IP Crawl: Living atlas of open webcams discovered on the public internet
ipcrawl.com
ipcrawl.com
There's also a difference between your neighbor not closing her blinds and you using a telescope to look inside her apartment, which is what sites like this are.
In other news I'm considering developing a new app and was wondering about VC funding. It's for mapping out ladders adjacent to windows down back alleys. I think it would dovetail well with nipalert.
This isnât a passive âwalked by the windowâ thing that you might have unwittingly viewed. To actively search for open cameras by crawling every IP then creating a tool to see them, then choosing to watch the footage is a very active, deliberate choice. No one is viewing this footage without making a multi-step choice to view it.
I'm surprised this is still a thing though. I remember being shocked when I came across an extensive feed of these inadvertently pubic CCTV feeds ~15 years ago. I had assumed it was no longer a problem.
We evolved for small tribes, e.g. Dunbar's number is ~150. Roughly 1/129 of the people on the internet are software developers, so in the days of everyone living in villages your in-group would include roughly one person who thinks like we think.
"Inadvertently live-streaming to the 1/129 of the world who consider searches like this to be trivial, with zero feedback unless you found your home accidentally went viral" is not like anything we otherwise experience.
If anything, projecting onto a nearby sidewalk as you describe is more like "I was bathing after my day's work scribing for the king and wouldn't you know it, that đđ đđ living by the temple decided to walk right in and say hi! Doesn't even think to knock, just opened my front door and walked right in.", while the closest thing you can find to accidental live webcams in old writing is gods spying on mortals for fun, making us the Anansi, the Loki, the Eshu. And for the furries, the Coyote.
How do so many people end up exposing these cameras to the public internet? Are their ISPs not using NAT by default? Are the users jumping through hoops in order to open it up?
This is an example of everything working as intended. The cameras are supposed to be accessable when you're not at home. Of course the cameras ought to ship with randomized default auth on a sticker attached to the unit the same way any half decent router does these days but they don't.
"Hey, so I can just do a HTTP request to the router and open a port? Neat"
Used to use it back in the day when my ISP didn't allow for port forwarding, but did allow UPnP, so had a cron job that re-opened it every x hours when it reset.
It takes active effort to expose a camera publicly
Open a Bittorrent client and it will try and port forward port 6881 using UPnP.
You don't even need to do UPnP, if you're okay with a random port, you can just do STUN.
Some cameras do also open ports with UPnP but it's rare in my experience. I think these cams are more users who are a bit technical but not too much to realise the implications.
Yes weak passwords are bad, but if nobody can access it itâs not the end of the world.
It's the swiss cheese model. I'm sure most of these people didn't mean to make their cam accessible to the internet. If there had been a unique username/pw they wouldn't have got exposed.
I doubt that the instructions for a cheap camera have enough information to walk a non-technical user through the process of setting up port forwarding on their specific router.
I could believe that itâs automatic port forwarding via UPnP for some of these cameras.
However a lot of them are from contractors who install the cameras for people as a service and this is the only way they know how to get them remote access. Itâs the same reason different industrial controls and other machines keep getting exposed to the internet. Some installer with a git-er-done attitude knows their customer wants a solution to something (remote access) and they use the first technique they can find to accomplish that without any concern about what it means. They accomplish the thing the customer wants, collect payment, and disappear.
If the customer calls back with a complaint about it, the contractor will happily come visit the site and try to âfixâ it for another fee.
If youâre thinking that this is a liability issue youâre not wrong, but in much of the world there is no realistic recourse. Most things like this are pure caveat emptor.
Most network security experts would quit before ever entering a hot attic.
So Cletus the CCTV guy who just spent 8 hours crawling through drop ceilings with a mask on, does a super-clean install, and sets it up as well as he knows how. Which is "good enough" â it works and he's off to the next job. The customer's happy and he gets paid.
Now which one of you network security guys is going to give up his cushy WFH job to go make house calls for CCTV wages?
Cletus is free to get a bank loan and mortgage his house to give it a try as well, though he doesn't have a decade of FAANG employment money to lean on, what he does have is experience with customers and crawling around houses.
It should be something simple like:
-everything is encrypted
- at install I tap my phone on the camera, now my Google account(or something similar) is linked to it as admin.
- on that some simple key management architecture should be built
The Chinese DVR the CCTV installer used doesn't work that way.
In fact it probably has a telnet server with a known, hardcoded root password.
But probably most of these cameras are bought through Amazon, AliExpress or Temu.
If your door is unlocked, either through ignorance or negligence, it's still not right for someone else to just walk into your home and look through stuff you thought was private.
Sure, they can do it, but just being able to easily do something doesn't make it right.
It is also funny, and depressing that many of the same people who think might makes right on the internet ends up lamenting how fucked up life is in their low trust societies, when their mindset is exactly what makes a high trust society â you know, the ones where people don't lock doors â impossible.
With that said, the specific someone you refer I am sure has a valid point. When you knock on someone's door and nicely ask for a cup of sugar and whomever is answering the door happily gives it to you, it is reasonable to assume that is something you can take. They would say "no" otherwise.
I get it might be a friend that doesn't fully understand the boundaries of the homeowner answering the door, but it is unrealistic to place the onus on the neighbour looking for a cup of sugar to decide whether or not the occupant is acting in the interests of the homeowner. The fact that the person is already in the home to be able to answer the door implies that there is trust in that person to do right by the home.
By the same token, if the homeowner found out about the cup of sugar that they didn't want given away, most people would address it with the friend to see that it doesn't happen again, not go on a rampage with the neighbour. It is well understood that anyone within the home saying "yes" is to be considered authoritative. It is the only reasonable way.
Yes, the people setting up these cameras are not following security best practices. But are you sure that you will not make the same mistakes? Are you sure you have never exposed anything you should not have on the Internet, and never will, even as you age?
Let anyone among you who is without fumbling security be the first to throw a stone.
That said, I'm not 100% convinced I could set up a webcam streaming online without accidentally exposing it to the wider internet. Maybe 95% sure? But if even I couldn't guarantee it, what chance does your average joe who mostly only uses his computer for netflix have?
How else are things supposed to change. Hopefully this will embarrass some oligarch enough to force companies to close their loopholes.
While right, there are multiple definitions of "private" and for others OP's point still stands.
No. No. No. No. No. No. No. No. No.
So if I put an IP camera inside your bedroom without your notice or consent, and hook that up to the Internet, you'd be okay with that? Because it's public!
A lot of these are probably from default or misconfigurations. A lot of these people with IP cam feeds visible to the Internet probably do not know they are open.
The intent was to say "You cannot call a space private if it has a networked camera in it." Not "only a public space can host a camera".
This:
> If the room has an IP camera in it, it is by definition not private.
Does not necessarily mean this:
> Since cheap cameras have begun to appear everywhere I treat them all as if they were publicly viewable.
The implication is that if someone misconfigured or otherwise didn't know their camera was broadcasting to the world, anyone is morally and legally correct in doing whatever they want with it, and it is their fault because it is "public". That is wrong.
I think it's more so similar to that if you leave something shiny and expensive in a visible position in a car in a neighborhood known for high rate of thievery there are good odds of your stuff being stolen. They are not claiming that the thieves are morally or legally correct.
That said, there are many people for whom "blaming the victim" is forbidden at all costs, and thus don't seem to have the facility to understand not making oneself a target. I suspect that you are replying to somebody possibly like that.
I'm not sure you do. Or at least you're replying to a very uncharitable interpretation.
From my perspective, this read as: the moment you put one of these IP cameras in a room, you should assume you're now in public, no matter what assurances you might have from the manufacturer or what safeguards you might have put in place. So if you intend for a particular space to remain private, don't put one of these cameras there.
> it is their fault because it is "public"
From my reading at least it didn't seem to imply that "it's the camera owner's fault", or that they should know better or that they deserve what they get, etc.
> "Many of these cameras are in private spaces"
To which the gp answered
> It's not private if it has a ip cam in it
So what? Either he meant to contradict the op (and then it's correct to push back), or this is an entirely superfluous comment given they both understand what the problem is.
They are not contradictory statements.
Which makes me think that people proposing such view are not, in fact, trying to communicate its (obviously wrong or entirely trivial, depending on the interpretation) content; they're trying to say "hey look at me, how tech savvy I am, I'm so in it that for me an open port is, like, a window open on the village square yeah".
When I'm in my home, I can consider that private and have a right to privacy, and at the same time there can be a camera in there broadcasting to a million people so in no stretch of the word do I have privacy, and my home is not private, and those two truths are not dependent on whether the camera being there, or people watching the feed, is right or wrong.
Agreed
> at the same time there can be a camera in there broadcasting to a million people so in no stretch of the word do I have privacy and my home is not private
Agreed.
And this is the situation we're discussing now: people who are in a private space, whose privacy is violated by an ip camera that makes their private things accessible to the public. This is the description of the website this entire thread is about. What did you add to the conversation?
You just said :
"> When I'm in my home, I can consider that private and have a right to privacy Agreed > at the same time there can be a camera in there broadcasting to a million people so in no stretch of the word do I have privacy and my home is not private Agreed."
So, to paraphrase, "A space can be considered private by the occupant, but the addition of an IP camera makes it not private.", right?
Those are not contradictory statements.
a] they may be exhibitionists
b] they dont realise they are misconfigured
c] someone hacked them to whatever end
d] they are doing nothing wrong thus believe they have nothing to hide.
Sharing on the internet should be one of the hardest things to do in your product. You need to make enough friction that the user can never do it by accident or by default. And the user should be warned at every step.
All with informed consent of course.
Edit: Come to think of it, video chat apps (WhatsApp, Signal, etc.) seem to do this, at least sometimes.
The idea of tech sovereignty for the sake of it is not an idea that resonates with many people outside of the tech community. Many people buy a product or service based solely on their immediate need.
> The idea of tech sovereignty for the sake of it is not an idea that resonates with many people outside of the tech community.
That's a failure of the tech community to educate the public, and accepting the idea that it 'just doesn't resonate' is a failure of responsibility and a condescending arrogance. The people in the public are intelligent and learn many things, such as literacy and sanitation.
> for the sake of it is
It's not for the sake of it, it's necessary for security and freedom, and it's a practical, simple solution to the problem of technically analyzing every product and every update to every product.
It could be necessary for âfreedomâ depending on your definition, which is a political argument and not a technical one.
I donât know if youâve ever tried to explain RMSâs opinions to anyone outside of tech before, but the primary disconnect is not an issue of education or literacy, but priority.
The primary reason people are not dissuaded by a services model is because they want a service.
Imagine you are reading a lawnmower enthusiast forum and everyone unanimously agrees that lawn services are immoral because they donât let the homeowner own the mower or make adjustments to it. This is what this argument sounds like to many people. Many people just want their lawn cut, they donât give a shit about the tool that accomplishes it.
That moves the goalposts from 'tech sovereignty' to self-hosting.
The rest describes the tech community's failure to communicate its importance. Sanitation is also inconvenient, as is quitting smoking, wearing seatbelts, and forgoing lead where it might be eaten or breathed, but people are persuaded. We've failed so far, and it's even more embarassing to blame the circumstances.
If you give laypeople a DIY project outside of their expertise, you can expect failures.
"admin admin is fine"
So you either host some infrastructure it calls back into, so you get around things like NAT. Or you punch holes in the network.
The same users who want simplicity don't want the complexity of having to remember passwords either...
âElectrical Network Frequency (ENF) analysisâ.
Iâm going to dig more and will leave some links when I get back to a computer.
Google â4chan tracks down Shia LaBeoufâ
isn't this handled by AI nowdays? In my experiments (some time ago) AI was extremly good at it.
You'd be forgiven for thinking this was the 'after' footage of an end-of-the-orld movie where all the humans have been disappeared, Mary Celeste style.
> As a rule of thumb, if you believe that "nobody would connect that to the Internet, really nobody", there are at least 1000 people who did.
https://hackaday.com/2026/06/27/requiem-for-long-wave-as-the...
It's also long been decommissioned.
In one way I think it's a bad idea because long wave works even when satellites and cables no longer work. It's great for emergencies. On the other hand, the number of people with equipment to receive it is shrinking (even though you can build it with a few components). That of course really hampers its value for emergencies.
> Baiting deer is illegal!
> This corn pile is intended for squirrels, chipmunks, and other such critters.
> Any deer found eating this corn will be shot!
The point is valuable, and the mission is important, but the ends do not justify the means. If this must be shared, at least use static pictures and donât stream the content for viewers.
Should Shodan be taken down because it can search for these devices? What about Google because it can find admin consoles?
And standing out in the street staring through with binoculars is still wrong and creepy.
> Should Shodan be taken down because it can search for these devices? What about Google because it can find admin consoles?
Itâs not a new idea, nor that controversial, that we restrict things specifically aimed at doing something rather than ones just capable of it.
> What about Google because it can find admin consoles?
Intention and proportion matters. Google is overwhelmingly not used for discovering unsecured endpoints and that is what makes it OK. If you build a search engine that only serves admin consoles and markets itself as the search engine for admin consoles then you have a problem. There is a reason why DDOS for hire services market themselves as selling "stress testing for your own servers," because they are smart enough to know the consequences of knowingly breaking the law.
Being able to do something, even if you can do it without the police showing up, is not the same as it being right to do something.
I think itâs wrong to cheat in a relationship but itâs probably legal.
These things are open server ports on the wild internet. Anyone with a "for" loop can find them easily. If they care about privacy they shouldn't have them public.
If you roll your eyes at the thought of having to manage credentials or refuse to learn how the internet works on a basic level, you're not fit to set up devices connected to the internet.
Secure your shit or don't play with technology you can't handle.
I get it if you think this is a legal gray area (it's not), but it's surprising to see how many people seem to think this is plain justified. Makes me think that there's some users that gravitate towards this site because the hacker in hackernews refers to hacking as in accessing systems without permission.
If you think hosting a website like this is ok, I encourage you to talk to a criminal lawyer and consider if you are a criminal. At least do it knowingly, do not pretend shit like this is fine.
Then everyone could get what they want: voyeurs can watch exhibitionists like God intended.
(Not sure how much metadata there is on the site since itâs currently suffering the hug of death so I canât see anything at the moment.)
I recall most of them were in Asia.. street cameras, supermarkets.. then I suddenly found myself looking into someone's bedroom.
Fortunately it was empty, but I promptly shat myself and turned off my computer.
Iâm not even convinced these are all real, or at least are staged:
https://ipcrawl.com/?page=6&cam=63f7feaf5042d223
Thatâs the invisible man hanging out at a tennis matchâŚ
If you look at it, all "feeds" that are without any moving part or human are "live", and when there is anything that could have movements, then it is a "snapshot" that doesn't move.
And then there is this very funny one that I'm quite sure is AI generated: https://ipcrawl.com/?page=2&cam=63f7feaf5042d223 The picture: blob:https://ipcrawl.com/939da98f-dfbf-4019-8518-8bfbdfbcb8df
The "live" aspect is also questionable, as I can see broad daylight on a camera where in reality it's currently after sunset and pitch black.
If I had to guess I'd say that the project is obviously AI generated and the creator has probably not caught all the "workarounds" and "clever tricks" the vibe coding has produced...
https://images.shodan.io/?query=port%3A554+country%3A%22GB%2...
Edit: they're literally the same image
2fc4ad21cfce564f7aa65942eae7d4529c8af3d7ffb6287aa1fd79ebb78eb648 ipcrawl.jpg
2fc4ad21cfce564f7aa65942eae7d4529c8af3d7ffb6287aa1fd79ebb78eb648 shodan.jpg
If a subsequent probe fails, the system cross-references threat intelligence platforms like Shodan to match the host and falls back to their specific indexing methods.
So it uses Shodan, but is not purely a mirror.Plot-twist: large bunch of people here are willing to have their life made public.
Would be interesting if people could claim their camera and use the site to keep a long-term archive of footage. AI could detect various activities too and notify owners of thieves, intruders or infidelity. Could also charge outsiders to view. Best if streams were made private first to stop mirror sites. What happens if certain householders or visitors aren't told about the camera while being recorded?
Feeding faked looped security camera footage is a classic plot device in many films, and could make some good comedy!
These days you could do with AI. Godzilla over Tokyo anyone?
Adults too, if you had a pool like this wouldn't everybody want to share their "sex pool party cam"?
Which I thought was hilarious!
Without realizing that the entire world can see what the owners are doing when they are at home. Without using any special app at all.
Also so many people are infected with malware constantly scanning that ISP's don't bother
Like trespass, requires intent. When a car-park is private land, it's inferred that the public has access.
I also question whether this site really fits with HN's values. By being so highly ranked here, a great number of eyeballs are being directed at cameras that are clearly not supposed to be publicly accessible. At a minimum that doesn't seem especially kind.
What is the goal?
And they've created a reddit page specifically for this!
I don't really understand this b/c it's trivial to say "write me a letter in the style of <famous letter writer A> mixed with the style of "<famous letter writer B>"
Or
"Here are some examples websites, make a new website that is a remix of all of the example sites".
You would be surprised at the results.