Insecam: Large Directory of Unsecure Cameras
insecam.org
insecam.org
www.insecam.org/en/view/386702/ - Somebody's RSA keyfob with automatic button presser.
Edit: I guess you are right. It does seem a bit improbable that you would get such a good reading on the numbers. Definitely scary as fuck...
I've joked about writing an app on my phone that would just auto-respond to all the 2FA prompts with my PIN, and have been told that other people actually tried to (or did) implement such an application.
Meanwhile I was at a Googler's place a year ago and watched him tap a U2F device on the side of his laptop to complete the second factor. Sigh.
You mean you work there and accessing services or tools requires you to do 2FA every time?
I hope they are already planning to overhaul that because it does seem like a very cumbersome and insecure way of "securing" accesses.
I just bought one the other day for personal use, pretty cheap, cant say more becuase I have yet to receive it, but I have high hopes.
For at least 2 linux boxes I use, I needed to add udev rules for the yubikey. That wasn't immediately obvious and took a few minutes to figure out why it wasn't working.
If your payroll system has a web interface, you can have an applicative firewall in front replay your stored credentials as a hacky SSO (after checking your identity another way, of course).
And Kerebos does nothing for these 2FA woes sadly.
Could you explain more what you mean by this? Presumably it's not typing a phone into a PIN...?
Okta at least shows which app is requesting permission.
Instead, MS's 2FA send a notification to your phone where you type in a static, pre-defined PIN. There is no way of knowing what actor or application triggered the 2FA request.
An open door is not an invitation to trespass, especially when it has obviously been left open in error.
It genuinely feels like these devices are unintentionally intentionally left open.
The distinction is important, because an implication of secure-by-default means that the manufacturer has dropped the ball. If there's nothing to imply that the device is secure (as opposed to just providing 'security' via CCTV), then this is more a case of the installer of the device willingly, and knowingly, providing a live-stream of their property to the world.
I think part of the problem is that more and more technology products are being sold as "simple to use", although they might actually be really complex tools with far reaching implications not necessarily understood by the end users.
Compare this to, say, driving a vehicle. In most (all?) countries you need a driving permit which implies you have some training to operate said tool. In part because not knowing how to drive could cause damage and/or injury to third parties. And you also have some sort of liability if things go awry.
However consumer technology products are not considered as tools capable of damage (in most cases at least, e.g. computers, routers, phones, etc) and so the implication is that anyone can use them without proper training, since there's no way you can affect a third party.
Obviously those of us who have some sort of training realize that this is not the case, and so I would guess most HNers would secure their routers or Internet connected cameras (I hope...).
So in this context, can you actually blame those that have no training at all, to be doing "unsafe" things, especially since no one will tell them otherwise, including the manufacturer?
It's definitely a non-trivial subject.
Insecam has been around for over two years...
I can't think of a better analogy, but what if I had a Polaroid camera and go around taking pictures in my property and then throwing those pictures away on the street. If a stranger picks up one (or several) of those pictures, would you consider that trespassing as well?
I'm not saying I am for or against this, but it's definitely a tricky subject. Obviously part of that trickiness is because complex tools (for the general populace) are being sold as simple tools, and so people who buy them have no idea what they are capable of or what is the proper way of using them (securing them with a password, etc).
That's a lot of uncertainty to shoulder just for the joy of looking at someone's incidentally public camera feed.
- Only filtered cameras are available now. This way none of the cameras on Insecam invade anybody's private life.
http://www.insecam.org/en/view/376032/
This is...puzzling...
Edit: Ah... it says "You can play Zork and Ladder on this computer and watch as the LED flashes !"
Back then you could make an html file with one frame or iframe and point it to a website like this or embed a flash stream.
You could just embed this website and have random webcams as background and your icons and everything else would still work normally on top of your new "background".
Eventually the embedded IE would crash and you'd press F5 and it would fix itself.
That's a Foucault pendulum.
The pendulum on that feed belongs to the geophysical institute of the university of munich.
Eg. https://www.geophysik.uni-muenchen.de/outreach/foucault-pend...
http://141.84.11.4/view/viewer_index.shtml?id=1362
And this link lets you change the "feed profile"
The problem is if you let people try as many passwords as they want.
It's all a tradeoff. But a smart rate limiter is complex, and rarely necessary when you can be expected to have physical access to the device. Plus, these things haven't even managed basic security, why should we expect them to implement a good rate limiter?
Oh, and cheaper cameras support only mjpeg, which makes live viewing high-bandwidth.
What software/hardware do you use?
See: http://8ch.net/ipcam/index.html
for how people use Shodan and other tools to do some fairly shady things. It's like grey hat at best (find these things and move them around/leave messages to secure your cams) and serious invasion of privacy at worst (people trading caps of women undressing, people having sex, etc).
[0]http://www.insecam.org/en/view/392890/
[1]https://goo.gl/bG4sxk