Website with 1000s of live baby monitors, web cams and CCTV feeds has shut down
m.bbc.com
m.bbc.com
That's a terrible analogy. These webcams are accessible publicly on the web with no security. A better analogy would be, it's like leaving your window open, and your window location can be indexed by google, and your window can simultaneously be viewed by anyone around the world in their underwear. And in some cases they can pan, rotate, and zoom your window.
"If we can take one lesson away from this experience, it is that default passwords do not provide protection from the threats that exist in the modern world."
No, if we take away one lesson from this experience it's that the person exposing the serious issue can sometimes recieve the most criticism. Nothing is better, just back to being hidden.
My understanding is that the site would try various manufacturer default passwords (perhaps even common passwords as well) to gain access. I think if there's access control, albiet poor, it still does not quality as "no security" or "public." Look, the blinds in my house are open like 5mm or so. If you press your face against my window you can see in. That's not public, just because its easy for you to do.
>exposing the serious issue can sometimes recieve the most criticism.
This wasn't some selfless security researcher. This was a monetized site.
Personally, I'd like to see legislation that forces password changes on devices before they are allowed network access. The wild west of consumer electronics has given us the "internet of (compromised) things." This is not a good trend.
Setting a password should be part of the installation process for these kinds of products, and you should not be able to get it up and running without that step.
But none of these companies want to absorb the support costs of dealing with customers who will struggle with that step (and there will be plenty, Insecam was proof of that), so they pass the risk onto their customers and then try to vilify the people who point it out.
Actually, I'm pretty sure it does.
I'm a photographer, so I'm constantly following discussions and lawsuits about it. Anything that can be photographed (or videoed) while the operator is standing on public space is fair game. I can absolutely take photos and video of the front of your house while standing on the road. If you happen to have your window down, that's your problem not mine.
https://www.aclu.org/kyr-photo
opening paragraph:
"Taking photographs of things that are plainly visible from public spaces is a constitutional right "
I may be very confused, but Wikipedia only lists 206 sovereign states (193 full UN member states)[0]. Even with border disputes 250 seems like a very inflated number. Is there some other common definition of "country" I'm not aware of, or did this article just fail to perform basic fact-checking on the claims?
I think a better analogy would be someone putting up a tv screen on the side of their house showing a camera feed of the inside of the house, with a sign that asks people "Don't look at this TV"
On the rare occasion someone found a not-empty cam, there would be screencaps immediately. It was like crowdsourced voyeurism before crowdsourcing was a thing. The best one was a guy who was using the camera to monitor his weed grow op. Apparently, according to more knowledgable users on this forum, he was using the lights inefficiently. It sparked a massive debate on the intricacies of grow lights and that's when the thread died.
It was creepy but far less creepy or exciting than I imagined when I first stumbled upon the thread. Still, change your passwords people.
Now, after about two months, I realize that I hardly ever use the video feature and the audio is almost always enough. I guess we'll see if I change my mind as the babies get a little older, but I'd rather have my $250 back and just have gotten a simple audio monitor.
No shit.... Also this article covers what not to make your password which I think is misleading... This isn't about a hacker guessing easy passwords it's about people setting up these devices and not changed the DEFAULT user/password which is easy to find (or guess: user/user, admin/admin, root/root, user/root, etc).
I don't think shodan does that.
> use some form of secure password vault on your phone [instead of writing them down]
Writing passwords on a piece of paper and keeping that paper in your wallet makes it impossible for a remote hacker to obtain your passwords from you. It is only against very powerful adversaries like the government or a targeted attack where this becomes a weakness.
Compare this with storing your passwords in "some form of secure password vault".
1. A remote hack targeting thousands of people at once from the comfort of ones own home is now possible, any weakness in the vault can now be exploited en mass.
2. Instead of trusting that you can keep you wallet secure, you now need to:
a. Trust the manufacturer of the phone
b. Trust the supplier of nearly every IC to the manufacturer of the phone.
c. Trust the author of the baseband processor blob (Broadcom).
d. Trust the Android operating system
e. Trust the modifications to the Android operating system on your device.
f. Trust Google play services (which has root access to android).
g. Trust that Google will not use it's privileged position in your phone to grab your passwords on behalf of any three letter agency.
h. Trust the author of the password vault
3. To make the password vault any more effective than paper in your wallet, you need to encrypt the vault with a strong pass-phrase, and you are back to square one again.4. The chances are that the average Joe that reads that and chooses to use "some form of secure password vault" will choose a bad one.
The only reason to use a "password vault" if for convenience once you have too many passwords to write on a small piece of paper in your wallet or if you face a adversary where you expect them to be able to steal your wallet. In which case just memorize some 100 bit diceware passwords which is surprisingly easy.
Isn't this true for most people? Paying my bills and utilities alone requires nearly a dozen passwords: bank, rent, electricity, gas, water, internet access, phone bill, health insurance, renters' insurance, car insurance.
AD can handle long passphrases. Granted, its cryptography only considers the first 14 characters, but I've read case studies where shops have moved away from complexity to minimum 14 characters and suddenly things like password resets become a thing of the past. Turns out its easier for humans to process "mydogsnameismrmittens" vs "M1tt3ns"
I've tried long passphrases in embedded devices like cameras and routers. Most of the time they can't handle it. Don't knock AD as being the bad guy here. Go after the nightmarish cockup that defines the security of consumer embedded world.
And even if you make a policy that meets PCI requirements, I've been in many-a PCI audit where the auditor doesn't want to move past the password policy section if you don't use AD's 'strong password' feature. Because it takes a bit of time and effort to explain your password policy without that little checkbox.
It's not Microsoft's fault that everyone uses their strong password checkbox. But Microsoft could move into the 21st century and make sure that what they label as 'strong passwords' actually meet the criteria of being strong passwords.
AD's password rule enforcement is almost completely inflexible[0] and originates from 1980s US Government requirements they incorporated to get some certification.
It is completely inappropriate in 2014 and don't even get me started on how convoluted Microsoft make adding 2 factor to NT login (i.e. use our expensive convoluted solution or nothing, no RFC 6238 you can just slot in).
[0] http://technet.microsoft.com/en-us/library/cc875814.aspx
I'm glad it's been shut down.
I don't see anybody making such a big fuss when people don't close the curtains in their home at night (or even during the day). Sure you can see who is peeking into your house, but technically is it much different then a insecure/unconfigured webcam?
I think it might. It was one of the top headlines on the evening news in the UK and the main message was to users - change your password. How many acted on that I don't know but the reports certainly got out to regular people.