7 ms·
This sounds basically like a STUN/TURN + P2P solution which in itself _does not_ mean it's unsafe! It can be unsafe just as anything else out there if it's made
by dimman 11y ago
This sounds basically like a STUN/TURN + P2P solution which in itself _does not_ mean it's unsafe! It can be unsafe just as anything else out there if it's made unsafe.
As explained by the company representative (including my own added explanations) the devices, when behind NAT, can not receive any incoming requests without setting up port forwarding in the router (this is done automatically and temporarily for outgoing requests to allow incoming respones, but thats another story). Setting up port forwarding is not a good solution so what I pressume they are doing is that they are connecting to a TURN/STUN server from the camera outwards to be able to communicate. When the application wants to connect that one also connects to this server to have the camera create a p2p link (that means direct connection between camera and the device the app is running on). If that one fails then they are relaying the data through their servers.
Now there's some ceveats for the above solution. If one relies solely on encrypted channels and certificate security it should be as safe as the encryption is strong or the strength of the certificates. If not done properly, say client/peer verification is missing or the encryption chain isn't complete, then it's most likely bad. However:
The single most important thing is that the _functionality itself_ and the technique used is not unsafe per se.
The author makes it sound like it's a giant P2P-pool of camera devices, however this does not seem to be the case. Rather it seems to be a big network of relay servers to reduce latency for the connected devices. Big big difference there.
(Then one may question the inability to turn it off or that its enabled by default, but thats another question)
- wmt 11y agoMaybe you should read the story again. The core focus of the criticism is directed at punching holes through firewalls by default, and in this case you cannot even disable it. "This is a concern because the P2P function built into Foscam P2P cameras is designed to punch through firewalls and can’t be switched off without applying a firmware update plus an additional patch that the company only released after repeated pleas from users on its support forum." Later he quotes Nicholas Weaver from ICSI: "Given the seemingly cavalier attitude and the almost certain lack of automatic updates, it is almost certain that these devices are remotely exploitable."
- dimman 11y agoI do fully understand how the technology works. Let me explain: "punching holes through firewalls" <-- This _simply_ means that the device does a connect() call towards the clients IP:port while the client does a connect() towards the device:port at roughly the same time. You simply use the fact that a simple home router opens up a temporary rule allowing the destination:port to respond to your outgoing request. This won't work on symmetric NAT's for instance. It's basically a completely safe method and does not open up for anyone else to connect ... (The enabled by default is as I wrote in my original post is another question. The way I read the article it seems like the core focus of the post is to say that the solution used is bad or unsafe, which with given information cannot be said).
- wmt 11y agoThere you go again, misunderstanding what was actually said. I never questioned your understanding of the technology, but your understanding of what Krebs says. Krebs also understands the technology, and quotes David Qu from Foscam about how their P2P technically works.
- dimman 11y agoYeah I noticed that it sounded like I misunderstood you, however I did not. Lets just get it straight: I agree with you and him that it would be a lot nicer to let the user choose to enable this, and definitly not make it impossible to disable. With that said, I'm still not sure that the author actually understand the technology behind or how it works. Reading David Qu's answers they just align with what I'm saying about the technical part though. No matter what the author says, I think it's easy to misunderstand the text and make it sound like the manufacturer are doing something unsafe...
- tremon 11y agoIt's basically a completely safe method and does not open up for anyone else to connect ... Except that it's opening a port into an unverified P2P network. How can you say for certain that none of the peers are compromised or nefarious?