Live data from Hacker News

A Warning to Users of NurseryCam

cybergibbons.com

61–70 of 75 posts

Re: A Warning to Users of NurseryCam

#61

> To make matters worse, the connection to the DVR is using HTTP, not HTTPS. It is unencrypted, allowing someone to eavesdrop on the video feed, username, and password. What is the proper way to provide certificates to devices with embedded servers? - Generate a self-signed certificate with the appropriate IP address and train users to bypass the browser's scary warnings? - Buy certificates for every deployed device.…

Issue a proper HTTPS certificate for each DVR. Do it with the DNS validation method, so the DVR company can set up the necessary DNS TXT records to obtain the certificate, and then the device can retrieve that certificate and use it. Set the DNS A record to either be a publicly routable IP (if UPnP has worked) or to a local IP (if It didn't). Sure, an internet connection is required. But most users have that. Now all…

> Sure, an internet connection is required.

It's much worse than that. The existence of the company and their servers is required. So when those disappear, the customer-owned hardware is bricked? No thanks.

No customer-owned hardware should ever depend on the continued existence of the company that sold it.

Re: A Warning to Users of NurseryCam

#62
post #48

Earlier quoted context omitted.

They get attached to specific kids and grab them in the park after they see the kids are getting ready for their daily trip? On average, yeah, nothing bad will happen. But that’s true for someone leaving their front door unlocked too. Eventually you are likely to get fucked.

I guess. I take issue with the use of the word "likely" here though.

Any individual kindergarden may be unlikely to have it happen, but this is a business selling to multiple.

The more salient point is that even once is too many.

Re: A Warning to Users of NurseryCam

#64
post #61

Earlier quoted context omitted.

Issue a proper HTTPS certificate for each DVR. Do it with the DNS validation method, so the DVR company can set up the necessary DNS TXT records to obtain the certificate, and then the device can retrieve that certificate and use it. Set the DNS A record to either be a publicly routable IP (if UPnP has worked) or to a local IP (if It didn't). Sure, an internet connection is required. But most users have that. Now all…

> Sure, an internet connection is required. It's much worse than that. The existence of the company and their servers is required. So when those disappear, the customer-owned hardware is bricked? No thanks. No customer-owned hardware should ever depend on the continued existence of the company that sold it.

> So when those disappear, the customer-owned hardware is bricked? No thanks.

Yes please. If the company that developed some consumer networked hardware goes away, I don't want botnets of that hardware sending spam...

Software updates for security are now the norm for internet connected things, and if a piece of hardware can't be supported anymore, it will probably be exploited and siphon your private data to the highest bidder. It's far better to disable unsupportable hardware than keep using it.

If companies going bankrupt starts harming consumers, government could step in and force companies to contribute to a "support fund" for continued support of their hardware after bankruptcy if necessary.

Re: A Warning to Users of NurseryCam

#65

Earlier quoted context omitted.

Not sure why I’m trying downvoted. Maybe the mere mention of pedophelia disgusts people. This is a real threat, but honestly I’m not concerned... and I have a toddler in a facility that uses a system like this (not the same one).

I have a toddler in a facility too. But I'm not at all convinced that this is a real threat. I'm having trouble even imagining it as a theoretical threat. Pedophiles are bad for sure. But internet people watching nursery footage doesn't seem to make that any better or worse. I expect roughly all of nursery footage to be uniformly boring. Even if a pedophile got access to it... then what? Where's the threat?

> Even if a pedophile got access to it... then what? Where's the threat?

The material gets collected and sold via darknet forums.

Re: A Warning to Users of NurseryCam

#66
post #61

Earlier quoted context omitted.

> Sure, an internet connection is required. It's much worse than that. The existence of the company and their servers is required. So when those disappear, the customer-owned hardware is bricked? No thanks. No customer-owned hardware should ever depend on the continued existence of the company that sold it.

> So when those disappear, the customer-owned hardware is bricked? No thanks. Yes please. If the company that developed some consumer networked hardware goes away, I don't want botnets of that hardware sending spam... Software updates for security are now the norm for internet connected things, and if a piece of hardware can't be supported anymore, it will probably be exploited and siphon your private data to the hig…

Thank you for advocating for the continued erosion of user rights with regards to hardware they own. How about we stop tethering devices to manufacturer servers and reserve that for optional, over-the-top features?

Re: A Warning to Users of NurseryCam

#67

(Tried to re-write your intro article a bit for ... you know ... a non-technical audience.) # Summary Let me get straight to the point. If you (or your daycare) uses NurseryCam, ANYONE CAN SPY ON YOUR CHILDREN. Let me repeat that. If you (or your daycare) uses NurseryCam, ANYONE CAN SPY ON YOUR CHILDREN. ANYONE. Hi, my name is John Doe and I'm a cyber-security consultant who specialises online video security. Nursery…

While I agree the article is more technical than the author claims, that summary says very little and sounds like fear mongering. It is important to have a credible tone in order for a serious issue to be treated seriously.

One of the interesting things about the original article are the technical details. If the claims are true, almost anyone who has a decent knowledge of computer networking can circumvent the security measures. Even replacing jargon with descriptions more amenable to a non-technical audience would likely convey the same thing. This is in stark contrast to most of the vulnerabilities we hear about these days, where a much deeper knowledge is required to exploit the vulnerability even when a thorough description is provided.

Re: A Warning to Users of NurseryCam

#68
post #66

Earlier quoted context omitted.

> So when those disappear, the customer-owned hardware is bricked? No thanks. Yes please. If the company that developed some consumer networked hardware goes away, I don't want botnets of that hardware sending spam... Software updates for security are now the norm for internet connected things, and if a piece of hardware can't be supported anymore, it will probably be exploited and siphon your private data to the hig…

Thank you for advocating for the continued erosion of user rights with regards to hardware they own. How about we stop tethering devices to manufacturer servers and reserve that for optional, over-the-top features?

The right to swing your fist ends at my nose.

Internet connectivity is an optional over the top feature. You don't deserve the right to be on the shared public internet using a computer someone else made if you can't be cut off for antisocial behavior.

You can make your hardware from raw components if you want.

Re: A Warning to Users of NurseryCam

#69
post #66

Earlier quoted context omitted.

Thank you for advocating for the continued erosion of user rights with regards to hardware they own. How about we stop tethering devices to manufacturer servers and reserve that for optional, over-the-top features?

The right to swing your fist ends at my nose. Internet connectivity is an optional over the top feature. You don't deserve the right to be on the shared public internet using a computer someone else made if you can't be cut off for antisocial behavior. You can make your hardware from raw components if you want.

That's a pendulum that swings both ways, however. Disabling a manufacturer's entire fleet of product when they go out of business is a little bit far on that scale, IMO. Like you said, the right to swing your fist ends at my nose.

That's why I said "how about we stop tethering devices to manufacturer servers" implying that their basic functionality should always be standalone. Why should we be increasing long-term waste by bricking such products?

Re: A Warning to Users of NurseryCam

#70

(Tried to re-write your intro article a bit for ... you know ... a non-technical audience.) # Summary Let me get straight to the point. If you (or your daycare) uses NurseryCam, ANYONE CAN SPY ON YOUR CHILDREN. Let me repeat that. If you (or your daycare) uses NurseryCam, ANYONE CAN SPY ON YOUR CHILDREN. ANYONE. Hi, my name is John Doe and I'm a cyber-security consultant who specialises online video security. Nursery…

Since 1) this is supposed to be for "a non-technical audience" and 2) the target audience is parents of young children who feel it's necessary to monitor (in real-time) their child(ren)'s day care facilities in the first place, I can't help but think that your rewritten intro missed out on an absolutely perfect opportunity by failing to include -- for maximum effect and attention-grabbing, obviously -- terms like "pedophile", "child predator", and so on.

(I'm only halfway joking.)

Post reply on HN