Live data from Hacker News

A Warning to Users of NurseryCam

cybergibbons.com

71–75 of 75 posts

Re: A Warning to Users of NurseryCam

#71
post #45

Earlier quoted context omitted.

> - Make the device use an ACME server to provision its certificate. The device must be publicly accessible so the ACME server can reach it. This seems like the most reasonable approach given that the need for HTTPS certificates arises from public accessibility.

Certificates arise from authentication. What does any part of it have to do with public accessibility? I can share GPG keys with my friend by printing them, but when it's a certificate I should really get it validated by Egypt Mubarak CA services, TurkTrust or RussiaRSA?

You should get it validated by Let's Encrypt so that the warning goes away.

The reality is that you either push the button (get the key certified), or bad things happen (users get warnings and - for the average user - simply can't use encryption). Pushing the button also doesn't have significant negative effects, and while you can lament alternative proposals at length, there is _some_ reason behind the status quo.

So you should push the button.

Re: A Warning to Users of NurseryCam

#72
post #42

Earlier quoted context omitted.

> - Make the device use an ACME server to provision its certificate. The device must be publicly accessible so the ACME server can reach it. Not really. The most common challenge is DNS which doesn't require the ACME servers to be able to connect to the subject via HTTPs. Probably the gold standard for how to do this is how Plex implemented it: https://blog.filippo.io/how-plex-is-doing-https-for-all-its-... Not exact…

As the Plex docs notice, this is still broken: if your DNS server filters local network IP addresses as a form of some voodoo DNS rebinding "protection", this doesn't work.

Still the best way of doing it IMO, even if not perfect.

And, this wouldn't affect this situation, since, you're doing it with external IPs for external clients.

Re: A Warning to Users of NurseryCam

#73
post #42

Earlier quoted context omitted.

As the Plex docs notice, this is still broken: if your DNS server filters local network IP addresses as a form of some voodoo DNS rebinding "protection", this doesn't work.

Don't embedded devices fix the DNS-server to a specific one? Worst case the provider fixes it to their own. That has downsides too though.

The DNS queries in question are on the clients, not on the server.

Re: A Warning to Users of NurseryCam

#74
post #12

Earlier quoted context omitted.

Wow the thread about the raspberry pi system was a wild ride. For anyone else who wants to give it a read: https://twitter.com/OverSoftNL/status/1357296455615197184

Reading about FootfallCam, I can't shake the feeling that someone gave the project to a single, heavily inexperienced developer, the developer quit, and the manufacturer shipped the contents of that developer's home directory, as-is, as the final product. And the marketing was written before the product was developed, based on what they wanted the product to do, rather than what it actually did.

Looks to me like some developer somewhere made a RaspberryPI camera prototype and some dumb money ran with it creating a marketing campaign and getting the prototype in the market as if it were a complete solution.

Re: A Warning to Users of NurseryCam

#75

(Tried to re-write your intro article a bit for ... you know ... a non-technical audience.) # Summary Let me get straight to the point. If you (or your daycare) uses NurseryCam, ANYONE CAN SPY ON YOUR CHILDREN. Let me repeat that. If you (or your daycare) uses NurseryCam, ANYONE CAN SPY ON YOUR CHILDREN. ANYONE. Hi, my name is John Doe and I'm a cyber-security consultant who specialises online video security. Nursery…

Hello, NO. > ANYONE CAN SPY ON YOUR CHILDREN

No one said that except you. You shuld get less into the technical, and more into the actual reading.

Post reply on HN