Hacking a $30 IoT camera to do more than it’s worth
hackernoon.com
hackernoon.com
Basically, the company gets a bunch of people to do work for free, the product gets improved, the company makes profit, everybody wins.
And boom, current state of affairs.
We should really value companies that actually make products you can take control over, rather than blindly relying on lack of security to being able to do what we want. Intent is quite important. It also sends a strange message when lack of security is seen as something good.
Now I don't have any criticism/knowledge about this product or xiaomi in general. IP cameras are generally quite overpriced in my uninformed opinion and you still almost always get locked into the cloud. So I really welcome this hack.
If the company sets out to create an open platform and has a business model which works in that world, that is a beautiful thing.
Is that the case here and are we seeing a virtuous cycle, are features contributed back to the company and actually integrated into their product? I think that’s a beautiful model but I’m not sure that’s actually what’s happenning here?
Literally the first sentence of the article;
“...its price is cheap but in exchange you are tied to the Xiaomi’s Mi Home App & Cloud.”
It also happens that Xiaomi later releases products which actually compete with their partners (in this case yeelight and their bedside lamps). Also the whole Yi Camera brand. First marketed with the help of Xiaomi and now a competitor to the Mijia brand (Xiaomis own brand).
(Citations and more insight needed, that was just from memory).
A couple other reasons:
* They want to sell the same product at different prices in different regions.
* They're concerned about copycat hardware vendors.
Hikvision (and I think Dahua) seems to want to prevent people from modifying their firmware; as far as I can tell it's for these reasons. I really wish they would just open it up. I'd love to put open source firmware on a decent outdoor IP camera. The vendors' own firmware is pretty lacking. It's untrustworthy (proprietary software from a Chinese company; how sure are you it doesn't have backdoors?), written insecurely (probably out of negligence rather than intent but again who knows), buggy in general, has mediocre motion detection (not sure I could do better on their hardware but I'd love to try), and has mediocre H.264 encoding (likewise).
If you choose them for their hackability, your core processors will probably have minimal development boards available for less than $2.50 each if you're using anything less powerful than a Cortex-M4 ARM core.
And now you have a huge part of your value proposition - the easy-to-use and user-configurable software - available for free. It will be cheaper for users to create their own version of your product unless you have some very complex or precise supporting hardware. End users will get a fun learning experience and customized product if they don't buy from you, and 3rd-party wholesalers will undercut you quickly and viciously.
So, hopefully your marketing department can pull at peoples' heart strings enough to make up for the order of magnitude difference in price. It works for companies like Adafruit and Sparkfun because they give back and people appreciate that, but how much room is there for companies that rely on goodwill to keep running?
There is a large exception for anything with a camera. Everything to do with the chipsets or sensors is under NDA and inaccessible unless you want to produce thousands of devices. I would love to be able to play with (say) a half-decent 2 year old camera chipset+sensor, which would apparently cost just a few $, but it's a no go.
For instance, the Raspberry Pi camera is entirely handled by closed-source blobs on the CPU and GPU. The best you can do is get cheap USB webcams from China for $20-30, but they're power hungry and you can't run them from a microcontroller.
I maintain a list of such things. It's amazing when I researched, there is not a central place that does it.
I can recommend the FP2, if you can afford it, since its a tad expensive. Esp for the out of date hardware. But it is unfortunately not all open firmware. Then again, is there any 4G phone out there with open firmware? The FP3 should be out within a year. We gotta see what it'll have in store.
Anyway, nice list. Maybe mention the open source router firmware such as OpenWrt (EDIT: oh, you did. Well, LEDE merged w/them recently). PC-Engines APU(2) [1] also supports Coreboot. There's also a plethora of Raspberry Pi clones out there, many of which run AllWinner which is a PITA.
FP2 is a respectable piece of hardware, by the way. I just never had it because I am too poor.
Fwiw, I recall that this is exactly how Dropcam started: they reverse-engineered the firmware for (iirc) an Axis net cam, then provided their own.
https://github.com/EliasKotlyar/Xiaomi-Dafang-Hacks/blob/mas...
Has anybody worked on above issues ?
A properly thought-out wireless system is the second-best way.
This might consist of P2P links, multiple access points, etc. over the subject property.
That's not to say this is expensive, check out Ubiquiti and Ruckus products for examples of the kinds of radios you need to make this happen. All should fairly affordable in comparison to renting a trenching tool and dropping cable.
I use engenius WAPs, a 100Ah battery, 2 100W solar panels, a $15 solar charge controller, various buck/boost converters for other power requirements. The system also powers an LTE repeater and LTE modem, to provide the farm with internet access.
It was like $25 on Amazon, pretty good deal I think.
Got the rtsp stream connected up to smartthings and blue iris and have had zero trouble with them.
They're only $20 if you order from wyze.com
That being said if you have a video server like MotionEye or maybe Smarthome has it (that was mentioned before), you can likely do some alerting based off that. I know MotionEye has email alerts and might have some other alerting that I don't use.
EDIT: currently 2-3 weeks backordered on wyzecam.com and out of stock on Amazon.
If you bought one, all the "hacking" required is inserting a MicroSD card with a custom firmware on it and pressing and holding the camera's reset button to flash the custom firmware. From then on, the camera has the ability to boot from your MicroSD which can contain services that allow the camera to stream to local clients, among other things. More detailed instructions in the article.
Recently bought a Nest camera since it seemed like a DIY approach was going to be harder than I thought. Might end up returning it if I can get this to work how I want.
In there lies a hidden threat. Possible from a tiger nation state.
Xiaomi has consistently shown that they don't care about security (or at least consistently enough that they have lost my trust).
* Xiaomi android phones had some kind of analytics APK built in around 2016 that would send a shitload of data over HTTP to their servers, and even would allow downloading emergency updates over HTTP. Their "fix" was to enable HTTPS, but leave the ability to force downloads and continue to run the analytics programs on the phones.
* Their robot vacuum used a password of "robotrock" to encrypt and sign updates.
* Their "yeelight" smart-bulbs were recording audio and sending them back to their servers over HTTP.
* Their "air purifier" also sends analytics and does updates via HTTP without any signatures.
IIRC many of these were fixed at some point, but I know at least once they said (paraphrasing) "we aren't going to fix it because the device isn't capable of HTTPS", but I don't remember which device it was. And it's enough for me to understand that they don't seem to take data privacy and security very seriously at all.
The surveillance threat is one that applies to any cloud-linked device, sadly. As a non-Chinese living outside of China I almost mind surveillance by China less; what are they going to do with it, after all? (Unless you count the Mariott guy they got fired?)
We would like to know if it's due do an actual "the cat wake up to go eat/play/whatever" or it's just "the cat is scratching itself"
so with that camera we could image the camera always recording a stream (or by chunk) and when a move over the threshold is detected, it call something on the camera it copy somewhere else the last N minutes so we can analyze it without staying up all nigh :)
It enables you to add more intelligence to your home automation because not only can it detect motion, if you offload the processing, it can enable object recognition.
So your cat doesn't trigger it. Or triggers a different action.
Because you can control the IR leds and filtering, you can mount it in a dome for ultra-cheap external pan and tilt with an external IR illuminator.