We Tracked Ourselves with Exposed Flock Cameras

24 Dec 2025 · 54 min · 22 chapters

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

404 Media co-founders discuss how Flock “Condor” PTZ cameras were misconfigured and exposed to the public internet, letting anyone view live and archived surveillance footage (including people, not just cars). They also do a year-in-review covering major security/privacy stories: the “Doge” website data tampering/SQL injection, the TeleMessage messaging app hack affecting government officials, the T dating app data leak (including ID selfies and later direct messages), and age-verification laws impacting adult sites like Pornhub.

Guests (hosts)

Joseph (host), Sam Cole (404 Media co-founder; helped geolocate cameras; reported on age-verification laws), Emmanuel Mayberg (404 Media co-founder; reported on the T app leaks), Jason Kebler (404 Media co-founder; worked on the Flock story).

Key claims

exposed cameras lacked HTTPS and had no login; footage showed people being tracked via pan-tilt-zoom; Flock said the issue was a small misconfiguration and was fixed; third-party facial recognition was used on leaked footage.

Notable examples

Bakersfield, CA intersection near a Big O Tire shop; Peachtree Creek Greenway in Brookhaven, GA where a rollerblader and bystanders were zoomed on; skate park/playground cameras; Doge site SQL injection; TeleMessage used by agencies; T app leaked ID verification selfies and later private DMs.

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Chapters

Tap a time to open that second in VO

Upcoming Podcast Segments Overview

1:18 to 2:18

Discussion on the upcoming segments including a story and year in review.

“It's last minute Christmas slash holiday gifts, or I think you can give it to yourself if you want, if you want to be clever.”

Introduction to Flock Cameras Exposed

2:18 to 3:40

Discussion of a story on Flock's AI-powered cameras and their exposure.

“So this first story, Jason, this is one you worked on with Sam as well, who did some additional reporting.”

The Discovery of Exposed Cameras

3:40 to 4:54

Details on how the exposed cameras were discovered and their implications.

“and what pan, tilt, zoom means is kind of in the name, but they are surveillance cameras that can move and track people.”

Technical Insights on Camera Functionality

4:54 to 6:12

Explanation of the technical aspects and functionalities of different Flock cameras.

“I say largely because, you know, they are taking footage and photos.”

Search Techniques for Camera Locations

6:12 to 7:56

Detailed methods used to geolocate the exposed cameras using various techniques.

“Some of them would be knocked off the internet and then they would be back on later that day.”

Surveillance Experiences at Various Locations

7:56 to 10:40

Experiences and observations from various locations where cameras were found.

“So off the top of my head, in the past, people have found smart billboards that have been streaming to the internet without an admin password.”

The Impact of Surveillance on Public Spaces

10:40 to 14:01

Discussion on the implications of surveillance cameras in public environments.

“But the intersection, I could see the name of one street, and I could see Big O tires.”

Experiencing Surveillance Through Flock Cameras

14:01 to 16:58

The hosts discuss the unsettling experience of viewing footage from Flock cameras in public spaces.

“there stopped on his phone watching footage of himself with he's been recording rollerblading I was just like, this is like so...”

Geolocating Flock Cameras

16:59 to 19:26

The discussion shifts to the process and implications of driving to confirm Flock camera locations.

“I could sort of figure out how they were situated.”

Understanding Flock's Surveillance Network

19:27 to 21:04

The hosts explain how Flock aims to create a comprehensive surveillance system for cities.

“But basically like the footage from these cameras, at least as Flock presents it to police, can be streamed directly to something called Flock OS, which you've written about.”
Show all 22 chapters

Flock's Response and Potential Risks

21:05 to 23:00

A discussion on Flock's response to surveillance misconfigurations and associated risks.

“I guess, just to round it out, what did Flux say when you approached them for comment about this misconfiguration?”

Facial Recognition and Public Surveillance

23:01 to 24:12

The hosts examine the implications of facial recognition technology in conjunction with Flock cameras.

“to clarify, Flock itself does not have facial recognition that they've said repeatedly, like, we don't have that capability.”

Facial Recognition and Public Surveillance

25:01 to 25:32

The hosts examine the implications of facial recognition technology in conjunction with Flock cameras.

“When you need to build up your team to handle the growing chaos at work, use Indeed Sponsored Jobs.”

Recapping Major Stories of the Year

25:33 to 28:00

The hosts discuss major stories from the past year, analyzing their impact and relevance.

“This is a job for Indeed sponsored jobs.”

Elon Musk's Financial Claims and Website Failures

28:00 to 30:20

Explore the claims made by Elon Musk regarding financial savings and the subsequent website issues that arose.

“And it actually wasn't a lot of money, but Elon Musk was saying that it was a lot of money.”

TeleMessage Hack and Government Oversight

30:20 to 33:19

Learn about the TeleMessage app used by the government and the implications of its security breach.

“It was emblematic of the damage they were doing.”

The T App: Data Leaks and User Safety

33:19 to 35:35

Discuss the T app's data leak incidents and their impact on user safety and privacy.

“Senator Ron Wyden sent a letter to the DOJ about it.”

Origins and Controversies of the T App

35:35 to 42:06

Uncover the background of the T app and the controversy surrounding its creation and marketing tactics.

“What is T, first of all, and what was the first hack?”

The Rise of the T App and Shady Practices

42:06 to 45:22

Learn about the unethical tactics used by the T app to poach users.

“It's just one that was well-organized and caught on.”

Surveillance Tech and Its Implications

45:23 to 51:36

Understand how accessible surveillance technology affects individuals and communities.

“And I'm sure that will come up next year also.”

Transition to Subscriber Content

51:37 to 52:21

Hear about the upcoming subscriber-only segment and its benefits.

“yeah I mean I don't want to think about the new year just yet me neither I just want to think about the next two weeks Yeah, we will be doing that.”

Transition to Subscriber Content

52:24 to 52:34

Hear about the upcoming subscriber-only segment and its benefits.

“You'll get unlimited access to our articles and an ad-free version of this podcast.”
Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:03Hello, welcome to the 404 Media podcast where we bring you unparalleled access to hidden worlds both online and IRL. 404 Media is a journalist founded company and needs your support to subscribe. Go to 404media.co. As well as bonus content every single week, subscribers also get access to additional episodes where we respond to their best comments. in access to that content at 404media.co. I'm your host, Joseph. And with me are the other 404 Media co-founders. The first being Sam Cole. Hello. Emmanuel Mayberg. Hey. And Jason Kebler. What's up? All right. Before we get into our last podcast of the year, I mean, there are still going to be podcasts on the feed.

0:50We'll explain in posts on the site, that sort of thing. Jason, we're doing a gift subscription thing for the next few days as a potential last minute Christmas or holiday gift. Can you just explain what the deal is then? Yeah, 25 % off of gift subscriptions. I don't have the link in front of me, which is not helpful. Well, I put it in the show notes. It's in the show notes. Yeah, so that's pretty much it. It's last minute Christmas slash holiday gifts, or I think you can give it to yourself if you want, if you want to be clever. But yeah, do that, please. I didn't realize you could do that. So if it's like, well, maybe I don't.

1:34You can be like a gift from Joseph to Joseph. I see. Yeah. I mean, I think you may need two different email addresses. I'm not exactly sure how it works because it uses a third party system because Ghost doesn't have gift subscriptions native, but it does work. We've been using it for a long time. Yeah. So if you want to take advantage of that, scroll down in the show notes, copy that link, click that link, whatever, and you'll be able to get a GIF for a loved one or yourself if you really feel like it. We're going to do the first segment about a story we just published as normal. Then the second section is going to be more of a year in review, some of our biggest and best and favorite stories and that sort of thing.

2:18So this first story, Jason, this is one you worked on with Sam as well, who did some additional reporting. The headline was Flock exposed. It's AI powered cameras to the internet. We tracked ourselves. A lot of fun stuff going on here. A lot of insight into Flock and how it does track people, not just license plates. And there's a bit of misunderstanding and miscommunication about that. But this starts with a tip that you got. What was that tip and who gave it to you? Yeah, so the YouTuber Ben Jordan, who has done some really amazing research and reporting into Flock, discovered this essentially.

3:04And he published a YouTube video about this earlier this week. Some of my reporting is in that YouTube video. And then I spoke to him for this story. but essentially, and I encourage you to check it out if you haven't seen it already, although the video has many, many views, so maybe you have seen it already. It's very good. But basically, Ben Jordan discovered that at least 60 Condor cameras were streaming directly to the internet. And Condor cameras are Phlox pan-tilt-zoom cameras. They're called PTZ cameras. and what pan, tilt, zoom means is kind of in the name, but they are surveillance cameras that can move and track people.

3:51And so they can pan, they can go left to right, they can go up and down, and they can zoom in on specific subjects. And they're different to the normal license plate reader cameras that everybody knows Flock for. It's like a variation of their camera. Yeah, so Flock has a few different types of cameras. It has a few different types of automated license plate reader cameras. Its main one is called Falcon, and those are ALPR cameras. And what those do is they are specifically targeted at license plates. They take photos for the most part of cars as they drive by, whereas these Condor cameras are recording 24-7, 365, and they're recording video.

4:40and their vantage point for the most part is a lot wider than a Falcon ALPR camera. So they're capturing like an entire scene, whereas an ALPR camera is largely just capturing like cars as they drive by. I say largely because, you know, they are taking footage and photos. And so, you know, you can see other things on the other types of cameras and you can sometimes see license plates on the Condor cameras. And it's part of this holistic flock surveillance ecosystem. So what Ben Jordan found was 60 of these exposed directly to the internet. What I mean by that is you just need an IP address. It was not HTTPS.

5:26They were all HTTP, which I think is an important distinction just in terms of the actual URL. and if you clicked it, you went to a Flock administrative portal and on that portal you could see live footage that was being filmed and streamed live, obviously. You could see 31 days of archived footage and download that footage. You could grab different clips. It was possible to change settings on these. You could see information about the cameras, like what type of camera it was, what software it was running. You could see logs, so access logs, things like uptime and downtime. Some of them would be knocked off the internet and then they would be back on later that day.

6:23And there would be a history of that, more or less. and then also you know you could the big thing was that the footage was there and all without a password as you say it's not like there was some vulnerability in the admin panel that was then exploited and hacked inside like this is not hacking this is just a panel completely exposed to the wider internet you just visit it and it's like damn I'm now looking through a flock camera. Yeah, you click a link and it's like you immediately see the footage and or you see the administrative panel from which you can click another link to get to the footage.

7:07But there was no login, no password, no, none of that, which suggests a huge misconfiguration because this is not supposed to happen. And the way that Ben Jordan and John Gaines, who goes by Gainsec, he's a security researcher who found some vulnerabilities that Ben Jordan previously worked on. The way that he found these was through a commercial search engine called Shodan. And it is essentially an Internet of Things search engine that has led to a lot of different stories that we've written over the years because security researchers use it to find Internet of Things devices that are streaming directly to the internet.

7:56So off the top of my head, in the past, people have found smart billboards that have been streaming to the internet without an admin password. And so you can go in and you can change what the billboard says or the image that it displays. Sometimes you see road signs, like automated road signs that they put up in work zones. And people often hack those. And sometimes they find them through Shodan. And they either have no password or they have a password that's like admin, admin. And you can then change what they say. You're able to basically search for very particular devices because you can search by show me all of the servers or devices that have a certain port open.

8:43And if there is something particularly unique about the products you're looking at, oh, maybe they have a weird port open that's only specific to that sort of service. You can sort of identify them. I don't know how the pair here identified these ones, but presumably they found some sort of like fingerprint of flock cameras and then just searched Shodan for that. I mean, I think you could probably even search showdown for flock safety.com, but their domains or something like that, very similar to census as well, which basically does the same thing. Yeah, I think it was a mix of those few things because I know that some of them were, you could just type in flock and they showed up.

9:25I do know that, but then there was like, they iterated and they were able to find more just by doing like better searches. Let me talk about what we did. So we see this footage that's streaming to the internet and we try to discover like, where are these cameras located? Because all of them had IP addresses that gave us like a general geographic location, but it was still a very wide margin for where something would be. For example, the cameras that I ended up going to see were in Bakersfield, California, which is about two hours north of LA with no traffic, which I got lucky and I went up and I saw them.

10:11But their IP addresses matched to Sacramento, which is six hours north of LA. How did you figure that out? Because that's a big discrepancy. Yeah. I mean, so I played GeoGuessr. I played the GeoGuessr guy, basically. And so, for example, one of the ones that I found was at this Big O tire shop. It wasn't owned by a Big O tires, like it was on a traffic light. But the intersection, I could see the name of one street, and I could see Big O tires. And so I just used Google Maps and a lot of searching. And luckily, there was a timestamp of the footage in the top left corner of all this. I could see the time zone that things were in because like, bizarrely for some of these, like some of the businesses would match or like the street names would match, but they would be in like different random cities across the country.

11:14and then I could sort of like figure things out via time zone. And then I used street view and I clicked around a lot through street view. Sam also did a lot of this for us, which was like extremely helpful. And she can talk a little bit more about what she saw, but we were like clicking through a lot of these. There were about 60 of them. Again, I think we were able to geolocate about maybe 10. The others were just super nondescript. So they would be filming a parking lot at an apartment complex where there was no visible street signs or businesses or anything. There was one at a skate park. There was one at a playground where children were playing, which was really quite alarming that this was there.

12:04And then I think the craziest one for me was the Peachtree Creek Greenway in Brookhaven, Georgia, which is a suburb of Atlanta. And there were at least three exposed cameras there. and like one these cameras zoom in on people who are walking by so there was a woman walking her dog and it just like zoomed in on her as she was you know walking the dog and then it would follow her around and then i don't know sam do you want to talk about the rollerblader yeah yeah this was a really crazy um camera feed to look at because like again this these cameras are not looking at cars specifically in a lot of cases, they're looking for people and there were no cars in this park, obviously.

12:56So like these cameras are put here to watch people. But this guy, we were able to watch him rollerblading up and down this one path. So you can click on one feed, see him come into view. The camera zooms in on him, watches him rollerblade away, like with a friend sometimes. And then you can click on another feed and watch him coming through a different part of the park in almost real time um and his friend drops off eventually um and then we did this for a while we just watched him like go around the park and obviously he has no idea these cameras are here but he rollerblades up at one point and the camera zooms in on his face and then he passes a woman it zooms in on her face and she kind of turns around and looks she's on the phone she's like turns around like kind of seems like she's saying to her friend like this dude just rollerbladed past me really fast um and then he comes up to the camera where the camera the pole that the camera is on stops directly underneath the camera and the camera has followed him all the way to that point and now it's looking directly down at the ground where he's standing like zooming in on his face and his phone and he's standing there stopped on his phone watching footage of himself with he's been recording rollerblading I was just like, this is like so...

14:16Yeah, that's how clear it is. Like you can see... I mean, this camera is probably like nine feet off the ground or something. It's not that high, but it zooms all the way down on his face and then you can see him holding his camera or holding his phone and he's watching like replays of himself. Obviously, he's like recording content or something or like watching his own form or something. But it's just so... It was so bizarre because like we write about this stuff all the time And we understand that these cameras are everywhere and knowing that they're everywhere and going about your day and not thinking really that much about them, but being like intellectually aware that they're everywhere and you're being watched is one thing.

14:53But then being able to look at the view from the camera, from the point of view of the flock camera, watching everyone in this park very closely all day long is such a different experience. And you're like, whoa, these people have no idea that these cameras are here or that they're being watched. It's just a really strange feeling. Yeah. So you were watching that footage of sort of these random people. And obviously, we didn't publish any identifying information about these random passes by. But as you said, Jason, you then with Sam's help geolocated some. You drove to a couple. and the benefit of that, I suppose, was, well, to confirm their Flock cameras, I mean, we already knew it because Flock is like in the configuration information, but you can look at it and go, well, that's a Flock Condor camera or whatever.

15:47They are very, very distinct looking branding wise. And then also, of course, it's just in the same sort of way we do some of our pieces where like, I've bought phone location data from a bounty hunter, blah, blah, blah. But it's just there's something about putting yourself and almost testing it yourself. And maybe that gets it across to the reader in a more tangible way. Was that the benefit of doing this? Because you didn't have to drive two hours. It's very good you did. I definitely didn't have to. I'm very glad that I did for the reason that you said. One, I knew exactly what I was doing because I had watched that footage already of that intersection.

16:30But then it was quite weird and sort of affecting to myself to drive to that corner, see the camera that I had been watching online, get out of the car and walk into the intersection, and then see myself show up on the feed, which is obviously what would happen. And yet, for some reason, it made it feel a lot more real to me. and then I was also just able to I was able to watch myself on the feed Sam was watching the feed as well and so she saw me and texted me and was like here's you she took a screenshot and sent me a screenshot of myself walking in the middle of the street in random Bakersfield Sam sitting 3 ,000 miles away and then I also could see the cameras so I was able to just make sure that it was flat cameras.

17:29I could sort of figure out how they were situated. In this case, it's like the camera's really high off the ground, like at the very top of the pole. I don't think anyone would notice it. It's very... It's not hidden by any stretch, but it's like 40 feet off the ground. And if you're driving or walking by, unless you're just staring up into the sky, you're not going to see it. And then another notable thing is that it was outside of a mall, outside of a Macy's, was one of the corners of the intersection. And they had a bunch of Flock ALPR cameras, the Falcon cameras at the entrance to this mall.

18:09And so it does sort of, it showed me that it's like part of a more holistic surveillance situation, like in this area. And then I went from that one, I drove five minutes and I found another one. And, you know, I only know of two that were exposed in Bakersfield, but Bakersfield has like dozens and dozens of these cameras. The other thing that I would say is that I then went and did more reporting. I pulled contracts about these cameras. I watched a Flock webinar that they gave to police introducing these cameras a few years ago. and I do think that our work over the last year has been really important as has the work of a lot of other journalists in sort of explaining how Flock works and how pervasive it is.

19:02But our work has almost entirely focused on its automated license plate reader cameras, which again is the dominant product that Flock sells. But it's very clear that this company wants to be a lot more and they want to be a holistic surveillance system for American cities that is networked in all the ways that we've talked about before. But basically like the footage from these cameras, at least as Flock presents it to police, can be streamed directly to something called Flock OS, which you've written about. And it's basically like a police operating system for all of their Flock cameras. And you can also sometimes put other devices in there as well.

19:47Brain cameras now, recently? And so if you're a cop sitting in a command center or whatever, you can pull up these cameras and their footage, and you can control the cameras. You can pan, tilt, zoom them. They can also be automated. So last year, they introduced AI that automatically tracks people. we have no idea whether these cameras that we saw were being operated manually or whether the AI was operating them it's just like we have no way of knowing but they were a lot of them were zooming in on people but anyways in this webinar they were like well if you have an ALPR hit like if you have a license plate hit you can then just pull up the surveillance camera and then you can like click from camera to camera to camera and you can operate them and all of this and it just sort of shows that flock again is not just tracking cars it is tracking people pedestrians um and then of course by tracking cars it's tracking the people who are in the cars but um it's it's just like they have a much bigger surveillance network than i think most people realize.

21:05Yeah. I guess, just to round it out, what did Flux say when you approached them for comment about this misconfiguration? Well, I asked them a lot of questions about how this happened, and they just sent a very short statement in which they said this was a misconfiguration that affected a small number of cameras. They didn't say what the misconfiguration was or how many cameras it ultimately affected. And they said that it has been fixed, which it has been fixed, um thankfully yeah um and yeah i mentioned this at the top but um the youtube video by ben jordan is really good on this um you know he he made it um and sort of like took i i gave him some of my footage because um like he was a he was a researcher on this story for him and he found the initial thing.

22:01And so I was like, well, I'm going to go check it out and I'll let you know. But he showed some of the stuff that is possible with this type of footage. We didn't do this because, I don't know, it just seemed, we didn't want to do it. But I think it's good that he did, which is like he used facial recognition on some of the footage that he saw and he was able to determine who individual people were. And then he did open source intelligence on some of them and learned a lot about people who were at different sites who were on these cameras. And of course, he anonymized it and he changed some details and that sort of thing.

22:45But he basically showed with this footage streaming insecurely, you can learn a lot about a person depending on what they're doing. and I thought that that was pretty shocking. Yeah, just to be clear, to clarify, Flock itself does not have facial recognition that they've said repeatedly, like, we don't have that capability. Maybe that changes in the future, I don't know. But right now, they don't do that. I guess what he did is kind of similar to what those students did, where they took those metal Ray-Bans, which at the time didn't have facial recognition in them either, but sort of glued that on.

23:25But yeah, the footage is incredibly crisp and very, very detailed. And I can imagine it'd be very, very easy to identify people in that footage. Yeah, he ran it through a third-party facial recognition system. Like PimEyes or something, probably. I assume PimEyes. I'm not sure which one. But yeah, he threw a non-Flock related one, but took the footage itself, exported it, put it through a different system. And then using Google and social media and all that, once you knew it, it's like, oh, this is what this person was actually doing at the Lowe's parking lot. Or this is what the person was doing at this Christmas market where another camera was.

24:09It's pretty crazy. All right. We'll leave that there. When we come back after the break, we're going to run through some of our major stories of the past year. We'll be right back after this.

24:53We'll be right back. and a year of Xbox Game Pass Ultimate with a custom color Xbox wireless controller. Learn more at windows.com slash student offer. While supplies last, ends June 30th. Terms at aka.ms slash college PC. When you need to build up your team to handle the growing chaos at work, use Indeed Sponsored Jobs. It gives your job post the boost it needs to be seen and helps reach people with the right skills, certifications, and more. Spend less time searching and more time actually interviewing candidates who check all your boxes. Listeners of this show will get a$75 sponsored job credit at Indeed.com slash podcast.

25:28That's Indeed.com slash podcast. Terms and conditions apply. Need a hiring hero? This is a job for Indeed sponsored jobs.

25:47All right, and we are back. I don't really have headlines for this one. Sam, you've written sort of preemptively, is it this Friday? Next Friday? Like a sort of year in review. Two Fridays from now. Two Fridays. I'm kind of already losing all sense of time. But you've done something, you've written something that kind of looks back over the year. How did you pick out these stories? They just jumped out to you? Or these were the ones that most people read? No, these are... So in lieu of the usual weekly roundup on January 2nd, because we'll all be out and not like publishing heavily that week. I put together just like a roundup instead of the weekly roundup.

26:28It's just a yearly roundup. It's pretty short, but it'll hold you over if you're in need of the roundup that day. But I looked at just like analytics for the site, like top stories that we have traffic wise for the last year. And then also just like, because a lot of the top stories are kind of like one-off, like not really part of a bigger beat, but people they went viral for whatever reason um but then um there were quite a few stories that were like part of like a consistent beat that all together make it like the most important or like most impactful beats um of of the year for that specific topic so that's kind of the the thinking for that it's a mix of like here's some stuff that people really liked to click on this year which we can go over.

27:21But then there are just like bigger, broader topics that all together kind of make up something that really resonated with people. Yeah, let's run through some of these. The first one is the Doge website, which I think anybody could push data to it or emojis or whatever they wanted, really. Jason, I think this is one you wrote. People were very interested in this Because I mean, this is way back when Doge... Doge was the news every day, like earlier in the year. Yeah, and I mean, for good reason. And I think that the damage that Doge did to our federal government and programs, obviously like USAID and NIH, etc., like cannot be overstated.

28:06But yeah, there was basically like a few days early in the year, if I'm remembering correctly, so much has happened this year, where Elon Musk was tweeting that Doge was saving all this money and it was saving billions of dollars, I assume. It was a lot of money. And it actually wasn't a lot of money, but Elon Musk was saying that it was a lot of money. Let me be clear. And so they were saying, we've killed all these programs. Also, we're super transparent. They weren't being transparent. And so they were like, we're making a website where we are going to explain everything that we've done and how much money it's saved and blah, blah, blah.

28:50And so they slapped together this really shitty website that I believe was being run on a WordPress that was not fully hosted on government servers because they spun it up so quickly. And not only did it first have a weird templatized thing that they put up publicly, that was one of the stories that we did. And when it did finally go truly live, the database that they were using was vulnerable to an SQL injection, I believe, like a SQL injection. And so it was a very rudimentary type of... Basically, in a very simple way for people who know what they're doing, they could add and delete things from this website.

29:39Or specifically, they could add to it. And so people were like adding their own projects that they had cut more or less. And so some of the hackers like sent us the entries that they had pushed onto the live site that said like rude things about Elon Musk. And we wrote about that. And it was during a period where there was such intense interest in this that it was like very viral story for us. I mean, it was a very bad situation altogether, but compared to the actual damage that the government was doing, this was largely just a really shoddy website configuration situation. It was emblematic of the damage they were doing.

30:25Yeah. Reminds me of the Epstein files dump, just in terms of how shoddy and things were showing up and they were disappearing and they're showing up again. Failed redactions. Yeah. We don't need to get into all of that, but we've all been looking into that in various ways. The redaction one is really funny. The second one was the telemessage hack. This is one I did. I worked with Micah Lee, the security researcher and journalist on this as well. Basically, there was a photo where a Trump administration official was using something that looked like Signal. And of course, coming after SignalGate, where the Atlantic Editor-in-Chief was accidentally added to a group chat with Yemen strike plans.

31:17Signal was very, very hot at the moment then. So I zoom in onto the photo and find out that's not Signal. That's something else. I can't remember exactly what it was, but I think it was definitely something in the UI. It's like, that is not quite Signal. I look around and it's this Signal clone from a company called TeleMessage. And the idea is that it claims to be able to provide the protection of Signal, which it doesn't, to be clear, but they say that, while also archiving messages for compliance or regulatory reasons or legal issues or whatever. Lots of these products exist. I remember Wicca is sort of this, it was a consumer end-to-end messaging app.

Read the full transcript

31:55They shut down after it was being used by child abusers way too much. An NBC News reported on that. I think we did a little bit as well. But they had a product where Customs and Border Protection, for instance, could use that app and then also archive the messages for later. Anyway, TeleMessage is one of those. We've reported that, Hey, look, the government is using this particular tool, which I'd never heard of. You go on YouTube and at the time it had like a couple hundred views. It seemed like a very, very small shop and operation. I mean, it was actually owned by a larger company, but the app itself didn't seem to be that well known.

32:33Then very shortly after it was hacked, sent a bunch of information, including data on CPP officials to verify it. I'm just going through the phone numbers of these officials and calling them and asking, hey, is that blah, blah, blah from CPP? They say yes. I'm like, I'm a journalist and there's been a breach. And usually they hang up at that point. And one definitely did do that. But we verified the data, published that. And then it was like 24 or 48 hours later, very soon after, another hacker got in and apparently got more data and NBC reported that. And obviously this was a massive security failure.

33:16The hackers managed to get a bunch more data about other government agencies. Senator Ron Wyden sent a letter to the DOJ about it. Honestly, I kind of almost forgot about the story because it has been such a crazy year. And I think people might sort of conflate it with SignalGate. I mean, they are related, but I imagine people may even forget about this hack as well because, I mean, SignalGate was so significant when we were sharing those Yemen attack plans. But yeah, that went crazy. I mean, what they have in common is that it just shows how people in high up at the administration just don't understand how Signal works.

34:01They don't take... It's only as secure as any of the endpoints. And it's just like they're super reckless about it. Including up to the point that it's just like they didn't vet this offshoot, this fork of Signal. all. I remember while it was happening, I had a lot of sources. Well, not sources. I'll say tipsters reaching out. They were sending me alleged photos from a security conference. It was happening at the same time. And I didn't write this up in an article at the time. But it was pretty interesting that TeleMessage was being... Or rather, I think it was Smash, the parent company. They were at a security conference displaying the product.

34:43And they has some sort of tagline about, oh, we're the most secure messaging product or something along those lines. And then someone took a photo. Then the day later, that had actually been taken off the stall because then we broke news of the hack. So I don't know. I thought that was pretty funny. And I'm just looking through contracts now which mention telemessage. There's one from September 22nd, 2025 with some agency. And then there's one September 11th with another agency there. So the government's still using this tool. They haven't got rid of it. So who knows? Maybe we'll see another hack in the future.

35:25Speaking of hacks, Emmanuel, you wrote a lot about T. It started with a hack, then another hack, and then your broader story. Just walk us through that. What is T, first of all, and what was the first hack? Yeah, so I would say that T's story begins in the media before we actually step into it. And that is back in July, I believe. Sometime during the summer, T shot up in the App Store ranking. And T is an app where women could log in and share information about men that they dated or want to date. And other women would chime in and share what we call red flags or green flags. Saying, oh, this man is someone you shouldn't date because he cheated.

36:27or sometimes more severe accusations like he was physically abusive, sometimes relatively benign things like he's rude, he ghosted, things like that. And that became very popular. It got some coverage in the news with the framing that this was a way for women to come together and fight back against men who are nasty that a lot of women run into on the dating apps. and I think this was on July 25. I woke up in the morning and I got a frenzied call from basically a good Samaritan who said that all the data from the T app, namely the selfies and photos of IDs IDs that women uploaded to the app in order to verify that they are actually women, which was like one of the selling points of the app, were being leaked on 4chan.

37:48And this person had tried reporting it to T, he tried reporting it to Google, which is where all this data was leaking from. There's this thing called Google Firebase, which is a platform where you can kind of deploy your mobile app and that was misconfigured and allowed anyone to dig through its data. And I think, Joe, at that point, I got in touch with you and we started to write that up. You sent me a frenzies text. Yeah, I was like, oh, this seems actually like... Because we get a lot of tips about leaks and sometimes they're from cybersecurity companies, sometimes they're just from people who know this stuff.

38:24But it's like, this one seemed really bad. And I think we both recognize that because of the intimate nature of the data. Like a lot of the time, it's text and addresses and emails and you have to sort through it. But we kind of took like one look and we were like, Okay, well, here's thousands of images of women's faces and their IDs. And we were like, Okay, well, this seems bad. Let's verify it. But it was also the 4chan connection. Right. And the 4chan... It wasn't just that the data leaked. It leaked with malicious intent, right? These guys on 4chan, the framing in the media was this was a way for women to fight back against bad men.

39:03And then the misogynist community on 4chan was like, fuck that. And we're going to fight back against that and really embarrass and make these women's life hell. We had some interesting, very quick methods for verifying that the hack was real. and we published about that. And that was a huge story. I think that was the most clicked-on thing that I published this year. With the exception of... There was an Alibaba AI video model that was released. And I noticed it was immediately turned into a porn-producing machine. And I wrote that in five minutes. And I think that maybe got a little bit more.

39:50But anyway... That's just how it is sometimes. Yeah. But we wrote that up. And I think that was a big enough story as is. But then things got much worse. Amazingly, as bad as that was, the more we reported on it, the worse the story got. And there's two big beats there. One is we immediately find out that there was another vulnerability. And we had good reason to believe that people took advantage of it. And this one was a leak of the direct messages that women were sending each other on the app and discussing extremely personal, extremely volatile things about each other, about things that happened to them, about accusations about men that they've been with.

40:43Personal data, phone numbers. Personal data, phone numbers, addresses. is like really, really like terrible hack just because of how specific the data is and also the context of the conversations there. You know, because of the subject of the app and what women are there to talk about is not the kind of thing you want leaked. Especially since the app is advertising itself. It's like, this is a safe space for you to discuss these things. So we wrote about that. And then a lot of people came out of the woodwork to tell me about the origin of the T-app, like how this whole thing got started and who was behind it.

41:24And the short version there is that there's this practice online that is most popular on Facebook. But there's one group in particular called Are We Dating the Same Guy that Sam had covered previously, which does basically the exact thing that the tea app does only it's on facebook and it's free and it's like a grassroots community managed uh thing and it came a it came a long time before yeah it came years before and the person behind that paula sanchez would say uh who i talked to for the story would say you know this is currently like the biggest one but she would admit that She's not the first person to do it.

42:12It's just one that was well-organized and caught on. And basically, the guy who founded T, Sean Cook, he essentially stole that idea, tried to recruit Paolo Sanchez, who is the founder of Are We Dating? The same guy, to be the face of the app. And once she made it clear that she is not going to do that, He essentially just started poaching her audience and her community by false advertising and trying to blur the lines between what is the Are We Dating the Same Guy community on Facebook and what is the T app. By making these fake groups, it's fake, fair to say. Fake Facebook profiles and just jumping into every conversation and telling women to join the T app because they'll find information about the man that they're asking about there, whether that was true or not.

43:11And just a lot of shady practices, which I know now by like... Because I've continued to talk to people about this story and people are still reaching out about it. And I am working on like a longer term follow up to something about T. And I know for a fact now that this is something that worked and it did confuse people in the Are We Dating the Same Guy community and cause them to join T. And then that resulted in their information being leaked. And I guess the other thing about this story that I think we will continue to report on in some fashion is that it touches on something that we've all written about at some point.

44:02Joe, the thing that always comes to mind is the story that you wrote about this account on TikTok that was doxing people randomly and using Pymize. Pymize or Pymize? Pymize. That we talked about on this podcast that it's like a facial recognition thing that anyone can pay for and use online to find people. We're just in this point with surveillance tech and how accessible it is and how knowledgeable the average person is about how it works and how to use and how to access it that anyone can docks anyone and anyone can find anyone and that's just created a new normal online that we i don't think fully adapted to yet uh and that that is just like i think a core component of the story.

44:57It's like, you have these women coming together for good reason. They want to share information.

45:06In doing so, they're using all the surveillance tech online. And then that backfires and that's used against them. And it's really, really messy, I guess, in a new and upsetting way. And I'm sure that will come up next year also. Yeah, I think that's a very, very good takeaway. We live in a very, very strange world when it comes to surveillance by ordinary people who think it's a good thing to just amask strangers for seemingly no reason and all that sort of stuff. Sam, to round us out, we touched on this, I think, a couple of episodes ago, but you've been doing a ton on the age verification laws, which now cover half of the United States.

45:53I mean, also people uploading their IDs or at least potentially in some cases, right? What's sort of been your takeaway this year after doing that coverage for the past year? Yeah, so the first story that I wrote on the first of the year, last year, was that Pornhub was now blocked in almost all of the US South. and that comprised 17 states at the time. And then when you look at a map, it's just like the entire south of the United States was not able to go to Pornhub without a VPN. Let me put it that way, I guess, because Pornhub had blocked access in all these states that have age verification legislation in place.

46:44This all started a long time ago, obviously, as these things do. But as far as legislation getting passed, It started about two years ago where Louisiana passed the first law to require platforms, specifically porn platforms and adult platforms that contain more than a third. God, what's the word they use? I don't even think that they say obscenity. They say harmful material. Objectional or something? It's material harmful to minors, I think, in most of the laws. But they do vary. It's like there's a different word for this, depending on what state you're in a lot of times, but, you know, quote unquote, material harmful to minors, and then they define material harmful to minors as porn.

47:31And then in some states, material harmful to minors is also like queer content, content with trans people in it, stuff like that. So this has been something that I've been following since then and since a little bit before then with the passage of these laws. And this year, as of a couple weeks ago, we're now looking at about half of the United States is we just passed the halfway mark is under age verification law. So that means that in most of these states, not every state, but in most of the states, Pornhub has decided to not service those states. You can't access them. You hit a wall. You see Sheritaville giving a very eloquent speech about why they're not.

48:14Sherry Deville is a porn performer, about why they're complying with the law by shutting down access to their site. Because Pornhub has the stance that the laws are censorship. This is also our stance, just to be clear. Censorship, chilling effect on adult speech, and is also privacy risky. There's implications for users' privacy when you're collecting something like licenses and IDs and passports in some cases and, you know, like biometric data and things like that that are required by the law. So most people have gone around this by using VPNs and now VPNs are up for debate. There's pushes here and there by people in power to oppose or even make VPNs illegal.

49:16I mean, there's nothing like actually in the books about this yet because it would be crazy. But obviously, crazier things are happening. How on earth would they do that? I mean, maybe it's not clear yet, but is it like we're going to tell the app stores you can't sell or deliver a VPN app in XYZ state? Like, has that even worked? I mean, it's like it wouldn't work. Like, the only way that it would work, it would be to crush a lot of the actual good uses of VPNs that lots of people and companies use VPNs for. So I don't know. It's like I'm not rolling that out. but it would be a big deal if that happened.

49:58There are places where I think the law is that, and I don't know if this is past law yet or if it's still kind of in the stage of moving through toward being enacted legislation, but adult sites might not be able to recommend VPNs, which is something that, you know, is what some sites are getting around this with. They're saying, you know, use a VPN to access our content. Yeah, it's something that I've been following for a long time and it starts to feel very incremental. And like we're repeating ourselves over and over when we report on this stuff. But every time I write about something like this passing in a new state, like, you know, we write a blog about how it passed in Mississippi, passed in Wyoming, passed in South Dakota.

50:48separately every time it happens. And I'm like, God, I'm repeating myself over and over. But then someone will reply and say, I didn't know that my state was one of these states. I didn't know I was in a state where this was happening, which I think is like a big deal. I think you should know what the law is in your state in order to decide whether or not you oppose it. So yeah, it's something that we're going to keep covering, obviously. it's a huge part of a huge part of the internet and being able to access it is being able to access it freely for adults and now especially we have increasing pressure on totally repealing and disbandling section 230 which is definitely all related so we're going to be following that into the new year as well yeah I mean I don't want to think about the new year just yet me neither I just want to think about the next two weeks Yeah, we will be doing that.

51:48All right. We'll leave that there. If you're listening to the free version of the podcast, I'll now play us out. But if you are a paying 404 Media subscriber, we can talk about a bunch of our fun recommendations. Well, mine is fun. I haven't actually looked at your others because I want to be surprised for the next segment. But I'm going to say they're fun. You can subscribe and gain access to that content at 404media.co. As a reminder, 404 Media is journalist founded and supported by subscribers. If you wish to subscribe to 404 Media and directly support our work, please go to 404media.co. You'll get unlimited access to our articles and an ad-free version of this podcast.

52:29You'll also get to listen to the subscribers only section where we talk about a bonus story each week. This podcast is made in partnership with Kaleidoscope. Another way to support us is by leaving a five-star rating and review for the podcast. That stuff really helps us out. This has been For a Full Media. We'll see you again next time. Maybe not next week.

53:11your skin. The sun is relentless, but so is our gear. Level up your summer at Columbia.com to spend more time outside and less time slathering on aloe lotion. You're welcome. Columbia, engineered for whatever.

From the publisher

We start this week with Jason’s story about Flock exposing a bunch of AI-powered cameras. These cameras zoom in on people as they walk by, sometimes so closely you can read what’s on their phone screen. After the break, we talk about some of our biggest stories this year. In the subscribers-only section, we give some of our personal recommendations of games, other reporting, or just a more chill life.

Timestamps:0:00 - Intro00:54 -  Gift a 404 Media subscription2:27 - Flock Exposed Its AI-Powered Cameras to the Internet. We Tracked Ourselves26:34 -  Anyone Can Push Updates to the DOGE.gov Website29:52 -  Mike Waltz Accidentally Reveals Obscure App the Government Is Using to Archive Signal Messages34:29 -  How Tea’s Founder Convinced Millions of Women to Spill Their Secrets, Then Exposed Them to the World44:59 -  Half of the US Now Requires You to Upload Your ID or Scan Your Face to Watch Porn

YouTube Version: https://youtu.be/DrGVGphD2L0

Subscribe at 404media.co for bonus content.
Learn more about your ad choices. Visit megaphone.fm/adchoices

More from The 404 Media Podcast

All 164 episodes
We Tracked Ourselves with Exposed Flock CamerasThe 404 Media Podcast · 54 min
Listen in VO