Cybersecurity experts are warning that the hack of an automatic number plate recognition camera highlights the need for manufacturers to focus on physical device security as well as protecting connected systems from remote attacks.
The comments follow a WIRED and 404 Media investigation that found hackers had physically removed a Flock camera, copied much of its stored data and recovered an encryption key held on the device. A typical passing vehicle generated around 28 images, while some produced more than 100.
The incident has provided an unusually detailed look at the software and security architecture inside a deployed IoT device, raising questions around physical access, firmware security, key management and how much data should be retained at the Edge.
“A lot of companies ignore physical device security when they’re building their threat models,” said John Strand, owner of Black Hills Information Security. “There’s that old saying that anytime you think no one will go through the trouble, some kid in Finland is already going through the trouble. Today, it’s more like this. Anytime you think no one is going to go through the trouble of pulling down your Flock camera and reverse engineering the hardware, there’s some hacker in a hoodie who absolutely will.”
Strand said manufacturers and operators of physical devices should consider how the hardware itself is protected, rather than focusing exclusively on network and Cloud security.
Cameras, sensors and gateways are often deployed in publicly accessible locations and can remain in the field for years, potentially making physical access a realistic part of the threat model.
Jacob Krell, Senior Director of secure AI solutions and cybersecurity at Suzu Labs, said the Flock incident demonstrated the amount of information that can be exposed when sensitive data and the credentials needed to decrypt it are stored locally. “Stealing one Flock Safety camera can expose a substantial amount of what that unit stored locally,” he said.
The investigation has also raised questions about the software running on the camera.
Security researcher Micah Lee, who analysed the published filesystem images, reported that the device was running a modified version of Android 8.1, with a June 2018 security patch level, alongside a Linux 3.18.71 kernel.
His analysis identified a hard-coded API key in a shared library used by 19 separate on-device applications. It also found device credentials stored in plaintext on an unencrypted partition and an encryption key stored on the same partition as the media it protected.
Larry Pesce, VP of services at Finite State, described the findings as a firmware issue that extends beyond Flock. “The Flock camera teardown isn’t a surveillance story. It’s a firmware story we’ve all seen before,” he said.
There’s plenty of other editorial on our sister site, Electronic Specifier! Or you can always join in the conversation by commenting below or visiting our LinkedIn page.
