Hacker Newsnew | past | comments | ask | show | jobs | submit | driverdan's commentslogin

Can you provide more details? Do you mean 100 public cameras anyone can access?

This reporting was done in collaboration with 404media. Here's the discussion for 404's article: https://news.ycombinator.com/item?id=49726577

Distributed Denial of Secrets has published the partition images: https://ddosecrets.org/article/flock-alpr-camera


I poked around in the boot partition. The kernel is ancient!

Linux version 3.18.71-perf-gaf770dc


3.18.71-perf-gaf770dc is a Qualcomm Android vendor kernel from roughly late 2017. The 3.18 branch went fully EOL in 2019, so nothing after that was ever backported to it.

2017 was also the year Flock was funded and founded and went through the YConbinator cohort.

But you would have thought that by 2021 when Andreessen Horowitz funded them or at least by 2025 [1] when both further funded them, someone would have actually done some minor due diligence. Coincidentally too, 2025 was when the flock surveillance matrix went up all over the country almost immediately.

We constantly hear that the magic of tech funding lies in the people, not even the product/service. These types of things always seem to uncover that that is effectively just a lie to cover up the ulterior motives of setting up a tyrannical surveillance matrix all around you … to protect the children, of course.

[1] https://www.flocksafety.com/blog/flock-safety-secures-major-...


In an ideal world they'd have people whose job it is to monitor upstream activity in the components used in the firmware and maintain this. Sounds like they did not have that.

It's almost as if they paid a contractor to design the hardware back in 2017 and put all the funding into marketing(bribes) since then. Shocker.

"It's only a problem if your definition of done makes it one".

Interesting that they are a YC Company. Does yC do any ethics vetting of saying "No, let's stop fascism before it spreads?"

YC does no meaningful vetting at all. You can steal another YC entrant’s product and still get funded.

https://deepdelver.substack.com/p/delve-fake-compliance-as-a...


many cases already public of rejected founders having their idea pushed on accepted founders with bad ideas.

TIL but not surprising.

I would recommend reading "The Nerd Reich" by Gil Duran for context on this question.

Security through obsolescence!

That's how we got Chinese APT in our phone systems that we are apparently going to do nothing about. Seriously, can be fixed, AT&T et all just won't

The oldest supported kernel is 5.10 and that loses support in December. That's wild they are using a 3.X kernel

You'd be surprised how many things you use daily that people still backport the bare minimum to clig to 2.4.x forever

I really hope those don't have access to any networks.

good chance the linux running in your high end phone's modem runs 2.x kernel.

i dont deal with that anymorrle, but last one I saw with 2.x was the pixel 6 pro.


Just check, my 2YO phone runs kernel 6.6, not latest but i think good enough for production.

Edited: I misunderstood what you mean, you were talking about the modem subsystem, sorry.


I don't think you misunderstood, I think they're talking out their arse. Modems don't run Linux, they run RTOS operating systems. ShannonOS in the case of the Pixel 6 with a exynos modem

The pixel 6 pro runs ShannonOS an RTOS system, it's an exynos modem

Yeah I've seen plenty of kernels that start with a 2 with no forward path possible due to "we don't know how to get our driver working anymore"

To be fair if you could SLTS support by CIP (which is designed for things like this) you have 4.19 at least still maintained. 4.4 might still be too but I'd have to check

>gaf770dc

missing a d(gaf)

sorry, had to get that out!



do the articles have significantly different information/coverage to warrant two submissions?

No, they're the same article. I had only read 404's when I submitted them and I assumed they'd both be submitted regardless.

I can't read the Wired article because I'm only allowed three excerpts and 15 ads a day at Wired.com

same, but i'm not sure how that's related to my comment. workarounds or alternate articles without significant new information are typically posted within the same submission, not separate ones.


This reporting was done in collaboration with Wired. Here's the discussion for Wired's article: https://news.ycombinator.com/item?id=49726586

Distributed Denial of Secrets has published the partition images: https://ddosecrets.org/article/flock-alpr-camera


Every single time what? Please, be specific in what you mean.

I see you're probably not a noticer.

Until they are held legally liable they will do the minimum necessary to keep the money flowing and avoid litigation.



Why wouldn't you set a PIN?

I already have a very long password. I object to unnecessary extra layers -- you can rely on secure hardware via the system if you must authenticate me again, but do not pretend to become your own steward.

Most of my apps that decide to ask for their own PIN (e.g. Klarna, Privacy.com, myFICO) have some deterministic garbage that's easy to guess because they provide no real security. I refuse to entertain security theater with real secrets. (real secrets = ones I don't remember)


What's the point of setting a PIN if Cellebrite can hack almost any phone?

Not every pocket thief or drunkard who finds your phone has cellebritr. Security measures consider the threat model.

More specifically, another commenter in this thread says it's to make sure the user is aware of the configuration of a VPN which, if done maliciously, funnels all your traffic toa a hostile place.


A pocket thief will bring the phone to a friend with a laptop and black market software. If the phone has no theft protection, they will factory reset it; if it has, they will use paid software to remove protection. I have not used that software and do not know if it is actual now, but Internet search shows that older phones are completely unlockable.

Just to give an example, here is publicly available information: https://github.com/youngrichu/frp-freedom/blob/main/FRP%20By...

Good thing is that some of the aforementioned exploits can be used to work around locked bootloader and liberate the phone.

Do not rely on any security in Android. It has lot of mistakes, poorly coded high privilege vendor software, so it would be dumb to use it for anything valuable.

> More specifically, another commenter in this thread says it's to make sure the user is aware of the configuration of a VPN which, if done maliciously, funnels all your traffic toa a hostile place.

I do not see how PIN protects the user, especially if user had PIN before installing a malicious VPN. Also, isn't Google Play supposed to check every application for malicious functionality?


Non-malicious VPN software can be used by malicious actors to route packets through servers they control.

How does PIN help against this? Also, my packets are already routed through malicious actors - ISPs, luckily most of them are encrypted.

As much as people who live in NYC like to believe they're a state they're not, they're a city. Most of the state of New York does not have good public transit.

Even in New York City, a very large number of people are not taking transit, there are a lot of cars. Generally gets about a third though different boroughs have different numbers, Manhattan, most people are walking, everywhere else cars are significant, though subway and transit are also there. But you can't really say overall for the city that transit is how people get around.

> Generally gets about a third though different boroughs have different numbers

> But you can't really say overall for the city that transit is how people get around.

It is 27%, but that's because of COVID. It used to be around 50% before and it's recovering to those levels.

So even now, during abnormal times, it's 27% plus walking around 40% and bikes are 5% and growing.

So non car transportation in all of NYC is 72%.

And the trend is only going one way, with transit on the way up and recovering post COVID and bikes also going up.

I wouldn't be surprised if 2030 NYC statistics put cars around 15-20%, so a quite small minority.


Pedantically true. By population density, NYC is essentially the whole state, or what matters anyway, to the huge majority of residents.

About 60% of New Yorkers are outside of NYC.

And what fraction of the traffic?

I don't live in NYC for the record, my point was more about not having to own a car than public transport, hence i gave a few options surrounding traveling through NYC.

There's already a WeatherNext 3 post on the homepage https://news.ycombinator.com/item?id=49552299 and it has been posted a bunch of times this week.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: