Live data from Hacker News

Hacking a $30 IoT camera to do more than it’s worth

hackernoon.com

31–40 of 77 posts

Re: Hacking a $30 IoT camera to do more than it’s worth

#31

Earlier quoted context omitted.

The linked article is a guide to "hacking" a $30 Xiaomi Dafang IP camera. This camera is an "indoor motorized WiFi camera capable of 1080P resolution and decent night-vision, its price is cheap". If you bought one, all the "hacking" required is inserting a MicroSD card with a custom firmware on it and pressing and holding the camera's reset button to flash the custom firmware. From then on, the camera has the ability…

I'm not a conspiracy nut but there is something to say about how attractive Xiaomi's offerings are. For everything from phones, TVs, and other electronics; you would be crazy not to purchase it. In there lies a hidden threat. Possible from a tiger nation state.

They don't even really advertise in the West much yet?

The surveillance threat is one that applies to any cloud-linked device, sadly. As a non-Chinese living outside of China I almost mind surveillance by China less; what are they going to do with it, after all? (Unless you count the Mariott guy they got fired?)

Re: Hacking a $30 IoT camera to do more than it’s worth

#32
post #30

Earlier quoted context omitted.

I don't think it's a "hidden threat" as much as it is a company racing to the bottom first. Xiaomi has consistently shown that they don't care about security (or at least consistently enough that they have lost my trust).

I want to believe this, but I have never seen something about Xiaomi/security. Can you please give some pointers/links/events that happened before

I don't have any links on hand, but I know of a handful of situations that I remember:

* Xiaomi android phones had some kind of analytics APK built in around 2016 that would send a shitload of data over HTTP to their servers, and even would allow downloading emergency updates over HTTP. Their "fix" was to enable HTTPS, but leave the ability to force downloads and continue to run the analytics programs on the phones.

* Their robot vacuum used a password of "robotrock" to encrypt and sign updates.

* Their "yeelight" smart-bulbs were recording audio and sending them back to their servers over HTTP.

* Their "air purifier" also sends analytics and does updates via HTTP without any signatures.

IIRC many of these were fixed at some point, but I know at least once they said (paraphrasing) "we aren't going to fix it because the device isn't capable of HTTPS", but I don't remember which device it was. And it's enough for me to understand that they don't seem to take data privacy and security very seriously at all.

Re: Hacking a $30 IoT camera to do more than it’s worth

#33
post #4

Speaking about cheap cameras. I'm planning to setup some cameras at home. Anyone have any recommendations for devices that are cheap, can see moderately good in the dark, can be connected to a raspberry and doesn't force you to connect to some cloud service?

I have a Wyze cam that I installed OpenIPC on. Very simple process if you’ve ever flashed a firmware before. OpenIPC lets you turn off the cloud stuff and I have mine pushing video over my local network to MotionEye on a Raspberry Pi. The Wyze has IR night vision but the IR can’t see through windows at night so be aware of that. It was like $25 on Amazon, pretty good deal I think.

First time heard about openipc, checked its github, it is still just binary format though, thought 'open' means some source code...

Re: Hacking a $30 IoT camera to do more than it’s worth

#34
This ecosystem is ripe for software based innovation. There's a lot of great hardware out there but the API's are often closed and the existing software lackluster. After some research I recently purchased a Wifi camera, and am planning on using it to track my 6mo old's sleep habits (using some custom scripts / classification / etc). Guide's like this are great because they help make these things possible. I hope over time as more people publish hacks and cool projects based on them, some of these companies will start to open up their platform / API's. There's so many potentially cool projects that will hatch out of these.

Re: Hacking a $30 IoT camera to do more than it’s worth

#35

Earlier quoted context omitted.

The linked article is a guide to "hacking" a $30 Xiaomi Dafang IP camera. This camera is an "indoor motorized WiFi camera capable of 1080P resolution and decent night-vision, its price is cheap". If you bought one, all the "hacking" required is inserting a MicroSD card with a custom firmware on it and pressing and holding the camera's reset button to flash the custom firmware. From then on, the camera has the ability…

I'm not a conspiracy nut but there is something to say about how attractive Xiaomi's offerings are. For everything from phones, TVs, and other electronics; you would be crazy not to purchase it. In there lies a hidden threat. Possible from a tiger nation state.

Xiaomi want to become an ecosystem/lifestyle provider, kind of a blend of Apple and IKEA. The margin on each individual product aren’t high (especially the electronic ones), but it leads to selling higher margin products down the line. I’m living in China and I now find myself buying Xiaomi towels and USB cables and pens and AA batteries and beer... since I know they will have an acceptable quality at a non-excessive price. Margin on all those is likely to be much higher than on that $30 IP camera.

Re: Hacking a $30 IoT camera to do more than it’s worth

#36
post #14
post #10

Earlier quoted context omitted.

Thanks, I saw said article as I'm commenting in it's thread :) But I wanted to avoid the hacking and just buy something that I don't have to force into doing what I want but rather come in a clean slate.

Not trying to sound (too) snarky, but the fact that there is an article on hacking a camera to do that kinda tells you that a boxed solution to do mostly the same things doesn't exist :)

No worries, my initial comment might have been on the wrong post ("hey, I see you hack cameras but if I don't have time for that, where can I buy one with acceptable out-of-the-box behaviour?") but I felt the subject was a bit related at least, and I don't know any of them so I asked :)

Re: Hacking a $30 IoT camera to do more than it’s worth

#37
post #33

Earlier quoted context omitted.

I have a Wyze cam that I installed OpenIPC on. Very simple process if you’ve ever flashed a firmware before. OpenIPC lets you turn off the cloud stuff and I have mine pushing video over my local network to MotionEye on a Raspberry Pi. The Wyze has IR night vision but the IR can’t see through windows at night so be aware of that. It was like $25 on Amazon, pretty good deal I think.

First time heard about openipc, checked its github, it is still just binary format though, thought 'open' means some source code...

Yeah, did the same. First reaction was regarding not finding any list anywhere of supported models, which is strange in itself. But the second point that they are still using a binary blob which no one knows what it does, doesn't feel very safe if you're worried about companies spying on you.

Re: Hacking a $30 IoT camera to do more than it’s worth

#38
post #4

Speaking about cheap cameras. I'm planning to setup some cameras at home. Anyone have any recommendations for devices that are cheap, can see moderately good in the dark, can be connected to a raspberry and doesn't force you to connect to some cloud service?

If you're planning on connecting directly to a Raspberry Pi, the simplest option is a NoIR Raspberry Pi Camera Module and a few IR LEDs.

Thanks! That's probably what I will end up doing, but the price will be much higher than just buying the IP Cameras.

Re: Hacking a $30 IoT camera to do more than it’s worth

#39
I see a lot of products like this on Alibaba that I wish I could put my own firmware on. I've messaged a few of them telling them "I'd buy 1000 of these if I can put my own firmware on them" but haven't gotten any good responses. What I'm aiming for sometimes gets lost in translation, but mostly I think they just don't get the premise I'm presenting to sales people who answer the Alibaba inquiries.
Post reply on HN