Live data from Hacker News

Why We're Pulling Our Recommendation of Wyze Security Cameras

nytimes.com

91–100 of 115 posts

Re: Why We're Pulling Our Recommendation of Wyze Security Cameras

#91
post #76

I have a bunch of wyze gear, given the price I never assumed they were meant to replace a security system. What I have been doing with these cheap little cameras is getting me closer to nature. We have a bunch of these outside and we've been watching the cats, possums, raccoons, and even turkeys frolic as they cross through our property. We even set up a little victorian style dog hours with solar panels in the backy…

I did use my wyze cams like that for a while (surveilling the garden pests mainly) but then wyze cut out that functionality. It used to record a little video clip when it detected motion, now wyze wants $5 a month for that.

You can still achieve this by saving video (configured either to be continuous or triggered by motion) to a micro SD card.

Re: Why We're Pulling Our Recommendation of Wyze Security Cameras

#92

Earlier quoted context omitted.

Reolink has hardcoded backdoor creds. https://www.cisa.gov/news-events/ics-advisories/icsa-21-019-...

Correct me if I’m wrong but that appears to apply to the cameras themselves which are not on my network. They plug directly into the NVR (which provides PoE) and are not exposed to the network at large.

Why do you assume the NVR is free from hardcoded creds?

Re: Why We're Pulling Our Recommendation of Wyze Security Cameras

#93

Earlier quoted context omitted.

Correct me if I’m wrong but that appears to apply to the cameras themselves which are not on my network. They plug directly into the NVR (which provides PoE) and are not exposed to the network at large.

Why do you assume the NVR is free from hardcoded creds?

Because it’s not listed in the list of affected devices. Also if that’s a concern then don’t expose the NVR. Use something like tailscale or a VPN to access it remotely (or don’t access it remotely).

Re: Why We're Pulling Our Recommendation of Wyze Security Cameras

#94
post #64

Earlier quoted context omitted.

The market for a product that requires the buyer to setup a VPN is not going to be very large. You seriously overestimate the average tech competence of people. It needs to be something you just plug in and it works.

Raspberry Pis have been sold out forever. There are plenty of competent people buying hardware with the training wheels removed.

Plenty relative to a small absolute number overall - right? I don’t know RPI sales but the difficulty buying them doesn’t signal that loads of average folks want to bother.

I have both RPI local cam set up and Wyze. Despite concerns, hard to argue with pure convenience of Wyze (and similar products)

Re: Why We're Pulling Our Recommendation of Wyze Security Cameras

#95
post #64

Earlier quoted context omitted.

The market for a product that requires the buyer to setup a VPN is not going to be very large. You seriously overestimate the average tech competence of people. It needs to be something you just plug in and it works.

Raspberry Pis have been sold out forever. There are plenty of competent people buying hardware with the training wheels removed.

One of the reasons for them being sold out is a lot of the demand for Raspberry comes from industrial customers. For example, back in 2020, they made up 44% of total Raspberry Pi sales.

Source: https://www.raspberrypi.com/news/supporting-raspberry-pis-in...

Re: Why We're Pulling Our Recommendation of Wyze Security Cameras

#96

Earlier quoted context omitted.

Do you honestly believe that a now public NSA style backdoor will never be used by anyone that is not NSA? Of course goofy script kiddies will be using this to see what cameras are seeing and then do a range of things from posting embarrassing images to the web for the lulz or up to blackmailing people. that's with less than 3 seconds of thinking about what a vuln could do for non NSA types

I think having all of this stuff behind a firewall and not exposed to the internet makes a pretty big difference. If an attacker gets onto my LAN, it's game over. Mass produced consumer gear that is also perfectly secure probably doesn't exist. I assume everything I use has bugs and none of it will stand up to a dedicated attacker. As for blackmail, my cameras all point outward. I suppose they could threaten to repor…

and exactly what firewall hardware is being used so that you feel assured that it is also not prone to the same issue?

Re: Why We're Pulling Our Recommendation of Wyze Security Cameras

#97

Earlier quoted context omitted.

I think having all of this stuff behind a firewall and not exposed to the internet makes a pretty big difference. If an attacker gets onto my LAN, it's game over. Mass produced consumer gear that is also perfectly secure probably doesn't exist. I assume everything I use has bugs and none of it will stand up to a dedicated attacker. As for blackmail, my cameras all point outward. I suppose they could threaten to repor…

and exactly what firewall hardware is being used so that you feel assured that it is also not prone to the same issue?

I'm almost certain it does have the same issue. I don't believe there's any networking gear out there that is believed to be bug and exploit free now and expected to stay that way in the future.

I believe a dedicated hacker could use the microphone and camera in my phone and laptop to spy on me. They could look at the street in front of my house. They could see my entire browser history, everything I've printed, every call I've made, everything I've said over email or text message.

Re: Why We're Pulling Our Recommendation of Wyze Security Cameras

#98

Earlier quoted context omitted.

Why do you assume the NVR is free from hardcoded creds?

Because it’s not listed in the list of affected devices. Also if that’s a concern then don’t expose the NVR. Use something like tailscale or a VPN to access it remotely (or don’t access it remotely).

Yeah but now everyone in your wifi range with commonly available hardware has access to your NVR and by extension your cameras.

And actually if any of your network machines or devices are breached, the attackers now have NVR/cam access.

Re: Why We're Pulling Our Recommendation of Wyze Security Cameras

#99

Earlier quoted context omitted.

Because it’s not listed in the list of affected devices. Also if that’s a concern then don’t expose the NVR. Use something like tailscale or a VPN to access it remotely (or don’t access it remotely).

Yeah but now everyone in your wifi range with commonly available hardware has access to your NVR and by extension your cameras. And actually if any of your network machines or devices are breached, the attackers now have NVR/cam access.

? My cameras aren't wifi, they are ethernet and the NVR isn't wifi-based either.

Re: Why We're Pulling Our Recommendation of Wyze Security Cameras

#100

Earlier quoted context omitted.

Yeah but now everyone in your wifi range with commonly available hardware has access to your NVR and by extension your cameras. And actually if any of your network machines or devices are breached, the attackers now have NVR/cam access.

? My cameras aren't wifi, they are ethernet and the NVR isn't wifi-based either.

Your wifi network probably isn't VLAN'd away from your hardwired network. It's all the same IP space.

You can check your NVR from your phone on wifi right?

Post reply on HN