# Flock Safety Is a Privacy Nightmare and It’s Getting Worse | Snubs On Security 04 # Shannon Morse — https://www.youtube.com/watch?v=A4bcPJk8roo What’s up S’mores, I’m Shannon Morse, and welcome back to Snubs on Security, the show where I spill the tea and share my caffeinated opinions on all things cybersecurity and hacking. We’ve got some updates about those Flocking cameras today, a big museum heist, and umm satellite hacking. COOL COOL EVERYTHING IS FINE. Let’s say someone on the ground with an $800 dish could eavesdrop on your calls, texts, airline Wi-Fi, power-grid chatter and even military movements - all from satellites? Sounds sci-fi, right? Researchers from University of California San Diego and University of Maryland, College Park spent a few years pointing a consumer-grade satellite receiver at space. What they found: roughly half of the geostationary satellite communications they could monitor were not encrypted. That means calls, texts, internet traffic, industrial control commands, even military and law-enforcement data were being broadcast in ways anyone with the right kit could capture. In one nine-hour stretch alone, the dish monitored unprotected satellite backhaul for a big U.S. carrier, logging more than 2,700 phone numbers, calls and texts passing through remote towers. And yes - military sea-vessels, Mexican aircraft maintenance logs, facility control systems for offshore oil rigs and national utilities also showed up in the data. Here’s why this is a concern: 1. Satellite communications are supposed to be one of the more secure backbones of global infrastructure - they connect the remote, the mobile (airlines, ships), the mission-critical. Yet here we are with whole swaths exposed. 2. The barrier to doing this is shockingly low: $800 in gear, a rooftop dish, and off-the-shelf software. The research paper even called it “Don’t Look Up” - because the default security mindset seems to be “nobody will bother.” 3. The worst part? The numbers suggest they only captured maybe ~15 % of the satellites they could peer into. Which means the vulnerability footprint is likely much bigger. Some telecoms moved quickly: for example, the carrier in the U.S. that got caught cited that it patched the issue after the researchers warned them. But many others - especially infrastructure firms, utilities, older remote networks - haven’t fully fixed the gap. The researchers say they alerted unnamed U.S. critical-infrastructure owners and found reluctance, cost hesitancy or just “we’ve always done it this way” inertia. From the military to your local power grid to the plane you’re on - if communications link via satellite and use “security through obscurity” (i.e., “nobody will listen” because it’s in space”), you might be exposed. The researchers even say they strongly believe intelligence agencies have been tapping this traffic for years - no dish required beyond their own setups. Okay, let’s shift from “That’s wild” to “What does this mean for us?” If your comms - phone calls, texts, IoT devices, remote installs - route through satellites (especially in rural/remote/off-grid spots), ask: are those links encrypted end-to-end or at least encrypted in the channel (link-layer or network-layer)? If not, you’re talking big, old exposure. Using an app like Signal, WhatsApp, using your own VPN or encrypted tunnel helps - but it starts with knowing your backhaul (or whoever’s routing your data) isn’t just sending everything in the clear. If you’re part of an org: Infrastructure that seems “remote” or “out of sight” is not out of threat. A dish on a roof at a university picked up phone calls, texts, utility controls. So remote = “less secure” by default is a myth. And yes, the “space” part is irrelevant. Attackers don’t need rockets - they just need a dish pointed at the right satellite. This also signals a big policy gap: regulators, standard bodies, and procurement folks need to treat satellite backhaul like any other critical network path - because it is. If we say “all network traffic must be encrypted,” then on-the-ground law and policy must enforce that for satellite links too. Last thought: it’s a huge reminder that security isn’t only about software or servers. It’s about infrastructure, assumptions, and what you don’t think might be visible. If you assume no one is looking, you’re already behind. So here’s what I want you to do: If you have devices or services reaching remote areas (airports, ships, off-grid towers, power substations), ask the vendor: “Are our satellite links encrypted end-to-end? Can we audit it?” For your personal life: assume some of your comms might pass over satellite links you don’t control, so keep using encrypted apps, use VPNs when roaming, treat “out of sight” as “out of secure.” Alright, quick break because it is officially that season. The season of peppermint mochas, cozy sweaters, and… identity thieves having the time of their lives. Yep. The holidays are basically Black Friday for scammers. Everyone is shopping online, everyone is distracted, and everyone is clicking on things they probably shouldn’t. And that is exactly why I use today’s sponsor, DeleteMe. DeleteMe goes through all those creepy data broker sites and removes your personal information. I’m talking your home address, phone number, even your family members' names. All of that ends up online without your permission and scammers absolutely love it. This time of year, those sites get scraped constantly by attackers who are looking for easy targets, and nothing says holiday spirit like someone trying to open a credit card in your name. Cybercriminals are now even using AI to trick holiday shoppers into clicking on links they shouldn’t be clicking on. They’re using AI tools to create phishing emails that are even harder to detect. They’re using retailer impersonation websites to trick you into putting your credit card number and billing info into fake checkout forms. So not only do I employ a lot of proper security hygiene when I do holiday shopping, but I also use DeleteMe so potential identity thieves can’t find my info and use it to buy stuff under my name. DeleteMe makes it super simple. You sign up, you tell them what data you want removed from the data broker sites, their team gets to work, and you get regular reports showing what they found and what they removed. Honestly, it is the most stress relieving thing I do during the holidays besides putting my phone on Do Not Disturb and hiding from group chats. So if you want one less thing to worry about this season, definitely check out DeleteMe. They’re offering 20 percent off with my code SNUBS at checkout. The link is down below. My coupon code is exclusively available to my viewers too. Go to joindeleteme.com/MorseCode and use the code SNUBS for 20% off. That’s joindeleteme.com/morsecode for 20% off with the code SNUBS. Protect your identity, protect your peace, and keep the holiday chaos where it belongs… in the mall parking lot. Start saving time and protecting your data today with DeleteMe! Thank you to DeleteMe for sponsoring this video. Alright S’mores, let’s talk about something that has been bubbling up for months - and is now full-on boiling. Flock Safety. You’ve probably seen their little black cameras perched on poles, at neighborhood entrances, next to shopping centers, at stop lights… they’re everywhere. My own dog park has one at each entrance. These things snap photos of the license plates of every car that drives past them. Billions of scans per year. And while Flock claims they’re “solving crime,” the past few weeks have exposed something a whole lot messier: weak cybersecurity, massive privacy gaps, legal battles, wrongfully accused civilians, and cities straight up saying “nope” to expanding this surveillance network. So, let’s break it down. If you run a giant surveillance network and feed your data directly to law enforcement, the bare minimum is protecting those accounts. Right? A group of lawmakers, including Senator Ron Wyden, sent a letter to the FTC revealing that police officers’ usernames and passwords for Flock’s system have been stolen - at least 30 to 35 accounts so far. And here’s the kicker: Flock does not require multi-factor authentication. Not optional - not “strongly recommended” - just straight up missing. So imagine having the keys to a nationwide database that can track people’s cars across cities and states in near real-time - and that access hinges on a single password that could be stolen. Congratulations, someone can browse a giant surveillance map of American life. This is a national infrastructure security failure dressed up like a startup oversight. Funny enough, I did have a conversation with an anonymous law enforcement agent right after I posted my first Flock video and I straight up asked him if they have 2FA. He told me his jurisdiction doesn’t… and apparently 2FA just isn’t a thing here! So this confirms the information that I was given. Just this week, I learned ever more about vulnerabilities in Flock Cameras. Benn Jordan on Youtube posted a very in depth video interviewing several security researchers who’ve found even more issues. Watch his full video, I’ll link it below, but TLDR: There are 47 vulns listed in White Papers, from creds to login already being sold on the dark web, to the ability to get a root shell on the cameras by pressing buttons, connecting via WiFi and installing your own software, plugging in a USB Rubber Ducky because apparently the USB ports are totally wide open on the back, a live website API found in the code on a public facing demo website, using a Wifi Pineapple to deauth the cameras and man in the middle those connections, YEAH SO EVERYTHING IS FINE HERE. Now, let’s talk about who owns this data. Several cities have argued that because Flock is a private company, its footage shouldn’t be subject to public-records laws. But a recent Washington state ruling flipped that on its head. A judge said Flock’s images are public records because government agencies “create” and “use” them - even if Flock stores them on its own servers. That means journalists, researchers, and everyday civilians have the right to request the data, just like bodycam footage or emails from a city department. This is a big deal. On one hand, you should absolutely be able to see what that tool records if a government agency is using surveillance to track your movement. On the other hand, I can see how this access could be abused by a stalker. Privacy watchdogs have been warning about Flock for years, and they’re now stepping in harder than ever. The ACLU and the Electronic Frontier Foundation are suing the city of Piedmont, California, which has a *blanket* of Flock cameras covering nearly every road in and out of town. According to the lawsuit, this setup allows police to “track every resident and visitor with perfect accuracy,” with no clear oversight, retention policy, or transparency about how data is shared. And the lawsuit also points out something Flock doesn’t exactly advertise So if you drive into one city, but law enforcement in a city two states away decides they want your plate data? They can request it, and boom - it’s shared. No warrant. No notice. No accountability. Now let’s talk about real-world harm. Actually this story happened RIGHT HERE, in the city that I live in. In Colorado, a woman named Chrisanna Elser was falsely accused of stealing packages because her car “kind of” matched one seen in a Flock alert - and her license plate passed a camera hours later. That’s it. That was the entire basis for the accusation. She had to prove her innocence using her own receipts and footage from her Rivian - because the police insisted the system doesn’t lie. This lady had to waste hours of time just to prove her innocence in this porch pirate case. When automated surveillance becomes the “source of truth,” and humans blindly trust it, innocent people end up getting detained, questioned, accused, or worse. And the Denver Police Department said they would reprimand the officer for mishandling the Flock data. These reprimands barely scratch the surface, because there’s no standardized training on how to use this stuff responsibly. The entire video is available to watch online, but I had this very visceral reaction to how accusatory this officer was, and the way he was talking down to her. I’m glad she made the entire interaction public. This isn’t the only story that hits really close to home for me. In a recent interview, our own Mayor said that a woman’s mrder case was solved by the use of Flock cameras. [video] I immediately knew he was lying because one of my very good Sailor Moonie friends was a REALLY good friend with Jax, and has been advocating for them to find the person who did this to her, and her case HAS NOT been solved. He straight up LIED about Jax’s case, and said it was because of these cameras. Then the Mayor’s office issued an apology to her mother because of this. This is the same mayor who also signed a contract to keep using the cameras in the Denver metro, against the unanimous council vote. That’s a whole ‘nother issue! This isn’t just a tech story. This is now a privacy advocacy one. Oakland voted down expanding their Flock contract after intense public comment. Cities in Washington State are turning off their ALPR systems entirely because of the legal ruling that makes images subject to public disclosure. Across the country, city councils are starting to realize they bought into a high-surveillance system pitched like a “Ring camera for your neighborhood,” not recognizing the massive civil liberties risks until after deployment. I think about what my stalker from a decade ago could’ve done with that data. What that man could have done if he had access to this data and was able to see my whereabouts. They were so concerned with stopping criminals by recording them but they aren’t taking into account potential problems, like when logins are hacked, when transparency fails, when citizens are misidentified - the consequences fall on everyday people. Not executives. Not investors. People like the Colorado woman who had to prove she didn’t steal a package based on where her car was. This is a foundational privacy issue that affects almost every community in the U.S. So if your city has Flock cameras - or is considering them - start asking questions. Who can access the footage? Is the data shared? How long is it stored? Is there an oversight committee? Is MFA required? Can you request the images under public-records laws? And what safeguards are in place to protect innocent people from bad matches? Maybe we should be watching the watchers. We have a couple of ways to figure out where these things are installed, including deflock.me, but I actually found a few cameras in my own community that weren’t even listed on this map. So I got into a convo with this hacker named Colonel Panic who offered to send me one of their physical detection tools, called the OUI Spy, so I can try out their firmware, Flock You, with it, and do some flockhunting - Do y’all want to see me go out into the real world and try to find some cameras with this lil device? I haven’t donned my hacker hat in a long time but I’m totes down with doing some real world wardriving. Flock driving? Ironically, I just watched Ocean’s 8. Love Sandra Bullock. Anyway, the actual world-famous Louvre in Paris - is now scrambling to patch some pretty shocking security gaps after a massive heist. So here’s the tea. Back on October 19, a group of thieves somehow managed to break into the Apollo Gallery and walk off with eight pieces from France’s crown jewel collection. We’re talking about roughly one hundred and two million dollars worth of treasures vanishing. And let me just say… the way they got in is wild. According to reports, they used a freight lift and a truck-mounted cherry picker. Imagine pulling up with a literal construction crane like, “Bonjour, we’re just here to steal some priceless royal artifacts.” And it worked. They slipped in, grabbed the jewels, and were gone. And here’s where things get even more face-palmy. During a hearing, the Louvre’s own director admitted that there were some absolutely glaring holes in their security setup. Apparently, only one perimeter camera covered the area - and it wasn’t even pointed toward the gallery that was robbed. And the password to their surveillance system? It was literally “Louvre.” I wish I were kidding. You can’t make this stuff up. So, now the Louvre is kicking into full crisis-mode, announcing more than 20 emergency security measures. We’re talking new anti-intrusion systems, beefed-up perimeter protection, and around 100 fresh surveillance cameras going up around the museum over the next year. They even announced they’re building an actual police station on-site and appointing a dedicated security coordinator. Some of the fixes are happening within days, but others - like all those new cameras - won’t be fully deployed until late next year. And that’s where the big lesson is. This is a perfect reminder that security isn’t just firewalls and encryption keys. Physical access matters. In fact physical penetration… nevermind. Operational culture matters. Password hygiene definitely matters. And if you’re relying on “we’ll fix it next year,” congratulations - you’ve created a giant vulnerability window for anyone paying attention. The Louvre’s director said she wants to instill a “genuine security culture,” and honestly, that’s the real takeaway. You can’t just sprinkle in some cameras and hope for the best. You need people thinking about security every day, in every department, at every door. Holistic security. And that’s it for this week’s episode of Snubs on Security! Huge thanks to DeleteMe for sponsoring this episode and to my incredible Patreon S’mores for keeping this show running. If you want to join the S’mores, get early access, and hang out with us on Discord, check out patreon.com/ShannonMorse. And don’t forget to snag your discount on DeleteMe over at https://joindeleteme.com/morsecode . And as always stay safe, stay secure, and I’ll see you in the next one. Bye yall!