Live data from Hacker News

TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years

github.com

61–70 of 96 posts

Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years

#61
post #7

Earlier quoted context omitted.

[flagged]

Security professionals - the progenitors of unrealistic expectations - also expect homeowners to buy $800 Axis cameras while they stroke their beards. When they get down to the $20 price point like the Chinese schlock, let me know, I'll be first in line to buy them.

Quality costs money, but money doesn't guarantee quality. Maybe the $800 camera is worth saving up for. But in this market for technological lemons, it's more likely they'll just buy the $20 camera and resell it to you for $800 and you're the sucker in the transaction.

Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years

#62

The fact that a firmware upgrade bricked the camera doesn't bode well for their other products...

Some of those products are banned from import into the US and will be destroyed by customs at the border. Because they're so full of probably intentional backdoors.

Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years

#64
post #32
post #11

Earlier quoted context omitted.

Consumers just don't care about security. It is what it is.

There is no reasonable way to assess security for the average consumer.

I agree. The market doesn't work well around this.

You can ask chatgpt.not a great way.

And when you ask it you the secure answers cost 3x more. And than require an installar. And some(Google) require a monthly subscription.

And even about the good systems, the chat recommends, since there's no mathematical guarantee for security, that you "Switch them off or physically cover the lenses while you are home.".

Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years

#65
post #48

Earlier quoted context omitted.

When I'm reading reviews of plans created by an agent especially on security boundaries it's suggesting huge matrixes to test even the very obscure situations, but then I'm also reading things like this and I just don't understand. Are we even using the same tools?

Management think models mean juniors can do senior work. Juniors don't know the footguns. Juniors can't read the code that the system outputs. Models get overwhelmed in any decent sized codebase. Why would you be surprised there are failures?

[flagged]

Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years

#66

Why do people keep buying all this garbage and putting it in their homes?

Because it's convenient and solves a problem and there's nothing better available for sensible money - maybe better to ask why no-one seems able or willing to make a product like this that isn't garbage?

This. They want to watch their cats when they are out but have absolutely no clue about security. So they just buy whatever is cheapest on Amazon and if it works the problem is permanently solved in their world. China has no reason to stop cranking these out at the lowest price point.

Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years

#67
post #60
post #16

Earlier quoted context omitted.

> I’m able to watch a camera that has no internet access because it passed through my Apple TV, which serves as a home hub. How exactly does this prevent the same kind of issue for Apple devices? Aren't you just trusting that Apple handles your data better than TP-Link? Not saying they don't but routing through another device doesn't really add security on its own.

> Aren't you just trusting that Apple handles your data better than TP-Link? I am, yes. Ultimately you’re going to need to trust some hardware, somewhere . No matter what you’re doing you have to trust that your home router doesn’t have an externally accessible SSH port with no password set. Personally I trust Apple more than I trust TP Link with this stuff.

> No matter what you’re doing you have to trust that your home router doesn’t have an externally accessible SSH port with no password set.

No, you don't have to trust. I build my own routers precisely because I don't.

Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years

#68
post #14

Earlier quoted context omitted.

HomeKit will take care of the VPN/remote access part, sure, but your devices still need to communicate with the HomeKit device, and that's usually over Wi-Fi, which puts the devices on the public internet, and carries the same security risk. There are various non-internet protocols for IoT devices, none of them good: * Zigbee: Requires some technical understanding to set up, devices randomly disconnect for hours even…

> devices randomly disconnect for hours even when they are 2ft from the coordinator I don't think that's normal. Like, to the point where I'm wondering if you have a bad opinion of the whole protocol because you got a faulty device.

Yes this. My experience with Zigbee is that it just works, but the setup and specific hardware probably matters. I use a SONOFF USB dongle through Zigbee2MQTT and Home Assistant.

Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years

#69
post #48

Earlier quoted context omitted.

Management think models mean juniors can do senior work. Juniors don't know the footguns. Juniors can't read the code that the system outputs. Models get overwhelmed in any decent sized codebase. Why would you be surprised there are failures?

[flagged]

Prod bugs up 260% since AI approval? Yeah, I'm gonna disagree.

BAs using AI make worse designs, management makes seniors redundant making code worse, and then QA is also laid off to make room for agentic testing. The results are not a surprise in anyway.

Post reply on HN