Live data from Hacker News

A Warning to Users of NurseryCam

cybergibbons.com

21–30 of 75 posts

Re: A Warning to Users of NurseryCam

#21
post #17

Out of curiosity, why is viewing nursery footage seen as serious? Should it be patched, sure. I see it as different than some random IOT device in the crib, this is at the nursery itself. Why are parents given access to particular feeds at a nursery? Why does it matter that they can watch other kids at a nursery if you’re already giving this access? Yeah I get that now ANYONE can watch them too, ooh scary men in tren…

Most of the nurseries here have big windows so everyone walking past can see nearly everything inside.

Sure, but anyone standing there for long enough to be noticed will eventually be asked to leave.

Re: A Warning to Users of NurseryCam

#22

Earlier quoted context omitted.

I haven't done any research on this particular system/device myself. I skimmed this article and just finished the Twitter thread about the other product designed to count people. Beyond the boogeymen watching the feed threat, this device itself can easily be taken over given the relaxed/non-existent security mentioned (everyone getting admin). This can in turn lead to all kinds of shenanigans ...

Ah yeah it was saying that was admin, the article didn’t go into that and was devoid of the threat greater than people watching footage

I honestly think the article skims this point in an effort to focus on the bare necessary information to communicate this to relatively non-technical people.

Re: A Warning to Users of NurseryCam

#23
> This blog post is intended for a non-technical audience

"OK, folks, let's start briefly with bridging firewall/NAT/non-static-IP-addr/UX by network port-forwarding, and then move on to the protocol scenario event trace diagrams..." :)

I appreciate this writer's work to document the surprising technical failings, and to try to protect people. And there's some good effort to make it accessible to non-technical audience, though some of it seemed a bit confusing/intimidating.

This might be a good occasion for coaching from (or collaboration with) a professional journalist or other writer. As a techie myself, I can only guess what the result of expert help might be, but maybe even more inverted-pyramid writing style for this audience's perspectives, getting into understandable threats/implications near the top, and then supporting that with the minimum technical explanation necessary. With a pointer to a very technical separate post, for credibility, and for the benefit of journalists and other techies.

BTW, maybe my contemporary US cultural bias is showing here (and the article mentioned UK)... I saw some mentions of "parent" where it seemed some of the threats might be more understandable, and more persuasive to some of the people who could benefit, were it to include something to the effect of "...or ill-intentioned computer-savvy person, outside the daycare, or even anywhere on the Internet". Not to promote paranoia over stranger-danger, but those aren't hypothetical additional vulnerabilities to which I think a parent would want their child exposed for (what appears to be) absolutely no reason.

Re: A Warning to Users of NurseryCam

#24

Out of curiosity, why is viewing nursery footage seen as serious? Should it be patched, sure. I see it as different than some random IOT device in the crib, this is at the nursery itself. Why are parents given access to particular feeds at a nursery? Why does it matter that they can watch other kids at a nursery if you’re already giving this access? Yeah I get that now ANYONE can watch them too, ooh scary men in tren…

> Out of curiosity, why is viewing nursery footage seen as serious?

As a parent you are your child's guardian, which generally means that it is your responsibility to protect your child. I would assume most people would try to protect themselves against having their surveillance footage accessed by unauthorized parties and so this parent (the author) is trying to achieve this for their children.

I personally can imagine scenarios where for the purposes of social engineering it is advantageous for a malicious actor to get access to the footage of your child's nursery to, for example, study when your child is generally there or when you pick them up or who picks them up.

Re: A Warning to Users of NurseryCam

#25
post #7

I guess this comment will be burned to the ground [instead of people telling me why they disagree], and yeah a single username and password is bad, but the article smells like fear-mongering. "Zomg, strangers will look at your children!", even though the kids are in a place that is semi-public, and the viewers are mostly remote. Hmm, then again, if someone was filming my children, I'd be creeped out. And if someone w…

It is a very real concern.

Most people know that taking an interest in children who are not in their care is frowned upon and will not watch other people's children unless there is very good reason to. As a result, someone watching children with unknown motivations is suspect. Should it be that way? Probably not, but it is given the social context.

This is even evident in public spaces. If an unknown person is watching children, someone will strike up a conversation with them. It isn't about being friendly. In fact, the person responsible for the safety of the children is probably quite annoyed. The point of that conversation to let the unknown person know that their presence is known and that they are being monitored. Why? A social norm is being violated so extra care must be taken. Is the concern excessive? Perhaps, but it is negligence if extra care is not taken and something happens.

That social expectation does not simply disappear when technology is involved. In some ways, the violation is worse since it is easier for that unknown person to conceal their presence.

(Source: I am involved with recreation programming.)

Re: A Warning to Users of NurseryCam

#26

The whole saga is just utterly insane. Its the same people who shipped the "people counting" raspberry pi system with the bruno mars mp3s in them. First they try and report the security consultants to the police, then they claim that they are too expensive to work with. Then even more bizarrely they launch a halfarsed sock puppet campaign using the CEO's wife's account. Then they start publishing reviews on their own…

Yeah... I didn't fully appreciate just how insane this is because the information's scattered all over the place. Then I read the Register article and a collated Twitter thread... and yeah, it's insane...

This company has absolutely no business being anywhere near security/software/hardware development.

https://www.theregister.com/2021/02/12/footfallcam_twitter_k...

https://twitter.com/_MG_/status/1359582048260743169

Re: A Warning to Users of NurseryCam

#27

Out of curiosity, why is viewing nursery footage seen as serious? Should it be patched, sure. I see it as different than some random IOT device in the crib, this is at the nursery itself. Why are parents given access to particular feeds at a nursery? Why does it matter that they can watch other kids at a nursery if you’re already giving this access? Yeah I get that now ANYONE can watch them too, ooh scary men in tren…

> Out of curiosity, why is viewing nursery footage seen as serious? pedophiles can view/record naked infants and toddlers with relative ease.

Not sure why I’m trying downvoted. Maybe the mere mention of pedophelia disgusts people.

This is a real threat, but honestly I’m not concerned... and I have a toddler in a facility that uses a system like this (not the same one).

Re: A Warning to Users of NurseryCam

#28
This should absolutely be an end of this company.

1. They did not just give unauthorized access, they gave admin access.

2. It’s been going on for 6 years.

3. It seems very basic.

4. Not using HTTPS is another big red flag

5. Having this secure access feature is one of their selling points, by not providing it they essentially defrauded the public.

Mistakes happen, and it worse when it happens in security field. But this is not an honest mistake, this is negligence.

Re: A Warning to Users of NurseryCam

#29
post #11
post #9

Earlier quoted context omitted.

Is your child's bedroom semi-public?

This is a system sold to commercial nurseries, not installed in peoples homes.

Yeah, and in this commercial nurseries children spend a good amount of time. So its their second bedroom.

Re: A Warning to Users of NurseryCam

#30
> To make matters worse, the connection to the DVR is using HTTP, not HTTPS. It is unencrypted, allowing someone to eavesdrop on the video feed, username, and password.

What is the proper way to provide certificates to devices with embedded servers?

- Generate a self-signed certificate with the appropriate IP address and train users to bypass the browser's scary warnings?

- Buy certificates for every deployed device. Make each device download a new certificate when its current one expires. Set up dynamic DNS so the user can reach the device at a URL that matches the certificate.

- Make the device use an ACME server to provision its certificate. The device must be publicly accessible so the ACME server can reach it.

- Proxy all device connections through a central server. This could be expensive for high-bandwidth uses like streaming video.

All of these options are poor. Why has nobody solved this problem? Is it because the powerful browser makers (first Microsoft and now Google) prefer lucrative centralized technology? Google will make a lot less money when everyone can easily run their own server to do shared docs and messaging. Or is it because IoT companies prefer centralization so they can sell subscriptions to users and gather user behavior data? Or is it just that nobody has put in enough effort to solve it yet?

Post reply on HN