Live data from Hacker News

Wyze security incident update

forums.wyze.com

141–150 of 161 posts

Re: Wyze security incident update

#141

Not my project but I have had great success with https://github.com/gtxaspec/wz_mini_hacks & V3 model. The V3 models need to be downgraded to a specific firmware first and patching it exposes RSTP streams using https://github.com/AlexxIT/go2rtc . Everything doable without ever installing Wyze app on an environment air gapped environment with no internet.

I'm having great success with half a dozen v3's in tandem -- for $30 a camera, the quality is really unbeatable -- setup / notes below. 1. all cameras (firmware v4.36.9.139) have 64gb+ micro SD cards and record to local storage -- many people seem to have issues with anything greater than 32gb in v3's but I've found that this Verbatim tool [0] formats FAT32 at high capacity with no problems 2. all cameras have wz_min…

This is really awesome. Thanks for the links. I'm done with everything iot cloud, even though it takes a bit more work on the home server upkeep side.

Re: Wyze security incident update

#142
post #109

Earlier quoted context omitted.

"Other than perhaps using cameras as a means to deter thieves, I’m not sure that low-value (under USD 5000) items like bicycles are worth the time and effort for insurers to launch full investigations over." I would agree, yet I have seen it happen. It is a somewhat difficult to predict path. I have seen some smaller claims (~$2000) take significantly longer and with more investigation than other very large (>$50,000…

> I would agree, yet I have seen it happen. You've seen insurance claims denied because someone didn't have an unverified video that allegedly showed a theft taking place, even with a police report in hand? (Seriously: How would an insurer know that you hadn't arranged to have your brother-in-law pretend to steal your bike for the camera?)

You said "...bicycles are worth the time and effort for insurers to launch full investigations over."

and I said:

"I would agree, yet I have seen it happen."

I was precise in answering your precise statement.

I have seen claims for less than $5000 items create significant investigative and delay-inducing efforts from an insurer. A video of the theft would have, in some of those cases, reduced that effort. Having video evidence is in almost no circumstances going to increase the time it will take to get an insurance claim paid. By you having the video evidence, you have the choice if you want to disclose it. It is just upside that you control.

If you do not want to put a camera in your garage pointing at your mountain bike, by all means do not.

Re: Wyze security incident update

#144

Earlier quoted context omitted.

My home insurance requires proof of theft. Often you use a police report. My local police department is on an unofficial slowdown strike because they don't feel appreciated post-BLM. Possibly also because if they "forget" to file police reports or they "get lost in the system" then the official crime rate goes down. It took me over a month to get a police report I could send to insurance for a simple break in, and sp…

Similar, but 6 or 7 years ago and with no discernible reason. The process of filing a police report and then compiling all the documentation required by insurance took longer and cost more by wage than I ultimately recovered through insurance. I wish I could say it was still worth it because filing the report and providing the information about the theft gave the police additional info to use if they ever caught the…

> Similar, but 6 or 7 years ago and with no discernible reason. The process of filing a police report and then compiling all the documentation required by insurance took longer and cost more by wage than I ultimately recovered through insurance.

How could it cost more? Are you counting the time spent compiling the documentation?

Re: Wyze security incident update

#145

Earlier quoted context omitted.

Why would your insurance require a proof of the theft? That is not how insurances work usually.

Of course you need to provide proof of theft. I can't simply go to my insurance, file a claim for a high-value item, and expect them to not ask any more questions. This would be rife with fraud (read: not a reasonable business model) otherwise.

You don't need a proof but a police report.

Re: Wyze security incident update

#146
This company non stop spams me, might just have to ditch the cam. I have grown used to throwing away hardware due to infinite fees, self bricking, or hacked out of the box. Consumer electronics have taken a painful dive in quality control. And hey Wyze unsubscribe me already !!!

Re: Wyze security incident update

#147

> We’ve identified your Wyze account as one that was affected. This means that thumbnails from your Events were visible in another Wyze user’s account and that a thumbnail was tapped. Most taps enlarged the thumbnail, but in some cases it could have caused an Event Video to be viewed. Kudos to Wyze for doing the things noted in the thread like being honest and prompt with notification etc, but "thumbnails from your E…

So 30 min of me sitting on my ass are on the web. Ok… enjoy viewers.

Re: Wyze security incident update

#148

Another in a long line of reasons to avoid low price, off-the-shelf, unauditable, cloud-enabled cameras. I continue to be amazed that there is not a reasonably priced, open source, audited, local-first solution, which doesn’t require a significant personal investment of time to install and maintain.

I swear sometimes you people post this ignorance bait to get product suggestions. Local-first cameras are super cheap and easy to find. Most just run their own local RTSP server, which you can connect to live with VLC, homeassistant, whatever. OpenIPC is like ddwrt for ip cameras, here is the supported devices page: https://github.com/OpenIPC/wiki/blob/master/en/guide-support... But unless you're Richard Stallman, go…

At least with my setup I prefer Amcrest over Reolink (based on compatibility and setup and plugins with the software I use). An open source option that just requires cameras, a computer, and a network is Scrypted + Frigate (+optional Google coral). Amcrest plugin in Scrypted to create a rebroadcast point, then capture it in Frigate for a birdseye view and other security features. If you have Google coral frigate can also do AI object detection (it can do it without but slower). Since Scrypted is the rebroadcast point I also have it hooked up to Apple home kit since I have an Apple TV 4K. Pretty happy so far.

Edit: Another comment mentioned https://gitlab.com/Shinobi-Systems/Shinobi which I haven’t explored but am definitely going to also try out now.

Re: Wyze security incident update

#149

Earlier quoted context omitted.

Too many. I've consulted with friends who installed "smart" security cameras and other IoT devices. I really spelled it out, saying that there's a very real possibility that one day they'll find out someone's been listening in on all of their private conversations (audio) or watching them through their own cameras. Responses typically range from "I'm not that interesting" to "I really don't care". I think it's too ab…

Where do you charge your cell phone? I totally agree with you, but then I put my phone on a qi charger on my nightstand and go to sleep. It's a device with both quality cameras and microphones, so I feel a little hypocritical given that there is a non-zero chance that someone could be listening or watching through my phone.

That's a possibility, but that would require an exploit and smartphones are far more secure and actively updated. I just keep on top of security patches and hope that's enough.

With IoT there often aren't any security patches and your audio & video are just being live streamed to the OEM's cloud waiting for someone to listen in, it doesn't even require a security exploit.

It's easily abused by employees, it even happened at Tesla where they watched their customers through the onboard cameras, taking screenshots of them walking around naked, and sharing them on company Slack channel for laughs.

That's why I find it so mind boggling, the company could incidentally hire a pervert and now you find yourself being watched in your own home by someone who knows your home address. I find this scary because it doesn't require a security exploit, just a deranged mind and those are dime a dozen.

Re: Wyze security incident update

#150

In the meantime, Wyze has rolled back RTSP support, where it was possible to use their devices locally: https://support.wyze.com/hc/en-us/articles/360026245231-Wyze... A good response to this might be to put it back, and to extend other devices to be dual-use (Wyze Cloud or HA).

For those that want their Wyze cams 100% local (with RTSP), you can use wz_mini_hacks[0]. I've set up v2 and v3 cams using this, and they've never touched the internet or wyze app. I've use the official RTSP firmware in the past on some v2 cams, but I remember it having some problems and not being as good as this solution. https://github.com/gtxaspec/wz_mini_hacks/

Thanks for this. I was using dafang hacks for v2 but didn't have solution for v3.
Post reply on HN