Full transcript
What’s up S’mores, I’m Shannon Morse,
and welcome back to Snubs on Security,
the show where I spill the tea and share
my caffeinated opinions on all things
cybersecurity and hacking. We’ve got some
updates about those Flocking cameras today,
a big museum heist, and umm satellite
hacking. COOL COOL EVERYTHING IS FINE.
Let’s say someone on the ground with an
$800 dish could eavesdrop on your calls,
texts, airline Wi-Fi, power-grid chatter and
even military movements - all from
satellites? Sounds sci-fi, right?
Researchers from University of California
San Diego and University of Maryland,
College Park spent a few years pointing
a consumer-grade satellite receiver at
space. What they found: roughly half of the
geostationary satellite communications they
could monitor were not encrypted. That
means calls, texts, internet traffic,
industrial control commands, even
military and law-enforcement data
were being broadcast in ways anyone
with the right kit could capture.
In one nine-hour stretch alone, the dish
monitored unprotected satellite backhaul
for a big U.S. carrier, logging more than
2,700 phone numbers, calls and texts passing
through remote towers. And yes - military
sea-vessels, Mexican aircraft maintenance logs,
facility control systems for offshore oil rigs
and national utilities also showed up in the data.
Here’s why this is a concern:
1. Satellite communications are supposed to
be one of the more secure backbones of global
infrastructure - they connect the remote, the
mobile (airlines, ships), the mission-critical.
Yet here we are with whole swaths exposed.
2. The barrier to doing this is shockingly low:
$800 in gear, a rooftop dish, and off-the-shelf
software. The research paper even called it “Don’t
Look Up” - because the default security
mindset seems to be “nobody will bother.”
3. The worst part? The numbers suggest
they only captured maybe ~15 % of the
satellites they could peer into. Which means the
vulnerability footprint is likely much bigger.
Some telecoms moved quickly: for
example, the carrier in the U.S.
that got caught cited that it patched the
issue after the researchers warned them.
But many others - especially infrastructure firms,
utilities, older remote networks - haven’t fully
fixed the gap. The researchers say they alerted
unnamed U.S. critical-infrastructure owners and
found reluctance, cost hesitancy or just
“we’ve always done it this way” inertia.
From the military to your local power grid to
the plane you’re on - if communications link via
satellite and use “security through obscurity”
(i.e., “nobody will listen” because it’s in
space”), you might be exposed. The researchers
even say they strongly believe intelligence
agencies have been tapping this traffic for
years - no dish required beyond their own setups.
Okay, let’s shift from “That’s wild”
to “What does this mean for us?”
If your comms - phone calls, texts, IoT
devices, remote installs - route through
satellites (especially in rural/remote/off-grid
spots), ask: are those links encrypted end-to-end
or at least encrypted in the channel
(link-layer or network-layer)? If not,
you’re talking big, old exposure.
Using an app like Signal, WhatsApp,
using your own VPN or encrypted tunnel
helps - but it starts with knowing your
backhaul (or whoever’s routing your data)
isn’t just sending everything in the clear.
If you’re part of an org: Infrastructure that
seems “remote” or “out of sight” is not out of
threat. A dish on a roof at a university picked
up phone calls, texts, utility controls. So
remote = “less secure” by default is a myth.
And yes, the “space” part is irrelevant.
Attackers don’t need rockets - they just
need a dish pointed at the right satellite.
This also signals a big policy gap: regulators,
standard bodies, and procurement folks need to
treat satellite backhaul like any other
critical network path - because it is.
If we say “all network traffic must be
encrypted,” then on-the-ground law and
policy must enforce that for satellite links too.
Last thought: it’s a huge reminder that security
isn’t only about software or servers.
It’s about infrastructure, assumptions,
and what you don’t think might be visible. If you
assume no one is looking, you’re already behind.
So here’s what I want you to do:
If you have devices or services reaching remote
areas (airports, ships, off-grid towers, power
substations), ask the vendor: “Are our satellite
links encrypted end-to-end? Can we audit it?”
For your personal life: assume some of your
comms might pass over satellite links you
don’t control, so keep using encrypted apps,
use VPNs when roaming, treat “out
of sight” as “out of secure.”
Alright, quick break because it is officially
that season. The season of peppermint mochas,
cozy sweaters, and… identity thieves having
the time of their lives. Yep. The holidays are
basically Black Friday for scammers. Everyone
is shopping online, everyone is distracted,
and everyone is clicking on
things they probably shouldn’t.
And that is exactly why I use
today’s sponsor, DeleteMe.
DeleteMe goes through all those creepy data broker
sites and removes your personal information. I’m
talking your home address, phone number, even
your family members' names. All of that ends up
online without your permission and scammers
absolutely love it. This time of year,
those sites get scraped constantly by
attackers who are looking for easy targets,
and nothing says holiday spirit like someone
trying to open a credit card in your name.
Cybercriminals are now even using AI to
trick holiday shoppers into clicking on
links they shouldn’t be clicking on. They’re
using AI tools to create phishing emails that
are even harder to detect. They’re using
retailer impersonation websites to trick
you into putting your credit card number
and billing info into fake checkout forms.
So not only do I employ a lot of proper security
hygiene when I do holiday shopping, but I also use
DeleteMe so potential identity thieves can’t find
my info and use it to buy stuff under my name.
DeleteMe makes it super simple. You sign up,
you tell them what data you want removed from
the data broker sites, their team gets to work,
and you get regular reports showing what they
found and what they removed. Honestly, it
is the most stress relieving thing I do
during the holidays besides putting my phone
on Do Not Disturb and hiding from group chats.
So if you want one less thing to worry about
this season, definitely check out DeleteMe.
They’re offering 20 percent off with my code
SNUBS at checkout. The link is down below.
My coupon code is exclusively
available to my viewers too. Go
to joindeleteme.com/MorseCode and
use the code SNUBS for 20% off.
That’s joindeleteme.com/morsecode for
20% off with the code SNUBS.
Protect your identity, protect your
peace, and keep the holiday chaos
where it belongs… in the mall parking
lot. Start saving time and protecting
your data today with DeleteMe! Thank you
to DeleteMe for sponsoring this video.
Alright S’mores, let’s talk about something
that has been bubbling up for months - and is
now full-on boiling. Flock Safety. You’ve
probably seen their little black cameras
perched on poles, at neighborhood
entrances, next to shopping centers,
at stop lights… they’re everywhere. My own dog
park has one at each entrance. These things snap
photos of the license plates of every car that
drives past them. Billions of scans per year.
And while Flock claims they’re “solving
crime,” the past few weeks have exposed
something a whole lot messier: weak
cybersecurity, massive privacy gaps,
legal battles, wrongfully accused
civilians, and cities straight up saying
“nope” to expanding this surveillance
network. So, let’s break it down.
If you run a giant surveillance network and
feed your data directly to law enforcement,
the bare minimum is protecting
those accounts. Right?
A group of lawmakers, including Senator Ron Wyden,
sent a letter to the FTC revealing that police
officers’ usernames and passwords for Flock’s
system have been stolen - at least 30 to
35 accounts so far. And here’s the kicker:
Flock does not require
multi-factor authentication.
Not optional - not “strongly
recommended” - just straight up missing.
So imagine having the keys to a nationwide
database that can track people’s cars across
cities and states in near real-time - and that
access hinges on a single password that could be
stolen. Congratulations, someone can browse
a giant surveillance map of American life.
This is a national infrastructure security
failure dressed up like a startup oversight.
Funny enough, I did have a conversation
with an anonymous law enforcement agent
right after I posted my first Flock video
and I straight up asked him if they have
2FA. He told me his jurisdiction
doesn’t… and apparently 2FA just
isn’t a thing here! So this confirms
the information that I was given.
Just this week, I learned ever more
about vulnerabilities in Flock Cameras.
Benn Jordan on Youtube posted a
very in depth video interviewing
several security researchers
who’ve found even more issues.
Watch his full video, I’ll link it below, but
TLDR: There are 47 vulns listed in White Papers,
from creds to login already being sold on the
dark web, to the ability to get a root shell on
the cameras by pressing buttons, connecting
via WiFi and installing your own software,
plugging in a USB Rubber Ducky because apparently
the USB ports are totally wide open on the back,
a live website API found in the code on a public
facing demo website, using a Wifi Pineapple to
deauth the cameras and man in the middle those
connections, YEAH SO EVERYTHING IS FINE HERE.
Now, let’s talk about who owns this data.
Several cities have argued that because Flock
is a private company, its footage shouldn’t be
subject to public-records laws. But a recent
Washington state ruling flipped that on its
head. A judge said Flock’s images are public
records because government agencies “create”
and “use” them - even if Flock stores them
on its own servers. That means journalists,
researchers, and everyday civilians
have the right to request the data,
just like bodycam footage or
emails from a city department.
This is a big deal. On one hand,
you should absolutely be able to
see what that tool records if a government
agency is using surveillance to track your
movement. On the other hand, I can see how
this access could be abused by a stalker.
Privacy watchdogs have been
warning about Flock for years,
and they’re now stepping in harder than ever.
The ACLU and the Electronic Frontier Foundation
are suing the city of Piedmont, California,
which has a *blanket* of Flock cameras covering
nearly every road in and out of town. According
to the lawsuit, this setup allows police to “track
every resident and visitor with perfect accuracy,”
with no clear oversight, retention policy,
or transparency about how data is shared.
And the lawsuit also points out
something Flock doesn’t exactly advertise
So if you drive into one city, but law enforcement
in a city two states away decides they want your
plate data? They can request it, and boom - it’s
shared. No warrant. No notice. No accountability.
Now let’s talk about real-world harm.
Actually this story happened RIGHT HERE,
in the city that I live in.
In Colorado, a woman named Chrisanna
Elser was falsely accused of stealing
packages because her car “kind of” matched
one seen in a Flock alert - and her license
plate passed a camera hours later. That’s it.
That was the entire basis for the accusation.
She had to prove her innocence using
her own receipts and footage from her
Rivian - because the police
insisted the system doesn’t
lie. This lady had to waste hours of time just
to prove her innocence in this porch pirate case.
When automated surveillance becomes the
“source of truth,” and humans blindly
trust it, innocent people end up getting
detained, questioned, accused, or worse.
And the Denver Police Department said they
would reprimand the officer for mishandling
the Flock data. These reprimands barely scratch
the surface, because there’s no standardized
training on how to use this stuff responsibly.
The entire video is available to watch online,
but I had this very visceral reaction
to how accusatory this officer was,
and the way he was talking down to her. I’m
glad she made the entire interaction public.
This isn’t the only story that hits really
close to home for me. In a recent interview,
our own Mayor said that a woman’s mrder case
was solved by the use of Flock cameras. [video]
I immediately knew he was lying because one of my
very good Sailor Moonie friends was a REALLY good
friend with Jax, and has been advocating for
them to find the person who did this to her,
and her case HAS NOT been solved. He straight up
LIED about Jax’s case, and said it was because of
these cameras. Then the Mayor’s office issued
an apology to her mother because of this. This
is the same mayor who also signed a contract
to keep using the cameras in the Denver metro,
against the unanimous council
vote. That’s a whole ‘nother issue!
This isn’t just a tech story. This
is now a privacy advocacy one.
Oakland voted down expanding their Flock
contract after intense public comment.
Cities in Washington State are turning off their
ALPR systems entirely because of the legal ruling
that makes images subject to public disclosure.
Across the country, city councils are starting
to realize they bought into a high-surveillance
system pitched like a “Ring camera for your
neighborhood,” not recognizing the massive
civil liberties risks until after deployment.
I think about what my stalker from a decade
ago could’ve done with that data. What that
man could have done if he had access to this
data and was able to see my whereabouts.
They were so concerned with stopping criminals
by recording them but they aren’t taking into
account potential problems, like when logins are
hacked, when transparency fails, when citizens are
misidentified - the consequences fall on everyday
people. Not executives. Not investors. People like
the Colorado woman who had to prove she didn’t
steal a package based on where her car was.
This is a foundational privacy issue that
affects almost every community in the U.S.
So if your city has Flock cameras - or is
considering them - start asking questions.
Who can access the footage?
Is the data shared?
How long is it stored?
Is there an oversight committee?
Is MFA required?
Can you request the images
under public-records laws?
And what safeguards are in place to
protect innocent people from bad matches?
Maybe we should be watching the watchers.
We have a couple of ways to figure out where
these things are installed, including deflock.me,
but I actually found a few cameras
in my own community that weren’t
even listed on this map. So I got into
a convo with this hacker named Colonel
Panic who offered to send me one of their
physical detection tools, called the OUI
Spy, so I can try out their firmware, Flock You,
with it, and do some flockhunting - Do y’all want
to see me go out into the real world and try
to find some cameras with this lil device?
I haven’t donned my hacker
hat in a long time but I’m
totes down with doing some real
world wardriving. Flock driving?
Ironically, I just watched Ocean’s 8. Love Sandra
Bullock. Anyway, the actual world-famous Louvre in
Paris - is now scrambling to patch some pretty
shocking security gaps after a massive heist.
So here’s the tea.
Back on October 19, a group of thieves
somehow managed to break into the Apollo
Gallery and walk off with eight
pieces from France’s crown jewel
collection. We’re talking about roughly
one hundred and two million dollars worth
of treasures vanishing. And let me
just say… the way they got in is wild.
According to reports, they used a freight lift
and a truck-mounted cherry picker. Imagine
pulling up with a literal construction crane
like, “Bonjour, we’re just here to steal some
priceless royal artifacts.” And it worked. They
slipped in, grabbed the jewels, and were gone.
And here’s where things get even
more face-palmy. During a hearing,
the Louvre’s own director admitted that
there were some absolutely glaring holes
in their security setup. Apparently, only one
perimeter camera covered the area - and it
wasn’t even pointed toward the gallery that was
robbed. And the password to their surveillance
system? It was literally “Louvre.” I wish I
were kidding. You can’t make this stuff up.
So, now the Louvre is kicking into full
crisis-mode, announcing more than 20
emergency security measures. We’re
talking new anti-intrusion systems,
beefed-up perimeter protection, and
around 100 fresh surveillance cameras
going up around the museum over the
next year. They even announced they’re
building an actual police station on-site and
appointing a dedicated security coordinator.
Some of the fixes are happening within
days, but others - like all those new
cameras - won’t be fully deployed until late
next year. And that’s where the big lesson is.
This is a perfect reminder that security
isn’t just firewalls and encryption keys.
Physical access matters. In fact physical
penetration… nevermind. Operational culture
matters. Password hygiene definitely matters.
And if you’re relying on “we’ll fix it next
year,” congratulations - you’ve created a giant
vulnerability window for anyone paying attention.
The Louvre’s director said she wants to instill
a “genuine security culture,” and honestly,
that’s the real takeaway. You can’t just sprinkle
in some cameras and hope for the best. You need
people thinking about security every day, in every
department, at every door. Holistic security.
And that’s it for this week’s
episode of Snubs on Security!
Huge thanks to DeleteMe for
sponsoring this episode and
to my incredible Patreon S’mores
for keeping this show running.
If you want to join the S’mores, get early access,
and hang out with us on Discord,
check out patreon.com/ShannonMorse.
And don’t forget to snag your discount on DeleteMe
over at https://joindeleteme.com/morsecode .
And as always stay safe, stay secure, and
I’ll see you in the next one. Bye yall!