Live data from Hacker News

TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years

github.com

71–80 of 96 posts

Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years

#71
post #14
post #13

Earlier quoted context omitted.

> It would be a no-go for non-techies. There are better solutions, like Apple’s HomeKit. I’m able to watch a camera that has no internet access because it passed through my Apple TV, which serves as a home hub. I didn’t have to set any of this up, it just works when you have the required hardware.

HomeKit will take care of the VPN/remote access part, sure, but your devices still need to communicate with the HomeKit device, and that's usually over Wi-Fi, which puts the devices on the public internet, and carries the same security risk. There are various non-internet protocols for IoT devices, none of them good: * Zigbee: Requires some technical understanding to set up, devices randomly disconnect for hours even…

I dunno, through HomeKit, I've got a couple Zigbee networks (Hue and Ikea), a Z-Wave network (Home Assistant) and a Matter-over-Thread (Apple/Ikea) network, and they all seem pretty good?

Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years

#72
post #60
post #16

Earlier quoted context omitted.

> I’m able to watch a camera that has no internet access because it passed through my Apple TV, which serves as a home hub. How exactly does this prevent the same kind of issue for Apple devices? Aren't you just trusting that Apple handles your data better than TP-Link? Not saying they don't but routing through another device doesn't really add security on its own.

> Aren't you just trusting that Apple handles your data better than TP-Link? I am, yes. Ultimately you’re going to need to trust some hardware, somewhere . No matter what you’re doing you have to trust that your home router doesn’t have an externally accessible SSH port with no password set. Personally I trust Apple more than I trust TP Link with this stuff.

> Personally I trust Apple more than I trust TP Link with this stuff.

What if a TP-Link camera supported HomeKit Secure Video? You access the camera through Apple but all of these cameras are still directly connected to the internet, meaning you still need to trust the camera manufacturer.

Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years

#74

A shocking number of devices are continuously reporting location data over random unencrypted protocols. What’s worse, they’re often sending the data to cloud IPs that aren’t even controlled by the company, so some random person is getting your real-time location.

Definitely curious about the breakdown of data-broker relationship for each link in the chain. Unencrypted data is easy to store and share so it’s reasonable to assume that even the most stringent privacy policy for an IoT device is essentially meaningless if it’s unencrypted PII passes through a single tracking server (including the user’s ISP who may have a direct relationship with multiple brokers)

Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years

#76
post #4

This underscores the principle that IoT devices should not be allowed to communicate over the public Internet. Pretty much all cheap, Chinese-made hardware of this kind has intentional or unintentional security holes waiting to be exploited.

routers could solve this for consumers with a checkbox for "intranet only"

99% of consumers won't know how to setup a firewall but could handle a checkbox

only problem I have is I can't seem to punch a hole for time sync and it won't use my local intranet time server

Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years

#77
I've used Kasa plugs for a long while and was not surprised that their API allowed relay control and basic info of them as long as you manage to get in the same internal network. It's local, so IMHO that is not just reasonable, it's desirable. I don't need to give my friends permission to toggle the lights manually either.

Routers having abnormal amount of zerodays, and not being fixed on the other hand is actually serious, unlike this.

Just a week ago I actually set up one of TP-link's new line of smartplugs (Tapo instead of the old Kasa), and for that I had to make an account. For actual security, I'd rather have an option to control them locally with zero additional authentication when you're already inside the network, instead of the cloud stuff. But I HAD to make an account even though the custom code I control said plug with only accesses the plug locally.

Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years

#78
post #8

Earlier quoted context omitted.

> Pretty much all cheap, Chinese-made hardware of this kind has intentional or unintentional security holes waiting to be exploited. Why single out bad Chinese coding? Bad US IoT coding has a longer history.

There’s bad, and then there’s egregious .

Like iRobot recording people on the toilet and uploading the videos?

Yeah, I agree - at least Chinese Roborock gives very granular controls for privacy.

Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years

#79
post #67
post #60

Earlier quoted context omitted.

> Aren't you just trusting that Apple handles your data better than TP-Link? I am, yes. Ultimately you’re going to need to trust some hardware, somewhere . No matter what you’re doing you have to trust that your home router doesn’t have an externally accessible SSH port with no password set. Personally I trust Apple more than I trust TP Link with this stuff.

> No matter what you’re doing you have to trust that your home router doesn’t have an externally accessible SSH port with no password set. No, you don't have to trust. I build my own routers precisely because I don't.

Pretty sure that just means that we trust Linux/Openwrt and the chip vendors.

Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years

#80
post #43

Earlier quoted context omitted.

Even if there’d be a way, there’s no culture of asking questions about how things work, especially outside the single “happy” path.

Because there are too many things. We've built society on the notion that you don't have to know. Which of course unethical corporations try to exploit. But if people knew how easy it was to use the camera they bought to spy on their family, then I bet many would care.

True, that's probably the biggest issue.

But the only solution here is very expensive marketing, so...

Post reply on HN