24 ms·
I’d caution against publishing the code directly to the public if we’re talking about a well known brand name like Ring, Wyze, Nest, etc. You may end up gettin
by datacruncher01 4y ago
I’d caution against publishing the code directly to the public if we’re talking about a well known brand name like Ring, Wyze, Nest, etc. You may end up getting involved in a legal dispute if you do that so for your sake report it through their vulnerability disclosure process. If it’s a no-name brand camera, those are frequently published and corrected in future firmware updates so it’s more or less ok to publish those.
Don’t count on that vulnerability being around forever though, at some point someone else is liable to find the same issue and report it. Sucks that vendors won’t give us access to the underlying OS for the device we’ve purchased. A lot of the consumer grade cameras would instantly be more valuable to me if I had that kind of access without having to hack the device for it.