There's also a difference between your neighbor not closing her blinds and you using a telescope to look inside her apartment, which is what sites like this are.
There's also a difference between your neighbor not closing her blinds and you using a telescope to look inside her apartment, which is what sites like this are.
I doubt that the instructions for a cheap camera have enough information to walk a non-technical user through the process of setting up port forwarding on their specific router.
I could believe that it’s automatic port forwarding via UPnP for some of these cameras.
However a lot of them are from contractors who install the cameras for people as a service and this is the only way they know how to get them remote access. It’s the same reason different industrial controls and other machines keep getting exposed to the internet. Some installer with a git-er-done attitude knows their customer wants a solution to something (remote access) and they use the first technique they can find to accomplish that without any concern about what it means. They accomplish the thing the customer wants, collect payment, and disappear.
If the customer calls back with a complaint about it, the contractor will happily come visit the site and try to “fix” it for another fee.
If you’re thinking that this is a liability issue you’re not wrong, but in much of the world there is no realistic recourse. Most things like this are pure caveat emptor.
Most network security experts would quit before ever entering a hot attic.
So Cletus the CCTV guy who just spent 8 hours crawling through drop ceilings with a mask on, does a super-clean install, and sets it up as well as he knows how. Which is "good enough" — it works and he's off to the next job. The customer's happy and he gets paid.
Now which one of you network security guys is going to give up his cushy WFH job to go make house calls for CCTV wages?
Cletus is free to get a bank loan and mortgage his house to give it a try as well, though he doesn't have a decade of FAANG employment money to lean on, what he does have is experience with customers and crawling around houses.
It should be something simple like:
-everything is encrypted
- at install I tap my phone on the camera, now my Google account(or something similar) is linked to it as admin.
- on that some simple key management architecture should be built
The Chinese DVR the CCTV installer used doesn't work that way.
In fact it probably has a telnet server with a known, hardcoded root password.
But probably most of these cameras are bought through Amazon, AliExpress or Temu.
Yes, the people setting up these cameras are not following security best practices. But are you sure that you will not make the same mistakes? Are you sure you have never exposed anything you should not have on the Internet, and never will, even as you age?
Let anyone among you who is without fumbling security be the first to throw a stone.
That said, I'm not 100% convinced I could set up a webcam streaming online without accidentally exposing it to the wider internet. Maybe 95% sure? But if even I couldn't guarantee it, what chance does your average joe who mostly only uses his computer for netflix have?
How do so many people end up exposing these cameras to the public internet? Are their ISPs not using NAT by default? Are the users jumping through hoops in order to open it up?
This is an example of everything working as intended. The cameras are supposed to be accessable when you're not at home. Of course the cameras ought to ship with randomized default auth on a sticker attached to the unit the same way any half decent router does these days but they don't.
"Hey, so I can just do a HTTP request to the router and open a port? Neat"
Used to use it back in the day when my ISP didn't allow for port forwarding, but did allow UPnP, so had a cron job that re-opened it every x hours when it reset.
If your door is unlocked, either through ignorance or negligence, it's still not right for someone else to just walk into your home and look through stuff you thought was private.
Sure, they can do it, but just being able to easily do something doesn't make it right.
It is also funny, and depressing that many of the same people who think might makes right on the internet ends up lamenting how fucked up life is in their low trust societies, when their mindset is exactly what makes a high trust society — you know, the ones where people don't lock doors — impossible.
With that said, the specific someone you refer I am sure has a valid point. When you knock on someone's door and nicely ask for a cup of sugar and whomever is answering the door happily gives it to you, it is reasonable to assume that is something you can take. They would say "no" otherwise.
I get it might be a friend that doesn't fully understand the boundaries of the homeowner answering the door, but it is unrealistic to place the onus on the neighbour looking for a cup of sugar to decide whether or not the occupant is acting in the interests of the homeowner. The fact that the person is already in the home to be able to answer the door implies that there is trust in that person to do right by the home.
By the same token, if the homeowner found out about the cup of sugar that they didn't want given away, most people would address it with the friend to see that it doesn't happen again, not go on a rampage with the neighbour. It is well understood that anyone within the home saying "yes" is to be considered authoritative. It is the only reasonable way.
This isn’t a passive “walked by the window” thing that you might have unwittingly viewed. To actively search for open cameras by crawling every IP then creating a tool to see them, then choosing to watch the footage is a very active, deliberate choice. No one is viewing this footage without making a multi-step choice to view it.
I'm surprised this is still a thing though. I remember being shocked when I came across an extensive feed of these inadvertently pubic CCTV feeds ~15 years ago. I had assumed it was no longer a problem.
We evolved for small tribes, e.g. Dunbar's number is ~150. Roughly 1/129 of the people on the internet are software developers, so in the days of everyone living in villages your in-group would include roughly one person who thinks like we think.
"Inadvertently live-streaming to the 1/129 of the world who consider searches like this to be trivial, with zero feedback unless you found your home accidentally went viral" is not like anything we otherwise experience.
If anything, projecting onto a nearby sidewalk as you describe is more like "I was bathing after my day's work scribing for the king and wouldn't you know it, that 𒈗𒍠𒄀𒋛 living by the temple decided to walk right in and say hi! Doesn't even think to knock, just opened my front door and walked right in.", while the closest thing you can find to accidental live webcams in old writing is gods spying on mortals for fun, making us the Anansi, the Loki, the Eshu. And for the furries, the Coyote.
In other news I'm considering developing a new app and was wondering about VC funding. It's for mapping out ladders adjacent to windows down back alleys. I think it would dovetail well with nipalert.
It takes active effort to expose a camera publicly
Open a Bittorrent client and it will try and port forward port 6881 using UPnP.
You don't even need to do UPnP, if you're okay with a random port, you can just do STUN.
Some cameras do also open ports with UPnP but it's rare in my experience. I think these cams are more users who are a bit technical but not too much to realise the implications.
Yes weak passwords are bad, but if nobody can access it it’s not the end of the world.
It's the swiss cheese model. I'm sure most of these people didn't mean to make their cam accessible to the internet. If there had been a unique username/pw they wouldn't have got exposed.
How else are things supposed to change. Hopefully this will embarrass some oligarch enough to force companies to close their loopholes.