Live data from Hacker News

TP-Link Tapo C200: Hardcoded Keys, Buffer Overflows and Privacy

evilsocket.net

31–40 of 128 posts

Re: TP-Link Tapo C200: Hardcoded Keys, Buffer Overflows and Privacy

#31
post #3

This is so bad that it must be intentional, right? Even though these are dirt cheap, they couldn't come up with $100,000 to check for run-of-the-mill vulnerabilities? There must be many millions sold. Quite handy for some intel agencies. I assume any Wi-Fi camera under $150 has basically the same problems. I guess the only way to run a security camera where you don't have Ethernet is to use a non-proprietary Wi-Fi 10…

[deleted]

Re: TP-Link Tapo C200: Hardcoded Keys, Buffer Overflows and Privacy

#32
post #18
post #3

This is so bad that it must be intentional, right? Even though these are dirt cheap, they couldn't come up with $100,000 to check for run-of-the-mill vulnerabilities? There must be many millions sold. Quite handy for some intel agencies. I assume any Wi-Fi camera under $150 has basically the same problems. I guess the only way to run a security camera where you don't have Ethernet is to use a non-proprietary Wi-Fi 10…

Don't put them on untrusted networks. This always seemed obvious to me.

My initial read of proximity being sufficient to exploit 3 is incorrect, so yeah as long as you control the Wi-Fi network sufficiently then things should be fine.

Re: TP-Link Tapo C200: Hardcoded Keys, Buffer Overflows and Privacy

#33
post #21

I'm a little frustrated with articles like this that scattershot their critique by conflating genuine failures with problems that even FAANGs struggle with. In particular, I don't love it when an article attacks a best practice as a cheap gotcha: "and this time it was super easy! After some basic reversing of the Tapo Android app, I found out that TP-Link have their entire firmware repository in an open S3 bucket. No…

I didn't notice a negative tone at all when he talked about the firmwares being publicly hosted. You did?

Re: TP-Link Tapo C200: Hardcoded Keys, Buffer Overflows and Privacy

#34
post #21

I'm a little frustrated with articles like this that scattershot their critique by conflating genuine failures with problems that even FAANGs struggle with. In particular, I don't love it when an article attacks a best practice as a cheap gotcha: "and this time it was super easy! After some basic reversing of the Tapo Android app, I found out that TP-Link have their entire firmware repository in an open S3 bucket. No…

I didnt really interpret that as a particular criticism really

Re: TP-Link Tapo C200: Hardcoded Keys, Buffer Overflows and Privacy

#35
post #3

This is so bad that it must be intentional, right? Even though these are dirt cheap, they couldn't come up with $100,000 to check for run-of-the-mill vulnerabilities? There must be many millions sold. Quite handy for some intel agencies. I assume any Wi-Fi camera under $150 has basically the same problems. I guess the only way to run a security camera where you don't have Ethernet is to use a non-proprietary Wi-Fi 10…

> This is so bad that it must be intentional, right? Even though these are dirt cheap, they couldn't come up with $100,000 to check for run-of-the-mill vulnerabilities?

The camera sells for $17.99 on their website right now.

Subtract out the cost of the hardware, the box, warehousing, transit to the warehouse, assembly, testing, returns, lost shipments, warranty replacements, support staff, and everything else, then imagine how much is left over for profit. Let's be very optimistic and say $5 per unit.

That $5 per unit profit would mean an additional $100,000 invested in software development would be like taking 20,000 units of this camera and lighting them on fire. Or they could not do that and improve their bottom line numbers by $100,000.

TP-Link has a huge lineup of products and is constantly introducing new things. Multiply that $100,000 across the probably 100+ products on their websites and it becomes tens of millions of dollars per year.

The only way these ultra-cheap products are getting shipped at these prices is by doing the absolute bare minimum of software development. They take a reference design from the chip vendor, have 1 or 2 low wage engineers change things in the reference codebase until it appears to work, then they ship it.

Re: TP-Link Tapo C200: Hardcoded Keys, Buffer Overflows and Privacy

#36
post #18
post #3

This is so bad that it must be intentional, right? Even though these are dirt cheap, they couldn't come up with $100,000 to check for run-of-the-mill vulnerabilities? There must be many millions sold. Quite handy for some intel agencies. I assume any Wi-Fi camera under $150 has basically the same problems. I guess the only way to run a security camera where you don't have Ethernet is to use a non-proprietary Wi-Fi 10…

Don't put them on untrusted networks. This always seemed obvious to me.

Untrusted network is not sufficient, you need to cut them off internet, in general.

Re: TP-Link Tapo C200: Hardcoded Keys, Buffer Overflows and Privacy

#37
post #23

I more and more tend to not buy any network-connected product if there's no open-source firmware to run on it. (Phones is one notable exception. I need contactless payments to work.)

Good thing some tapos do have alternative firmware like thingino.

Re: TP-Link Tapo C200: Hardcoded Keys, Buffer Overflows and Privacy

#38
Great article. I have the same model and few months ago I did notice it was restarting in a non-scheduled time, and you can tell it restarts because it does a full rotation. First time it happened I ignored it but the second time I knew something was up so I disconnected it and since then been offline, it was recording an insignificant thing anyway.

Re: TP-Link Tapo C200: Hardcoded Keys, Buffer Overflows and Privacy

#39
post #23

I more and more tend to not buy any network-connected product if there's no open-source firmware to run on it. (Phones is one notable exception. I need contactless payments to work.)

If you call up your contactless payment provider, most will send you a physical device that will do contactless payments on its own, for free even. You can tape it to the back of your phone, or anywhere else for that matter.

Also, your phone doesn’t need to be connected to the internet for contactless payments, anyway.

Re: TP-Link Tapo C200: Hardcoded Keys, Buffer Overflows and Privacy

#40
post #5

As soon as i read the author used grok as an ai assistant, i was somehow less interested to keep on reading. Not because of the usage of ai, but the chosen provider. (I don’t know whether grok is just the best choice for this kind of work.) Is it wrong to judge people for their choice of ai providers?

No, because it allows us to evaluate the type of person you are. For example, I can tell you're a member of Bluesky.
Post reply on HN