Plate reading and make, model, and color identification appear to happen on Flock's servers, not on the pole.
The recovered logs covered about 21 days of activity, not necessarily consecutive. In those windows the device photographed roughly 50,200 vehicles and generated about 1.6 million images. A typical day logged around 3,300 vehicles, with a high of 4,454. Older logs had been overwritten. The camera was also throwing more than 27,000 "no space left on device" errors while trying to save full-resolution images, plus tens of thousands of related crashes and reboots. A sensor that is out of disk is dropping evidence. The agency that owns it should see that from the vendor console before a reporter does.
Most of the most sensitive storage stayed encrypted. Enough did not.
Encryption that keeps the key next to the pictures
Flock has described the system as protected by on-device encryption. City-facing materials go further. A Flock privacy FAQ circulated to municipalities says data is encrypted throughout its lifecycle, stored with AES-256 in AWS, and kept on the device only briefly until upload. A 2025 security alert responding to independent research said the reported flaws were not material, required physical access, and that even then an attacker "would still not be able to gain access to footage, as the data is only stored for a very limited time duration on the device following its transmission to the cloud."
The recovered camera had unencrypted partitions, including one named media. That partition held an encryption key. The key unlocked videos and stills of thousands of vehicle detections.
Encryption with the key stored on the same device is not a novel failure. It is the difference between "the disk is scrambled" and "the disk is scrambled, and the combination is taped to the underside." TLS to the cloud can be real. AES-256 in AWS can be real. Neither of those claims answers the question a physical-security review would ask first: if I am holding the camera, can I read what it still has on it?
In early 2025, researcher Jon "GainSec" Gaines documented root-level issues on a Falcon/Sparrow unit he owned and disclosed them. Flock acknowledged the report, filed related CWEs, and said it would fix devices with over-the-air updates and new factory settings. It also said it had not determined a need to remediate units already in the field.
Flock's statement on this incident is that removing and tampering with a camera is illegal, that it maintains a public vulnerability disclosure policy, and that it did not receive a report through that process with enough detail to assess the claims. Those can all be true at once. A disclosure inbox is not a substitute for a threat model that includes a ladder.
People detection is already in the software
The product is sold as an automatic license plate reader. The software on the camera explicitly detects people, vehicles, plates, and bicycles. When it spots a person, it records where they appear in the frame and how confident it is.
WIRED extracted the models and ran them on 27,321 short clips from the camera. People showed up in 11 clips, all motorcyclists, which is what you would expect from a unit pointed down at a roadway. The plate detector also cropped bumper stickers, dealership frames, and an American flag patch on a saddlebag as if they were plates. WIRED found no face recognition in active use, only unused Android defaults.
Object detection of a person still produces coordinates and a confidence score. Those fields can be logged, queried, and joined to other records later, including in Flock's police software, now called OS Investigate, which WIRED reconstructed from frontend code in August. That tool can identify drivers from camera records plus police files and commercial data, surface vehicles that travel together, and search people by movement patterns.
I spent 13 years in law enforcement. Plate readers, used with a real case, a real hot list, and an audit trail, are a legitimate investigative tool. The procurement problem is the gap between the brochure and the model list. If the camera already isolates people in the frame, that belongs in the privacy impact assessment and the city council packet, in the same paragraph as retention and sharing. It should not arrive as a surprise in a journalists' dump.
The network you actually bought
The camera is the sensor. The product agencies argue about is the network.
Flock's national lookup lets other departments search cameras they do not own. In Alpharetta, Georgia, WIRED found records accessible to more than 2,000 organizations. 404 Media separately showed local officers running national lookups on behalf of ICE, including in places that had banned that cooperation, and a Texas officer searching nationwide for a woman who self-administered an abortion. Flock later pulled some states out of the national tool.
If the council approved "our cameras, our cases, 30-day retention," and the configuration that shipped is searchable by thousands of other orgs, you did not buy the system you thought you bought. Stealing the sensor does not fix that. Turning off nationwide sharing, or never turning it on, does.
Noel Pichardo, a former Pawtucket, Rhode Island officer who has been a public critic of his department's Flock deployment, told WIRED he understands the anger and still thinks vandalism will "crystallize the police and the state at large in their belief that this tool is necessary." He is right about the politics. The work that actually changes the deployment is still the contract: what the camera detects, where the key lives, how long images sit on the pole, and who can query the results, in writing.
What belongs in the next contract
If you are a chief, a city attorney, a board member, or a vendor in this market, the dump gives you a short list you can put in an RFP without waiting for the next pole to come down.
- On-device key management. Is the media encryption key stored on the camera? Can it be extracted from an unencrypted partition? If yes, say so, and state the residual risk in plain language instead of "on-device encryption."
- What the models detect. Publish the object classes: plates, vehicles, bicycles, people, anything else. If people are a class, the privacy impact assessment has to treat them as a class.
- What stays on the pole, and for how long. "Briefly" is not a retention period. Give hours or days, the overwrite policy, and what a stolen unit would still contain at hour 24, day 7, and day 21.
- Storage and health telemetry the customer can see. If the camera is throwing tens of thousands of disk-full errors, the agency should know before a reporter does.
- Sharing as a default-off control. Name every class of organization that can search the feed today. Require a logged, reason-coded, customer-approved grant for each one. Nationwide search is a product feature. It is not a side effect.
I keep a free AI Governance Toolkit for this kind of work: risk-tier the capability, write down what the model is allowed to see, and put a human on the hook for the configuration that actually shipped. A template does not replace a contract review. It beats discovering the model list from a stolen camera.
Flock can be right that taking the hardware was illegal, and still be wrong that physical access was a low-severity footnote. Agencies that already deployed these units should ask for the current key-storage answer in writing, not as a 2025 blog post. Agencies that have not deployed yet should put that question in the packet before the first pole goes up.