해커 그룹이 도로변에 설치된 플록 세이프티(Flock Safety) 감시 카메라를 탈취해 내부 데이터를 복사하고 암호화 키를 복구함으로써, 자동차 번호판 인식(ALPR) 카메라가 차량뿐 아니라 사람, 자전거, 심지어 범퍼 스티커까지 감지한다는 사실을 밝혀냈습니다. 이번 유출은 미국 전역 2,000개 이상 기관이 플록의 전국 네트워크에 접근할 수 있고, 일부 경찰이 이를 이용해 ICE(이민세관집행국) 조회나 낙태 여성 추적에 사용했다는 논란을 재조명했다는 점에서 중요합니다.
번역된 본문
이 기사는 WIRED와 공동으로 제작되었습니다. WIRED 버전은 여기에서 읽을 수 있습니다. 해커들이 도로 위에 설치된 플록(Flock) 카메라를 떼어내어 내부에 저장된 데이터를 거의 완전하게 복사했고, 해당 파일을 404 Media와 WIRED에 공유하면서 플록 세이프티의 카메라가 차량과 사람의 이동을 정확히 어떻게 추적하는지 새로운 세부 사항이 드러났습니다. 해커들은 다른 사람들도 자신들을 따라 할 수 있도록 소프트웨어를 입수한 방법도 공개하겠다고 밝혔습니다. 이번 침해 사건은 플록이 기기 내 암호화(on-device encryption)로 보호된다고 설명해온 시스템의 내부를 전례 없이 들여다볼 수 있게 했습니다. 해커들은 카메라의 저장 장치를 복사하고 기기에 저장된 암호화 키를 복구하여 수천 건의 차량 감지 영상을 해독할 수 있었습니다. 해커들은 이 자료를 404 Media와 투명성 비영리단체인 Distributed Denial of of Secrets에 공유했으며, 이 단체가 WIRED에 데이터를 전달했습니다. 404 Media와 WIRED는 공동 조사의 일환으로 이 파일들을 분석했습니다.
자동 번호판 인식 장치(ALPR)의 가장 민감한 저장 데이터 대부분은 여전히 암호화되어 접근할 수 없었지만, 복구된 데이터에 대한 공동 분석 결과 이 기기에서 작동하는 소프트웨어는 차량, 번호판, 자전거뿐만 아니라 사람도 명시적으로 감지하는 것으로 나타났습니다. 이 카메라는 지나가는 차량 한 대당 수십 장의 이미지를 생성할 수 있으며, 복구된 수 주 치의 로그에 따르면 100만 장 이상의 이미지가 생성되었습니다. 컴퓨터 비전 소프트웨어는 때때로 범퍼 스티커와 기타 그래픽도 분리해냈는데, 한 사례에서는 오토바이 운전자의 안장 가방에 붙은 미국 국기 패치까지 식별했습니다.
카메라를 떼어내고 소프트웨어를 추출한 이 행위는 일부 사람들이 단순히 카메라를 파괴하거나 제거하는 데 만족하지 않는다는 것을 보여줍니다. 전국 각지에서 여러 사람이 플록 카메라를 훼손하거나 파괴한 혐의로 체포되었습니다. 이에 대응해 일부 도시는 플록 카메라 사용을 완전히 중단하겠다고 발표했고, 한 경찰서는 잠재적 파손자들을 유인하기 위해 가짜 3D 프린팅 플록 카메라 케이스를 만들기도 했습니다.
💡 플록에 대해 알고 계신 다른 정보가 있으신가요? 제보를 환영합니다. 업무용이 아닌 기기에서 Signal(joseph.404)로 안전하게 메시지를 보내거나 joseph@404media.co로 이메일을 보내주시기 바랍니다.
"우리를 감시하는 자들의 비밀을 찾아내기 위해 카메라를 리버스 엔지니어링할 수 있는데 왜 그냥 부수기만 해야 할까요?"라고 stegan0gram이라고 자칭하는 집단 소속 해커 한 명이 인터뷰에서 말했습니다. "우리는 현장에 설치된 하드웨어를 해방시키고 무장 해제한 뒤, 카메라와 관련 태양광 장비에 대한 리버스 엔지니어링을 진행했습니다."
플록의 카메라는 지나가는 차량을 촬영하고 이미지와 다른 데이터를 회사 서버로 전송합니다. 서버에서 플록의 시스템은 번호판을 읽고 차량 색상, 제조사, 모델과 같은 특징을 식별할 수 있는 것으로 보입니다. 그런 다음 플록은 이 타임스탬프가 기록된 데이터를 카메라를 소유하거나 접근 권한이 있는 지역 기관이 검색할 수 있도록 합니다. 하지만 많은 경우 플록의 시스템은 회사의 전국 네트워크의 일환으로 전국의 다른 경찰서들도 이 카메라들을 검색할 수 있도록 허용합니다. 예를 들어 조지아주 앨파레타에서 WIRED는 이 도시의 플록 카메라 기록이 경찰서, 대학, 공항, 심지어 연방 총무청(GSA) 감찰관실까지 2,000개 이상의 기관에 접근 가능하다는 것을 발견했습니다.
이 전국 네트워크는 플록의 판매 포인트였지만 동시에 깊은 논란의 원천이기도 했습니다. 404 Media는 지역 경찰이 이민세관집행국(ICE)을 대신해 전국 네트워크에서 조회를 수행했다는 사실을 폭로했으며, 여기에는 이민 당국과 협력하거나 번호판 데이터를 주 외부로 전송하는 것을 금지한 지역도 포함되어 있었습니다. 또한 404 Media는 텍사스의 한 경찰관이 자가 낙태를 한 여성을 찾기 위해 전국의 플록 카메라를 검색했다는 사실도 폭로했습니다. 이러한 보도들을 비롯한 여러 이야기들은 사람들이 이런 감시를 원하는지에 대한 전국적인 논쟁을 촉발했습니다.
This article was produced in collaboration with WIRED. You can read their version of the article here . Hackers ripped down a Flock camera above a roadway, made a near-complete copy of the data stored inside it, and shared the files with 404 Media and WIRED , revealing in new detail how exactly Flock Safety’s cameras track the movements of both vehicles and people. The hackers say they are also publishing details on how they managed to obtain the software, in the hopes that other people may copy them. The breach provides an unprecedented look inside a system that Flock has described as protected by on-device encryption . The hackers were able to copy the camera’s storage and recover an encryption key stored on the device, which unlocked videos of thousands of vehicle detections. The hackers shared the material with 404 Media and the transparency nonprofit Distributed Denial of Secrets , which shared the data with WIRED. 404 Media and WIRED then analyzed those files as part of a joint investigation. While much of the automatic license plate reader’s (ALPR) most sensitive storage remained encrypted and inaccessible, the joint analysis of the recovered data shows that software running on the device explicitly detects people as well as vehicles, license plates, and bicycles. The camera can produce dozens of images of a single passing vehicle and, according to several weeks of recovered logs, generated more than a million images. Its computer-vision software also sometimes isolated bumper stickers and other graphics, including, in one case, an American flag patch on a motorcyclist’s saddlebag. The act of removing the camera and dumping its software shows that some people are not content with just destroying or removing the cameras. Across the country, multiple people have been arrested for allegedly tampering with or otherwise sabotaging Flock’s cameras. In response, some towns have announced that they are going to stop using Flock’s cameras altogether, and in one case, a police department even made a fake, 3D-printed Flock camera case in order to bait potential vandals. 💡 Do you know anything else about Flock? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co. “Why just destroy them when we can reverse engineer them and find the secrets of those spying on us?” one of the hackers, from a collective calling itself stegan0gram, said in an interview. “We liberated hardware in the field, disarmed them, and proceeded with reverse engineering of the cameras and associated solar equipment.” Flock’s cameras photograph passing vehicles and send the images and other data to the company’s servers. There, Flock’s system presumably reads the license plate and can identify characteristics such as the vehicle’s color, make, and model. Flock then makes these timestamped records searchable by whichever local agency owns or has access to the cameras. But in many cases, Flock’s system also allows other police departments from all over the country to search those cameras too, as part of the company’s national network. In Alpharetta, Georgia, for example, WIRED found that records from the city’s Flock cameras were accessible to more than 2,000 agencies, including police departments, colleges, airports, and even inexplicably the Office of Inspector General for the federal General Services Administration. This national network has been a selling point for Flock, but also a deep source of controversy. 404 Media revealed that local cops were performing lookups in the national network on behalf of Immigration and Customs Enforcement (ICE), including in areas that banned working with immigration authorities or transferring license plate data out of state. 404 Media also revealed a cop in Texas searched Flock cameras nationwide for a woman who self-administered an abortion. Those stories, among others, triggered a national conversation about whether people want Flock cameras, or ALPRs more generally, in their communities. And in the case of stegan0gram, the answer is clearly, no. The hackers said they were able to access the Android system on the camera, and found two partitions—sections of its hard-drive, essentially. A few of these were unencrypted, the hackers said, including one called “vendor” and another called “media.” The latter contained an encryption key that unlocked another part, which contained much of the media—think, the videos and stills—the camera took. In early 2025, security researcher Jon “GainSec” Gaines reverse engineered a Flock license-plate reader and documented flaws that could be used to gain root-level access. After Gaines disclosed his findings, the company acknowledged the findings but downplayed their severity, writing that the flaws required physical access to the device and that even someone who gained access to a camera “would still not be able to gain access to footage” because images remained on the device only briefly after being transmitted to the cloud. 404 Media and WIRED analyzed the camera’s contents. The device’s processor is similar to those used in midrange smartphones, and it runs about 20 Flock-built apps that handle everything from detecting motion and taking pictures to classifying objects, uploading data and receiving remote updates. According to the code, when something moves into view, the camera takes a rapid series of photos. A typical passing vehicle generated about 28 images, though some produced more than 100. The camera uses different exposures to capture both the license plate and the wider scene, then scans the images, selects and crops useful frames, and sends them with other data to Flock over the cellular network. The camera itself does not appear to read the plate or identify the vehicle’s make, model, and color. That appears to happen on Flock’s servers. According to our analysis, the camera’s logs recorded about 21 days of activity across several periods. During those windows, the device photographed roughly 50,200 vehicles and generated about 1.6 million images. On a typical day, it logged around 3,300 vehicles, with a high of 4,454. Those figures would vary considerably depending on where a camera is installed and how much traffic passes in front of it. The camera was almost certainly operating outside those periods, but older logs had been overwritten or were no longer recoverable from the device. The software running on the camera explicitly detects people, something which is typically overlooked in discussions around Flock cameras. When it spots a person, it records where they appear in the image and how confident it is in the detection. To test what the software could actually see, WIRED extracted the models from the camera’s files and ran them against test images and footage recovered from the device. The models readily detected people, including a selfie of a reporter. WIRED then ran them across 27,321 short video clips stored on the camera. The clips were mp4 files, each about one to two seconds long, recorded at 1024 by 768 pixels without audio. They were separate from the rapid bursts of higher-resolution still images the camera also takes as vehicles pass. The models detected people in 11 of the clips, all of them riding motorcycles. The small number is likely due to the camera’s position above a roadway, pointed down at passing traffic where pedestrians were unlikely to appear. The tests also showed how broadly the camera’s plate detector could interpret what it saw. In some cases, it mistook bumper stickers, dealership frames, and other graphics for license plates and cropped them out as if they were plates. In one video of a passing motorcycle, the detector cropped an American flag patch on the rider’s saddlebag as if it were a plate. Flock insists its cameras do not perform face recognition. WIRED and 404 Media found no evidence of any face-recognition capabilities in the camera’s software beyond ones