Disassembling an Amazon Blink Mini camera
astrid.tech
astrid.tech
Does anyone know of a good way to have a camera stream video over WiFi to my server, which can then forward it to the Internet, without passing through a third party? And, ideally, without opening ports. Burned too many times by buying cameras with streaming systems that are shut down two years later.
I think if I could get root on embedded linux on a WiFi camera, I could set up an SSH tunnel and go from there. But with the current IP camera I wasn't smart enough to get root (or a shell at all, IIRC) and it wouldn't take firmware updates.
So right now I have a terrible hacky solution where it FTPs an image to me every ten seconds, and then I put serve that... but a real stream would be way better.
I use lots of the Ubiquiti Cameras - I’ve had lots of success using them without the UniFi Protect controller app purely as RTSP devices.
If it works, it works?
The “outdated” knock on it is relevant because it points to Wyze once giving a nod to tinkerers, and apparently deciding it’s not in worth it to maintain that branch vs working on the firmware that drives monthly revenue.
The RTSP firmware for the v3 isn’t even a year old (was released after June 2021), so “once was a nod to tinkerers” combined the rest of your vitriol makes me wonder if you have an axe to grind. Did Wyze kick your dog or something?
https://support.wyze.com/hc/en-us/articles/360026245231-Wyze...
I might have a small axe to grind. My Wyze cams were much more capable when I bought them 3 years ago than they are today. Now the app takes much longer to load, and has the uncanny ability to insert an advertisement under my finger just before I touch the camera feed I want to view. Scrubbing through saved footage is slower now than it used to be.
It all smells like feature bloat that I can’t opt out of. RTSP was how I tried to escape that, but as their own site says, they no longer offer it for my cams.
Which platform? I’ve never once seen an ad in the official iOS app. The app was always slow to load for me in all the years I’ve used it, so that doesn’t have me riled up. My beef with them is the AI detection has taken a significant step backwards the last six months (why I flipped a bunch of my cams to the RTSP firmware).
And somehow I always seem to either click on the ad rather than my first camera, or click on a camera listed above my targeted one as the ad appears just as my finger lands on the screen.
And also to be clear, the axe I grind is small. I generally like these Wyze cams. For $20 each they’ve done a decent job. But knowing there is third party firmware out there is promising.
Ah, gotcha. I’ve seen those before, but haven’t experienced same issue with getting in way. Maybe I’m just slow to click.
> And also to be clear, the axe I grind is small. I generally like these Wyze cams.
The reason why I bought so many of them is because they don’t upload to the “cloud” unless they detect motion (or sound trigger). Yes, they phone home like crazy, but at least they aren’t streaming 24x7 to Google or Amazon or worse like some competitors products do. Add on to that that they are cheap, and I’m mostly a happy person. If only they could tell the difference between a person and absolutely nothing (no shadow, no movement, nothing!) I might still have all my cams on the mainline firmware.
If you'd like a secure setup, I'd advise a generic WiFi camera, accessible only on your LAN, and setting up OpenVPN or similar, to connect to your home network. This way you need to only trust your chosen VPN implementation, and I'd wager they are pretty secure.
with a battery life of a year? there is no competition. if you achieve this, please post it here!
https://awesomeopensource.com/projects/camera/firmware
Thanks for the supply chain diagram: https://astrid.tech/_/2022/08/03/0/blink-companies.svg
Microsoft's ThreadX RTOS was also used on RPi GPU, https://en.wikipedia.org/wiki/VideoCore#Linux_support
> Blink Video Doorbell, Outdoor and Indoor (gen 2), and XT2 cameras can expect battery life of up to 2 years, based on 5,882 seconds of Live View, 43,200 seconds of motion-activated recording and 4,788 seconds of Live View with two-way talk. This is roughly 70 seconds per day. For the Indoor (gen 1) and XT cameras, 2 years of typical use is defined as 40,000 seconds of Motion Clips and Live View. This is approximately 50 seconds per day.
Ahh 6 hours of continuous recording. That's a lot more reasonable. You could build something similar by combining a low power PIR sensor with a camera
I found the Blink camera was the best for a battery camera in terms of startup on PIR detection. In comparison my newer Eufy and Arlo cameras take a second or two (sometimes more) and have much less battery life.
The downside on the Blink is that you have to buy high end lithium AA batteries
If I may, regarding the "BUND" magic. I'm sorry to disappoint, but it's likely just "fourcc" (as in, a stirng that fits in an int32) for "bundle".
There are cheap used HP/Dell thin clients based on the venerable AMD Puma SoC family found in the coreboot-based PC Engines APU2 (an excellent classic device which even has ECC memory).
Hardkernel (small company from Korea) ODROID M1 is a capable Linux SBC /w NVME.
My point is that big tech FAANG-like corps never seem to sell anything nowadays that's just simply good out of the box without any sleazy scam-like caveats. That's a pretty sorry state of affairs.
It feels like we've taken one step forwards, one step backwards. Like in 80's you could buy a C64 which was just pure excellent right out of the box, but you had to be a bit of a tech nerd to buy one in the 1st place. Nowadays if you're a regular person and buy some popular computer you're buying into some sort of scam. You need to be tech-nerd to avoid the scam and get something good.
In 80's tech nerds had C64 and bbc micro and so on, and everyone else had nothing and just missed out competely on the magic of computing. Nowadays tech nerds have their own pc's and everyone else has iOS and Android and almost completely misses out on the magic of computing.
> everyone else has iOS and Android and almost completely misses out on the magic of computing
If some of the iOS/iPadOS/Android people bought a ~$100 used PC, RPi or Linux SBC, they could use it as a relatively libre home "server/cloud" for learning. With Ubuntu and search engines, it's still somewhat possible to take vacations from walled gardens to visit magic computing castles that are open to user mods.
> “History shows a typical progression of information technologies,” he writes, “from somebody’s hobby to somebody’s industry; from jury-rigged contraption to slick production marvel; from a freely accessible channel to one strictly controlled by a single corporation or cartel — from open to closed system.” Eventually, entrepreneurs or regulators smash apart the closed system, and the cycle begins anew. The story covers the history of phones, radio, television, movies and, finally, the Internet. All of these businesses are susceptible to the cycle because all depend on networks..
On a positive note, the current U.S. FTC has been making antitrust noises about tech companies and platforms, after years of relative inaction. There's a nascent global effort to enshrine "right to repair" in consumer hardware regulations, which aligns with circular economy initiatives and hardware shortages.
On a negative note, humans have deployed IoT "slave helmets" for realtime geofencing and control of construction workers with few legal rights, i.e. restricting not just the computing hardware, but the human body of the user, https://news.ycombinator.com/item?id=33675370
On a cage match note, banks and tech companies are at a 2023 global regulatory crossroads on the future of digital currencies, including crypto and CBDCs. The music/film industries led to DRM restrictions on consumer hardware. Now we have bank-vs-tech competition to be legal and physical custodian of private keys for digital currency wallets. How will that change computing hardware and supply chain security regulation?
Proprietary drivers for radio/sensors/audio were incredibly hard to get working and the blackbox security module they have made it nearly impossible to boot and use any peripherals. I was following somewhat closely for a long while and outside of hobby hacking, it was never a useable system from what I saw.
Do you know if it’s looking better in that regard for M1? I’ve been out of the loop.
As for software, that's more a matter of personal opinion that people just disagree over. One person's excellence is another person's hard-to-use, another person's super-secure is yet another person's too-locked-down. There's really no winning.
At least with Bink you get a service for that. With Apple you still need to pay the remaining 70% for the apps themselves.
But no, charging 30% isn't a "scam". I mean, is Microsoft scamming people on Xbox games by taking an equivalent 30%? Is Sony also scamming with their 30% for Playstation games?
30% is industry-standard for app store distribution tied to hardware. And while you can argue maybe the percentage should be different, it's not a scam.
The other scams you listed are also scams.
There's nothing fraudulent about 30% app store commissions. It's out in the open.
If your grocery store makes a 30% profit on a packaged dessert it sells, do you think that's a scam too...??
That grocery store analogy isn't remotely similar to hardware that is being arbitrarily crippled to suit the manufacturer.
I would think it was a scam if the grocery store could somehow stop me from shopping elsewhere.
everyone said it well here https://news.ycombinator.com/item?id=33684776
Just build a product that is excellent, without fuckery and small print.
Is there any other camera without an off switch, consumer or enterprise?
You have every reason not to want a smart speaker that learns about your questions and prompts to give you better targeted ads.
You also have every reason not to want to buy a piece of hardware fundamentally dependent on a server-side service the company could choose to turn off at any moment leaving you with a brick.
But people seem to treat these smart speakers with the kind of suspicion that would only be appropriate if you actually thought the speaker was listening all the time to your everyday conversations to truly INVADE your privacy.
Which - maybe you would think about a random piece of junk from a disreputable company (if you ignore the monumental amount of bandwidth this would involve that would likely be infeasible).
But I feel like you can probably trust weirdly enough companies like Amazon and Facebook NOT to do this because of the colossal news story it would be.
The other reason I can imagine technologists on here to not trust smart devices is that they might be used as a weakspot to hack into your network. Again - I can see not trusting that from a random 3rd party, but Amazon knows how to create strong secure systems. If you trust Cisco or Asus or 3Com to buy a router from them, it's really no different.
This is easily verifiable, and has been done so multiple times by independent parties.
The microphone is always listening, waiting for the wake word. If it can discern a wake word, it can speech-to-text everything (or will be able very soon), good luck noticing your daily <10kb of compressed text in what it sends up.
And this camera is a security camera, it's designed to send up video and audio 24/7.
If not, why not?
Definitely not blink.
These cheapskates only stream like 10 seconds before prompting you "continue?"
Can this render a nude body like Sony's did (by accident???)
http://www.aparchive.com/metadata/youtube/ad99e1a3930185817a...
EDIT: Part 3 of this is truly impressive. OP decoded the IP used, and it came from freaking EVERYWHERE.
Assuming that the platform is even secure boot capable, you'd blow a fuse or similar at the factory to put it into production mode.
However even then, secure boot isn't infallible. Either they're implemented shoddily, or you end up power glitching past verification.
(I've seen a certain vendor who's name starts with Qualco... fail because they didn't remember that u-boot was... configurable.)