Read this blog series about Wyze, and then make up you mind if you are comfortable having that piece of hardware in your home. I think it is pretty clear the risks are not trivial.
Read this blog series about Wyze, and then make up you mind if you are comfortable having that piece of hardware in your home. I think it is pretty clear the risks are not trivial.
They are a great cheap option when using their custom RTSP firmware with synology surveillance stations. I throw them on their own SSID that is isolated from other local networks and does not have internet access. The SS can reach into their network but they can't initiate connections out.
Still they briefly need internet when setting up to enable RTSP but I'm more concerned about them being remotely accessible at anytime and having access to anything else on my network. Even my setup would allow my email and the isolated network's topo to leak bc of brief internet access.
> Yi Camera is a front for the Chinese Ministry of State Security. Full stop.
> Yi Cameras send all customer data to Xiaomi as I have previously claimed with Wyze.
Honestly I’m not familiar with the Yi cameras, I haven’t read that newest post, I’ll have to look into it. But, 12 Security is credited with disclosing the 2nd Wyze security breach in December 2019 (the 1st one not even a full calendar year before).
Wyze reluctantly admitted the breach days later, but went into damage control mode, claiming the DB was only exposed for part of the month of December. 12 Security says otherwise, that it was exposed for the majority of the calendar year, and many parties across the globe accessed it according to logs.
https://web.archive.org/web/20200306023236/https://www.nytim...
So the risks are mitigated for the most part since it has no network connection.
Holy cow. And easy to do if you found their unsecured database.