Google "ethical disclosure." The standard in the security research community is you inform the manufacturer and give them an opportunity to patch the flaw. Then you wait some number of days (some people say 30, other say "depends on the details of the vulnerability"). Then you publish the code along with enough text to explain the vulnerability to a reasonably technical audience.
Ask HN: Do I publish code that affects millions of wireless security cameras?
11–20 of 109 posts
Re: Ask HN: Do I publish code that affects millions of wireless security cameras?
#12Of course, if you keep the approach private and use it for yourself, there's no guarantee that someone won't find it in the future and either exploit it or report it themselves. Do you feel comfortable having cameras in your house that could (in theory) be accessed silently by an unknown 3rd party?
Re: Ask HN: Do I publish code that affects millions of wireless security cameras?
#13Google "ethical disclosure." The standard in the security research community is you inform the manufacturer and give them an opportunity to patch the flaw. Then you wait some number of days (some people say 30, other say "depends on the details of the vulnerability"). Then you publish the code along with enough text to explain the vulnerability to a reasonably technical audience.
But it sounds like OP wants the flaw. If the company fixes it then OP will no longer have "full local access to [their] wireless security cameras without the cloud", so disclosing is directly against OP's interests. In that case it's probably best to just keep the flaw private to yourself.
Re: Ask HN: Do I publish code that affects millions of wireless security cameras?
#14Google "ethical disclosure." The standard in the security research community is you inform the manufacturer and give them an opportunity to patch the flaw. Then you wait some number of days (some people say 30, other say "depends on the details of the vulnerability"). Then you publish the code along with enough text to explain the vulnerability to a reasonably technical audience.
Re: Ask HN: Do I publish code that affects millions of wireless security cameras?
#15Re: Ask HN: Do I publish code that affects millions of wireless security cameras?
#16Re: Ask HN: Do I publish code that affects millions of wireless security cameras?
#17Or is this just the way the camera is supposed to operate (even if undocumented)?
Re: Ask HN: Do I publish code that affects millions of wireless security cameras?
#18Earlier quoted context omitted.
But it sounds like OP wants the flaw. If the company fixes it then OP will no longer have "full local access to [their] wireless security cameras without the cloud", so disclosing is directly against OP's interests. In that case it's probably best to just keep the flaw private to yourself.
You could presumably just not update its software.
Re: Ask HN: Do I publish code that affects millions of wireless security cameras?
#19NSA wants to know your location.
Re: Ask HN: Do I publish code that affects millions of wireless security cameras?
#20Google "ethical disclosure." The standard in the security research community is you inform the manufacturer and give them an opportunity to patch the flaw. Then you wait some number of days (some people say 30, other say "depends on the details of the vulnerability"). Then you publish the code along with enough text to explain the vulnerability to a reasonably technical audience.
But it sounds like OP wants the flaw. If the company fixes it then OP will no longer have "full local access to [their] wireless security cameras without the cloud", so disclosing is directly against OP's interests. In that case it's probably best to just keep the flaw private to yourself.