Smashing Security Smashing Security

Vibe-coded shops, and hackable Flock cameras

Sep 23, 2026 · 40m

Summary

In this episode, Graham Cluley and Dave Bittner discuss a New Zealand convenience store that accidentally left its Base44-built website open to public editing, leading to chaotic listings like national parks and Princess Diana plates. They also examine the security flaws in Flock safety cameras, which run outdated Android software and contain hardcoded API keys that allow attackers to impersonate devices and access backend data. The hosts conclude with their picks of the week: a website mapping every filming location from the movie La La Land and a BBC documentary about British pianist Miss…

Topics discussed

Intro: Amazon used condoms glitch Welcome, guest intro, and moving house update Episode preview: Vibe coding and Flock cameras Sponsor: Vanta trust management platform Crusty socks banter and the NZ store incident Vibe coding with Base44 and security risks Public hacking of the NZ store listings Store owner's failed security attempts Base44 history and AI website builder risks Aftermath: Traffic spike and marketing stunts Sponsor: Origin AI agent observability Flock Safety cameras: Overview and privacy concerns Steganogram hack: Physical theft and file system leak Vulnerabilities: Android 8, hardcoded API keys Exploiting the API key and GPS data Flock response and police misuse allegations Discussion on surveillance trade-offs Sponsor: ThreatLocker agentic AI defense Pick of the Week: La La Land filming locations Pick of the Week: Missy Mills and Abbey Road Outro, member shout-outs, and combat sports ad
Listen ad-free on Castria