For months, the most visible form of resistance to Flock Safety's network of license plate readers has been physical: cameras sawed off poles, lenses sprayed over, wiring cut. A new disclosure suggests a quieter and more consequential approach is now in play — one that turns the cameras into a source of documentation about their own capabilities.
According to a joint investigation by 404 Media and WIRED, a group of hackers removed a Flock camera from above a roadway, copied nearly everything stored inside it, and handed the resulting files to both outlets. The material offers a rare internal view of a system that Flock has publicly described as safeguarded by on-device encryption, and it indicates the hardware is doing considerably more than cataloging license plates.
The hackers said they also intend to publish a description of how they obtained the software, explicitly hoping others will repeat the process. The data was shared with 404 Media and with the transparency nonprofit Distributed Denial of Secrets, which passed it along to WIRED; the two newsrooms then analyzed the files together.
Inside a camera that is not supposed to be readable
The operation began with what the hackers describe as removing hardware from the field. One participant, speaking on behalf of a collective calling itself stegan0gram, framed the effort as a logical next step beyond vandalism: "Why just destroy them when we can reverse engineer them and find the secrets of those spying on us?" The same person said the group took the units down, disarmed them, and moved on to reverse engineering the cameras along with the solar equipment that powers them.
The technical breakthrough appears to have been the recovery of an encryption key stored on the device itself. With the camera's storage copied and that key in hand, the hackers were able to unlock video covering thousands of vehicle detections. Not everything fell open — the analysis indicates a substantial portion of the automatic license plate reader's most sensitive storage remained encrypted and out of reach — but the accessible slice was large enough to characterize how the system behaves in ordinary operation.
What the recovered logs reveal
Among the clearest findings: the software running on the camera is built to identify people, not just cars. The joint analysis found that the on-device computer vision explicitly detects people alongside vehicles, license plates, and bicycles.

The volume of imagery is notable as well. A single passing vehicle can generate dozens of separate images, and the logs recovered from just a few weeks of operation contained more than a million images in total.
The software also appears to take an interest in details that have little to do with registration plates. In one instance documented in the recovered data, the computer vision isolated an American flag patch affixed to a motorcyclist's saddlebag — an example of the system flagging graphics and bumper stickers as distinct objects of attention.
- Detection categories visible in the software: people, vehicles, license plates, and bicycles.
- Image generation: dozens of frames per passing vehicle, and more than a million images across several weeks of recovered logs.
- Object-level attention: bumper stickers and other graphics, including a flag patch on a motorcycle saddlebag.
- Encryption: an on-device key was recovered, while some of the most sensitive stored data remained inaccessible.
How the system is meant to work
Flock's cameras photograph passing vehicles and transmit the images and associated data to the company's servers. From there, the system reads license plates and can identify vehicle characteristics — a pipeline that moves raw roadside imagery into a searchable database available to law enforcement customers.
The company has positioned on-device encryption as a core protection for that pipeline, and the recovered material does not contradict that its strongest safeguards held in places. But the episode complicates the framing: a key sitting on the camera itself can be extracted by anyone who takes possession of the hardware, which locates the security boundary at the physical device rather than somewhere on the network.
From spray paint to soldering irons
The disclosure lands amid a broader wave of friction over automated license plate reading. People in communities across the United States have been taking cameras down, and multiple individuals have been arrested on allegations of tampering with or sabotaging Flock equipment.
Responses have varied. Some towns have announced they will stop using Flock's cameras altogether. In at least one case, a police department tried a different tactic: fabricating a fake Flock camera housing with a 3D printer and mounting it in public, apparently as a decoy intended to catch would-be vandals in the act.

Against that backdrop, the reverse-engineering effort represents a shift in strategy. Destroying a camera removes one node from a network. Extracting and publishing its software tells the public what that node was doing — and gives anyone with the inclination a template for repeating the process.
Why it matters beyond a single camera
The most significant aspect of the disclosure may be evidentiary rather than technical. Debates over surveillance systems often hinge on what a vendor says its products do. A recovered copy of the software, even a partial one, offers a concrete alternative: a description of detection categories, image volumes, and classification behavior drawn from the device itself rather than from a marketing page.
That matters because the scope of a detection category is not a trivial detail. A system that reads plates is one kind of tool. A system that reads plates while also recognizing people, bicycles, and the graphics on a saddlebag is a different one, and the distinction shapes how communities weigh the tradeoffs of hosting such hardware on their streets.
The hackers' stated goal of publishing their methods raises its own questions. The same documentation that helps residents understand what is mounted above their roads could help others compromise equipment, and the legal exposure for tampering remains real, as the arrests to date demonstrate.
What the files cannot show is the full picture. Much of the camera's most sensitive storage resisted the recovered key, meaning the disclosed records are a window rather than a complete inventory. Flock has described its system as protected by encryption, and this episode does not so much disprove that claim as locate its limits.
Still, the trajectory is clear. Communities that once encountered these cameras as anonymous gray boxes now have a partial look inside them — and a group of hackers publicly promising to show anyone else how to get the same view.
This article is based on reporting by 404 Media. Read the original article.
Originally published on 404media.co







_.png)
