Flock seeks to have security researchers' map of Flock cameras taken down
- ID
- 29087
- Status
- summarized
- Published
- 27 Sep 2026, 8:00 PM
- Fetched
- 27 Sep 2026, 9:45 PM
- Provider
- Tom's Hardware
- Category
- technology
- Original URL
- https://www.tomshardware.com/tech-industry/cyber-security/flock-seeks-to-have-security-researchers-map-of-flock-cameras-taken-down-unauthenticated-flaw-exposed-335-701-camera-locations-nationwide
- Source URL
- https://www.tomshardware.com/feeds/all
Summary
- Score
- 4.5
- Created
- 27 Sep 2026, 9:45 PM
- Tags
- Audience
- developerssaas_founders
What happened
Flock has asked security researchers to take down a public map of its camera locations, after an unauthenticated flaw let 335,701 camera locations nationwide be enumerated. The article excerpt is largely Tom's Hardware subscription boilerplate, so the disclosure timeline, Flock's specific legal/technical response, and any fix status are not in the text provided.
Why it matters
The concrete lesson is enumeration: a single unauthenticated endpoint returned 335,701 device locations, turning an asset list into a nationwide map. If you ship an API with any listing endpoint (devices, sites, users, tenants), test it right now as an anonymous caller and decide whether an unauthenticated list response is acceptable — for most SaaS products it is not, and the fix is auth plus pagination/rate limits, not obscurity.
Discussion angle
Where should a builder draw the line between a takedown request and a legitimate security disclosure — and does anyone in the room have a public /list or /devices endpoint they have never tested unauthenticated?