reverse engineering · embedded security

FlockCamRe

Open hardware teardown and firmware analysis of Flock Safety ALPR cameras. Boards, chips, boot chains, radios, and the cloud they phone home to.

Cassowary CCB main board · 401-00027-3
3 boards documented
GPLv3 released license
APQ8053 application processor

What's documented

Browse the repo

Hardware

Full teardowns of the mainboard, the LED board, and the camera module. Annotated PCB shots, pinouts, connectors, power design, revisions, and microscope images.

hardware/

Firmware & Boot

Bootloader, u-boot, secure boot, TrustZone, kernel, rootfs, and the update process. Extraction scripts and an inventory of firmware versions and hashes.

firmware/

Chips & Silicon

Every IC identified. The APQ8053 CPU, cellular, GPS, and wireless radios, image sensor, PMIC, and a full FCC ID inventory with links to datasheets.

chips/inventory

Cloud & Networking

Endpoints, MQTT and WebSocket traffic, DNS, certificates, firewall rules, and captured traffic analysis. All of it shows how the camera phones home.

networking/

Security

Threat model, attack surface, secure boot, encryption, and key handling. Plus an advisories directory for responsible disclosure of real findings.

security/

Reverse Engineering

Ghidra and IDA projects, exported databases, function maps, pseudocode, and extracted strings. All the messy work, kept open.

reverse-engineering/

Where to start

"When I was a boy and I would see scary things in the news, my mother would say to me, 'Look for the helpers. You will always find people who are helping.'"
— Fred Rogers