Why We're Pulling Our Recommendation of Wyze Security Cameras
nytimes.com
nytimes.com
I'm not sure if the product exists, but something that replicates a homemade setup would be amazing.
Think of a bundled camera(s) + raspberry pi + 1tb backup drive or whatever that you can only access over your own dedicated personal wireguard vpn (or tailscale, something like that), but sold as a retail bundle.
Of course, that would cut out all the SaaS/app data selling aspect so it seems unlikely to happen.
> RTSP was considered a beta feature and we are currently assessing the path forward as the firmware versions have aged quite a bit. We have removed the firmware files for these versions for now and we’ll update the pages when plans are finalized. Please note that firmware files take a while to work on and test so you may not see an update in the near future.
Krebs jumped the gun on that accusation and apologized
https://krebsonsecurity.com/2022/08/final-thoughts-on-ubiqui...
Mass produced consumer gear that is also perfectly secure probably doesn't exist. I assume everything I use has bugs and none of it will stand up to a dedicated attacker.
As for blackmail, my cameras all point outward. I suppose they could threaten to report me to the HOA when my grass gets too long...
I believe a dedicated hacker could use the microphone and camera in my phone and laptop to spy on me. They could look at the street in front of my house. They could see my entire browser history, everything I've printed, every call I've made, everything I've said over email or text message.
Cisco? https://www.tomshardware.com/news/cisco-backdoor-hardcoded-a...
Juniper? https://www.schneier.com/blog/archives/2021/09/more-detail-o...
Huawei?
So don't read the article as being about Unifi currently being backdoored by the NSA, but that the USG3 was one of the products using the Cavium/Marvell chips with the flaw that were being used globally in 2013 when the Snowden archive was released.
However, you can set things up to run locally with self hosted servers. I've got a couple of wifi points, a switch and the old security gateway along with a couple of their cameras. I've got the Unifi device management software running in docker on a Raspberry Pi swarm and the old Unifi Video server running on x86 hardware in docker. It's probably about time I figured out how to self host the Protect server and move the cameras to that.
You could just as easily give local camera's the "printer" treatment, and most people are somehow able to successfully setup printers on their PC's.
With that being said, I did still have to setup the Wyze cameras for my 50 year old tech-inclined dad, haha.
It's ostensibly the same UX as the current cloud set-up, only without the operational costs of running a cloud service.
I'm confused by the use of the word "ostensibly" there. Do you mean that the makers would claim that it would set up a tailscale kinda thing for you while doing something completely different to avoid the cloud?
Sorry that it wasn't clear.
I have both RPI local cam set up and Wyze. Despite concerns, hard to argue with pure convenience of Wyze (and similar products)
Source: https://www.raspberrypi.com/news/supporting-raspberry-pis-in...
B) What about the apparently huge majority of us that prefer these devices precisely because the video is not stored on-site?
It's just a complete pain in the ass. I have a collection of "cool, but painful to maintain" devices.
Finding someone trustworthy enough to store your offsite footage, though, is a real problem. If only there were some sort of union of peoples capable of causing consequences for companies that act as poor stewards of data.
Would be a great idea! Your wish is granted! Only one catch. The only consequence they can actually level is an insignificant fine ~ 1% of the profit they've made violating the law. Oh, plus a pinky pwomise to not do it again after a finger wag, or they'll get real angry, and the fine will be UP TO a whopping FOUR percent of profits!!!
Seriously though, re offsite storage, one could encrypt all data locally and then offsite anywhere, right? Could be google drive for all you care.
Besides, if the thieves were savvy enough to find and take your surveillance gear with them, they'd be unlikely to expose anything meaningful (like their faces) on your video feeds anyways, right?
It seems like HomeKit Secure Video has pretty good security design: https://support.apple.com/guide/icloud/icloud-homekit-secure...
often you have to use port forwrding to connect, on ports not recognized for protocols your ISP filters out.
NTFY and Node-Red, with a dash of MQTT, can be bolted on for remote alerting.
And the huge mess of bad publicity, when someone breaks into a home, and as part of the theft, steals the device that has all the video of their crime.
I think the minimum requirement for a legally secure cloud hosted camera is E2EE and the camera can't upload unencrypted video at all without the decryption key from the owner.
Sadly, very few companies are trustworthy.
Not all of them are evil; wanting to get into their users' data; many are just cheap and lazy. They don't want to spend money on the types of employees and process that will result in trustworthy kit.
It's actually not hard to understand (less easy to forgive). The device market is crazy cutthroat. Margins are razor-thin, support costs can be high, and competition (especially with nation-state-funded competitors) is savage.
But I don't know how many times I have had one of my friends proudly whip out their smartphone, showing me live video of their kids playing at home, not realizing that their ultra-secure password ("fuckyouhacker") is no impediment to lots of others, getting the same feed.
Random predatory individuals are bad, so are zombie apocolypse denizens.. but the subject of lawful-in-name-only betrayal, in very large commercial markets, seems much more to the point today, here.
Good point.
never underestimate the power of a post-sales revenue stream.
(a business model which may take place in a software update after your purchase)
I use standard cameras so I can write my own software. It's been a fun project but it's still pretty rough around the edges
https://en.wikipedia.org/wiki/Dahua_Technology#Cybersecurity...
Cheap IP CCTV cameras like Reolink, Loryta, or Amcrest, isolated in their own physical LAN (they're full of security vulnerabilities, but you can keep them isolated and not care), and combined with Frigate + HomeAssistant is pretty good too if you want to nerd out on a solution. I personally hate needing out on home computing stuff but this is the one place I chose to invest because off the shelf cloud solutions are _so bad_.
So many times I'd go to pull up a feed in ZoneMinder and realize the system was down, locked up, having some other odd issue. With my Reolink NVR "It just works", it was worth every penny and it wasn't even that expensive.
https://www.cisa.gov/news-events/ics-advisories/icsa-21-019-...
And actually if any of your network machines or devices are breached, the attackers now have NVR/cam access.
You can check your NVR from your phone on wifi right?
At a certain point you are being overly paranoid and I think we crossed that line a while back.
Unlike breaking into your window, you are unlikely to get the cops to do anything if someone breaches your network. There's also direct and indirect financial incentive.
So now your entire livestreaming security setup depends on the security of your wifi network, which can be broken with $20 of dedicated hardware.
And yeah, if someone puts hardcoded creds into their cameras.. they probably do it for all their firmware. It doesn't even have to be malicious, it's just a lazy way to test and debug software.
There was a security kerfuffle last year because motion notifications sent to your phone contained video previews which were then stored insecurely. They fixed that, and it's a feature you can disable. It's not nearly as bad as what has happened to Nest/Wyze cams where attackers can gain access to live video and even talk through the speakers.
We have a bunch of these outside and we've been watching the cats, possums, raccoons, and even turkeys frolic as they cross through our property. We even set up a little victorian style dog hours with solar panels in the backyard and the wild animals have been using it to rest. We have a ton of video of these little animals just relaxing and stretching out in the dog house too. The family loves it, every morning we get to see what the critters were up to.
Before that we were doing hydroponics and we had cameras on the fruits, the instruments for things like ph, ec, and a camera in the reservoir so we could monitor water levels.
I don't use them to watch my home, but they have been pretty solid in terms of watching other things that aren't security related or sensitive.
I have 2 looking out my windows at the front door and car. I move those to watch the dog when she stays home. I have one over my pool table to record shots. I've used them in the past to watch stray cats outside.
I am least happy with their outdoor cam since it doesn't do continuous recording and it requires a separate hub. I recommend the plugged in ones to everyone though.
NDAA - National Defense Authorization Act
TAA - Trade Agreements Act
an unintentional, adult, video shareing platform, sounds like something a sector of society would consider a feature.