26 ms·
Bought and returned set of WiFi home security cameras; can now watch new owner
- nateguchi 10y agoYou can more than likely pick up the serial through the web-admin panel that these cameras expose on the local network. God forbid they have a wireless AP with the serial number somehow encoded in the SSID. How is it that these companies still don't give security a passing concern?
- mtgx 10y agoThat's why "surveillance cameras" better describes these products, than "security cameras", especially if they're cloud-connected.
- digi_owl 10y ago> How is it that these companies still don't give security a passing concern? Lack of lawsuits. The kind that bankrupt companies and set binding precedents for everyone else.
- userbinator 10y agoI set up an online account The title is missing an important fact: these are not traditional network cameras, they're ones that apparently stream video into the cloud. Those cameras that do not "phone home" to a cloud service don't have this problem; the ones that you can set up with a username/password and then connect directly to from the network. Ironically it's the cheap no-name ones that usually work like this, as the company just sells the hardware and isn't one to bother with their own set of servers/accounts/etc. IMHO these cameras that do rely on a third-party service are to be avoided, since what happens to that service is completely out of your control.
- chiph 10y agoAt the very least, they go out of business and now your expensive hardware stops working.
- digi_owl 10y agoPeople thought the Shadowrun authors where off their meds when they made gear lose stat points from being offline, and now here we are... Buzzwords combined with profit motive produce some worrying outcomes.
- cookiecaper 10y agoThe cameras you're discussing are not very safe for the layman either; you wanna be sure you have a properly-configured perimeter firewall before you use them and that they don't open any ports with UPnP. A cursory glance at shodan will reveal many such cameras that are happily streaming their images out to the open internet.
- digi_owl 10y agoUpnp in its intial form, getting media devices to talk to each other and exchange data, was fine. But how the heck did it end up being about punching holes in firewalls?!
- Aelinsaar 10y agoUntil people start demanding security, and become willing to pay for it, the IoT is going to be positively defined by this kind of nonsense. That, or some kind of legislative action I guess, but that seems like pure fantasy.
- nateguchi 10y agoMaybe a protocol / standard that has all the security / best practices baked into it?
- arca_vorago 10y agoNot a single one, but people need to be better educated on their options. How about, here are the options where you can actually have control of your devices as under property rights. I do however also think the gplv3 sphere needs to offer better netguis for the non cli-heroes.
- Aelinsaar 10y agoI'm not sure how easy it would be to communicate, and insulate from marketeering. "Steel roll cage" or "Airbags" and "Seatbelts" are relatively simple concepts. I don't know that even something as common as "SSH" would mean much to the average person, and by the time they learned, any given term or technique would probably have been supplanted by another, newer, better one.
- matt_wulfeck 10y agoThat's like saying "until people start demanding safety on cars and become willing to pay for it there will always be fatalities". Sure part of the blame is on the consumer, but maybe the company shouldn't be selling cameras that are inherently insecure. These types of things typically play out with lawsuits which increase liability for the producers. The problem is that it's (currently) difficult to prove damages when it's only privacy.
- tacos 10y ago> That's like saying "until people start demanding safety on cars and become willing to pay for it there will always be fatalities" Uh, that's how it sorta works -- for better and for worse. https://en.wikipedia.org/wiki/Unsafe_at_Any_Speed https://en.wikipedia.org/wiki/Unsafe_at_Any_Speed "On March 22, 1966, GM President James Roche was forced to appear before a United States Senate subcommittee, and to apologize to Nader for the company's campaign of harassment and intimidation. Nader later successfully sued GM for excessive invasion of privacy. It was the money from this case that allowed him to lobby for consumer rights, leading to the creation of the U.S. Environmental Protection Agency and the Clean Air Act, among other things."
- walrus01 10y agohttps://twitter.com/internetofshit?lang=en https://twitter.com/internetofshit?lang=en
- JChase2 10y agoI've tried finding a camera that has a server that can encrypt traffic, and I can't. It'd be nice to have access from outside of my network but I don't trust it. It really took me by surprise how bad at security these things are. I guess I could set up some kind of vpn but I assumed when I bought it I could enable ssl or something.
- Retr0spectrum 10y agoPossibly overkill, but you could set up some kind of home VPN to remote in securely.
- tener 10y agoThis is probably the only way to be sure about security in this scenario.
- m_eiman 10y agoMaybe the Apple HomeKit ones are better - at least it'd be a big PR problem for Apple if they aren't.
- walrus01 10y agoPut IP cameras in their own VLAN on a network that also contains network DVR software. Access it via VPN tunnel and/or https. For unauthorized access to an individual camera somebody would need to be on the same layer 2 broadcast domain as the camera, local on site. Following that principle, if an adversary has physical access to a device it's likely pwned anyways.
- markbnj 10y agoSystems that provide an online account tied to a physical device have to be carefully designed for transfer of ownership scenarios, and it sounds like they didn't do the work here, or else something went wrong and the resulting error state is unfortunate.
- digi_owl 10y agoFrankly i suspect the devs never even contemplated a transfer of ownership scenario. The whole idea seems more and more foreign, or perhaps quaint, to the people involved in tech these days. tech is treated as something disposable, not something durable to transfer from person to person.
- HannibalLecter 10y agoMore like someone's boss said, "Why would we want to give them the ability to transfer ownership? Make them buy A NEW ONE!" Not considering the returns/exchanges scenario. Not considering the customer's advantage. Only considering profit. Same tune that will spell doom for humanity is the sound of gold coins in the coffers of lesser men.
- mtkd 10y agoI guess the devops team can view all of them
- jessaustin 10y ago...I guess they've curated a set of good-looking and sometimes-not-completely-dressed camera users whom they view more often than the rest of their customers.
- matt_wulfeck 10y agoThese types of exceeding invasive products need to have their damages tested in courts. After a few lawsuits and payouts the liabilty will begin to increase and that will force companies to adapt/improve or go under. The problem is our entire generation doesn't care about privacy. They willingly hand over everything about them to an app and care not a single drop that their government spies on them without a warrant.
- cfallin 10y ago> The problem is our entire generation doesn't care about privacy. Yup -- law follows culture, not the other way around. IMHO this (cultural priorities) is at the root of other ills too, e.g. educational system and criminal justice system brokenness. I think most people genuinely do want the right thing but just aren't aware of the long-term consequences of the current approach.
- dredmorbius 10y agoSecurity and privacy awareness are not wholly absent, and awareness, including among the young, can be high. The awareness is, however, highly uneven, and is quite problematic especially in how it's reflected among commercial enterprises and law. As I've been saying for quite some time: Data are liability. This is simply the home-security edition.
- seanp2k2 10y agoThe other part to this is what can they do about it. Kids these days see riots responded to with military force. Cops kill people on sight and get off unpunished. People get imprisoned over enumerating URLs and we're trying to extradite a person to charge them with treason for revealing that the government is indeed spying on everyone. I don't think kids these days are naive, I think they just see that trying to fight this stuff can realistically get them life in prison and/or killed.
- dredmorbius 10y agoI've yet to hear of reporting product defects or opting out of Facebook leading to an armed occupation. (Though security researchers might want to take care in how they identify and report vulnerabilities.)
- louprado 10y ago"I'm not mistaken, anyone could get the serial number off your cameras and link them to their online account, to watch and record your every move without your permission." There's a name for a hacking strategy where you mass purchase products, modify it or acquire relevant information, then resell them or return them. "Catch and release" comes to mind, but I can't find any references.
- kordless 10y agoYou can also do this with PG&E accounts. Based on my conversations with them about it, it appears to be a feature.
- geofffox 10y agoI had the same problem with a WD home server. I returned it when it wouldn't do what it was supposed to do. Later, I started receiving emails from the server as it kept me up-to-date on its status.
- arca_vorago 10y agoYet people still recoil as if in horror when I try to explain that this is one of the core reasons why gplv3 is so important. Look, we've lost the hardware freedom wars so far, but we still have software, and we can work on improving our hardware side as we progress. One of the Common arguments I hear in response is, "But open source doesnt pay, and therefore doesnt innovate as much." While the lack of funds coming arent ignorable, innovation is always happening in the foss space, often surpassing the proprietary alternatives, often falling far behind as well. It still gives you the power to control your own systems, which is the freedom you can choose to not give up. The only way you surrender your freedom is voluntarily.
- deleted 10y ago[deleted]
- nxzero 10y agoSeen this same method applied to used equipment for sale, especially if it was stolen. Basically, someone steals a laptop, wipes it, reinstalls the OS with backdoors, sells the laptop for cash, exploits backdoor access to own other devices, exploits owned devices, etc.
- gist 10y agoTake it one step further. Someone has a target that they are trying to acquire (company website access). So they run a fake contest where the prize is a laptop. The laptop that they ship to the "winner" is backdoored as you have described.
- nxzero 10y agoRight, hacker might even target a website that's known to be visited by the targets, hack it, use it for drive by downloads attacks - and use the contest win a backdoored device (laptop,iPad,drive,etc) to cherry pick any targets that have not been compromised.
- RickS 10y agoHN readers: Do you think the engineers knew? I ask because I've worked on various products, and single units change hands between engineers constantly. Phones for testing, accounts with shared dev passwords, the actual hardware, all kinds of test units get spun up and passed around, even on crappy products where the engineers' imaginations are the only QA. Surely one engineer set up a camera, passed it along to another engineer, who set up the camera and encountered this error? There are lots of classes of error that can hide in a product, but this feels like one that it's nearly impossible not to hit.
- acgourley 10y agoIf it's really as simple as knowing a serial number to get access to a camera then yes I'm sure an engineer conjured this corner cases in their head.
- mmaunder 10y agoIf something like this happens to you - where you gain unauthorized access inadvertently to something - I'd be careful. Under the CFAA you can be charged criminally and the penalties are severe. So for example, if the OP was to casually drop a few photos the camera took and a badly worded warning in their mailbox trying to help, the 'victim' could report it to the police and an inexperienced DA might try to bag their first cyber prosecution. I'd definitely not contact the customer. Contact the vendor instead with an email and immediately remove your own access to the system. That way you have it on record (the email) and mention in the email you immediately revoked your own access. The CFAA is a blunt and clumsy instrument that tends to injure bystanders. Here's an extract from the CFAA: Whoever having knowingly accessed a computer without authorization or exceeding authorized access, and by means of such conduct having obtained information that has been determined by the United States Government pursuant to an Executive order or statute to require protection against unauthorized disclosure for reasons of national defense or foreign relations, or any restricted data, as defined in paragraph y. of section 11 of the Atomic Energy Act of 1954, with reason to believe that such information so obtained could be used to the injury of the United States, or to the advantage of any foreign nation willfully communicates, delivers, transmits, or causes to be communicated, delivered, or transmitted, or attempts to communicate, deliver, transmit or cause to be communicated, delivered, or transmitted the same to any person not entitled to receive it, or willfully retains the same and fails to deliver it to the officer or employee of the United States entitled to receive it; https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act
- sandworm101 10y agoThat;s the wrong part of the CFAA. I doubt the CFAA even applies. >..accessed a computer without authorization... AND having obtained information .... determined ... to require protection against ... disclosure for reasons of national defense ... [AND]... willfully communicates ... to any person not entitled to receive it... Unless in the control room of a nuclear power plant, that part doesn't criminalize taking a pic via someone else's webcam.
- downandout 10y ago
- jedberg 10y agoProps to Dropcam/Nest for solving this problem. My brother gave me his Dropcam after setting it up for himself, and I had to prove my identity and he had to prove his to get them to move the camera to my account. It was a hassle at the time, but I was glad to know that they at least had decent security.
- yuhong 10y agoI reported 768-bit DHE on one of Nest's servers to Google security around mid-2015. Do anyone remember the tweets by @NestSupport on Twitter around this time (there was also https://bugzilla.mozilla.org/show_bug.cgi?id=1170833 https://bugzilla.mozilla.org/show_bug.cgi?id=1170833)? It wasn't long after that they had to hire a VP of security (when Alphabet was formed I think).
- yuhong 10y agoHere is some of the old tweets actually: https://twitter.com/nestsupport/status/606246459822997505 https://twitter.com/nestsupport/status/606246459822997505 https://twitter.com/nestsupport/status/604682180242108416 https://twitter.com/nestsupport/status/604682180242108416 https://twitter.com/nestsupport/status/604714262834069505 https://twitter.com/nestsupport/status/604714262834069505 https://twitter.com/nestsupport/status/604718648595333121 https://twitter.com/nestsupport/status/604718648595333121 (Notice that they eventually posted a clear screenshot showing the problem and there was still not much of a response) I still have the old emails from Google Security in my mailbox. June 2, 2015 was when I received the first "received" email. June 3, 2015 is when I received the "triaged" email. June 4, 2015 is when I received the "filed a bug" email. You can see from the Bugzilla bug that it was fixed by June 5, 2015.
- seanp2k2 10y agoNest really went down hard after the acquisition. They were a company who built a cool thermostat. That is all. Everyone who didn't work on engineering the thermostat seems incompetent, especially management. The UI which took them like a year to do once they bought Dropcam is much worse than the old Dropcam site. They never came through for Dropcam Pro buyers who they promised 1080p recording to (the hardware can do it, but they never made fixing it any kind of priority). They then go and slap those users and early adopters in the face by releasing the Nest cam with the same hardware with 1080p enabled. The connected smoke detector is useless, since it's only useful in emergencies, and an app-connected thing which runs complex firmware is the absolute last thing I'd trust to save my life. There's a reason why sprinkler heads to put out fires are dead simple. They did nothing with an unlimited budget for 2 years: http://arstechnica.com/gadgets/2016/06/nests-time-at-alphabet-a-virtually-unlimited-budget-with-no-results/ http://arstechnica.com/gadgets/2016/06/nests-time-at-alphabe...
- Mister_Snuggles 10y agoI have a handful of D-Link cameras, and plan to buy more. D-Link offers some sort of cloud service, but I've never used it. I keep the cameras segregated onto a separate Wifi network that can't access the internet, and they work just fine in that configuration. The cameras have built-in HTTP servers and present what they see as an MJPEG stream. I use 'motion' running on a machine to handle motion detection, recording, etc. I use a VPN server to handle my remote access needs. I get everything that the cloud stuff offers, but all hosted locally. What's described in the article scares me, which is why I've set things up the way I have. Even if the cameras were used (they weren't) and tied to someone else's account, they can't send anything back to the cloud service.
- tylervigen 10y agoIf it's hosted locally, what stops an intruder from stealing or destroying your server once they break in?
- tmptmp 10y agoLocally doesn't mean it has to be stored on the same physical premise thus physical access to cameras does not necessarily mean physical access to storage machines/devices. Great work GP, congrats for taking extra steps. Is there any open-source/documentation that is accessible to more people (not just network experts) on how to do this kind of setup?
- Mister_Snuggles 10y agoThere are really three separate problems that need to be solved: * Remote access to your home network * Recording and storage of video, possibly with motion detection and alerting. * Remote storage of video/events (optional). Each problem is "sort of" solved: Most routers have some kind of VPN server built in. My Asus router supports PPTP, which isn't very secure, out of the box. I think some routers are starting to support OpenVPN, but without some easy wizard to set it up and distribute the profiles and certificates it would probably be beyond the average user. A lot of NAS devices come with software to record from IP cameras. My QNAP has it, but I have no idea how good it is as I've never tried it. I know that to use more than two cameras they want you to buy extra licenses. A lot of NAS devices can also sync folders up to various cloud storage providers. This could solve the optional remote storage requirement. As for making it all work together, that's another story. I'm not aware of any kind of easy to follow HOWTO for a user who's goal is "access my cameras remotely without sending everything to the cloud".
- andrewclunn 10y agoHoly shit. Never buying off the shelf consumer grade security equipment now.
- wepple 10y agothis is a general class of problems that is only going to get bigger. When I returned my lease car I had to have a bit of a think about what might be sync'd from my phone via bluetooth with it, and what functionality existed to erase that. The answers didn't make me feel great. The fun pastime of buying old HDD's off ebay and carving deleted files off them to see what might be kicking about is going to get a whole lot more interested with everything-connected society moving forward.
- happyslobro 10y agoWow. You know the situation is bad when you are actually better off implementing you own security as a bunch of Arduinos with webcam shields on the LAN and a server with a feature phone in the closet. LOL, just look at this vigilant little bastard :p http://www.arducam.com/arducam-porting-raspberry-pi/arducam-pizero-3/ http://www.arducam.com/arducam-porting-raspberry-pi/arducam-... No one is sneaking up on that without leaving a mugshot.
- voltagex_ 10y agoYep, but what does the average consumer do?
- takeda 10y agoWhat's with the "cloud" security systems? Why don't they just provide hardware where you store the information locally? Ignoring the privacy implications mentioned here, and that you esentially pay monthly/yearly for storage, if your ISP has an outage your security system is becoming useless. It also is a weak point for smarter thieves (just make sure that Internet access is cut).
- hackney 10y agoSounds like the security part is sorely lacking. That and someone needs to get a life.
- dboreham 10y agofwiw I recently started using the Samsung network camera sold by Costco (SNH-V6414BN), after various homebrew and RPi solutions over the years. It has an on-camera password that is set as part of the WiFi pairing process so is not open to this kind of attack. This password is separate from the cloud account credentials, so provided you don't ask the web site or mobile app to retain it (optional), without that password the camera content can't be accessed remotely (of course the firmware could be compromised and I don't know if the password is adequately protected from eavesedropping).
- reiichiroh 10y agoI can't tell but it doesn't seem like the OP reset the devices before he returned him. Isn't this his or her fault then? Like having nude selfies on a phone and returning it without wiping the phone to factory defaults?
- NETGEAR 10y agoNETGEAR has previously informed our resellers that retailers are not to resell cameras which have been returned. The Arlo camera system in this instance was resold without our authorization. When setting up a previously owned camera it is advised that all Arlo cameras be reset from the original base station, which will clear connection with any previously existing account. The configuration for the camera needs to be cleared as the settings may contain associated account information of the previous owner. NETGEAR is aware of this concern and takes the security of our customers seriously.
- NETGEAR 10y agoAdditionally, NETGEAR has tested for various scenarios in which unauthorized access to an Arlo video might be possible (including using randomized serial numbers). From the testing we have conducted, NETGEAR has not seen a possible scenario where an unauthenticated user plugs in random serial numbers and has unauthorized access to a video stream. The Arlo camera system is secured by design and has been tested by independent auditors and security researchers. NETGEAR also conducts bug bounty programs to further ensure the security of Arlo customer’s video streams and other NETGEAR products.