HaJ3FgupAm8RrDJW3MHgT9X7Ft27eVaD
What is that? That's a hard-coded API token that Flock cameras use to identify themselves and get OAuth credentials, which can then be used to talk to Flock's production servers. Like, anyone on the internet can probably do this right now.
Ethically? Expire the token since it’s compromised, and offer to refurbish all units in the field since flock screwed up, a now all customer data could be poisoned/suspect now.
Realistically? Keep going like nothing happened an make it a customer support problem while pushing new hardened cameras that cost more. Because the product alone loudly flags Flock as a bunch of amoral greedy fuckwits.
I won’t suggest ways to actually make their product bulletproof because I care and we don’t need to make this problem worse for everyone. It is a tantilizing problem space but there are never any perfect answers in security, only relatively better/worse ones.
Ethically? Expire the token since it’s compromised, and offer to refurbish all units in the field since flock screwed up, a now all customer data could be poisoned/suspect now.
Realistically? Keep going like nothing happened an make it a customer support problem while pushing new hardened cameras that cost more. Because the product alone loudly flags Flock as a bunch of amoral greedy fuckwits.
I won’t suggest ways to actually make their product bulletproof because I care and we don’t need to make this problem worse for everyone. It is a tantilizing problem space but there are never any perfect answers in security, only relatively better/worse ones.
Oh, I don’t mean afterwards. I meant before it even happened.
You give each camera its own token, and validate it with hardware ID.
Even better, give them hardware token, that can sign, but does not leak its keys.
In either way, you can ID the device, and block unsold and confirmed stolen/damaged ones. And never accept traffic from anything else.