Family traumatized after Nest system hacked by stranger
fox4kc.com
fox4kc.com
I know we've moved as a society fairly quickly from expecting users to generate entropy to something that is actually secure. So it's understandable that some companies lag behind.
But Google is attempting to connect everything they can to the internet. If the bar for them isn't to at least prevent the easiest, most obvious hack from causing catastrophes then we're living in an idiocracy.
A user reusing passwords is bad. But in a civilized technological society the consequences for doing that cannot be a disembodied voice appearing communicating with one's child to give them nightmares.
Google's security teams surely know you can't "educate the user" to stop reusing passwords. If their official response is, "We did the right thing by suggesting two-factor authentication," then it doesn't matter how many engineers they throw at the problem.
Evil is afoot.
Still low quality, but for different reasons.
Alright, maybe I'm being a little extreme or cynical, and my goal here isn't victim blaming, clearly this sort of thing should not have to be a concern for people, but still... Don't they have a duty to understand what they're exposing their children to? Then again I've been tech savvy since I was like 11 years old (23 now) so maybe it's just easy for me to say. I just can't comprehend simultaneously having children and not understanding technology.
Subtly, Nest did not actually claim that the attacker had a correct password. For all we know this instance was a breach.
Seriously, though, my neighbor's entire house is wired up. His lights, his camera / security system, his shades, his music player, his TV... just about everything is integrated into Alexa. It boggles my mind why an otherwise intelligent person would do this.
A camera pointing at your face hooked up to the Internet should be assumed to be broadcasting that information to the world.
We know this intuitively. Humans dislike eye contact from strangers because of what it implies. Cameras don't hit the same basic reflexes (likely because we've optimized them that way).
If we haven't done a good enough job of educating users on that, we need to address it. The UK Government run cybersecurity adverts occasionally. I don't think they go far enough.
I tell everyone I encounter to assume the worst case unless proven otherwise.
The purveyors of a commercial product aren't going to detail these things unless forced. See 'everything else ever' - food, drink, medicine, ...
My millenial girlfriend, my youngest siblings and cousins, etc., don't seem to be aware; nor do they have the same ideas of rudeness/politeness with camera use that I have.
I think the real solution will be for Android and iOS to eventually have 2FA so integrated that any app can use OS APIs to implement it.
Not affiliated with either company.
I didn't see anywhere in the article that says Google promised that, and from what I know of security that's impossible. The article did say Google offered a way of increased security, an answer the consumer neglected to use and says isn't enough. (edit - says with absolutely no knowledge on the subject that 2FA isn't enough)
In your opinion, what should Google have done differently here? And where did you see that Google promised no one would be able to log in if that person had the correct username and password and 2FA wasn't enabled?
Are your parents tech wizards? How about your grandparents?
Generational differences aside, pretty much everyone is clueless about some aspects of technology. You call yourself tech savvy, and I don't doubt you're correct, but I do doubt that your knowledge has no holes. Mine has plenty. And of course the general population's knowledge skews much thinner than HN readers. Many are on the Internet nearly every day of their lives, but ask them about something outside of the few select apps they use, and you're greeted with blank stares. Whether or not they have children is pretty much irrelevant. Giving birth may trigger some instinctive behaviors that come with a certain functional knowledge, but the layers in the OSI model aren't generally included.
I guess Fox 4 KC didn't want to implement the GDPR… But what happens with the GDPR if I, a European citizen in Europe, access this website (blocking EU IP addresses) using a VPN?
The heuristic they use (IP address = country on which the user lives) is not a perfect method to assess whether they need to apply the GDPR regulation.
But I think this is the same event: https://www.dailymail.co.uk/news/article-6338113/Familys-Nes...
That’s because archive.is crawlers are hosted in Netherlands, Europe.
LONG ISLAND, N.Y. -- A mother in Long Island says a stranger hacked her family’s Nest camera and tried having a conversation with her five-year-old son, according to WPIX.
Nest ads will show you beautiful images of mother nature captured on their outdoor cameras, life’s silly moments and even those moments when your child is up to no good. But for this Long Island mother, the Nest cam she and her husband set up around their home to act as a nanny cam became a full-on nightmare.
“My son came running out of the playroom and found me in the kitchen and said 'it’s not daddy talking to me. It’s not daddy.'”
Nearly every day, after school, this mother, who asked PIX11 to hide her identity, said her 5-year-old son chats with her husband through the Nest cam, a home monitoring system users can connect through their cell phones. This time, however, it was a complete stranger on the other end.
“He asked my son if he took the school bus home and he was asking him about the toys he was playing with and when my son said 'mommy, mommy,' he told him to shut up,” she recalled.
When she walked into her child’s playroom, the ominous voice addressed her directly.
Now she is frightened and wonders how long a complete stranger was watching her family. Since this frightening violation, this mother called police, who, while sympathetic, said there was little they could do.
As for Nest? She was simply told to change her password and switch to a two-factor verification when logging on, but for this mom it’s not enough. She wants to speak out to warn others about this potential danger lurking in their home.
A Nest spokesperson responded to our request for comment and issued this statement:
"We have seen instances where a small number of Nest customers have re-used passwords that were previously exposed through breaches on other websites, and made public. None of these breaches involved Nest. This exposes these customers to other people using the credentials to log into their Nest account. We are proactively alerting affected customers to reset their passwords and set up two-factor authentication, which adds another layer of account security. Customers can reach out to Nest customer support with questions or report anything suspicious to security@nest.com."
So, yeah, if the odd EU-based client like me decides to VPN/Tor their way in, then legal action against the site operators for not dealing with my data appropriately shouldn't stand up.
Just a guess. IANAL.
I think the content you're seeing, "Sorry, this content is not available in your region." is an implementation of GDPR compliance, no?
Of course it does! It's their website. You don't have some god-given right to view fox4kc.com on your own terms.
WDAF Kansas City, is a Fox affiliate located out of Missouri state.
GDPR is an EU regulation, not a global regulation, nor a US regulation. The EU and GDPR has no legal standing over most media companies in the US and very few US Web sites, because they do no business in the EU and are not bound by EU laws. It does not matter if you're an European citizen in Europe or not, if GDPR does not apply to the owner of the server you're accessing.
If I - an American citizen - access a server in China, US laws are not what govern what they can do with my information. That is governed by Chinese law.
The US government apparently has a different interpretation. For example, they asked Microsoft for the information of a user from the servers in Ireland.
Then everyone involved (except the lawyers, who will make out quite well) can risk getting wiped out as the EU’s extraterritorial application of privacy regulation and the US’s civil and criminal laws on unauthorized access combine into a firestorm of transatlantic litigation.
[1] I'm happy to see in my personal experience that even my non-technical friends are starting to use password managers. [2] According to https://hackernoon.com/why-do-most-people-ignore-two-factor-..., "less than 10 percent of active Google accounts use two-factor authentication. Furthermore, as per findings of the Pew Research Center, password managers are only used by approximately 12 percent of Americans." If people aren't using 2FA for their gmail account, which is arguably the most important account to protect, then they probably aren't using it anywhere else.
I remember a story about someone getting an absurdly long prison sentence for guessing a simple password to a secure system.
Hacking only specifies the knowing and intentional circumvention of an authorization system. It doesn't place a value on how easy it was to do it.
> "We have seen instances where a small number of Nest customers have re-used passwords that were previously exposed through breaches on other websites, and made public. None of these breaches involved Nest.
It's surprising how many people reuse their password or use unsafe passwords. Including my own family.
Unfortunately, they do not provide "true" 2fa, only through text message.
On one hand, it's easy to dismiss this as the nest owners being naive with internet security. This is incident was easily avoidable if the owners had put in the tiniest more effort. I think it's _fair_ to expect people who own these devices to know the basics about how to not get exploited from it.
On the flip side, although I think that knowing the basics is a _fair_ expectation, I don't think it's _pragmatic_. These devices are only going to get more powerful in their abilities, only going to get more ubiquitous in their distribution, and only going to get more opaque as to their inner workings. I don't think it's unreasonable that manufactures _force_ a higher level of security on such devices.