Live data from Hacker News

Zero-Day Bug Allows Hackers to Access CCTV Surveillance Cameras

threatpost.com

31–37 of 37 posts

Re: Zero-Day Bug Allows Hackers to Access CCTV Surveillance Cameras

#31

My house security and automation systems are all behind a firewall and access to them is proxied, including the video feed concentrator for the security cameras. I've had folks call this overkill but I won't directly expose any IoT-like thing to the Internet these days.

Do you mind if I ask what cameras / software you use? or a good site to read up on this topic?

Bonus if it has a mobile app/interface, my use case is video monitoring of my kids rooms while they sleep.

Re: Zero-Day Bug Allows Hackers to Access CCTV Surveillance Cameras

#32

My house security and automation systems are all behind a firewall and access to them is proxied, including the video feed concentrator for the security cameras. I've had folks call this overkill but I won't directly expose any IoT-like thing to the Internet these days.

isolation is hard if you can't trust the device. Have fun blocking nonstandard upnp hacks and worrying about outgoing traffic from the cameras.

https://www.schneier.com/blog/archives/2016/02/eavesdropping...

Re: Zero-Day Bug Allows Hackers to Access CCTV Surveillance Cameras

#33
post #14

My house security and automation systems are all behind a firewall and access to them is proxied, including the video feed concentrator for the security cameras. I've had folks call this overkill but I won't directly expose any IoT-like thing to the Internet these days.

Unless you left upnp enabled, in which case all precations are useless.

Tell me, Mr. Anderson: what good is UPnP, if the firewall blocks it?

Re: Zero-Day Bug Allows Hackers to Access CCTV Surveillance Cameras

#34
post #17

Any Internet-connected device is, in fact, a server, and must be seen and managed as one. This means strict control of installed services and, first and foremost, regular updates of all its software components (including firmware). If you acquire and install such a server which either can’t be updated or one which you know, realistically, won’t get any updates six months after installation, that’s asking to lose.

In my experience, keeping software and firmware aggressively up to date is far more likely to randomly break functionality and workflow and require my time and effort to fix than doing nothing and crossing my fingers I'm not subject to a zero-day. I can't even imagine how annoying this would be for someone without technical know-how. I think manufacturers who seem desperate to trick users into installing updates coul…

If you don’t update, you will be subject to an exploit, and you and your devices will then possibly be unwitting members of (possibly multiple) botnets.

Not updating for X days just increases the risk from only zero-day exploits to the risks of X-or-less-days exploits.

Re: Zero-Day Bug Allows Hackers to Access CCTV Surveillance Cameras

#35
post #15

Doesn't CCTV stand for close circuit television? It shouldn't be applied when these are rather obviously not closed at all.

Agreed, but it has become a holdover catch-all term roughly meaning 'permanantly affixed, security camera' no matter the actual tech. I suspect many built for the purpose still use ccd detectors, but I lack domain knowledge in this case.

Re: Zero-Day Bug Allows Hackers to Access CCTV Surveillance Cameras

#36
post #30

My house security and automation systems are all behind a firewall and access to them is proxied, including the video feed concentrator for the security cameras. I've had folks call this overkill but I won't directly expose any IoT-like thing to the Internet these days.

Are they able to initiate outbound connections?

No. They can't route out themselves (only through the proxy, which they don't know how to use and won't accept outbound connections from them anyway), and there is no UPnP enabled on that network.

Re: Zero-Day Bug Allows Hackers to Access CCTV Surveillance Cameras

#37
I look at mainstream security devices.

I look at cheap camera modules and Linux boards.

I look some more at the mainstream security devices.

I look again at the cheap cameras and Linux boards.

Sadly, security cameras are among the most hackable targets on the Internet, because You™ haven't released that competitive solution you've been thinking about that prioritizes security over unnecessary bells and whistles. When you do, you'll corner that vocal fraction of the community you've always been wanting to meet.

It doesn't have to be a bureaucratic, incoherent, legacy-burdened headache built from clipboard-remixed vendor samples. Linux, no blobs, a couple lightweight services; and you're done. Remote access in the palm of your hand? Too easy. Anything is possible when you design without agendas.

--

Your plaintext passwords (which were also using in two other places - argh) just leaked from a vendor's stolen cloud database.

A HTTP URL hack that dumps the root password into the browser window surfaced seven months ago.

Post reply on HN