Live data from Hacker News

TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years

github.com

41–50 of 96 posts

Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years

#41
post #31

Earlier quoted context omitted.

> Unless you're dumb enough to (...) It sounds like you are blaming the user for providing data that a service can leak. That's like blaming a user for writing personal emails when faced with an email provider that leaks emails.

Really enjoying the picture of this user who logs into his router and decides that all unsolicited network traffic from the internet should go to his network camera. Absolute legend. God amongst men.

Heck I've seen it admins do this, then I rooted the camera and pivoted into their data center and put it into the report, "security contractor told is they needed it"

Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years

#42
post #37
post #23

Earlier quoted context omitted.

> Nowhere did I had even half an hour of disconnection. Well my garage door opener sensor has been disconnected for two 30 minute gaps today and my plant humidity sensors go offline for 2 weeks at a time. So yeah, it's not ready for prime time. > LORA No, let's not even go there. Tech nerd protocol here that's an awkward middle ground that creates even more problems. Average Joes aren't going to set that crap up.

Is your zigbee running at 2.4GHz? Everything interferes with that.

Practically all consumer Zigbee devices only support 2.4GHz. You would need to go for ZWave for the sub-GHz range.

Also, it's not like 860-930 MHz (depending on the country) is without interference.

Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years

#43
post #32

Earlier quoted context omitted.

There is no reasonable way to assess security for the average consumer.

Even if there’d be a way, there’s no culture of asking questions about how things work, especially outside the single “happy” path.

Because there are too many things. We've built society on the notion that you don't have to know. Which of course unethical corporations try to exploit.

But if people knew how easy it was to use the camera they bought to spy on their family, then I bet many would care.

Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years

#44

Why do people keep buying all this garbage and putting it in their homes?

Because it's convenient and solves a problem and there's nothing better available for sensible money - maybe better to ask why no-one seems able or willing to make a product like this that isn't garbage?

Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years

#45
post #12
post #4

This underscores the principle that IoT devices should not be allowed to communicate over the public Internet. Pretty much all cheap, Chinese-made hardware of this kind has intentional or unintentional security holes waiting to be exploited.

> Chinese-made hardware Honestly, I'd rather it leak my GPS to the Chinese government than the US government. They don't have jurisdiction over me anyway. > should not be allowed to communicate over the public Internet It would be a no-go for non-techies. One of the biggest draws to IoT devices for "average Joes" is being able to view and control them from remotely, and they aren't going to have the skills or know-ho…

Anything any government can access, motivated criminals can too.

Pissed off script kiddies have been confused as government plenty of times by unsuspecting victims.

Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years

#46

Earlier quoted context omitted.

There is only two ways to receive this unencrypted data: - to do the song and dance to allow the whole Internet to access this cam - and 'security professionals' have been advising no to do that no matter what vendor it is - to sit on your wire, literally and sniff everything Unencrypted personal data is not good but if you have a habit of leaving your car with the open doors, windows and a key in the ignition - don'…

That's because you live in a shitty place where your can't do that with your car, and think that's normal. There are places in the world where you can just leave your car unlocked with cash sitting out, and no one steals it. Yeah, the Internet is not such a place, so we can't act that way here, but in the physical world, there are safe places where you can relax.

> . There are places in the world where you can just leave your car unlocked with cash sitting out,

And most of the time it's because there is only a couple humans and bears out there. But sure, attacking me would get your point across, Mr. Beautiful Garden citizen.

Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years

#47
post #31

Earlier quoted context omitted.

> Unless you're dumb enough to (...) It sounds like you are blaming the user for providing data that a service can leak. That's like blaming a user for writing personal emails when faced with an email provider that leaks emails.

Really enjoying the picture of this user who logs into his router and decides that all unsolicited network traffic from the internet should go to his network camera. Absolute legend. God amongst men.

> Really enjoying the picture of this user who logs into his router and decides that all unsolicited network traffic from the internet should go to his network camera. Absolute legend. God amongst men.

If that idea surprises you then you definitely need to touch grass. Even cloud computing engineers are surprised to see random internet requests hitting services,and here you are assuming that any regular consumer that just wants a security camera to work will somehow have deep understanding of networking and DevSecOps and trying to ridicule those who don't.

Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years

#48
post #19

Earlier quoted context omitted.

> I bet that security will be better. Not doxing myself, but... Company with a known name vibecoded a dashboard with Claude. Which also hardcoded a password into the client-side of the dashboard, which I caught. I reckon security will be about the same.

When I'm reading reviews of plans created by an agent especially on security boundaries it's suggesting huge matrixes to test even the very obscure situations, but then I'm also reading things like this and I just don't understand. Are we even using the same tools?

Management think models mean juniors can do senior work. Juniors don't know the footguns. Juniors can't read the code that the system outputs. Models get overwhelmed in any decent sized codebase.

Why would you be surprised there are failures?

Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years

#49
post #4

This underscores the principle that IoT devices should not be allowed to communicate over the public Internet. Pretty much all cheap, Chinese-made hardware of this kind has intentional or unintentional security holes waiting to be exploited.

> This underscores the principle that IoT devices should not be allowed to communicate over the public Internet. TP-Link is a prominent maker of network hardware, including home and mesh routers.

Yea, where? :-)

Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years

#50
post #4

This underscores the principle that IoT devices should not be allowed to communicate over the public Internet. Pretty much all cheap, Chinese-made hardware of this kind has intentional or unintentional security holes waiting to be exploited.

> This underscores the principle that IoT devices should not be allowed to communicate over the public Internet. TP-Link is a prominent maker of network hardware, including home and mesh routers.

TP-Link is absolute crap of network hardware. Not to mention “leftover debug code”: https://nvd.nist.gov/vuln/detail/CVE-2024-21827
Post reply on HN