10 ms·
Wanted to spy on my dog, ended up spying on TP-Link
- micah94 1y agoSo we're at the point that finding hardcoded admin passwords is no big deal.
- j45 1y agoSmartphones can be seen by some as the initial hostile devices. Network devices can at least be monitored and discovered like this.
- xp84 1y agoI mean, given that it's updated after setup with the normal flow, I'm okay with it. The thing I've most been convinced of in the past 5 years of building as much 'iot/smart home' stuff out as possible in my house is that nearly every vendor is selling crap that has marginal usefulness outside of a 'party trick' in isolation. Building out a whole smart home setup is frustrating unless it's all from one vendor, but there isn't one vendor which does all of it well for every need. On my phone I have apps for: Ecobee, Lutron, Hue, 4 separate camera vendors[1], Meross, and Smart Life. Probably a couple more that I'm forgetting. Only Lutron and Hue are reasonable in that they allow pretty comprehensive control to be done by a hub or HomeKit so I never have to use those apps. It's been years since Matter and Thread were supposedly settled upon as the new standards for control and networking, but the market is, instead of being full of compatible devices, instead absolutely packed with cheap wi-fi devices, each of which is cloud-dependent and demands to be administered and even used day-to-day only through a pile-of-garbage mobile app whose main purpose is to upsell you on some cloud services. [1] I admit the fact I have 4 is my fault for opportunistically buying cameras that were cheap rather than at least sticking with one vendor. But many people have a good excuse, perhaps one vendor makes the best doorbell camera, while another might make a better PTZ indoor camera.
- hleszek 1y agoHome Assistant is making more and more sense to make your own fully local and private home automation system.
- radlad 1y agoAbsolutely. I've been using Home Assistant for around 6 years now and it's absolutely amazing for tying hardware from varying ecosystems together. Even if your hardware doesn't support local APIs, there's a good chance someone has made an HA integration to talk to their cloud API.
- borski 1y ago> Even if your hardware doesn't support local APIs, there's a good chance someone has made an HA integration to talk to their cloud API. And if they haven’t, you can pretty trivially write your own and distribute it through HACS (I’ve got three integrations in HACS and one in mainline now)
- xp84 1y agoThank you for your contributions btw! There is so much amazing work that's gone into HA and I appreciate it every day.
- borski 1y agoThanks, but it really is a community effort. Even the one I wrote the most of was still me and another guy (the Lucid Motors integration).
- joostlek 1y agoI'd love to see what's needed to get some of these integrations in core!
- xp84 1y agoI love it! But my setup has a lot of sharp edges. It's a combo of things where the "standards compatible" way to connect to HA lacks things like camera control, by dastardly vendors like Chamberlain who basically killed HA support for spite, and finally, by having to use Google or Amazon for voice assistants. My #1 wish would be for someone to build a HA-native voice assistant speaker. I'd pay $100 each for a smart speaker of the physical quality of the $30 Google Home Mini but which integrated directly with HA and used a modern LLM to decide what the user's intent was, instead of the Google Assistant or Siri nonsense which is like playing a text adventure whose preferred syntax changes hourly. I'd pay that plus a monthly fee to have that exist and just work.
- mtlynch 1y agoIt's a hardcoded default password, not a permanent backdoor. If I'm understanding the post correctly, the user changes it as part of the onboarding flow. This is the way most apps work if they have a default password the user is supposed to change.
- bri3d 1y agoThe device should ideally have some kind of secret material derived per device, like a passphrase generated from an MCU serial number or provisioned into EEPROM and printed on a label on the device. Some form of "enter the code on the device" or "scan the QR code on the device" could then mutually authenticate the app using proof-of-presence rather than hardcoded passwords. This can still be done completely offline with no "cloud" or other access, or "lock in"; the app just uses the device secret to authenticate with the device locally. Then the user can set a raw RTSP password if desired. This way unprovisioned devices are not nearly as vulnerable to network-level attacks. I agree that this is Not Awful but it's also Not Good. Right now, if you buy this camera and plug it into a network and _forget_ to set it up, it's a sitting duck for the time window between network connection and setup.
- yannyu 1y agoAT&T routers, for example, ship like this. There's a wifi network and a wifi password printed onto the device. But that also means then that often anyone with physical access can easily get into the device. The complicated password provides an additional layer of illusion of security, because people then figure "it's not a default admin password, it should be good". The fundamental problem seems to be "many people are bad at passwords and onboarding flows", and so trying variations on shipping passwords seem to result in mostly the same problems.
- some_random 1y agoIf you have physical access you can just factory reset the device and onboard it with the normal flow though
- some_random 1y agoHard coded admin passwords that you have to change in order to start using the device aren't really an issue.
- jama211 1y agoWell, they aren’t here though.. I feel like you just wanted to be annoyed at this tech
- HexPhantom 1y agoHardcoded admin creds should've gone extinct with Flash-based websites, but here we are
- gnabgib 1y agoSomewhat related: The Tapo C200 research project https://drmnsamoliu.github.io/ https://drmnsamoliu.github.io/ (https://news.ycombinator.com/item?id=37813013 https://news.ycombinator.com/item?id=37813013) PyTapo: Python library for communication with Tapo Cameras https://github.com/JurajNyiri/pytapo https://github.com/JurajNyiri/pytapo (https://news.ycombinator.com/item?id=41267062 https://news.ycombinator.com/item?id=41267062)
- tripdout 1y agoAlso somewhat related: (TP-Link Firmware Decryption C210 V2 cloud camera bootloaders) https://watchfulip.github.io/28-12-24/tp-link_c210_v2.html?utm_source=feedly https://watchfulip.github.io/28-12-24/tp-link_c210_v2.html?u...
- huflungdung 1y ago[dead]
- GuinansEyebrows 1y agoThank you for including the final part about what your dog has been up to :)
- ssgodderidge 1y ago> "She sleeps" The fact that OP did all this work to find out the dog sleeps is pure hacker culture. Love to see it :)
- 201984 1y agoAre techniques like using Frida and mitmproxy on Android apps still going to be possible after the signing requirement goes into effect next year?
- bri3d 1y agoOverall: yes, but it will get much harder for apps which need attestation, which is sort of the point, for better or for worse. As far as I know you'll still be able to OEM unlock and root phones where it's always been allowed, like Pixels, but then they'll be marked as unlocked so they'll fail Google attestation. You should also be able to still take an app, unpack it, inject Frida, and sideload it using your _own_ developer account (kind of like you can do on iOS today), but it will also fail attestation and is vulnerable to anti-tampering / anti-debugging code at the application level.
- josteink 1y agoSo for people with any practical needs what so ever (like banking): No. At this point Android isn’t meaningfully an open-source platform any more and it haven’t been for years. On the somewhat refreshing side, they are no longer being dishonest about it.
- bri3d 1y agoI don't think any vendor should be solving for "I want to do app RE and banking on the same device at the same time;" that seems rather foolish. These are sort of orthogonal rants. People view this as some kind of corporate power struggle but in this context, GrapheneOS, for example also doesn't let you do this kind of thing, because it focuses on preserving user security and privacy rather than using your device as a reverse-engineering tool. There is certainly a strong argument that limiting third-party app store access and user installation of low-privilege applications is an anticompetitive move, but by and large, that's a different argument from "I want to install Frida on the phone I do banking on," which just isn't a good idea. The existence of device attestation is certainly hostile to reverse engineering, and that's by design. But from an "I own my hardware and should use it" perspective, Google continue to allow OEM unlock on Play Store purchased Pixel phones, and the developer console will allow self-signing arbitrary APKs for development on an enrolled device, so not so much has changed with next year's Android changes.
- Gualdrapo 1y agoGot one for my house but what really annoyed me was that I wasn't able to set a fixed IP for it
- hank808 1y agoOn your dhcp server (probably your router/gateway), statically assign (reserve) the camera's MAC address to the IP that you want it to have. Sometimes called MAC binding.
- crazysim 1y agoSome of them support it but not all.
- xrd 1y agoReally? Mine has a switch for static. You aren't seeing that in the app? Configuration -> Advanced settings -> Network
- BLKNSLVR 1y agoConfirmed here. I've got four of them, and they all have this setting. I know because I changed them from DHCP reservation to static IP recently.
- xrd 1y agoAre any of these outdoor cameras? Do you use rtsp if so? I'm trying to find an outdoor camera that supports frigate and surprised my new c402 does not.
- pooloo 1y agoUnrelated, but I wonder if the OP's dog moves from the bed to the floor because the radiator turns on? might need more sensor data :D
- jama211 1y agoOr just because she noticed she was cold
- serf 1y agogo2rtc is great. the compatibility range it offers is just huge and gets rid of 90% of the difficulty in making a decent NVR app.
- ComputerGuru 1y agoAnyone have a similar fix for Yi/Kami cameras?
- bstsb 1y agoreally like how this blog is written. a lot of writeups like this recently have been generated by an LLM, and it's quite distracting to read - this was a pleasant surprise. it strikes a good balance between technical and laid-back (yes i know the cover image is AI-generated, that's incidental to the content)
- jraph 1y agoI've been blocking by default bigger media files with uBlock Origin to avoid needless resource usage. Cover images are typically blocked, and they are usually useless anyway. It's too bad people spend energy for generating them now.
- concats 1y ago>> It's too bad people spend energy for generating them now. How do you mean? Some quick back of the napkin math. Creating a 'throwaway' banner image by hand, maybe 15 minutes on a 100W CPU in Photoshop: 15 minutes human work time + 0.025 kWh (100W*0.25h) Creating a 'throwaway' banner image by stable diffusion on a 600W GPU. In reality it's probably less than 20 seconds to generate, but let's round it up to one full minute of compute time: 5 minutes human work time + 0.01 kWh (600W*(1/60)h) The way I see it it seems to spend less energy, regardless of whether you're talking about human energy or electrical energy. What's the issue here exactly?
- jraph 1y agoYou can't take the human energy in account, because there's no reason to believe they won't live for the same amount of time and use the same amount of energy regardless. You are not accounting for the model training (which can't be ignored, first because you can't ignore fixed costs, and second, because we keep training newer models, so amortizing doesn't quite work), rebound effect, the subsidized bot crawling, etc. I won't comment further on this, this discussion has been rehashed to death anyway and in better ways that I can. IMHO the better way is to not do meaningless cover images, and this is also true of stock, non-AI generated images (I'm not against art, so if it's your strength, by all means, please do meaningful or nice cover images).
- pessimizer 1y agoThe cover image is a 2.8M png, if the author is reading. I gave up my github account so cannot comment.
- kennedn 1y agoNow a ~300kB webp, thanks.
- awilson5454 1y agoOof, I need to go through my personal site and resize some images. I never considered that. Also, fantastic write-up
- deleted 1y ago[deleted]
- ck2 1y agotapo annoyingly is also one of the only cameras that doesn't have a still snapshot url after all these years and endless requests from many someone needs to make replacement firmware ffmpeg can fake it but takes a few seconds to grab from the video stream and of course you can't run ffmpeg from your browser (or wait, can you now?) ffmpeg -rtsp_transport tcp -i "rtsp://cameraname:camerapass@192.168.1.23:554/stream1" -an -y -vframes 1 -f image2 -vcodec mjpeg "snap.jpg"
- deleted 1y ago[deleted]
- g-mork 1y agotry reducing your buffer size and -probesize to help with that delay (and/or optionally fixing the video format parameters so probing isn't needed at all)
- fnord77 1y agoThey cracked the APK to get the default password, but googling for it I see it is in a CVE from 2022 https://nvd.nist.gov/vuln/detail/CVE-2022-37255 https://nvd.nist.gov/vuln/detail/CVE-2022-37255
- downrightmike 1y agoMon key toge ther strong
- pimterry 1y agoOh awesome, this is using my Frida scripts! These: https://github.com/httptoolkit/frida-interception-and-unpinning https://github.com/httptoolkit/frida-interception-and-unpinn.... Nice project, great to see the scripts doing good work in the wild. If you needed any extra additions or tweaks to get them working, I'd love to hear about it.
- stavros 1y agoHTTP Toolkit is fantastic, great job Tim!
- cute_boi 1y agoHttp toolkit is one of the best software i have used. I have used mitmproxy, proxyman and charles proxy and httptoolkit is the best and is open source too.
- kennedn 1y agoThey worked amazingly out of the box, thanks Tim! The command I used in the end was just a subset of the example given in your repository: frida -U \ -l ./config.js \ -l ./android/android-proxy-override.js \ -l ./android/android-system-certificate-injection.js \ -l ./android/android-certificate-unpinning.js \ -f com.tplink.iot
- rcarmo 1y agoEvery single post on this site is worth reading. Loads of fun with hacking electronics. :)
- johng 1y agoInteresting... from the terminal I see he named his laptop the same thing I've named one of my cheaper laptops too... craptop. LOL.
- selinkocalar 1y agoIoT security is generally terrible, but the fact that consumer routers are essentially unaudited black boxes processing all your network traffic is genuinely concerning. Most people have no idea their router firmware hasn't been updated in years and is probably running known CVEs. The supply chain trust model for networking hardware is broken.
- teaearlgraycold 1y agoThe solution is pfsense
- arminiusreturns 1y agoThe soulutions is iptables. The solution is nftables. The solution is bpf. The solution is emacs-m-x-butterfly-bpf.
- baby_souffle 1y agoOr openWRT. The bsd based distributions sure are powerful, but with the power/heat budget to match.
- bmurphy1976 1y agoI love me some OpenWRT but updating it has always been a risky chore.
- fignews 1y agoCheck out attended sysupgrade
- nuker 1y agoBetter go OPNsense
- drnick1 1y agoActually, pfsense kind of has a shitty reputation in the FOSS community and opnSense is preferred. But I don't like the limitations of BSD systems in terms of hardware compatibility and performance, so I build my router using a plain Linux distro (Debian).
- levid042 1y agoYes Pls I'm begging u
- BLKNSLVR 1y agoI tried and failed at enough suggestions I found on the internet and via AI to cobble together a frigate configuration that eventually worked with the Tapo cameras. RTC setup section: go2rtc: streams: <Camera RTC name>: - rtsp://tapoadmin:<local camera account password>@<camera IP address>:554/stream1 - ffmpeg:<Camera RTC name>#audio=opus - tapo://<Tapo cloud password>@<camera IP address> <Camera RTC name>_sub: - rtsp://tapoadmin:<local camera account password>@<camera IP address>:554/stream2 - ffmpeg:<Camera RTC name>_sub#audio=opus - tapo://<Tapo cloud password>@<camera IP address> Main section: <Camera name>: ffmpeg: output_args: record: preset-record-generic-audio-aac inputs: - path: rtsp://127.0.0.1:8554/<Camera RTC name>_sub input_args: preset-rtsp-restream roles: - detect - path: rtsp://127.0.0.1:8554/<Camera RTC name> input_args: preset-rtsp-restream roles: - record - audio detect: enabled: true width: 640 height: 360 fps: 7 live: streams: <Camera RTC name>: <Camera RTC name> record: enabled: true retain: days: 0 mode: all Where: * <Camera RTC name> is just any old short name you want to assign to the camera. * <Camera name> is the main name for the camera that will be shown in the frigate UI * <local camera account password> is something set individually on each camera (settings > Advanced > Camera Account, set it to On and setup username/password > Account Information) * <Tapo cloud password> is the password setup for the Tapo app (I'm not sure how necessary this is, since there's nowhere that the username is specified... this is the only bit I'm fuzzy on) This is the basics that works for me for the Tapo cameras. There are a boatload of other settings specific to Frigate (but not specific to Tapo cameras). This is nowhere near as cool hack as the article, however.
- xrd 1y agoDo you use an outdoor camera with this? I'm trying to find one and my c402 does not appear to have that support.
- BLKNSLVR 1y agoSorry no. I use Reolink's for outdoor. The Tapo's are all indoor C210/C211 (cheap, but do the job just fine). Looks like the C402 has two different hardware versions[0] so maybe the old one doesn't work but the new one does? A firmware upgrade might also be worth trying. This reddit page suggests trying ONVIF as the go2RTC connection[1]. Good luck! [0]: https://www.tp-link.com/us/support/download/tapo-c402/ https://www.tp-link.com/us/support/download/tapo-c402/ [1]: https://www.reddit.com/r/frigate_nvr/comments/1liosei/tapo_cameras_frigate_tapo_app/ https://www.reddit.com/r/frigate_nvr/comments/1liosei/tapo_c...
- xrd 1y agoDoes anyone have a good reference for which tapo cameras support rtsp? I have a c210 that works well (sort of, you can't use it with their cloud capture) and I have it working with frigate. But today I got a c402 (outdoor) thinking I could use it to capture my son's soccer practice. But that doesn't have the camera account option under advanced. I love the price point of these devices but the functionality is all over the place. If anyone knows a good outdoor camera, preferably with solar panel, that is cheap and has an rtsp stream, please let me know.
- kennedn 1y agoYou should still be able to use the tapo:// go2rtc stream source even if the camera does not support the rtsp:// via the camera account option. Have a look at my frigate configuration for reference - https://github.com/kennedn/frigate/blob/7c56604e819d2cb1da284b402d6df74645b3752e/values.yaml#L61-L63 https://github.com/kennedn/frigate/blob/7c56604e819d2cb1da28...
- xrd 1y agoFantastic. Why do you use rtsp for some streams and then tapo protocol for others? Are these all tapo cameras?
- bayesianbot 1y ago> SIDENOTE: If you want 2 way audio to work in frigate you must use the tapo:// go2rtc configuration for your main stream instead of the usual rtsp://. TP-Link are lazy and only implement 2 way audio on their own proprietary API. Annoyingly when this is in use, I can't use ONVIF which seems like the only way to pan and tilt the camera using open tools. So if I want to use two way audio and also control the camera, I have to stop the process reading tapo:// stream, start onvif client and rotate, turn off onvif client and start streaming using tapo:// again
- ChaoPrayaWave 1y agoI know people who are still using the router their ISP gave them, and they’ve never even changed the default password. The thing is, they don’t even know it can be updated, let alone that there might be security vulnerabilities. To most users, if the internet works, that’s all that matters.
- TeMPOraL 1y agoAs it should be. The problem is that for ISPs, "Internet works" is defined as minimum possible service level that doesn't cause active revolt of majority of customers. Good hardware? Costs money. Connecting to anything that goes beyond Netflix and Facebook requirements? Costs money, operations isn't cheap. Anything unusual (so much so as being seen borderline criminal) as hosting your own server, email, or $deity forbid networking hardware? Forget it, support costs money. And so on.
- cleartext412 1y agoHacking together something usable out of cloud-first piece of hardware you ended up with is respectable, but I would like to bring up another option to go with if you're choosing a new device: buy camera that doesn't require a phone app to initial setup and serves RTSP out of the box.
- roygbiv2 1y agoWhat cheap camera doesn't require a phone app and serves RTSP out of the box?
- cleartext412 1y agoNote that I didn't say "cheap". If price difference comes from manufacturer's hope of selling its cloud service, then the time and effort required to set it up is not worth the money. If I were to solve one-time task of keeping an eye on someone indoors I would go with USB camera (if lighting conditions allows even the laptop's build in), which is going to be cheaper than ones with IP and WiFi support.
- ur-whale 1y agoI used to get in the kind of frustrated situations where, like the author, I spent two days reverse-engineering something I had just bought just to get it to do what I thought it obviously would when I bought it. IOT things like the thing he bought are (were) typically the worst kind of offenders. I just don't do that anymore. It used to bring me pleasure cracking the nut, and that's not the case any longer. These days, if it does not do what I need more or less out of the box, I just return it / send it back and research the follow-up buy better.
- marcosscriven 1y agoSide note - “full-proof” is an eggcorn of “foolproof”.
- NoPicklez 1y agoAnd eggcorn means "a word or phrase that results from a mishearing or misinterpretation of another, an element of the original being substituted for one which sounds very similar (e.g. tow the line instead of toe the line )." I'd never heard of it before
- otikik 1y agoVery nice project and writeup. I wish there was a repository of "appliances that don't try to shove an app and a subscription down your throat"
- h4ch1 1y agoI mirror this sentiment so much as well. Not aware of a list or something, but before buying any appliance I try searching if it's "jailbreak-able". For example I'll search if the router I want to purchase has guides to install openWRT on it, how hard it is to break out of the vendor software loop. Recently even my Aircon had a mandatory app that it required to even finish installation. I got so pissed I dumped the firmware and reverse engineered the protocol enough to figure out how to set fan speed, temperature and mode. Sitting in the sweltering New Delhi heat really expedited the process.
- HexPhantom 1y agoAt this point, I'd pay extra for a camera, thermostat, or doorbell that just does its job without demanding an account, a cloud link, and a monthly fee to unlock basic features
- deleted 1y ago[deleted]
- mijoharas 1y agoIf the author is here, did you find a way to prevent the tapo from trying to connect to the internet every 20s? (I just blocked it's access, but it's annoying to see it all the denied requests in my router logs.) I'm guessing not, and it's not really an issue since it can be used entirely locally without, but it's still kinda annoying.
- wpm 1y agoI love little projects like this, but man does this make me glad things like Thingino exists. Installing the firmware takes like 5 minutes, a little self-hosted web configurator pops up, you put in an SSID and a password, the camera reboots, and its yours. We should not have to reverse engineer crap like this. https://thingino.com https://thingino.com
- gslin 1y agoThe password `TPL075526460603` is also mentioned in CVE-2022-37255[1]. [1]: https://nvd.nist.gov/vuln/detail/CVE-2022-37255 https://nvd.nist.gov/vuln/detail/CVE-2022-37255
- HexPhantom 1y agoThis is the most gloriously overengineered way to find out your dog naps all day, and I respect the hell out of it.