Comment on Hackers Got Inside a Flock Camera. Its Data Shows How the System Really Works
derry@midwest.social 3 days ago
Maybe I’m out of the loop but storing an encryption key on the encrypted device itself seems like bad opsec. Or I’ve misunderstood the article
Eric@lemmy.blahaj.zone 3 days ago
It sounds like Flock fucked up. A camera shouldn’t have keys to decrypt videos. Maybe they were using symmetrical encryption rather than having the camera encrypt the videos using a public key.
TehPers@beehaw.org 3 days ago
This. You’d definitely want the cameras to have only the public key. If they’re not doing that, then their security must be as bad as their morals because they know people are tearing these down everywhere already anyway.
Of course, not using assymetric encryption makes them more auditable by “third parties” which is an unexpected benefit.
I wonder if they at least use a different key per camera. This would be less necessary for asymmetric encryption, of course, but they don’t seem to be using it. If all the cameras are using the same key, then you can theoretically use the key these people pulled to access data on every other camera as well (possibly remotely if you can remote in somehow).
wyldrstallyns@lemmy.dbzer0.com 3 days ago
Remote in somehow? Considering they’re apparently quite simple to access, I imagine it’s not all that complicated to add a bit of clever inside the casing to facilitate remote access. Still, that’s a small number of them —unless that was shared too, of course. 😉
Ashtear@piefed.social 3 days ago
Yet again, incompetence being the only thing saving us from fully entrenched fascism