10 ms·
Detect and disconnect WiFi cameras
- ck2 11y agoExcept a $10 spare smartphone can be turned into a wifi camera very easily. So it only works if they are using one of those two off the shelf cameras.
- aaronem 11y agoSo says the script's own front matter, and it is at least better than nothing.
- lordnacho 11y agoThe smartphone can also be its own WiFi network that beams an IP camera's output to the owner. No way to stop that with this script.
- pavel_lishin 11y agoAre there any guides to doing this? We're about to have a baby, and don't want to drop a few hundred bucks on a baby video monitor system - I'd rather just ziptie a phone to the shelf above the crib.
- grahamburger 11y agoSearch either app store for 'baby monitor' and take your pick. I can't remember the name of the one we settled on when my son was born earlier this year but all of the ones I tried worked reasonably well.
- jonknee 11y agoThere are a lot of apps that do this. http://www.igeeksblog.com/iphone-apps-to-use-iphone-as-webcam/ http://www.igeeksblog.com/iphone-apps-to-use-iphone-as-webca... https://play.google.com/store/apps/details?id=com.pas.webcam&hl=en https://play.google.com/store/apps/details?id=com.pas.webcam...
- JabavuAdams 11y agoQ: Why do you want a baby monitor? We got one as a gift, but hardly used it. Of course both my kids are little Darth Shnorkulas. I just can't really think of a scenario where the monitor helps. I mean I've had those panicked moments where I'm like "Is my kid dead, and I've just been sitting here playing computer games?" But either get up and check, or just keep playing. They almost never die.
- DanBC 11y agoSome children sleep in rooms that have decent sound insulation, and the parents want to know if the child is awake and distressed. (You don't start sleep training a child who is under 6 months.)
- JabavuAdams 11y agoDon't worry, you'll know when they're awake and distressed. I tend to let kids cry for at least a minute before intervening, well, unless they're old enough to be asking for help. The alternative is madness and leads to divorce or murder-suicide. EDIT> Actually, I just made that number up. It's all context. My main warning / peeve is that our unrealistic standards of care as modern, educated, intelligent, self-improvement-minded parents actually leads to a shitty child-rearing experience that produces somewhat shitty children, rather than a more laissez-faire approach. Crying is like the weather. We don't always have to fix it.
- pavel_lishin 11y agoI agree with you, and hope I'll be strong enough as a parent to not always come running when my kid starts crying.
- DanBC 11y agoWhen the child is under 6 months you probably don't want to delay when the child is crying. Under 6 months they cry to communicate a need - they're hungry; they need changing; they're in pain; they're cold' they're lonely. Most people think it's a good idea to address those needs. Even the people who like sleep training think you probably shouldn't start when the child is under 6 months. There are a couple of people who think you can start sleep training under 6 months (Ferber; Gina Ford), but even Ferber sets a minimum age of 4 months. If you are going to go down the "cry it out" route you will want to carefully investigate the different systems. Some of them have been discredited as harmful and cruel. Ferberization (or Gina Ford, they're pretty similar) is about the harshest system that a modern parent could get away with, but you need to be aware that a lot of people hate this method.
- brbsix 11y agoNo need for a guide. I've done this several times and it's very simple. Assuming you have an Android, use the following app: IP Webcam https://play.google.com/store/apps/details?id=com.pas.webcam https://play.google.com/store/apps/details?id=com.pas.webcam It will be accessible on the local network via web browser (it starts a web server on the phone) or client app on another phone (e.g. tinyCam Monitor).
- lostlogin 11y agoI saw a great app that turned old iOS devices into baby monitors. It wasn't the one I link to below, but you get the idea. Another weird hack was to buy a pair of cheap phones with unlimited minutes or unlimited to one number on one of them. Dumb phones are best as the battery is better. Then just call the phone and leave the call running. Unlimited range as long as you have cell signal. Telcomes here in NZ got wise and limited the minutes of a call. Cloud Baby Monitor https://appsto.re/nz/N99Yz.i https://appsto.re/nz/N99Yz.i
- andersonmvd 11y agoOne easier way to detect (without jamming afterwards), for iOS at least, is to install the "Fing" app, connect to the wifi and scan the network. Then you will know the connected devices and their names. Chances are that cameras will have easy to recognize names on them. EDIT: you'll get the MAC address too, so you can compare if they match camera companies.
- aaronem 11y agoFor those who don't own an iOS device, or don't feel it is the best tool to do this kind of analysis: The standard tool on OS X or Linux appears to be Kismet[1], which, while I haven't actually used it and so can't vouch for it firsthand, appears to be quite capable. I don't know what, if any, equivalent tool exists for Windows, and since I don't own a Windows laptop, I also don't really care. Edit: Having now installed Fing and looked at what it does, it seems to basically just look at its assigned IP and netmask to determine the address space of the local network, and then perform an nmap-style ping scan to see what doesn't time out. When it gets a packet back, it uses the MAC address to identify the type of device, and a PTR lookup with the DHCP-provided DNS server to obtain a hostname. These are pretty cool capabilities to have on a handheld device, of course, but if you can't or won't install Fing, you can do pretty much everything it does with a 15-line Perl script on any device that can connect to the wireless network. [1] http://www.kismetwireless.net/ http://www.kismetwireless.net/
- maxerickson 11y agoIn the past I used inSSIDer to view nearby networks, checking to see how capable it is led here: https://www.reddit.com/r/networking/comments/3fyjbm/now_that_inssider_is_not_free_what_else_is_out/ https://www.reddit.com/r/networking/comments/3fyjbm/now_that... Which points to (pdf): http://www.xirrus.com/cdn/pdf/Xirrus-Wi-Fi-inspectorguide-1-2-1-RevB-6.pdf http://www.xirrus.com/cdn/pdf/Xirrus-Wi-Fi-inspectorguide-1-...
- darkr 11y agoYeah, kismet and/or airscan are pretty much the two go-to tools for wifi security auditing. Kali Linux (can run from a bootable live image) has these two plus a whole lot more useful tools for doing this kind of thing.
- awqrre 11y agoTo disable all cameras that only save data to the "cloud", like dropcam and many others, you can also just temporarily disconnect the cable or phone wire on the outside of the house.
- mcintyre1994 11y agoWouldn't that stop you using their Wifi, presumably included as part of the listing? That's probably another surveillance risk to be fair, but I think most people expect it and tolerate that risk.
- banku_brougham 11y agoI like this because presumably it is not illegal to do so.
- notwhereyouare 11y agoIf you read the article at the end the author says it's legality is questionable due to FCC changes that include kicking somebody off the wireless as jamming them
- awqrre 11y agoDropcams could be illegal in many states in this case since they can record audio... but laws should be updated to include video. (see two-party/all-party consent states: https://en.wikipedia.org/wiki/Telephone_recording_laws#United_States https://en.wikipedia.org/wiki/Telephone_recording_laws#Unite... )
- awqrre 11y agoWhether you like it or not, it appears that everything that helps privacy will soon become illegal.
- TazeTSchnitzel 11y agoI like the massive fanfare the script makes when it finds a camera.
- singularity2001 11y agoAnd don't forget to report those cameras to the authorities, since in many countries it is completely illegal to film people without their consent (in private places).
- Retric 11y agoIn the US is legal to monitor babysitters / house cleaners with hidden cameras. Just don't record bathrooms etc.
- Tharkun 11y agoThe US is obviously a very fucked up place.
- lectrick 11y agoThe US is a fucked up place because they want to make sure a babysitter doesn't shake their baby to death or a housecleaner doesn't break or pocket something without admitting it? Hyperbole much?
- izacus 11y agoHrmf, and your sentence isn't a hyperbole? I mean, if we extend your logic, we should monitor everyone at all times because someone might just accidentally do something to hurt your child right? You never know why an extremely rare event like you mentioned could happen.
- icebraining 11y agoEveryone is usually being monitored when around children of strangers; we just usually do so with human eyes instead of cameras. Babysitting is an exception, but why should it be?
- izacus 11y ago
- mapgrep 11y agoCool but some questions on the command line args: Call be dumb but I have no idea what my wireless NIC is called and that's the first arg to the script. How do I find out the handle for my wireless network card (I didn't even know it had a name), but also does anyone know why the script can't self detect that? Don't most people only have one? Ditto for the SSID, couldn't the script just figure out what SSID I'm connected to? Asking as much for self education as anything else...
- mschuster91 11y agoOn Linux, run ifconfig as root. The problem is that there's no naming convention for NIC names. Some systems use ethX for both wired and wireless systems, some ethX/wlanX, and some use wlx-(macaddress) unique name.
- arca_vorago 11y agoJust heads up ifconfig is considered deprecated and ip addr show is the correct command on many modern distros.
- finnn 11y agoWhy would you need to to root to see the list of network cards? ifconfig as non-root, or just ip addr, works fine. Note that newer debian versions seem to have moved ifconfig to sbin so it's not in a normal user's $PATH
- andmarios 11y agoYou can see your wireless card's name in the network management widget details' dialog/pane, or simply run 'iwconfig' in a terminal. The script could automate the discovery of both information but that would make it larger and much more error prone. Your comment is nice, it shows how Linux Desktop nowadays is so easy to use, one does not have to worry about technical details.
- forgottenpass 11y agoThat disclaimer bugs me. Just admit you don't know what the fuck you're talking about and to consult a lawyer before using on equipment the user doesn't own and control. Instead it misleads the uninformed, and shows the slightly-informed you skimmed half a news article once.
- deleted 11y ago[deleted]
- wutbrodo 11y agoCan you clarify the problem you have with the disclaimer? The important parts of the disclaimer seem to be the lines "this might be illegal, make sure to check, use with caution" as well as mention of de-authing being the potential problem. Those seem to me to be enough for an informed user to be able to do their research and enough for an uninformed user (or those unconfident in their ability to research it) to be sufficiently scared away.
- forgottenpass 11y agoHeres why: > Due to changes in FCC regulation in 2015, It wasn't a change in regulation. There was an enforcement advisory that the FCC considered interfering with WiFi connections to be interference under 47 USC 333. That's not a new law or regulation, it's just the FCC publicizing that they have already and will take further action over new way to violate a law. > it appears intentionally de-authing WiFi clients, even in your own home, The radio spectrum is a public resource, even when it radiates through your home. I can't use a stingray just because the phones are being used in my house either. I can understand why some people might disagree with the public resource nature of RF. But it's neither clear if the author is trying to pick that bone for real, nor am I here to defend that classification. Just pointing it out. > is now classed as ‘jamming’. Up until recently, jamming was defined as the indiscriminate addition of noise to signal - still the global technical definition. Jamming is used colloquially to refer to all interference under 47 USC 333. But with a little googling I don't see the FCC using the term "jamming" for this style of WiFi interference. The law is written the way it is because spoofing deauth messages is just one of the many ways to cause interference without "jamming." > It’s worth noting here that all wireless routers necessarily ship with the ability to de-auth, as part of the 802.11 specification. I don't think I understand that it's "worth noting." There is a large difference between an access point managing it's clients, and a rogue actor spoofing messages to mislead those clients that the message came from the AP. The fact it's part of the spec is the only reason this tool works at all, and the concept of layer 2 interference isn't particularly hard to grasp, especially when that's the explicit purpose of the tool. Also: >The very fact this code exists should challenge you to reconsider the non-sane choice to rely on anything wireless for home security. More so, WiFi jammers - while illegal - are cheap. If you care, use cable. There are a great many things in my life that someone could fuck up if they wanted to break the law that are much more important than my wifi based home security. Even with this tool, the greatest threats to wifi devices are still lousy wifi performance before interference, and lousy residential internet connections. I don't need someone with a baseball bat loitering around the parking lots I use to pester me about my car. That doesn't "challenge me to reconsider the non-sane choice" of using a mode of transportation that is just so darn easy to damage with a baseball bat.
- kazinator 11y agoIf you're seriously worried about this issue/threat, you have to take into consideration non-Wi-Fi cameras also! Not to mention microphones.
- brownbat 11y agoAgreed, this is a pretty narrow slice. Though if you're seriously worried about all forms of surveillance, you can end up heading down a deep rabbit hole pretty fast. Consider "The Thing:" https://en.wikipedia.org/wiki/The_Thing_(listening_device) https://en.wikipedia.org/wiki/The_Thing_(listening_device)
- georgemck 11y agoJust need to have two separate networks: one for guests, other for security. Security network has its own hidden SSID. This is not an AIRBNB issue, it's a privacy issue anywhere you go...
- simoncion 11y agoBecause clients connected to a "hidden" SSID broadcast -in cleartext- that AP's SSID in many frames that they and the AP transmit as a normal part of operation, [0] deactivating SSID broadcasts gains you no security, a fair bit of inconvenience, and -potentially- reduced battery life when you move out of range of the AP as the client spams "are you here?" messages, rather than taking the absence of SSID broadcasts as a sign that it's out of range of the AP. Now, you could "hide" your SSID to reduce the number of SSIDs that appear in a WiFi network browser in a congested area... but that's a thing that -IMO- doesn't get you much for the hassle. For security, either use WPA2-Personal in AES/CCMP-only mode with a long, randomly-generated password, or WPA2-Enterprise [1] in the same mode. [0] https://en.wikipedia.org/wiki/Network_cloaking#False_Sense_of_Security https://en.wikipedia.org/wiki/Network_cloaking#False_Sense_o... [1] Maybe even with client authorization through certs! :D
- hannob 11y agoBeside the legal issues I fear that this is a risk in a way that it could create a false sense of security. I.e. non-technical people thinking "this will make sure I'm not filmed" while this isn't the case. There can be cameras not affected by the script, cameras with cables, cameras with their own storage etc. pp. Of course everyone here will say "that's obvious", but I'm not sure this is obvious for everyone.
- coob 11y agoNon technical people are going to run shell scripts?
- yareally 11y agoIt's more likely someone will naively create a gui wrapper app that does it for them.
- hippo8 11y agohah. On a serious note, wonder how long before someone converts this an app. -edit- oops, didn't see the other comment to the parent comment.
- roywiggins 11y agoThey're called scriptkiddies: they have just enough technical know-how to hang themselves, more or less. Enough to copy and paste lines into a terminal window.
- scurvy 11y agoIronic that you're going to worry about legal issues while renting an illegal hotel room. Considering AirBnB is all about pushing boundaries and outright disregard for the law, the use of this script seems completely apropos.
- icebraining 11y agoYou know, there is life beyond your own city. Hotels aren't granted a monopoly over short-term rentals everywhere.
- bkjelden 11y agoSay someone is renting out a room on AirBNB, and they also have some dropcams monitoring the perimeter of their house. Someone rents the room, and runs this script, disabling the cameras. During the stay, the property is burglarized, and there is no surveillance footage of the crime because the renter disabled the cameras. That seems like an incredibly messy legal situation. Would the renter even be able to exonerate themselves? They disabled the cameras, it almost feels like they inadvertently framed themselves for a crime they didn't commit.
- simoncion 11y ago> Would the renter even be able to exonerate themselves? If you can convince the cops to do their job, then yes? If my apartment was burgled when I was at work and my new roommate had the day off, the cops would -hopefully- do some investigation to determine if anyone else might have possibly entered the space, as well as checking and enquiring with pawn shops and grey-market street vendors for my stolen goods.
- arbitrage 11y agoThe cops are not going to go looking for your lost stuff for you. I know this from experience.
- rdancer 11y agoEven more clearcut, all the cameras in all the neighbouring flats get disabled (this is actually the reason why jamming is illegal -- EM radiation doesn't know to respect property boundaries).
- brbsix 11y agoThis particular script is not really a jammer in the traditional sense. It's simply a de-auth command to a specific device on a specific network. So with a little care you could ensure you were only dropping the indoor cameras.
- 11y ago
- hammock 11y agoTitle was edited from the original to censor the mention of Airbnb (a YC company)? Really, Dang?
- officemonkey 11y agoThat's against Hacker News policy to only use the actual title of the article (even if it's a worse one.) I wonder if integrity will win out.
- dominotw 11y agoYep there have been many submissions critical of AirBnb that were silently removed from the front page in the past. I am surprised this is still holding up.
- brudgers 11y agoOne could make a plausible case there's a bit of click bait in the original title because there is nothing specific to AirBnB in the script; the use of hidden cameras is not part of their business; nor are AirBnB rentals a unique market for hidden cameras. Anyone who clicks on the link can read the title and decide its relevance to the hack. The primary people whose needs aren't accommodated by the change are those whose interest is triggered by "AirBnB."
- morgante 11y agoThe "in that AirBnB you’re staying in" is totally superfluous and is mere outrage fodder.
- enraged_camel 11y agoNot really. The script was written as a result of the recent AirBnB stories about hosts spying on and recording their guests. The relevance is direct and immediate, and taking it out of the title is shameless editorializing.
- jzwinck 11y agoThe very first vignette in the very first link (http://fusion.net/story/49806/beware-houseguests-cheap-home-surveillance-cameras-are-everywhere-now/ http://fusion.net/story/49806/beware-houseguests-cheap-home-...) is about someone who was spied on when staying for free at some person's apartment. Not AirBnB. Journalists often concoct an "ongoing" narrative to make it sound like there is a big trend when there are only one or two anecdotes. Write a weak article with one example, follow it up with a second article with a second example, then write a third article proclaiming that something is "sweeping the nation," linking to what "we previously reported." The linked title could just as well have said "when you're staying in a stranger's home," but that doesn't carry as much currency as "AirBnB." I think that's clickbait, albeit subtle.
- Sephr 11y agoWouldn't 802.11w protected management frames prevent this script from working, as long as the homeowner has that enabled on their router?
- SuperKlaus 11y agoThe original link isn't forwarding right from http to https, working link: https://julianoliver.com/output/log_2015-12-18_14-39 https://julianoliver.com/output/log_2015-12-18_14-39
- xgbi 11y agoWhy not just scan for cameras and simply tell that there are some cams in the local network? You can then search for them and simply place some cloth on it? Might be more legal.
- stevefeinstein 11y agoYou're missing the point people! Don't record other people who are renting your house, or tell them you're going doing it. Detecting and disabling a camera on the network (and assuming it's on the same subnet as any wifi you are authorized to use) is ass backwards.
- nick_name 11y ago> arp-scan -I $NIC --localnet If the camera runs on a separate network to which you don't have access to, the script wouldn't work.
- theoh 11y agoAs someone with a bit of familiarity with the world of contemporary art, I think it's important to see this as a provocation, not something intended for real world use. One might find Oliver's other projects (e.g. the "transparency grenade", which is an actually transparent acrylic grenade that "blowns open" wifi insecurity) to be a bit irresponsible or less sensitive than you would expect from a "critical engineer".
- 05 11y agoThat's why you put security cameras on a separate VLAN..
- rosege 11y agowhat I was thinking
- awqrre 11y agoVery similar to: https://julianoliver.com/output/log_2014-05-30_20-52 https://julianoliver.com/output/log_2014-05-30_20-52