This investigative report exposes a critical security vulnerability enabling unauthorized real-time surveillance and tracking of individuals via 60+ exposed AI-powered cameras across multiple US cities. The article documents specific surveillance of identifiable people including children, and demonstrates capability for mass identification through facial tracking and movement following. The reporting strongly advocates for privacy rights protection while the independent publication model enables critical investigation despite potential commercial or institutional pressure.
I just watched the Benn Jordan's video on this. Even if this is just configuration error on some of their cameras this is terrifying and I think they should be held accountable for this and their previous myriad of CVEs.
Flock or their defenders will lock in on the excuse that “oh these are misconfigured” or “yeah hacking is illegal, only cops should have this data”. The issue is neither of the above. The issue is the collection and collation of this footage in the first place! I don’t want hackers watching me all the time, sure, but I DEFINITELY don’t trust the state or megacorps to watch me all the time. Hackers concern me less, actually. I’m glad that Benn Jordan and others are giving this the airtime it needs, but they’re focusing the messaging on security vulnerabilities and not state surveillance. Thus Flock can go “ok we will do better about security” and the bureaucrats, average suburbanites, and law enforcement agencies will go “ok good they fixed the vulnerabilities I’m happy now”
I don't want these cameras to exist but, if they're going to, might we be better off if they are openly accessible? At the very least, that would make the power they grant more diffuse and people would be more cognizant of their existence and capabilities.
i guess that while it is alarming that these feeds were "unsecured" I'm just as concerned that they exist at all. Folks worry about it getting into the "wrong hands" but from my POV it was put up by the wrong hands.
While both are a problem I am far more concerned about the power this gives our, increasingly authoritarian, government than about individual stalkers/creeps.
I would love to watch a shorter version of this video that just discussed the deltas between the status quo and Flock, rather than breathlessly reporting the implications of cameras as if they were distinctive to Flock. He'll spend 30 seconds talking about how you can see every activity and every person on the camera --- yeah, that's how cameras work. There are thousands of public IP cameras on the Internet, aimed at intersections, public streets, houses, playgrounds, schools; most of them operated that way deliberately.
There are Flock-specific bad things happening here, but you have to dig through the video to get to them, and they're not intuitive. The new Flock "Condor" cameras are apparently auto-PTZ, meaning that when they detect motion, they zoom in on it. That's new! I want to hear more about that, and less about "I had tears in my eyes watching this camera footage of a children's playground", which is something you could have done last week or last year or last decade, or about a mental health police wellness detention somewhere where all the cops were already wearing FOIA-able body cams.
If open Flock cameras gave you the Flock search bar, that would be the end of the world. And the possibility that could happen is a good reason to push back on Flock. But that's not what happened here.
Children could go missing thanks to Flock default settings. HN would tell me to never attribute to malice ... but there may be criminal negligence.
To cover their butts I strongly suggest Flock implement a default "grading system" that will show a city in a banner at the top of their management and monitoring system that based on their camera and network configuration they get an A+ to F-. If the grade is below a C then it must be impossible to get rid of the banner and it must be blinking red. The grading system must be both free, mandatory and a part of the core management code. This assumes Flock will have the willpower to say no when a city demands removal of the flashing red banner. Instead up-sell professional services to secure their mess. I would like to see the NCC Group review their security and future grading system.
I wonder what our founders would think about tools like Flock.
From what I understand these systems are legal because there is no expectation of privacy in public. Therefore any time you go in public you cannot expect NOT to be tracked, photographed, and entered into a database (which may now outlive us).
I think the argument comes from the 1st amendment.
Weaponizing the Bill of Rights (BoR) for the government against the people does not seem to align with my understanding of why the Bill of Rights was cemented into our constitution in the first place.
I wonder what Adams or Madison would make of it. I wonder if Benjamin Franklin would be appalled.
I wonder if they'd consider every license plate reading a violation of the 4th amendment.
In Brazil there is a similar problem, but it's not as widely discussed. Here, police investigations revealed that a website sold access for less than $4 to the nation-wide surveillance system, which included live feed of public safety cameras and person search by tax identifier. It was also shown that criminal organizations used it to locate their targets. Access was through the open internet, with leaked credentials, the federal government's system requires no VPN for access.
Really valuable research. A benefit to public safety, and drawing attention to a sloppy vendor in the security space, claiming to secure the public, but instead putting the public at risk. However I'm deeply concerned for the researcher and all involved because this may be a criminal violation under the CFAA - accessing these systems without authorization, even if they don't have authentication.
Was fortunate to talk to a security lead who built the data-driven policing network for a major American city that was an early adopter. ALPR vendors like Flock either heavily augment and/or anchor the tech setups.
What was notable to me is the following, and it’s why I think a career spent on either security researching, or going to law school and suing, these vendors into the ground over 20 years would be the ultimate act of civil service:
1. It’s not just Flock cams. It’s the data eng into these networks - 18 wheeler feed cams, flock cams, retail user nest cams, traffic cams, ISP data sales
2. All in one hub, all searchable by your local PD and also the local PD across state lines who doesn’t like your abortion/marijuana/gun/whatever laws, and relying on:
3. The PD to setup and maintain proper RBAC in a nationwide surveillance network that is 100%, for sure, no doubt about it (wait how did that Texas cop track the abortion into Indiana/Illinois…?), configured for least privilege.
4. Or if the PD doesn’t want flock in town, they reinstall cameras against the ruling (Illinois iirc?) or just say “we have the feeds for the DoT cameras in/out of town and the truckers through town so might as well have control over it, PD!”
Layer the above with the current trend in the US, and 2025 model Nissan uploading stop-by-stop geolocation and telematics to cloud (then, sold into flock? Does even knowing for sure if it does or doesn’t even matter?)
Very bad line of companies. Again all is from primary sources who helped implement it over the years. If you spend enough time at cybersecurity conferences you’ll meet people with these jobs.
Flock cameras would be so easy to disable by motivated people. Dress in nondescript clothing, mask, sunglasses, and just spraypaint over the lenses. This is completely asymmetric warfare because it is trivial how long it would take for you to do this. You could hit dozens of cameras across an area overnight. Meanwhile, flock or the city, whoever maintains this stuff, needs to identify the vandalized cameras, flag them for repair, pay a technician to go out and presumably repair the unit outright. You pay cents and they are paying potentially thousands in labor and hardware costs.
And this would absolutely work at scale too. Streetlights are already being vandalized for their copper and most cities cannot afford to hire more technicians to even keep up with streetlight repair. I believe I’ve seen the backlog for streetlight repair in LA is over 10x what the current street services crew is capable of repairing in a year of constant work and growing by the day.
Municipalities and these technology companies cannot keep up against a motivated crew and can’t afford to scale either. Totally asymmetric.
What I don’t understand is how you can work at a company like Flock and look yourself in the mirror.
Seriously. You must be aware of the inherent evil, of the privacy invasive nature of your product, of how it’s being actively abused. How do you rationalize this for yourself?
Systems like this that exist to facilitate dispatching government violence will never be "good" by whatever the standards of the time is because they don't need to be. They have "at-cost" access to nearly infinite government violence they can dispatch capriciously and an unequally good relationship with any system that would hold them accountable for any misuse of their stuff.
Yes and the biggest problem with this kind of ALPRs are they bypass the due process. Most of the time police can just pull up data without any warrant and there has been instances where this was abused (I think some cops used this for stalking their exes [1]) and also the most worrying Flock seems to really okay with giving ICE unlimited access to this data [2] [3] (which I speculate for loose regulations).
Nothing will be done until one of the investors of the tech end up embarrassed from weaponization of the tech against themselves. These people have no clue how creepy some of their technologic betters can be. I once witnessed a coworker surveilling his own network to ensure his girlfriend wasn't cheating on him (this was a time before massive SSL adoption). The guy just got a role doing networking at my company and thankfully he wasn't there for very long after that.
> The financing was led by Andreessen Horowitz, with backing from Greenoaks Capital, Bedrock Capital. Meritech Capital, Matrix Partners, Sands Capital, Founders Fund, Kleiner Perkins, Tiger Global, and Y Combinator also participated.
In my experience, people respond much more strongly to naming a specific company or person. Clearer plan of action than a resigned “This tech is old news.”
I always found Hanlon's Razor a bit too optimistic in tone. I prefer it restated in the form of Clarke's third law:
"Sufficiently advanced stupidity is indistinguishable from malice."
I think so, but it is a loosely held opinion at this point. Fundamentally, I think it is a huge, asymmetric power grab by Flock and local police to install these systems. It only takes one officer looking up their local politician and finding them doing something that could even look like a bad deed (or to fake it in the era of AI videogen...) to enable blackmail and personal/professional gain.
If they're going to exist, it may be better for that to be spread among the public than to be left in the hands of the few.
Did you see the other post about this where the guys showed a Flock camera pointed at a playground, so any pedo can see when kids are there and not attended?
Or how it has become increasingly trivial to identify by face or license plate such that combining tools reaches "movie Interpol" levels, without any warrant or security credentials?
If Big Brother surveillance is unavoidable I don't think "everyone has access" is the solution. The best defense is actually the glut of data and the fact nobody is actively watching you picking your nose in the elevator. If everyone can utilize any camera and its history for any reason then expect fractal chaos and internet shaming.
He's pretty open in this video about how Flock is far from alone in this space, and he's just using them as an example because they're so popular and flagrantly abusive.
“Are the fires of Hell a-glowing?
Is the grisly reaper mowing?
Yes! The danger must be growing
For the rowers keep on rowing
And they're certainly not showing
Any signs that they are slowing!” - Willie Wonka
I've thought the same regarding license plate readers (and saw considerable pushback on HN) — feeling like you suggest: if they have the technology anyway, why not open it up?
I imagined a "white list" though (or whatever the new term is—"permitted list"?) so that only certain license plates are posted/tracked.
Have you ever gone fishing? Did you catch all the fish?
Often it is more impactful to address one major/tangible player in a particular space than it would be to "boil the ocean" and ensure that we are capturing every possible player/transgressor. I agree that some of the video was overly breathless, but if that's what wakes people up to the dangers of unsecured cameras/devices then so be it.
This is pretty naive. What happens when you develop and extend such a system in a way that it can track who you interact with? What about social credit scores? You might go out to a social event with a very distinguished social credit score of 820 and get knocked down to 69 just because you were in proximity to Bob and Alice, who happen to be on some blacklists for their work in cryptography.
What you're staring at is the gateway tech that brings in a dystopian society. At first stuff like this is fairly benign, but slowly over time it ramps up into truly awful outcomes.
I live in an Atlanta neighborhood where one of the founders lived. A prototype for Flock Camera was designed by three Georgia Tech grads because someone kept breaking into their car (not uncommon in our neighborhood tbh).
The trick is that the camera was pointed towards a middle school. Which means they were constantly recording kids without adult consent.
Now, years later, Atlanta is the most surveilled city in North America and one of the most in the world. Flock cameras are everywhere. There are 124 cameras for every 1,000 people. Just last week, a ex-urb police chef was arrested for using the Flock network to stalk and harass citizens.
I know a lot of people who work at Flock. I’m shocked that they do though.
He has said his goal is for a "world with no crime. Thanks to Flock." and his goal is not aspirational, visionary, but quite literal.
He sees false negatives as more problematic than false positives. He has admitted being inspired by Minority Report (to me it's always very telling when someone takes a cautionary tale like this and finds it "inspirational").
I wonder if such a business model could exist where they were effectively "public" and thus, access was uniformly granted to anyone willing to pay. not sure if this would be net better for society, but an interesting thought.
Depends how fast we lost him to porn on the internet
Editorial Channel
What the content says
+0.80
Article 12Privacy
High Advocacy Framing Practice
Editorial
+0.80
SETL
+0.49
Core focus: unauthorized surveillance and recording of individuals without consent, including in semi-private and private contexts (parking lots, playgrounds, bike paths). Strong advocacy for privacy rights through exposure of massive-scale violation.
Observable Facts
Article states at least 60 Flock Condor cameras livestreaming without authentication to open internet.
Reporter personally verified exposure by watching themselves on live feed in Bakersfield, California.
Article documents specific tracked individuals: woman with dog on bike path, man in parking lot, children on playground, rollerblader on greenway.
Researchers able to download 30 days of video archives and access administrator control panels.
Article describes automatic facial zoom capability: 'can be set to automatically zoom in on people's faces as they walk through a parking lot, down a public street, or play on a playground.'
Inferences
Exposure of unprotected livestreams without authentication represents fundamental privacy violation affecting hundreds of individuals.
Specificity of tracking (facial zoom, movement following, cross-camera tracking) demonstrates capability for mass identification.
Documentation of children and family activities (dog-walking, playground play) indicates privacy violation extending to sensitive personal contexts.
+0.50
PreamblePreamble
Medium Advocacy Framing
Editorial
+0.50
SETL
+0.32
Article implicitly invokes fundamental rights and dignity by documenting systematic violations of privacy and security of person through mass surveillance.
Observable Facts
The article documents unauthorized real-time surveillance of individuals without consent or notification.
The article demonstrates specific surveillance capability: tracking individuals across multiple locations, zooming to facial detail, automatic tracking.
Inferences
The detailed documentation of privacy violations implies commitment to fundamental human rights and dignity principles.
Publication by independent journalists suggests structural commitment to rights reporting despite potential commercial pressure.
+0.50
Article 3Life, Liberty, Security
Medium Advocacy Framing
Editorial
+0.50
SETL
+0.32
Article frames unauthorized surveillance as a threat to security of person, particularly emphasizing vulnerability of children and unattended minors.
Observable Facts
Article describes surveillance of children on a playground without parental knowledge or consent.
Article documents high-resolution facial tracking and movement following, enabling individual identification.
Researcher quoted as frightened by discovery of unattended children visible on exposed livestreams.
Inferences
Emphasis on children's surveillance suggests framing of security threat to vulnerable populations.
Documentation of system capability to track and identify individuals demonstrates practical threat to security of person.
+0.40
Article 13Freedom of Movement
Medium Framing
Editorial
+0.40
SETL
+0.28
Article documents surveillance systems that track and follow individual movement, creating potential chilling effect on freedom of movement.
Observable Facts
Article describes rollerblader automatically tracked and zoomed on, then identified again on another camera further down bike path.
Multiple tracking examples across locations: parking lots, streets, bike paths, greenways.
Article states Condor cameras can 'be controlled manually' to follow subjects, and 'automatically zoom in' as people walk.
Inferences
Comprehensive tracking capability could discourage public movement through surveillance awareness and chilling effect.
Cross-camera continuity of tracking demonstrates ubiquitous coverage that could constrain freedom of movement.
+0.40
Article 19Freedom of Expression
Medium Advocacy Practice
Editorial
+0.40
SETL
-0.22
Article practices freedom of expression through investigative journalism; implicitly advocates for freedom of expression by documenting how surveillance threatens it.
Observable Facts
Article published by independent media without apparent editorial restriction or censorship.
Reporter conducted original research, traveled to locations, collected primary evidence.
Sources quoted directly with attribution: Benn Jordan, Jon Gaines, researcher statements.
Inferences
Publication of critical surveillance investigation demonstrates structural support for freedom of journalistic expression.
Independent sourcing and direct voice to researchers shows commitment to unmediated expression.
+0.30
Article 30No Destruction of Rights
Low Framing
Editorial
+0.30
SETL
ND
Article documents systematic breach that destroys the right to privacy, implicitly defending against destruction of established human rights.
Documentation shows vulnerability of established rights to institutional failure and security negligence.
Inferences
Reporting on privacy rights destruction implies commitment to preventing erosion of human rights.
+0.20
Article 8Right to Remedy
Low Framing
Editorial
+0.20
SETL
+0.14
Article provides detailed evidence of violations with specific locations and technical details, supporting potential legal or regulatory remedy.
Observable Facts
Article specifies camera locations (Bakersfield, Atlanta, Brookhaven), enabling geographic verification.
Article provides technical details: camera model (Condor PTZ), access methods, data available (30 days archive, admin panels).
Inferences
Detailed documentation provides foundation for legal remedies or regulatory investigation.
+0.20
Article 28Social & International Order
Low Framing
Editorial
+0.20
SETL
ND
Article implicitly references international surveillance/privacy norms by treating exposure as a serious rights concern affecting multiple jurisdictions.
Observable Facts
Article references cameras deployed across multiple US cities and states, suggesting national institutional scope.
Researcher methodology (Shodan tool, open source investigation) indicates reference to global security standards.
Inferences
Treatment of surveillance exposure as urgent social concern implies alignment with international human rights norms.
ND
Article 1Freedom, Equality, Brotherhood
Not addressed in this content.
ND
Article 2Non-Discrimination
Not addressed in this content.
ND
Article 4No Slavery
Not addressed in this content.
ND
Article 5No Torture
Not addressed in this content.
ND
Article 6Legal Personhood
Not addressed in this content.
ND
Article 7Equality Before Law
Not addressed in this content.
ND
Article 9No Arbitrary Detention
Not addressed in this content.
ND
Article 10Fair Hearing
Not addressed in this content.
ND
Article 11Presumption of Innocence
Not addressed in this content.
ND
Article 14Asylum
Not addressed in this content.
ND
Article 15Nationality
Not addressed in this content.
ND
Article 16Marriage & Family
Not addressed in this content.
ND
Article 17Property
Not addressed in this content.
ND
Article 18Freedom of Thought
Not addressed in this content.
ND
Article 20Assembly & Association
Not addressed in this content.
ND
Article 21Political Participation
Not addressed in this content.
ND
Article 22Social Security
Not addressed in this content.
ND
Article 23Work & Equal Pay
Not addressed in this content.
ND
Article 24Rest & Leisure
Not addressed in this content.
ND
Article 25Standard of Living
Not addressed in this content.
ND
Article 26Education
Not addressed in this content.
ND
Article 27Cultural Participation
Not addressed in this content.
ND
Article 29Duties to Community
Not addressed in this content.
Structural Channel
What the site does
+0.50
Article 12Privacy
High Advocacy Framing Practice
Structural
+0.50
Context Modifier
ND
SETL
+0.49
Independent journalism exposes breach; however, structural tension exists: site itself employs ad tracking infrastructure despite privacy advocacy focus.
+0.50
Article 19Freedom of Expression
Medium Advocacy Practice
Structural
+0.50
Context Modifier
ND
SETL
-0.22
Independent publication structure enables unrestricted investigation; transparent sourcing and attribution demonstrate commitment to free expression.
+0.30
PreamblePreamble
Medium Advocacy Framing
Structural
+0.30
Context Modifier
ND
SETL
+0.32
Independent journalism structure enables publication of rights-focused investigation without corporate constraint.
+0.30
Article 3Life, Liberty, Security
Medium Advocacy Framing
Structural
+0.30
Context Modifier
ND
SETL
+0.32
Investigative reporting documents surveillance systems deployed without transparent security controls, threatening personal security.
+0.20
Article 13Freedom of Movement
Medium Framing
Structural
+0.20
Context Modifier
ND
SETL
+0.28
Documentation of movement-tracking system; limited structural engagement with movement freedom.
+0.10
Article 8Right to Remedy
Low Framing
Structural
+0.10
Context Modifier
ND
SETL
+0.14
Documentation provides factual record that could inform legal or administrative processes.
ND
Article 1Freedom, Equality, Brotherhood
Not addressed in this content.
ND
Article 2Non-Discrimination
Not addressed in this content.
ND
Article 4No Slavery
Not addressed in this content.
ND
Article 5No Torture
Not addressed in this content.
ND
Article 6Legal Personhood
Not addressed in this content.
ND
Article 7Equality Before Law
Not addressed in this content.
ND
Article 9No Arbitrary Detention
Not addressed in this content.
ND
Article 10Fair Hearing
Not addressed in this content.
ND
Article 11Presumption of Innocence
Not addressed in this content.
ND
Article 14Asylum
Not addressed in this content.
ND
Article 15Nationality
Not addressed in this content.
ND
Article 16Marriage & Family
Not addressed in this content.
ND
Article 17Property
Not addressed in this content.
ND
Article 18Freedom of Thought
Not addressed in this content.
ND
Article 20Assembly & Association
Not addressed in this content.
ND
Article 21Political Participation
Not addressed in this content.
ND
Article 22Social Security
Not addressed in this content.
ND
Article 23Work & Equal Pay
Not addressed in this content.
ND
Article 24Rest & Leisure
Not addressed in this content.
ND
Article 25Standard of Living
Not addressed in this content.
ND
Article 26Education
Not addressed in this content.
ND
Article 27Cultural Participation
Not addressed in this content.
ND
Article 28Social & International Order
Low Framing
Not addressed in this content.
ND
Article 29Duties to Community
Not addressed in this content.
ND
Article 30No Destruction of Rights
Low Framing
Not addressed in this content.
Supplementary Signals
Epistemic Quality
0.69
Propaganda Flags
2techniques detected
appeal to fear
Researcher quoted: 'I actually got like immediately scared... the one that affected me most was the playground. You could see unattended kids, and that's something I want people to know about so they can understand how dangerous this is.'
loaded language
Repeated use of emotionally charged terms: 'exposed', 'dangerous', 'unattended kids', 'vulnerable', 'intimate' contexts
Solution Orientation
No data
Emotional Tone
No data
Stakeholder Voice
No data
Temporal Framing
No data
Geographic Scope
No data
Complexity
No data
Transparency
No data
Event Timeline
20 events
2026-02-26 12:20
dlq
Dead-lettered after 1 attempts: Flock Exposed Its AI-Powered Cameras to the Internet. We Tracked Ourselves
--
2026-02-26 12:18
rate_limit
OpenRouter rate limited (429) model=llama-3.3-70b
--
2026-02-26 12:17
rate_limit
OpenRouter rate limited (429) model=llama-3.3-70b
--
2026-02-26 12:16
rate_limit
OpenRouter rate limited (429) model=llama-3.3-70b
--
2026-02-26 10:14
dlq
Dead-lettered after 1 attempts: Flock Exposed Its AI-Powered Cameras to the Internet. We Tracked Ourselves
--
2026-02-26 10:13
dlq
Dead-lettered after 1 attempts: Flock Exposed Its AI-Powered Cameras to the Internet. We Tracked Ourselves
--
2026-02-26 10:11
dlq
Dead-lettered after 1 attempts: Flock Exposed Its AI-Powered Cameras to the Internet. We Tracked Ourselves
--
2026-02-26 10:11
dlq
Dead-lettered after 1 attempts: Flock Exposed Its AI-Powered Cameras to the Internet. We Tracked Ourselves
--
2026-02-26 10:10
dlq
Dead-lettered after 1 attempts: Flock Exposed Its AI-Powered Cameras to the Internet. We Tracked Ourselves
--
2026-02-26 10:09
dlq
Dead-lettered after 1 attempts: Flock Exposed Its AI-Powered Cameras to the Internet. We Tracked Ourselves
--
2026-02-26 10:09
dlq
Dead-lettered after 1 attempts: Flock Exposed Its AI-Powered Cameras to the Internet. We Tracked Ourselves
--
2026-02-26 10:09
dlq
Dead-lettered after 1 attempts: Flock Exposed Its AI-Powered Cameras to the Internet. We Tracked Ourselves
--
2026-02-26 10:09
dlq
Dead-lettered after 1 attempts: Flock Exposed Its AI-Powered Cameras to the Internet. We Tracked Ourselves
--
2026-02-26 10:07
dlq
Dead-lettered after 1 attempts: Flock Exposed Its AI-Powered Cameras to the Internet. We Tracked Ourselves
--
2026-02-26 10:07
dlq
Dead-lettered after 1 attempts: Flock Exposed Its AI-Powered Cameras to the Internet. We Tracked Ourselves
--
2026-02-26 10:06
dlq
Dead-lettered after 1 attempts: Flock Exposed Its AI-Powered Cameras to the Internet. We Tracked Ourselves
--
2026-02-26 10:05
dlq
Dead-lettered after 1 attempts: Flock Exposed Its AI-Powered Cameras to the Internet. We Tracked Ourselves
--
2026-02-26 10:04
dlq
Dead-lettered after 1 attempts: Flock Exposed Its AI-Powered Cameras to the Internet. We Tracked Ourselves
--
2026-02-26 10:03
dlq
Dead-lettered after 1 attempts: Flock Exposed Its AI-Powered Cameras to the Internet. We Tracked Ourselves
--
2026-02-26 10:03
dlq
Dead-lettered after 1 attempts: Flock Exposed Its AI-Powered Cameras to the Internet. We Tracked Ourselves