What a Removed Flock Camera Reveals About Surveillance
A removed Flock camera exposed stored media, detection logs and an encryption key, sharpening the debate over roadside surveillance and oversight rules.
Written by AI. Zara Chen

A Flock Safety camera that snapped about 28 images of a typical passing car makes the old “nothing to hide” debate feel almost adorably outdated. A generation was asked whether one photo of one innocent trip should matter. This box could take more than 100 photos of one vehicle, classify what it saw and send the results into a searchable system. Privacy math gets weird fast when one glance becomes a database entry.
The collective stegan0gram pulled the camera down from above a roadway, copied nearly all its data and supplied the files to 404 Media and Distributed Denial of Secrets, which passed them to WIRED. The two newsrooms analyzed the material and published their findings on September 16. The operation required physical possession of the camera; the published accounts do not describe a remote breach of Flock’s network.
That requirement matters, but roadside hardware lives outside. “You need the box” is a useful security boundary only while nobody can get the box. The recovered device offers a case study in what happens after that boundary has already called in sick.
What the Camera Was Doing
The Next Web’s account of the joint investigation says the researchers found unencrypted partitions named “vendor” and “media.” The media partition held a key that unlocked another section containing much of the camera’s video and still imagery. Much of the device’s most sensitive storage remained encrypted.
Flock’s description of on-device encryption therefore survives with a large asterisk attached. The examined camera contained encrypted storage, while a key found elsewhere on that device opened a substantial media collection. The findings do not establish that every Flock camera has the same configuration, that one device’s key works on another or that physical access provides entry to Flock’s servers. This is one camera with roughly 21 days of recovered logs, not a census of the fleet.
Inside that one box, though, the workload was busy. It reportedly ran about 20 Flock applications handling motion detection, photography, object classification, uploads and remote updates. The recovered periods covered roughly 50,200 photographed vehicles and 1.6 million images. A typical vehicle generated about 28 photos, while some generated more than 100.
A summary of the joint analysis says the device logged around 3,300 vehicles on a typical day and peaked at 4,454. Its software detected vehicles, bicycles, plate-like shapes and people. When it flagged a person, it recorded their location in the frame and a confidence score.
Investigators found people in 11 of 27,321 short clips they tested, all on motorcycles. They found no sign that Flock used the default facial-detection capabilities included with Android. The plate detector did crop bumper stickers and dealership frames as possible plates. In one clip, it selected an American flag patch on a motorcyclist’s saddlebag. Computer vision saw a rectangle and basically said, “close enough.” Any harm then depends on how servers, officers and agency rules handle that guess.
The camera’s logs add a slightly cursed product-demo vibe. More than 27,000 entries said “no space left on device.” About every two minutes, a health check announced “Who’s a good boy?!” The second detail is funny because software engineers remain software engineers, even inside surveillance infrastructure. The first raises a serious operational question: when storage is throwing thousands of errors, what gets retained, dropped or processed inconsistently?
The roadside box performs only part of the job. Plate reading and descriptions such as vehicle color, make and model appear to happen on Flock’s servers. The camera detects and crops potential targets, then uploads crops and original images, according to Tom’s Hardware’s account.
So the system has two surfaces to govern. The pole holds media and makes initial classifications. The server converts observations into information that agencies can search. A secure cloud cannot erase images recovered from roadside storage, while a locked enclosure cannot prevent misuse of records already uploaded. Retention rules also need nouns: raw images, crops, clips, detection logs, search results and copies shared with other agencies. “Deleted after seven days” sounds crisp until six different data products enter the group chat.
Encryption Had Already Entered the Chat
Security researcher Jon Gaines reverse engineered a Flock reader in 2025 and documented flaws that could provide root access. Flock acknowledged the findings while emphasizing that exploitation required physical access and that images stayed on a device only briefly after upload.
The latest extraction tests that defense against the messiness of deployment. Physical access produced a large archive from this camera, including media, logs and software. Outdoor surveillance hardware should be assessed on the assumption that loss or tampering can happen, because poles are infrastructure, not force fields.
Flock told 404 Media that unauthorized removal and tampering were illegal. The company said it had received no report through its public vulnerability-disclosure policy, lacked enough detail to assess the claims and wanted the hackers to use that process. Those objections address how the material was obtained and disclosed. The files raise a separate engineering question for agencies buying the product: which protections remain after a deployed unit leaves its mount?
That question has older political roots. In a September 2001 essay, Richard Stallman warned about “massive surveillance” of communications and physical movements, including computerized cameras promoted after a crisis without evidence that they would achieve their stated purpose.
Flock expanded through local purchasing and routine policing, unlike the emergency federal measures Stallman was discussing. The useful parallel sits in the sequence: surveillance capacity can arrive before lawmakers settle access, retention, sharing and audit rules. Once the national argument begins, local cameras and databases may already be talking to each other.
In Alpharetta, Georgia, WIRED previously found that more than 2,000 agencies could access the city’s camera records through Flock’s network. Flock launched an AI search tool for police in August and shortened its data-retention period to seven days that month. Seven days reduces the period records remain available. Broad access can still put those records in front of many institutions during that shorter window.
Garden Shears, Reverse Engineering and Policy
The fight over Flock hardware has also produced a revealing comparison. Police in Oviedo, Florida, installed 3D-printed decoy camera shells and watched them to catch vandals. Evan Meyer allegedly knocked one down and destroyed it with garden shears. Police initially charged him with three felonies. Prosecutors later reduced the case to two second-degree misdemeanors after placing the damage at $200 or less, 404 Media reported.
Meyer’s case and stegan0gram’s extraction both involved civilians interfering with pole-mounted hardware. The resemblance stops quickly. One allegedly destroyed a low-value decoy and led to criminal charges. The other involved removing a functioning camera, copying data and supplying evidence about its design to journalists. The available reporting does not establish whether stegan0gram’s members will face charges.
Physical sabotage can also feed the argument for more surveillance. Tom’s Hardware quoted former Pawtucket, Rhode Island, police officer Noel Pichardo saying vigilantism would “crystallize the police and the state at large in their belief that this tool is necessary.” That creates a grim little loop: cameras provoke resistance, then resistance becomes evidence for officials who support cameras.
Congress is considering a narrower route. Representatives Raja Krishnamoorthi, an Illinois Democrat, and Michael Cloud, a Texas Republican, announced the proposed No FLOCK Act on September 16. It would direct the transportation secretary to withhold 10% of certain federal road funding from states that fail to limit automated plate readers to five uses: toll enforcement, stolen vehicles, missing or endangered people, vehicles registered to people with felony warrants and vehicles involved in felonies.
The proposal would keep cameras operating and would not prohibit agencies from sharing plate data. President Donald Trump said on September 13 that the cameras help law enforcement. Locating a stolen car or a missing person without posting officers along every road is the strongest public-safety case for the technology, and the bill preserves it.
The removed camera shows why permitted uses cannot carry the whole oversight load. A valid search can draw from excessive collection. A detector can crop an American flag instead of a plate. A seven-day cloud policy can coexist with recoverable media on an edge device. Encryption can protect one partition while a key elsewhere opens another.
One device cannot describe Flock’s entire national network. It can identify the questions that “encrypted,” “temporary” and “restricted” fail to answer alone. If a typical drive past one camera produces 28 images, oversight has to follow the whole trip those images take, from the pole to the server to every agency allowed to search them.
More Like This
God's Eye View Brings Open-Source Intelligence Home
God's Eye View combines flights, ships, cameras and disaster data on a 3D globe, raising questions about civilian access, accuracy and surveillance risks.
Flock Cameras, Warrants, and Who Bears the Cost
Flock cameras aren't really a safety-vs-privacy debate. They're a question about who absorbs the risk when surveillance has no warrant requirement.
Airport Theft at MIA Exposes Deep Trust Failures
A passenger's stolen Cartier watch, sold online, reveals the layered accountability failures behind airport baggage theft at Miami International Airport.
Texas Pulls Funding for AI Flock Cameras
Texas Governor Greg Abbott halted state funding for AI-powered Flock cameras after $30M in charges appeared on car insurance policies without public notice.
Flock Camera Errors Put Innocent Drivers at Gunpoint
A Wisconsin woman was surrounded by police at gunpoint twice due to a Flock license plate reader error. Her story isn't an outlier—it's a pattern.
Flock Cameras Track Far More Than License Plates
Flock Safety's AI-powered cameras are spreading fast across U.S. cities—and they're capturing far more than license plates. Here's what's at stake.
GNU Coreutils Now Run Natively on Windows
Microsoft has ported GNU Coreutils to Windows as native binaries. Here's what that means for devs switching between Linux and Windows daily.
iOS 27 Beta 1 Hands-On: Cool Features, No Siri
iOS 27 Beta 1 is here with Photos AI tools, Liquid Glass tweaks, and Wallet upgrades — but the new Siri everyone wants? Still on a waitlist.