6 ms·
A Warning to Users of NurseryCam
- KaiserPro 6y agoThe whole saga is just utterly insane. Its the same people who shipped the "people counting" raspberry pi system with the bruno mars mp3s in them. First they try and report the security consultants to the police, then they claim that they are too expensive to work with. Then even more bizarrely they launch a halfarsed sock puppet campaign using the CEO's wife's account. Then they start publishing reviews on their own staff, including private health info. Just utterly bat shit insane
- Judgmentality 6y ago> First they try and report the security consultants to the police, then they claim that they are too expensive to work with. Hahaha what? Are you saying they paid these guys, then reported them to the police, and then the police found a contract and they just said "well they're too expensive!" > Then even more bizarrely they launch a halfarsed sock puppet campaign using the CEO's wife's account. Sure, why not? > Then they start publishing reviews on their own staff, including private health info. I am so confused. I read the article and still don't understand this comment.
- Limb 6y agoWow the thread about the raspberry pi system was a wild ride. For anyone else who wants to give it a read: https://twitter.com/OverSoftNL/status/1357296455615197184 https://twitter.com/OverSoftNL/status/1357296455615197184
- walrus01 6y agoPeople should mirror this whole twitter thread and its content to use as a literal textbook example of everything not to do.
- carwyn 6y agoThere's an article over at TheRegister related to the FootFallCam saga: https://www.theregister.com/2021/02/12/footfallcam_twitter_kerfuffle/ https://www.theregister.com/2021/02/12/footfallcam_twitter_k...
- duskwuff 6y agoReading about FootfallCam, I can't shake the feeling that someone gave the project to a single, heavily inexperienced developer, the developer quit, and the manufacturer shipped the contents of that developer's home directory, as-is, as the final product. And the marketing was written before the product was developed, based on what they wanted the product to do, rather than what it actually did.
- bsenftner 6y agoLooks to me like some developer somewhere made a RaspberryPI camera prototype and some dumb money ran with it creating a marketing campaign and getting the prototype in the market as if it were a complete solution.
- wackget 6y agoYeah... I didn't fully appreciate just how insane this is because the information's scattered all over the place. Then I read the Register article and a collated Twitter thread... and yeah, it's insane... This company has absolutely no business being anywhere near security/software/hardware development. https://www.theregister.com/2021/02/12/footfallcam_twitter_kerfuffle/ https://www.theregister.com/2021/02/12/footfallcam_twitter_k... https://twitter.com/_MG_/status/1359582048260743169 https://twitter.com/_MG_/status/1359582048260743169
- deleted 6y ago[deleted]
- carwyn 6y agoThe initial blog post with more of the technical detail is here: https://cybergibbons.com/security-2/serious-issues-in-nurserycam/ https://cybergibbons.com/security-2/serious-issues-in-nurser...
- Animats 6y agoThe short version: For all parents connecting to a given nursery, they are given the same username and password for the DVR. In the examples I have been shown, the username is admin and the password is either admin888 or nurserycam888. Sigh.
- comrh 6y agoAnd they knew about the issue for over 5 years...
- orf 6y ago> This blog post is intended for a non-technical audience – specifically parents and nurseries using the NurseryCam system. Good idea, but the article is full of specific technical details + technical diagrams that are irrelevant to getting the point across.
- brmgb 6y agoI think that statement was about the first three paragraphs and those are pretty clear and to the point. Then again, I doubt most people are going to be particularly alarmed. The flaw means that people who know the nursery ip and the password to the camera could connect after they lose access to the website if they are tech savvy enough. Most people will probably shrug at that. It's a nursery cam for parents. What's the threat model exactly? It might be of interest to people buying a new system however.
- netsharc 6y agoI guess this comment will be burned to the ground [instead of people telling me why they disagree], and yeah a single username and password is bad, but the article smells like fear-mongering. "Zomg, strangers will look at your children!", even though the kids are in a place that is semi-public, and the viewers are mostly remote. Hmm, then again, if someone was filming my children, I'd be creeped out. And if someone was using this to identify kids and their day-to-day patterns (e.g. pick up hours), they could theoritically show up 10 minutes earlier, say they're there sent by the parents to pick up someone, and "the kid is wearing a blue top and yellow shorts" or whatever. But IMO kidnap scares are overblown, and if a nursery falls for that trick without calling the parents first, they should be shut down for being too stupid.
- mplewis 6y agoIs your child's bedroom semi-public?
- jowsie 6y agoThis is a system sold to commercial nurseries, not installed in peoples homes.
- leipert 6y ago> but the article smells like fear-mongering. "Zomg, strangers will look at your children!" 1) It should be reasonable to expect some privacy when you give your kids into the care of other people. There is a whole lot difference: someone can walk by a day care and see kids playing outside and anyone on the internet can access these systems. I don’t know how these nurseries work that use these systems, but I assume that not that many people have access to the kids, only staff and maybe other parents/guardians. 2) The company producing these camera systems claims them to be more secure than online banking. This is flat out wrong, one might even argue fraud.
- vmception 6y agoOut of curiosity, why is viewing nursery footage seen as serious? Should it be patched, sure. I see it as different than some random IOT device in the crib, this is at the nursery itself. Why are parents given access to particular feeds at a nursery? Why does it matter that they can watch other kids at a nursery if you’re already giving this access? Yeah I get that now ANYONE can watch them too, ooh scary men in trench coats and top hats watching children. I’m missing something about the wording of this: “The issues with NurseryCam are about as serious as it gets.” Is it though?
- u678u 6y agoMost of the nurseries here have big windows so everyone walking past can see nearly everything inside.
- turminal 6y agoSure, but anyone standing there for long enough to be noticed will eventually be asked to leave.
- TedDoesntTalk 6y ago> Out of curiosity, why is viewing nursery footage seen as serious? pedophiles can view/record naked infants and toddlers with relative ease.
- TedDoesntTalk 6y agoNot sure why I’m trying downvoted. Maybe the mere mention of pedophelia disgusts people. This is a real threat, but honestly I’m not concerned... and I have a toddler in a facility that uses a system like this (not the same one).
- recursive 6y agoI have a toddler in a facility too. But I'm not at all convinced that this is a real threat. I'm having trouble even imagining it as a theoretical threat. Pedophiles are bad for sure. But internet people watching nursery footage doesn't seem to make that any better or worse. I expect roughly all of nursery footage to be uniformly boring. Even if a pedophile got access to it... then what? Where's the threat?
- neilv 6y ago> This blog post is intended for a non-technical audience "OK, folks, let's start briefly with bridging firewall/NAT/non-static-IP-addr/UX by network port-forwarding, and then move on to the protocol scenario event trace diagrams..." :) I appreciate this writer's work to document the surprising technical failings, and to try to protect people. And there's some good effort to make it accessible to non-technical audience, though some of it seemed a bit confusing/intimidating. This might be a good occasion for coaching from (or collaboration with) a professional journalist or other writer. As a techie myself, I can only guess what the result of expert help might be, but maybe even more inverted-pyramid writing style for this audience's perspectives, getting into understandable threats/implications near the top, and then supporting that with the minimum technical explanation necessary. With a pointer to a very technical separate post, for credibility, and for the benefit of journalists and other techies. BTW, maybe my contemporary US cultural bias is showing here (and the article mentioned UK)... I saw some mentions of "parent" where it seemed some of the threats might be more understandable, and more persuasive to some of the people who could benefit, were it to include something to the effect of "...or ill-intentioned computer-savvy person, outside the daycare, or even anywhere on the Internet". Not to promote paranoia over stranger-danger, but those aren't hypothetical additional vulnerabilities to which I think a parent would want their child exposed for (what appears to be) absolutely no reason.
- YeBanKo 6y agoThis should absolutely be an end of this company. 1. They did not just give unauthorized access, they gave admin access. 2. It’s been going on for 6 years. 3. It seems very basic. 4. Not using HTTPS is another big red flag 5. Having this secure access feature is one of their selling points, by not providing it they essentially defrauded the public. Mistakes happen, and it worse when it happens in security field. But this is not an honest mistake, this is negligence.
- mleonhard 6y ago> To make matters worse, the connection to the DVR is using HTTP, not HTTPS. It is unencrypted, allowing someone to eavesdrop on the video feed, username, and password. What is the proper way to provide certificates to devices with embedded servers? - Generate a self-signed certificate with the appropriate IP address and train users to bypass the browser's scary warnings? - Buy certificates for every deployed device. Make each device download a new certificate when its current one expires. Set up dynamic DNS so the user can reach the device at a URL that matches the certificate. - Make the device use an ACME server to provision its certificate. The device must be publicly accessible so the ACME server can reach it. - Proxy all device connections through a central server. This could be expensive for high-bandwidth uses like streaming video. All of these options are poor. Why has nobody solved this problem? Is it because the powerful browser makers (first Microsoft and now Google) prefer lucrative centralized technology? Google will make a lot less money when everyone can easily run their own server to do shared docs and messaging. Or is it because IoT companies prefer centralization so they can sell subscriptions to users and gather user behavior data? Or is it just that nobody has put in enough effort to solve it yet?
- PurpleFoxy 6y agoThis kind of highlights the problem with these kinds of products. They are extremely difficult to do properly and expose the user to quite a lot of danger. Really we should be settling for “well it is quite hard so we will let these faults pass”. The product should simply not be allowed to be sold if it can not be done properly.
- userbinator 6y agoI'll go with the first one, because it is as you said: the authoritarian security industry, and the corporate types in general, love centralised control, and HTTPS-everywhere is their attempt at grabbing more of it. Honestly, as another commenter here noted, I don't think this is that big of a problem --- and is comparable to all the other open webcams out there.
- kccqzy 6y ago> Proxy all device connections through a central server. This could be expensive for high-bandwidth uses like streaming video. The central server doesn't need to proxy the actual data stream. There are plenty of peer-to-peer video implementations that only require a central server for signaling and connection establishment.
- exikyut 6y agoSooo, getting Java in Firefox working has completely taken the wind out of my sails and I am VERY bored now, but suffice it to say that - I image-searched "nurserycam dvr" and immediately found a video, from NurseryCam itself, showing how to reboot the DVR - I also found a PDF with some "HDD reset" instructions and noticed the PDF had a closeup of the control panel buttons - Googling the button labels from found me some extremely hazy model info - your standard "but which manufacturer?!" fare, it seems to be around the midpoint of "full AliExpress" at one end and actual reputability at the other - After image-searching "<manufacturer> web interface" I stumble on a screenshot of a directory service that registers DVRs via DNS and gives them a domain - "site:*.<domain>" found a few results - visit one of them, open devtools, and yes, there's a unique Server: string Then it was your standard - how to into applet in 2021? oh, FF 52.0 ESR, ok - download java 8 - find random website with java 8 .tar.gz because Oracle - unpack java 8, create symlink, yay! - security exception. oh. - replace with java 7 - [A LONG TIME LATER] ohhhh, firefox updated itself and that's why everything looks wrong and the plugin stopped working - okay let's go through shoda... actually you know what this is really boring. TL;DR: it look about 3 hours to install Java and about 25 minutes to figure out what brand of DVR this company is using. Security through... ADHD incompatibility, anybody?
- quickthrower2 6y agoThe words “NurseryCam” is warning enough for me :-). Will leave IoCrap stuff like that well alone.
- Rainymood 6y ago(Tried to re-write your intro article a bit for ... you know ... a non-technical audience.) # Summary Let me get straight to the point. If you (or your daycare) uses NurseryCam, ANYONE CAN SPY ON YOUR CHILDREN. Let me repeat that. If you (or your daycare) uses NurseryCam, ANYONE CAN SPY ON YOUR CHILDREN. ANYONE. Hi, my name is John Doe and I'm a cyber-security consultant who specialises online video security. NurseryCam is a camera system that is installed in nurseries, allowing parents to view their children remotely. There are tens of nurseries stating that they use this system. News articles go back as far as 2004. The problem is that NurseryCam's system contains serious security issues. The worst part is that NurseryCam is lying about it. NurseryCam were informed of these as early as February 2015 – 6 years ago and still haven't done anything to fix them. These issues would allow any parent, past or present, to access the video feeds from the nursery. There is also the chance that anyone on the Internet could have accessed them. So if you use NurseryCam, anyone can spy on your children. Do you really want that? If you are a concerned parent now, please do not hesitate to reach out to me on john@doe.com. If you want more technical details, keep reading on down below. # Technical details ...
- II2II 6y agoWhile I agree the article is more technical than the author claims, that summary says very little and sounds like fear mongering. It is important to have a credible tone in order for a serious issue to be treated seriously. One of the interesting things about the original article are the technical details. If the claims are true, almost anyone who has a decent knowledge of computer networking can circumvent the security measures. Even replacing jargon with descriptions more amenable to a non-technical audience would likely convey the same thing. This is in stark contrast to most of the vulnerabilities we hear about these days, where a much deeper knowledge is required to exploit the vulnerability even when a thorough description is provided.
- jlgaddis 6y agoSince 1) this is supposed to be for "a non-technical audience" and 2) the target audience is parents of young children who feel it's necessary to monitor (in real-time) their child(ren)'s day care facilities in the first place, I can't help but think that your rewritten intro missed out on an absolutely perfect opportunity by failing to include -- for maximum effect and attention-grabbing, obviously -- terms like "pedophile", "child predator", and so on. (I'm only halfway joking.)
- imdsm 6y agoI'd just like to highlight the response to Andrew: https://twitter.com/A_Mitchell1966/status/1361024362124566531 https://twitter.com/A_Mitchell1966/status/136102436212456653...