Skip to content
World clockEU--:--UK--:--USA--:--CN--:--PLDEFRIT中文EN

portal about AI and technologyevents · analysis · interviews · technical background

Search
LIVE
›

Flock wants a 335,701-camera surveillance map taken down

Flock has filed a trademark complaint against the security researcher whose map of its cameras lists 335,701 locations, Tom's Hardware reported on 27 September.

AI & modelsAnalysisGrace OkonkwoPublished: 28 September 20264 min readSources 4
Flock wants a 335,701-camera surveillance map taken down

Flock has issued a trademark infringement complaint aimed at forcing Joshua Michael to shut down the Flock Surveillance Map, a site he built after finding an unauthenticated flaw in the company's website, according to Tom's Hardware. The map lists 335,701 camera locations.

The dispute goes back to November 2025. Michael says he found an access token exposed on Flock's site, with no login required. He told The Intercept, which Tom's Hardware cites, that he reported it to the company right away.

His email, dated 13 November 2025, stated that "all testing was strictly non-intrusive, limited to open unauthenticated endpoints, and did not involve bypassing authentication, modifying data, or invoking any billable ArcGIS or Google operations." Flock's first reply, after two more attempts, was that it was "internally triaging" the findings and would reach back with next steps, Tom's Hardware reports. Michael says that reply never came.

What the researcher did with the data

Michael used the token to query ArcGIS, the third-party mapping layer Flock runs on, and pulled a database of Flock devices in November 2025. Flock appears to have fixed the vulnerability in January 2026, after he published his findings, but by then the device location data had already been extracted. The map, which Tom's Hardware describes as presumably updated in December 2025, remains online.

The company's public position is that it has never been hacked, that Flock information has never leaked, and that the Flock Safety cloud platform "has never experienced a data breach." Michael disputes that account. He told The Intercept the statement was made "after I pulled their database of devices."

"That leaves two possibilities," he said. "Either they knew and chose not to disclose it for fear of bad press, or they didn't know I exfiltrated the data at all. The first is a transparency failure. The second is a detection failure with national security implications."

"That leaves two possibilities. Either they knew and chose not to disclose it for fear of bad press, or they didn't know I exfiltrated the data at all."

Separate reporting cited by Tom's Hardware has already raised questions about the hardware itself. Hackers found encryption keys stored directly on Flock cameras, which let them extract more than 27,000 clips and establish that the system had captured more than 1.6 million images over 21 days. There have also been documented cases of misuse, including police officers using the network to track romantic partners, and a car reviewer detained for an hour in a store parking lot over a mistyped police report.

The map's own numbers point at a broader exposure. Michael says people living within a 20-mile radius of 22 sensitive sites, among them Eglin AFB, CIA Headquarters, FBI Headquarters, Joint Base Andrews and the Pentagon, have a 57.22% to 93.94% chance of passing a Flock camera.

Elsewhere in agent evaluation

The same week brought two very different pieces of safety research. On 27 September The Decoder reported that researchers at Stanford and Caltech built HomeBody, a system that lets a Unitree G1 robot navigate an unfamiliar kitchen, tidy up and fetch items from drawers. The setup removes the trained control layer between model and robot: a swappable vision-language model, in this case GPT-6 Astra, calls directly into a skill library for grasping, navigating and opening drawers. The robot explores the room first, builds a digital twin in Nvidia's Isaac Sim, and logs objects in spatial memory so it can find items that leave its field of view. The Decoder lists Astra's latency, overheating finger servos and high compute costs as limitations, and notes the code is on GitHub. Earlier benchmarks, it adds, showed improved spatial reasoning for Astra while another flagged safety issues when the model controls a robot.

On the same day, The Decoder also reported that Boris Power, OpenAI's Head of Applied Research, puts 80 to 90 percent of the company's research toward GPT 7, GPT 8 and beyond, because that is where "most of the value" comes from. Power described incremental updates such as GPT 5.1 to 5.2 as intentionally short-term bets, and said such updates are seen internally as "extremely shortsighted." He argued the main problem with today's assistants is onboarding rather than model quality, since most ChatGPT users do not know what the tools can do.

Meta's contribution is a launch post rather than a benchmark. On 25 September Meta AI Research published details of Muse, a personal agent it has used internally since early 2026. The post says the harness runs in an isolated cell that does not see real credentials, that every outside interaction passes through a Sentinel the agent cannot override, and that security-sensitive services run outside the runtime cell so attackers cannot disable them. Meta also opened its bug bounty to anyone, with awards up to $300,000 and up to $130,000 for prompt injection attempts affecting a single user.

Read together, the four items show where evaluation effort is currently going. At Flock, the test is whether a company can detect an extraction at all, and its answer is disputed. In the lab work, the test is whether a model wired straight into hardware, or handed a shell and an inbox, can be measured before something goes wrong.

Comments 0

Sources

4
  1. 01Flock seeks to have security researchers' map of Flock cameras taken downEN
  2. 02Researchers plug GPT-6 Astra directly into a robot and let it clean up an unfamiliar kitchenEN
  3. 03OpenAI says 80 to 90 percent of its research already targets GPT 7 and beyondEN
  4. 04How We Built Safety Into MuseEN

All figures and quotations in this text come from the sources listed below.

Content prepared by the editorial team with AI assistance.

Grace Okonkwo

Grace Okonkwo

AI, models and technology

Grace Okonkwo covers AI, models and technology for FLASH24, working from primary sources such as model cards, API documentation and benchmark papers rather than vendor summaries. She checks training data provenance, evaluation conditions and reported scores against the underlying datasets before any figure reaches print. She interviews researchers and engineers directly, tracks release calendars from major labs, and compares successive model versions on the same tests. Her own self-hosting, home-network and documentation-reading habits feed straight into that desk, since she tests tools on her own hardware first. She does not publish benchmark claims without a reproducible method.

Newsroom →

Comments

0
  1. No comments yet — be the first.

Write a comment

Comments are public. We do not publish abuse, spam or advertising.