Zero-Day Bug Allows Hackers to Access CCTV Surveillance Cameras
threatpost.com
threatpost.com
Recently I watched a news segment in Korea about CCTVs connected to the internet without proper security: so many were wide open, and some could even record sound and play it real-time, and their lists were plainly accessible on some websites. The reporter said that the government had responded by blocking these websites from the Korean internet but people still found ways to access them via VPN.
As if that's the crux of the problem.
The mind boggles.
> Shodan is the world's first search engine for Internet-connected devices
Bonus if it has a mobile app/interface, my use case is video monitoring of my kids rooms while they sleep.
https://www.schneier.com/blog/archives/2016/02/eavesdropping...
So most people aren't going to bother unless they get an alarming email from the manufacturer (assuming they even have a list of customer email addresses). Although these appear to be DVR systems for commercial use so it's more likely that a business would have a service contract with someone to manage these things. The service vendor would probably be more inclined to patch the thing than the business owner would.
Not updating for X days just increases the risk from only zero-day exploits to the risks of X-or-less-days exploits.
I look at cheap camera modules and Linux boards.
I look some more at the mainstream security devices.
I look again at the cheap cameras and Linux boards.
Sadly, security cameras are among the most hackable targets on the Internet, because You™ haven't released that competitive solution you've been thinking about that prioritizes security over unnecessary bells and whistles. When you do, you'll corner that vocal fraction of the community you've always been wanting to meet.
It doesn't have to be a bureaucratic, incoherent, legacy-burdened headache built from clipboard-remixed vendor samples. Linux, no blobs, a couple lightweight services; and you're done. Remote access in the palm of your hand? Too easy. Anything is possible when you design without agendas.
--
Your plaintext passwords (which were also using in two other places - argh) just leaked from a vendor's stolen cloud database.
A HTTP URL hack that dumps the root password into the browser window surfaced seven months ago.
Another benefit is that updating a single instance of firewall or VPN software is much easier than updating dozens of cameras. Of course, if there are more VPN clients than cameras, that ceases to be true.
Adding such a layer is also just a kind of defense-in-depth. With the instant example, both the cameras and the VPN software (or firewall) would have to have vulnerabilities, at the same time.
(obligatory https://www.shodan.io/ link ;) )