This underscores the principle that IoT devices should not be allowed to communicate over the public Internet. Pretty much all cheap, Chinese-made hardware of this kind has intentional or unintentional security holes waiting to be exploited.
TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years
11–20 of 96 posts
Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years
#12This underscores the principle that IoT devices should not be allowed to communicate over the public Internet. Pretty much all cheap, Chinese-made hardware of this kind has intentional or unintentional security holes waiting to be exploited.
Honestly, I'd rather it leak my GPS to the Chinese government than the US government. They don't have jurisdiction over me anyway.
> should not be allowed to communicate over the public Internet
It would be a no-go for non-techies. One of the biggest draws to IoT devices for "average Joes" is being able to view and control them from remotely, and they aren't going to have the skills or know-how to set up a VPN correctly with dynamic DNS so that their phone can VPN into their home and then sideload/jailbreak their phone to load a custom app to control it. "It just works from anywhere" is a big sell for them.
Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years
#13This underscores the principle that IoT devices should not be allowed to communicate over the public Internet. Pretty much all cheap, Chinese-made hardware of this kind has intentional or unintentional security holes waiting to be exploited.
> Chinese-made hardware Honestly, I'd rather it leak my GPS to the Chinese government than the US government. They don't have jurisdiction over me anyway. > should not be allowed to communicate over the public Internet It would be a no-go for non-techies. One of the biggest draws to IoT devices for "average Joes" is being able to view and control them from remotely, and they aren't going to have the skills or know-ho…
There are better solutions, like Apple’s HomeKit. I’m able to watch a camera that has no internet access because it passed through my Apple TV, which serves as a home hub. I didn’t have to set any of this up, it just works when you have the required hardware.
Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years
#14Earlier quoted context omitted.
> Chinese-made hardware Honestly, I'd rather it leak my GPS to the Chinese government than the US government. They don't have jurisdiction over me anyway. > should not be allowed to communicate over the public Internet It would be a no-go for non-techies. One of the biggest draws to IoT devices for "average Joes" is being able to view and control them from remotely, and they aren't going to have the skills or know-ho…
> It would be a no-go for non-techies. There are better solutions, like Apple’s HomeKit. I’m able to watch a camera that has no internet access because it passed through my Apple TV, which serves as a home hub. I didn’t have to set any of this up, it just works when you have the required hardware.
There are various non-internet protocols for IoT devices, none of them good:
* Zigbee: Requires some technical understanding to set up, devices randomly disconnect for hours even when they are 2ft from the coordinator, all-around horrible experience for non-techies
* Non-standard Zigbee variants: even worse
* Matter-over-Thread: horrendously designed from a UX perspective. Easy-to-lose barcodes stuck on cards in the packaging, weird 12-letter codes, and your non-techie cannot understand what the hell Matter or Thread is. Pairing is an absolute nightmare.
Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years
#15The report seems obviously AI generated, so I can't be bothered to read in its entirety, but based on my quick skim, "leaked home GPS" makes it sound worse than it is. Unless you're dumb enough to set DMZ on this device, this won't be exposed to the internet, and if it's LAN only, don't you already know the location? Even for a remote attacker who somehow got LAN access remotely, they can probably deduce the location…
[flagged]
It's not the best company but they're cheap.
Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years
#16Earlier quoted context omitted.
> Chinese-made hardware Honestly, I'd rather it leak my GPS to the Chinese government than the US government. They don't have jurisdiction over me anyway. > should not be allowed to communicate over the public Internet It would be a no-go for non-techies. One of the biggest draws to IoT devices for "average Joes" is being able to view and control them from remotely, and they aren't going to have the skills or know-ho…
> It would be a no-go for non-techies. There are better solutions, like Apple’s HomeKit. I’m able to watch a camera that has no internet access because it passed through my Apple TV, which serves as a home hub. I didn’t have to set any of this up, it just works when you have the required hardware.
How exactly does this prevent the same kind of issue for Apple devices? Aren't you just trusting that Apple handles your data better than TP-Link? Not saying they don't but routing through another device doesn't really add security on its own.
Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years
#17The report seems obviously AI generated, so I can't be bothered to read in its entirety, but based on my quick skim, "leaked home GPS" makes it sound worse than it is. Unless you're dumb enough to set DMZ on this device, this won't be exposed to the internet, and if it's LAN only, don't you already know the location? Even for a remote attacker who somehow got LAN access remotely, they can probably deduce the location…
[flagged]
- to do the song and dance to allow the whole Internet to access this cam - and 'security professionals' have been advising no to do that no matter what vendor it is
- to sit on your wire, literally and sniff everything
Unencrypted personal data is not good but if you have a habit of leaving your car with the open doors, windows and a key in the ignition - don't run around telling horror stories what someone didn't close the lid on a cookie jar.
Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years
#18Earlier quoted context omitted.
[flagged]
There is only two ways to receive this unencrypted data: - to do the song and dance to allow the whole Internet to access this cam - and 'security professionals' have been advising no to do that no matter what vendor it is - to sit on your wire, literally and sniff everything Unencrypted personal data is not good but if you have a habit of leaving your car with the open doors, windows and a key in the ignition - don'…
Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years
#19Earlier quoted context omitted.
> Pretty much all cheap, Chinese-made hardware of this kind has intentional or unintentional security holes waiting to be exploited. Why single out bad Chinese coding? Bad US IoT coding has a longer history.
All of there IoT devices will be slop coded soon, and I wonder whether that will be an improvement or not. I bet that security will be better.
Not doxing myself, but... Company with a known name vibecoded a dashboard with Claude. Which also hardcoded a password into the client-side of the dashboard, which I caught.
I reckon security will be about the same.
Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years
#20The report seems obviously AI generated, so I can't be bothered to read in its entirety, but based on my quick skim, "leaked home GPS" makes it sound worse than it is. Unless you're dumb enough to set DMZ on this device, this won't be exposed to the internet, and if it's LAN only, don't you already know the location? Even for a remote attacker who somehow got LAN access remotely, they can probably deduce the location…
[flagged]
When they get down to the $20 price point like the Chinese schlock, let me know, I'll be first in line to buy them.