Micah Lee Finds Flock License-Plate Cameras Running Eight-Year-Old Android With Hardcoded Keys

Hackers who pulled a camera in Wauwatosa, Wisconsin extracted firmware running a Linux kernel abandoned since 2019, Auth0 credentials stored in plaintext.
- Security researcher Micah Lee published "Flock Cameras Are Riddled With Security Vulnerabilities and Hard-Coded Credentials" on September 16, 2026, examining leaked ALPR firmware.
- "Why just destroy [Flock cameras] when we can reverse engineer them and find the secrets of those spying on us?"
- The firmware stored a hardcoded Auth0 API key, HaJ3FgupAm8RrDJW3MHgT9X7Ft27eVaD, unencrypted on the device.
Why it matters: The agencies buying these cameras trusted a device its own maker never bothered to update.