Someone Is Taking Over Insecure Cameras and Spying on Device Owners (bleepingcomputer.com) 57
As security webcams, security cameras, and pet and baby monitors become part of our lives, their underlying technology is increasingly receiving scrutiny from researchers. Many of these devices are woefully insecure, and an attacker could -- and in some cases, has -- take over these devices to perform internet scans, among other things. BleepingComputer's Catalin Cimpanu dives into the subject: In the last nine months, two security firms have published research on the matter. Both pieces of research detail how the camera vendor lets customers use a mobile app to control their device from remote locations and view its video stream. The mobile app requires the user to enter a device ID, and a password found on the device's box or the device itself. Under the hood, the mobile app connects to the vendor's backend cloud server, and this server establishes connections to each of the user's device in turn, based on the device ID and the last IP address the device has reported from.
'Someone'? (Score:1)
This indicates that it's a rare or relatively small occurrence, when in reality this is happening by thousands of people at any one moment. Stop buying terrible insecure public-facing IP cameras!
Re: (Score:1)
And yours is in your head.
The other one.
Re: (Score:3)
When nobody can find the open networks, then the wide open IoT networks are not going to be accessed.
Nobody can design their own internet search engine to scan global networks.
Even if some smart person could design the method to run their own search engine they could not buy the bandwidth needed.
A person with the smarts and bandwidth would need a lot of time to collect such IoT data globally.
N
Re: (Score:3)
Re: (Score:2)
Re: (Score:3)
Re: (Score:2)
Re: (Score:2)
You mean shodan.io
https://www.shodan.io/ [shodan.io]
Re: 'Someone'? (Score:3)
I've installed Hikvision cameras in my warehouse. They are pretty neat cameras for the money, with h265 support and nice resolutions, saving you A LOT of data storage. But they are seriously unsecured. All of them are inside a VLAN that doesn't allow traffic to the internet or the rest of the network. Despite that, Hik-Connect works just fine through a VPN, so I don't know why you need this stuff uploading to the "Cloud".
But despite all these simple things you can do to secure these security cameras, nobody
Re: (Score:2)
Why? From the installer's point of view actually securing the cameras is a lot more work and raises the cost. Cost is the driving factor in the consumer's mind, and most consumers have no way to evaluate the security. So an installation that's actually secure costs much more than an installation that merely claims to be secure. A secure system also generates a lot more service calls. "Help! I lost m
Re: (Score:1)
so I don't know why you need this stuff uploading to the "Cloud".
The only real reason I've been able to come up with for why you want to upload your home security video to "the cloud" would be to have an off-site backup so you have a way to look at the video and see who burned your house down. A reasonable solution to that would be to have it periodically encrypt the footage and upload it to some general "cloud" storage solution where only you have the key to unlock it. Why anyone would want to have a camera in their home watching them all the time being uploaded and con
Re: (Score:2)
Quite. It's closer to everyone.
Unsecured (Score:2, Informative)
Please use the right term. I know the other can mean it but..ugh
Re: (Score:2)
Seriously, this should not have been downvoted.
That a request for precision in technical language is considered troll worthy on /. is about as sure a sign that we're gonna get that this place has well and fully jumped the shark.
Re: (Score:2)
This. Don't anthropomorphize cameras. They hate that.
Re: Foscam (Score:2)
And with the previous story (Score:2)
We now can have hackers tapping all those cameras in schools!
What's old is new again (Score:4, Interesting)
Spent the next couple hours opening up these brand new workstations and clipping a wire.
Why yes, I do have tape over my laptop camera. Why do you ask?
Re: (Score:2)
You could do that with SGI workstations as well. Login remotely, take a framegrab of the camera and record the microphone.
This story answers the question asked... (Score:5, Insightful)
... in the previous story: Should facial recognition cameras be in schools? [slashdot.org]
This is nothing new... (Score:2)
Re: This is nothing new... (Score:2)
No way? (Score:2)
You mean putting an always on, always connected streaming camera in your home is a privacy and security issue?
I just can't believe that.
"Someone"? (Score:1)
Harmless curiosity (Score:2)
So does Scarlett Johansson have a baby monitor?
Asking for a friend.
Re: (Score:2)
A buddy of mine used to set their baby monitor up in the rec room. It picked up the one in the house next door flawlessly.
Inaccurate description (Score:2)
i have 4 iot foscams (Score:2)