All Topics
All Topics
Technology
Technology
Design
Design
Programming
Programming
Science
Science
News
News
Gaming
Gaming
Entertainment
Entertainment
Business
Business
Finance
Finance
Sports
Sports
Health
Health
Food
Food
Travel
Travel
Art
Art
Music
Music
Books
Books
Education
Education
Politics
Politics
Personal
Personal
No algorithm. No AI slop. No ads. Just RSS. Pro-human. Indie writers. Real journalism. Open web. Chronological. Hand toasted.

Flock Safety Exposed ArcGIS API Key Across 53 Public Assets, Compromising Surveillance Infrastructure

By

fuck_flock

4mo ago· 13 min readenInsight

Summary

A security researcher discovered that Flock Safety, a surveillance technology company, had hardcoded a default ArcGIS API key across 53 public-facing assets, exposing the mapping infrastructure used by approximately 12,000 law enforcement agencies, community deployments, and private businesses. The vulnerability granted access to 50 private data layers containing sensitive information about police departments, community surveillance deployments, and private sector installations. The issue was remediated following responsible disclosure, but it highlights significant security risks in critical surveillance infrastructure.

Key quotes

· 5 pulled
I discovered a Default ArcGIS API key embedded in Flock Safety's public-facing JavaScript bundles.
This single credential granted access to the company's ArcGIS mapping environment, and 50 private layers.
53 separate instances across public-facing assets compromising 50 data layers
~5,000 police departments, ~6,000 community deployments, and ~1,000 private businesses
A responsible disclosure documenting an organization-wide ArcGIS API key exposed across 53 public-facing assets
Snippet from the RSS feed
A responsible disclosure documenting an organization-wide ArcGIS API key exposed across 53 public-facing assets, granting access to the mapping infrastructure underlying approximately 12,000 law enforcement, community, and private sector deployments.

You might also wanna read