Flock cameras are finding it difficult to accurately identify certain objects, sometimes mistaking them for license plates. Ironically, while they struggle with this essential function, they seem to be reliably detecting something else: people.
Recently, some hackers dismantled a Flock license plate reader mounted above a road, copied the data, and shared it with technology outlets. The data suggested that the software running on the device is capable of detecting not only vehicles and license plates but also individuals.
A report by two outlets detailed how, over several weeks, the Flock camera produced over a million images. With a processor akin to that of a midrange smartphone, it operates around 20 built-in applications that manage various functions including motion detection, photography, data uploading, and software updates.
The reports claimed that whenever something moved into its view, the camera would capture between 28 to 100 photos. It uses different exposures to gather both the license and the broader scene before processing the image and cropping what it deems relevant. Afterward, this data is transmitted to Flock via a local cellular network.
Allegedly, the camera does not directly identify license plate numbers or vehicle models—those processes appear to occur on Flock’s servers. At the same time, the software supposedly can “explicitly detect people,” noting their presence in the images and recording the level of confidence in those detections.
It was reported that during about 21 days of operation, the camera logged more than 50,000 vehicles and created 1.6 million images, averaging between 3,300 and 4,500 vehicles per day.
However, challenges emerged as the camera struggled to manage large data storage requests. The logs reportedly documented around 27,000 instances of “no space left on device” errors related to saving full-resolution images, alongside numerous other errors marked by crashes and reboots.
Interestingly, the camera’s software reportedly executes an operational check every two minutes, with a peculiar logged message: “Who’s a good boy?!” This phrase appeared over 12,000 times in the logs.
Additional concerns were raised regarding the camera’s propensity to misidentify bumper stickers, dealership frames, and other graphics as license plates, thus cropping them out of the saved pictures. For example, one motorcycle’s American flag patch was incorrectly detected as a license plate.
The hackers involved explained their motives for not simply destroying the camera. They stated, “Why just destroy them when we can reverse-engineer them and find the secrets of those spying on us?” The collective, identifying as stegan0gram, further shared that they “liberated hardware in the field, disarmed it, and proceeded with reverse engineering of the cameras and associated solar equipment.”
In response to the report, Flock emphasized that tampering with their cameras is illegal and highlighted their commitment to security. They maintain a Vulnerability Disclosure Policy for researchers to report potential vulnerabilities directly, but noted they hadn’t received any through that channel. They encouraged anyone identifying legitimate vulnerabilities to submit their findings through the proper process.
One hacker responded, expressing concern about investigations. They commented, “Being investigated is a legit concern, and something we are trying to avoid. I’m sure our actions have attracted some attention as it is, but we are careful and try to keep a low profile.”
Flock did not reply to a request for comments on the matter. Additionally, the two outlets found no evidence that the Flock camera software includes facial recognition capabilities beyond what is part of the Android operating system.
According to available data, there are now over 140,000 license plate readers operating in the United States, with 81% of them managed by Flock, while only 5% are operated by Motorola.

