this post was submitted on 18 Dec 2023
430 points (97.4% liked)
Technology
59323 readers
4666 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related content.
- Be excellent to each another!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, to ask if your bot can be added please contact us.
- Check for duplicates before posting, duplicates may be removed
Approved Bots
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
You can't connect home system that is never connected to internet, basically make home server and hook up cameras and don't ever connect that to internet
The problem is cameras like these, the kind that people are putting up inside their own homes, facing their living spaces, their own damn bedrooms, they're sold to people that have this desire to be able to check in with those cameras remotely at any time, without a good reason.
The only reason my mother seems to have crap like this set up is so she can see the dogs when she's not home. They're just sleeping.
Internet connected, living space directed cameras are this bizarre consumer electronics trend that has no legitimate use case for like 90% of the people that rush to use it. Certainly not one that merits the security risks and the privacy invasion that they are inviting on themselves.
Bro, if I find any ingress point onto your network, I can connect to your networked cams.
Little brother downloads a Trojanised pirate copy of a game? I can connect to your cams via your lil bro's computer.
Not patched your stuff and there was a drive-by-download and RCE exploit? I can do it through your computer.
Your firewalls are important but they aren't impenetrable.
Yeah, but you’d pretty much need to target the person so these blanket hacks where a bunch of cameras are exposed aren’t really possible
No I don't. Like the first example above I can simply trojanise an executable, and release it to the public.
Once I'm on your network, the first thing I'm always going to do is see what I'm working with. That means a network and system info sweep. If I'm efficient, I already have a script to do this.
That sweep will reveal the presence of the camera. I might be interested in extortion material or I can sell this to a criminal gang, if I can get it open. I already have the camera's MAC address, so finding the make and model isn't too hard.
Then I might browse to it, see what system software it is running. Then I would try default usernames and passwords (people don't always change them) and see if there are any usable exploits on the software.
If I come across a certain camera type with certain vulnerabilities a lot, making a script to autofuck these cameras is child's play.
Source: am an ethical hacker/ red teamer.
Seperate network that's physically not connected to a network which connects to the internet or cameras with local storage.
You can't hack into the wildlife camera in my backgarden. It doesn't even have wifi, just an SD card.
Of course, that's less useful if you want to check up on your house when you're away.
That's what I've been trying to say, thank you for backing me up
Vlans
not a common feature of home networks
If the compromised machine has access to both vlans, you're still fucked
It’s a feature on mine
That’s why my security has multiple layers
It isn't a common feature on ISP provided routers, which is what most people use. Some ISPs (example: my own) even make it exceptionally difficult to use other routers. I had to install OpenWRT on my retail router to get it, and getting that working was such a pain.
Half the reason to own a security camera system is so you can monitor it while away. Can't do that if the system isn't online.
Online or cloud-accessed? Those are two separate things.
It’s going to be cloud accessed. People who install these to check on whether Mittens is sleeping aren’t setting up a domain or remembering an IP.