# T010 — Condor Internet Exposure Competing Accounts 404 Media and Flock agree that some Condor/PTZ devices became publicly discoverable after a cellular-network configuration change, but sharply disagree about the number and what unauthenticated access allowed. The dispute is material to live-video, archived-video, device-control, and remediation claims. ## Statement A 404 Media reported that at least 60 Condor PTZ systems it examined exposed unauthenticated live streams, approximately 30 days of archive, and administrative functions (web research 2026-07-20, [404 Media report](../../web%20archive/2026-07-20/404media.co/flock-condor-camera-internet-exposure-2025-12-22.md)). The archived extract omits operational targeting details. ## Statement B Flock says a carrier moved a small number of PTZ cameras from a private IoT network to the public cellular network, briefly exposing a diagnostic interface. It denies cloud access, camera control, and recorded-video modification; says the carrier configuration was corrected; and says it added detection and interface authentication controls (vendor primary/self-description, [Flock cybersecurity response](../../web%20archive/2026-07-20/flocksafety.com/flock-safety-cybersecurity-how-we-protect-customer-community-data.md)). ## Why it matters The accounts imply materially different exposure and oversight consequences. If Statement A is accurate, public reach extended to live/archive/admin functions. If Statement B is complete, exposure was narrower and bounded to diagnostics. Neither account establishes that an Arkansas device was involved. ## Resolution status `open` — resolve with an independent incident report, carrier records, affected-device inventory, access logs, forensic scope, and a versioned remediation record. Vendor assurance alone and third-party observation alone do not settle the full scope. ## Discovery Surfaced during the 2026-07-20 dossier source audit after comparing the archived investigative report with Flock's March 27, 2026 response. ## Notes Technical discussion is publication-safe: exploitation steps, credentials, discovery queries, and precise device locations are not reproduced.