4 ms·
I've been a happy user of frigate (https://frigate.video https://frigate.video) with fully local isolated setup: multiple poe cameras on a dedicated network, co
by VTimofeenko 2y ago
I've been a happy user of frigate (https://frigate.video https://frigate.video) with fully local isolated setup: multiple poe cameras on a dedicated network, coral to supplement on-camera recognition, HA+Prometheus for alerts and smarts.
Excited to see another project, especially in Rust(not for the memes; python env management has bit me a few times when hacking).
One major gripe with frigate that I have is the way it treats detection events as pointers to video files. This makes replicating events off site a major pain.
- stevenpetryk 2y agoHave you found cameras you’re happy with? That’s the main thing holding me back is not knowing a good PoE camera to use.
- hughesjj 2y agoHikvision and reolink are highly rated onvif ones that support poe, but as long as the camera support ONVIF from there just compare as normal
- hunter2_ 2y agoSearch for "Hikvision compromised" though. The results are damning. I suppose there's not much of a concern if using a proper firewall on a managed network, however.
- hipitihop 2y agoI can second Frigate and welcome any work in this space, so nice work OP will have a look. For others asking, I have found so far Hikvision POE PTZ domes like DS-2DE2A404IW-DE3 have been reliable, depends on your budget. I have cams themselves fully locked down from internet and on a separate subnet on the local net. OPNSense is also a friend here. I would love some OSS firmware for these cams. For remote, I find ZeroTier to Frigate & Home Assistant machines is all I need. I get why others WireGuard too. YMMV
- hughesjj 2y agoOh wire guard is a requirement imo, regardless of NVR or camera vendor. I'm less worried about a nation on the other side of the Pacific getting a livestream of my property than I am someone social engineering some rando employee at Ring/whereever and figuring out the best time to rob me or whatever. Also set up alerts on shodan opencve etc. If you have anything but a phone and personal computer on your home network, assume they're hacked and treat it like you would coffee shop wifi during defcon. Because... Well they are. Zero days are a thing, and by definition by the time you learn of one it's too late. Honestly I'm more concerned about the compromised device being an attack vector for network sniffing etc moreso than the video itself... Which is yet another reason why I try to 100% VPN even at home, but man okta doesn't play well with VPNs.
- nonrandomstring 2y agoAren't HikVision the ones banned by many governments because they have dodgy "call home to China" firmware? Persoanlly I go with the Eyeball Entities Omnicam with an Omniscient Systems Xcam-REAM control centre [0]. [0] https://cybershow.uk/media/ads/cctv-ads.mp3 https://cybershow.uk/media/ads/cctv-ads.mp3
- paranoidrobot 2y agoEven if it does have phone-home functions, why does the camera itself need internet access? IMO, audit the hardware for wireless radios (PoE cameras shouldn't have them), and put them on a camera-only VLAN that can only talk to the video server. Maybe not suitable for super secure TS locations, but in general should be fine for 99% of situations.
- nonrandomstring 2y agoI think if you've got total control over them, not a problem compartmentalising. Problem is, they're like loitering munitions, next person comes along and connectes them up to a router or misconfigures a firewall... Much as I hate e-waste sadly best place is in the bin. They're cheap but, easy come easy go.
- VTimofeenko 2y agoReolink have not disappointed me so far. I am using a duo 2 cam watching over the front of the property and a collection of their bullet cams. There's a lot of recommendations on frigate github discussions. Some models indeed have quirks. On top of decent cameras they also have pretty well-documented API.
- arrdalan 2y agoA fully isolated setup on a dedicated network can certainly provide good privacy. A key benefit of Privastead is that it can send the videos to your smartphone remotely using a strong (MLS-based) end-to-end encryption. And I share your excitement about Rust. :-)
- VTimofeenko 2y agoThe remote access part can be solved by wireguard or tailscale for less hands-on approach. Ntfy.sh/telegram/whatever cool kids use these days for notifications. This and my previous comment probably amount to a full Dropbox comment now :) Can you elaborate on the sending video part -- do you transfer the whole file or a link to the file on the server? Curious about the replication piece I mentioned
- arrdalan 2y agoPrivastead uses end-to-end encryption between the hub and the app. The hub encrypts the whole video file and sends it (through an untrusted server) to the app. The app will have a local copy of the video. The hub deletes the video upon delivery to the app. The server never has access to the unecrypted video.
- tehlike 2y agoWebRTC might provide a good way to handle this.
- arrdalan 2y agoYes, indeed. Using WebRTC and MLS together should provide good performance and privacy. In fact, Discord recently did that: https://discord.com/blog/meet-dave-e2ee-for-audio-video https://discord.com/blog/meet-dave-e2ee-for-audio-video It's something I plan to look into at some point.
- windexh8er 2y agoI've been using locally hosted NVRs going on two decades now and so I definitely appreciate another local NVR option. But given the current lack of common requirements (e.g. more than 1 camera), curious if you're seeing any usage outside of your own? As others have mentioned Frigate is filling a nice gap for many, currently. I can only connect to it via a VPN I control and I can easily get notifications via Home Assistant. I feel as though I have protection of getting the feeds to my phone securely, already. And while I'd love to be able to trust exposing Frigate and making it more accessible, I really don't have a need nor would I as the barrier to entry is already low enough to not impose much friction. My intent isn't to dissuade you (obviously you wrote it for yourself) but I'd be curious if implementing a more secure transport in an existing OSS NVR that has traction was something you considered?
- deleted 2y ago[deleted]