[HN Gopher] Hackers break into thousands of security cameras, ex...
       ___________________________________________________________________
        
       Hackers break into thousands of security cameras, exposing Tesla,
       jail, hospital
        
       Author : f430
       Score  : 645 points
       Date   : 2021-03-09 22:11 UTC (1 days ago)
        
 (HTM) web link (www.bnnbloomberg.ca)
 (TXT) w3m dump (www.bnnbloomberg.ca)
        
       | dhdhhdd wrote:
       | I own reolink and amcrest cameras. I put them in a vlan with no
       | outside connectivity (and frankly no inside either!). They try to
       | call home constantly :-(
        
       | irthomasthomas wrote:
       | "Kottmann said their reasons for hacking are "lots of curiosity,
       | fighting for freedom of information and against intellectual
       | property, a huge dose of anti-capitalism, a hint of anarchism --
       | and it's also just too much fun not to do it."" .... "Kottmann
       | says they found a user name and password for an administrator
       | account publicly exposed on the internet"
       | 
       | Excuse me but finding a password that some idiot included in
       | their public git project is not fucking hacking.
        
       | cwkoss wrote:
       | I wonder how much footage has been captured. Hackers could have
       | produced a prison reality TV show with all that access.
        
         | edoceo wrote:
         | Never be as good as Oz, that show was amazing
        
       | bredren wrote:
       | Sequoia is mentioned prominently here. What is the role of
       | venture funds in ensuring their startups operate or endure some
       | basic regular external security audits?
        
       | soheil wrote:
       | Is there an archive of the raw photos/videos someone can link to?
        
       | naebother wrote:
       | If they've got nothing to hide, they've got nothing to fear.
        
       | TobySKT wrote:
       | "If you've ever searched for content and interacted with the
       | results on a mobile device, you've probably encountered AMP, or
       | Accelerated Mobile Pages. AMP is a good solution for websites
       | that deal with huge volumes of data and need to retain fast
       | performance. These can be informational websites, blogs, and news
       | sites. For large projects, AMP can't substitute for responsive or
       | adaptive web design.
       | 
       | If you're interested in using AMP or If you want a free
       | consultation from our team, feel free to contact us. We'd be
       | happy to help." https://steelkiwi.com/blog/accelerated-mobile-
       | pages-what-is-...
        
       | jtsiskin wrote:
       | Why would the footage not be E2E encrypted? Hospitals and police
       | stations are installing cameras which store unencrypted footage
       | remotely?? What is this madness
        
         | ocdtrekkie wrote:
         | End-to-end between the cloud provider and the cameras at the
         | site, sure. But it's stored unencrypted, mostly because cloud
         | providers provide the web interfaces and such to stream the
         | video, provide services to analyze and classify the video, etc.
         | 
         | Nobody encrypts their surveillance video storage, AFAIK.
        
           | d110af5ccf wrote:
           | > End-to-end between the cloud provider and the cameras at
           | the site, sure
           | 
           | That's TLS, not E2EE. E2EE means the provider never sees the
           | unencrypted data. (Ex SMS is unencrypted, most internet
           | services use TLS these days, Matrix and Signal use E2EE.)
           | 
           | > Nobody encrypts their surveillance video storage, AFAIK.
           | 
           | This is a serious problem.
        
             | ocdtrekkie wrote:
             | It's never going to change because of the performance
             | implications. Most video surveillance systems have poor CPU
             | to begin with.
        
               | d110af5ccf wrote:
               | What performance implication?! AES-NI has been standard
               | for mainstream x86 hardware since ~2013 and ARMv8
               | introduced optional crypto instructions in 2011!
               | 
               | The issue is that manufacturers choose the cheapest
               | possible SoC that lacks these abilities. Given the small
               | cost savings and importance of basic security measures,
               | that really needs to change.
               | 
               | (A quick look at Amazon shows many of the top sellers
               | advertising various "AI" features and streaming video at
               | 4K or better. Given their apparent capabilities, I
               | strongly suspect that such SoCs do in fact have hardware
               | support for crypto.)
        
       | philip1209 wrote:
       | Isn't Cloudflare notorious for otherwise wanting only on-premise
       | software?
        
         | lima wrote:
         | Yeah... I bet today was the security team's "told you so" day.
        
           | ocdtrekkie wrote:
           | Especially if https://twitter.com/nyancrimew/status/136943725
           | 6193343496?s=... is true.
        
             | mcv wrote:
             | Tweet account has been suspended. Could you tell us what
             | was in it?
        
               | ocdtrekkie wrote:
               | The person behind this claimed to have root shells on the
               | networks of both Cloudflare and Okta. (FWIW, if the
               | network is well segmented, this may have limited impact.)
        
       | throwawaygulf wrote:
       | Hilarious. Software development at Verkada is filled with "non-
       | traditional backgrounds" leftist SJW types that spew neurotic
       | delusional beliefs on Slack all day.
       | 
       | I bet management wishes they would have hired some real devs with
       | backgrounds in software development and security. You reap what
       | you sow.
        
       | hummel wrote:
       | Note to HN. I know personally the attackers, and they send me
       | proof of the attack before making it public. They are just two
       | south america teens having fun cause they can't leave home. They
       | were doing just for the lolz, there is no complex supply chain
       | attack or state-actors involved. Just two kids pwning billions of
       | VC money.
        
         | 19h wrote:
         | Not sure who contacted you but one of them is definitely from
         | Switzerland.
        
           | moosebear847 wrote:
           | Idk anything, except that one of these ninjas is lying.
        
             | adtac wrote:
             | unless Switzerland happens to be in South America!
        
       | rozab wrote:
       | Cloudflare? Wonder if any were pointed at their lava lamps ;)
        
         | jgrahamc wrote:
         | No.
        
         | ocdtrekkie wrote:
         | Yeah, I wonder if the hackers had the same feed used to
         | generate Cloudflare's randomness... that could be a vastly
         | bigger security breach on top of this one.
        
           | karlding wrote:
           | If their blog posts are to be believed [0], lava lamps are
           | not the only source of entropy available.
           | 
           |  _> Hopefully, the primary sources of randomness used by our
           | production servers will remain secure, and LavaRand will
           | serve little purpose beyond adding some flair to our office.
           | But if it turns out that we're wrong, and that our randomness
           | sources in production are actually flawed, then LavaRand will
           | be our hedge, making it just a little bit harder to hack
           | Cloudflare._
           | 
           | [0] https://blog.cloudflare.com/randomness-101-lavarand-in-
           | produ...
        
       | walrus01 wrote:
       | This is the same company that was in the news back in October
       | related to harassing its own female employees with fratboy
       | douchebag behavior:
       | 
       | https://www.theverge.com/2020/10/26/21535089/surveillance-co...
        
         | Hypocritelefty wrote:
         | Tesla shills will find anything lol
        
         | tartoran wrote:
         | Good catch. I wonder if it's just kharma or they were targeted
         | specifically in response to those behaviours
        
           | walrus01 wrote:
           | Or maybe companies run by sleazy people have less than
           | stellar infosec/netsec practices, or are prone to sweeping
           | gaping security holes under the rug rather than fixing them,
           | which will inevitably result in something like this.
        
             | Balgair wrote:
             | It's talked a bit more downthread, but I mean if the sales
             | director is making public slack channels featuring female
             | employees alongside explicit jokes, then long-term thinking
             | may not be a strongly selected for attribute at the
             | company.
             | 
             | https://news.ycombinator.com/item?id=24906940
        
         | adolph wrote:
         | To be fair, it was a specific person with a set of other
         | employees who were all punished for the incident. It wasn't the
         | company which includes the people were harassed.
        
           | wavefunction wrote:
           | Why is a sales employee enabled with access to the
           | surveillance footage of the home office? It's not trust-
           | inspiring.
        
             | scubazealous wrote:
             | You would be surprised the unrestrained access given to
             | sales and support employees at most small SAAS companies.
        
             | mcv wrote:
             | Exactly. I'm not entirely surprised to see a company with a
             | history of unprofessionalism and poor security policies,
             | hacked.
        
           | jhanschoo wrote:
           | The headline oversells it but your comment undersells it.
           | 
           | The specific person and set of other employees were "a group
           | of men in leadership positions on the sales team", including
           | the "sales director". When found out,
           | 
           | > Verkada CEO Filip Kaliszan gave employees in the Slack
           | channel [i.e. those involved] a choice: leave the company or
           | have their stock options reduced. All of them chose to stay
           | and take the stock option cut, according to Vice. "I was
           | shocked. To me that's not just a fireable offense, that's a
           | career-ending offense," one employee told IPVM.
        
             | walrus01 wrote:
             | It says a great deal about the CEO's character and judgment
             | that he even considered for a moment _not_ firing everyone
             | involved.
        
               | guiriduro wrote:
               | Even if the CEO is unshameable, the investors can be.
               | Here they are[0]. Remind them publicly they invest in a
               | broken company and make their association toxic as and
               | until they distance, disinvest and hold the company and
               | its officers fully accountable.
               | 
               | [0] https://www.crunchbase.com/organization/verkada/compa
               | ny_fina...
        
               | baxtr wrote:
               | You need a have subscription to see all investors...
        
               | vermilingua wrote:
               | I can see them all just fine.
               | 
               | Sequoia Capital, First Round Capital, Felicis Ventures,
               | Meritech Capital, and Next27 are the lead investors.
        
               | HenryBemis wrote:
               | 1. Sequoia Capital
               | 
               | 2. First Round Capital
               | 
               | 3. Felicis Ventures
               | 
               | 4. Founder Collective
               | 
               | 5. Meritech Capital Partners
               | 
               | 6. Next47
               | 
               | 7. Fifth Down Capital
               | 
               | 8. Nick Candito
               | 
               | 9. Hans Robertson
               | 
               | 10. Idan Koren
               | 
               | 11. Hector Garcia-Molina
               | 
               | Edit:
               | 
               | I used AdBlockPlus to block their pixel-filter, and then
               | when I went back in they served me this nice message:
               | Access to this page has been denied because we believe
               | you are using automation tools to browse the website.
               | 
               | Javascript is disabled or blocked by an extension (ad
               | blockers for example)
               | 
               |  _wink_
        
               | [deleted]
        
               | bredren wrote:
               | The video event annotations or filenames described in the
               | article sound like what you might get out of a company
               | culture that allowed the previous behavior to go largely
               | unpunished.
        
               | TedDoesntTalk wrote:
               | It was not clear to me if the Arizona prison (the
               | customer) chose those filenames or Verkada did. I could
               | see prison guards doing the same thing... archiving clips
               | that they find entertaining and naming them
               | inappropriately. Not defending Verkada, I just wish the
               | article made the culprit more clear.
        
               | alexeldeib wrote:
               | From a different article, seems like the staff
               | 
               | > Inside Arizona's Graham County detention facility,
               | which has 17 cameras, videos are given titles by the
               | center's staff and saved to a Verkada account.
               | 
               | https://www.bloomberg.com/news/articles/2021-03-09/hacker
               | s-e...
        
               | bredren wrote:
               | My mistake. Would edit if possible.
        
               | throwawayboise wrote:
               | Never trust a man named Flip.
               | 
               | Edit: Argh... it's Filip. HN's tiny font strikes back.
        
       | A4ET8a8uTh0 wrote:
       | So a real question.. was HIPAA violated or since they used a
       | 'good' vendor, the check mark is on the compliance list and
       | auditors will be happy?
        
         | SilverRed wrote:
         | I think anyone who has had to comply with those compliance
         | lists knows how useless they are. Easy to make the minimum
         | change that makes you compliant without being any more secure.
        
       | bronson wrote:
       | Also Verkada, 4 months ago: Surveillance company harassed female
       | employees using its own facial recognition
       | 
       | https://news.ycombinator.com/item?id=24906940
        
         | f430 wrote:
         | > Last year, the sales director accessed these cameras to take
         | photos of female workers, then posted them in a Slack channel
         | called #RawVerkadawgz alongside sexually explicit jokes. The
         | incident was first reported by IPVM and independently verified
         | by Vice.
         | 
         | damn that is despicable but this sort of brogrammer behavior
         | appears rampant. How would you address this as a manager? This
         | is absolutely not okay.
        
           | ALittleLight wrote:
           | You think their sales director is also a programmer? What's
           | the point of combining "programmer" and "bro" like this?
        
             | vineyardmike wrote:
             | > What's the point of combining "programmer" and "bro" like
             | this
             | 
             | This is a known (to some) phrase, with a known (to some)
             | meaning... its about bro-y silicon valley culture more than
             | actual programmers
        
               | ALittleLight wrote:
               | You use a portmanteau of programmer to refer to people
               | who aren't programmers? Seems like this is just the wrong
               | pejorative to use in this case.
        
               | vineyardmike wrote:
               | It could be a programmer. I think the origin comes from
               | bro-y men around 2005 moving to silicon valley (eg zuck
               | in that movie) but then having a very frat-culture vibe
               | (eg. lots of booze, house parties but with programming,
               | etc). It grew to be anyone silicon-valley and tech-
               | adjacent that acted like this.
        
           | stjohnswarts wrote:
           | You're right, it "appears" rampant with quotes. It really
           | isn't. The world is a big place and such solacious news
           | because almost instantly popular (because internet) even
           | though it's a 1 in a million thing.
        
           | 46Bit wrote:
           | fire for cause, file a police report depending on what the
           | photos are, and support the victims
        
             | mcv wrote:
             | Not what they did, mind you. The culprits merely got their
             | stock options reduced. And the fact that the sales manager
             | could access the camera feed may have been a big hint that
             | security was not their biggest priority.
        
       | ck2 wrote:
       | If only there was a way to keep an intranet inaccessible from the
       | internet like not connecting the two.
       | 
       | You think there are nuclear missiles somewhere on the internet?
       | Someday some general will want to monitor them and order that.
        
       | rapjr9 wrote:
       | I'd like to see an overview of everything that has been hacked so
       | far, arranged by both device/protocol and industry/gov/social
       | structure. It would be interesting to see if there are any
       | categories that have not yet been hacked and what their
       | characteristics are and where in society they reside. Maybe
       | secure internal networks at the DoD have not yet been hacked?
       | (How would we know, aren't those networks the ones the state
       | attackers really REALLY want to attack? Who would tell us if
       | they'd been compromised? There have been some news reports on the
       | use of insecure drone control wireless protocols.) Crypto
       | protocols used for chemical plant SCADA? Have parts of Starlink
       | been hacked yet? Which banking protocols and hardware security
       | modules have been hacked and which have not (SWIFT? HSM's based
       | on ASC X9 standards?) Might give us some clue as to what actually
       | works, what needs to be abandoned, and what needs changes. At the
       | moment this looks like a losing battle (possibly a loss of
       | civilization?) with the number of big data thefts and compromises
       | if something does not change. Does anyone know if such a
       | comprehensive review exists in the literature?
        
         | brk wrote:
         | I started this list when I was part of IPVM:
         | https://ipvm.com/reports/security-exploits
         | 
         | It's probably missing some, and is specific to security
         | cameras, but it is a start.
        
       | heracles wrote:
       | I'd like to add a bit of context to how security cameras most
       | often are installed.
       | 
       | In the industry in general you have producers of the equipment
       | and you have buyers, but in between there you have integrators.
       | The integrators plays a crucial role when installing big systems.
       | They win the bid for an installation and carries out the work.
       | This means that there is seldomly any direct path between camera
       | producer and the customer. For the producer to get access to
       | footage they must go through the integrator, so the friction is
       | non-trivial.
       | 
       | Direct contact producer <=> buyer might happen in the small case,
       | like a store with a single camera or you placing one at home.
       | 
       | My guess (!) is that verkada tries to pry away the integrators
       | with a simpler model for installation.
       | 
       | Most larger producers now have cloud offerings, which could have
       | some similar vulnerabilities to those mentioned in the article.
       | However, my impression is that security is taken VERY seriously.
       | Not just lipservice, but in practice. This makes sense as it is a
       | key selling point and the larger buyers are competent judges of
       | this. This is in stark contrast to the "typical" hacked target,
       | which seems to be autoshops and hospitals (I am generalising to
       | get through a point, I am not sure what the most common victim
       | is).
        
       | DudeInBasement wrote:
       | So, do they know what happened to Jeffery?
        
       | cosmodisk wrote:
       | You hardly need to be a hacker for this. I did some Google dorks
       | out of boredom. In 15 min, I saw live feed from some CCTVs
       | exposed to public internet. The most disturbing one was someone's
       | living room...
        
       | ak217 wrote:
       | Earlier feature about the culture at the security camera company
       | in question: https://www.vice.com/en/article/pkdyqm/surveillance-
       | startup-...
        
       | gibolt wrote:
       | Quite comical that the image in the article is subtitled 'Madison
       | County Jail', but is actually seemingly a Tesla service center.
       | 
       | Other options are the reporting site got hacked or it is quite
       | the experience at that jail.
        
         | xiphias2 wrote:
         | I thought that jail workers are used to fix Tesla cars. I have
         | read that people in jail are used for work in the US.
        
           | marshmallow_12 wrote:
           | They do actually get pay from what i hear. It's not like its
           | forced labour (labor).
        
             | danaliv wrote:
             | A whopping $0.14-$1.41 per hour.
             | 
             | https://www.prisonpolicy.org/blog/2017/04/10/wages/
        
               | [deleted]
        
               | marshmallow_12 wrote:
               | I still think it's better then sitting and staring at the
               | walls, yet that option is open to them .
        
               | to11mtm wrote:
               | It's a worse option for everyone:
               | 
               | - Pushes down wages for other workers doing similar
               | labor, by taking demand out from the normal market
               | 
               | - Because the prison itself (or, more likely, the prison-
               | industrial-complex corporation running it) is seeing a
               | huge profit from these ventures, it provides a perverse
               | incentive to keep their labor pool 'strong', be it
               | through lobbying for harsher sentences, or encouraging
               | shot quotas amongst their guards/COs.
               | 
               | - Conditions prisoners towards working less for equal
               | work (we shouldn't encourage the idea that -any- class,
               | race, or creed of human being is worth less for the same
               | amount of work)
        
               | SilverRed wrote:
               | No its not, because that work generate value for
               | companies at a very low cost. So it both builds a system
               | that pushes for more people in prison and displaces
               | workers who would have been paid higher.
               | 
               | Prisoners should be given some kind of work / study /
               | something. But it should't generate value for anyone but
               | the prisoner or perhaps lower costs for the prison
               | (cleaning/etc)
        
       | klingon78 wrote:
       | I wonder about Cloudflare. It seems like the Windows Vista of its
       | genre. It's big, pretty, and possibly doomed to be replaced.
       | 
       | Tesla is fine. It may as well have been a publicity stunt for
       | them. "For a limited time, you can tour the Tesla facility, but
       | please don't. (wink wink!)"
        
       | robbyking wrote:
       | A while ago there was a post on Reddit about something similar,
       | and there wasn't even any "hacking" going on; the video feeds
       | were just unsecured.
       | 
       | Using Google, someone search for a proprietary video protocol
       | (IIRC) and found tons of video streams that weren't even password
       | protected. Some in schools, some in warehouses, and some just on
       | the street as part of neighborhood surveillance. I think I have
       | the link saved, I'll look for it.
        
         | Mixtape wrote:
         | Finding unprotected streams via Google Dorking like this is
         | easy. Here's an article that doesn't cover this particular use
         | case, but rather the broader practice:
         | 
         | https://exposingtheinvisible.org/guides/google-dorking/
         | 
         | I've personally dabbled with it a bit in the past, and while I
         | didn't find anything particularly interesting, it did make me a
         | bit more cautious about enabling anyone with a link to access a
         | Google Doc. With a good enough scraper or even just a lot of
         | patience, there are a lot (potentially sensitive) data out
         | there for people to harvest. That's not to say there aren't a
         | number of benefits to having access to advanced search tools
         | though, just that individual mindfulness when making something
         | completely open for anyone to access is all the more important.
        
         | judge2020 wrote:
         | https://www.shodan.io/explore/tag/webcam
        
         | SilverRed wrote:
         | Its horrible how common this is. I used to do work on local
         | business sites and the security was horrific. Pages that
         | contain sensitive data or even CRM management pages exposed to
         | the public internet with no password at all. On some of the
         | less sensitive ones I had a look I found details of family
         | members in these exposed sites.
         | 
         | Not only that, but it was all horribly outdated. Seen some
         | things running on rails 1 pre release on a debian server about
         | 6 years passed end of life.
         | 
         | Its a wonder the world works at all.
        
         | Teknoman117 wrote:
         | Wasn't there a website along the lines of "camroulette" that
         | showed you random unsecured IP camera feeds?
        
           | d110af5ccf wrote:
           | Yes. There also used to be a subreddit where every post was
           | an unsecured camera IP address.
        
       | TameAntelope wrote:
       | These folks (the hacker group) are a hoot to follow on Twitter, I
       | do recommend searching for and finding them there. Hacker demons,
       | the lot of them. :)
        
       | ocdtrekkie wrote:
       | Putting surveillance video on the cloud is... kinda dumb. It's
       | rarely viewed outside your network, and local drives cost
       | drastically less than the bandwidth needs. Also it's incredibly
       | sensitive data that shouldn't leave your network without really
       | good reason anyways.
       | 
       | The solution to this hack is simple: Shut this company down,
       | because it's a bad idea.
        
         | httpz wrote:
         | When Microsoft Exchange servers were hacked a few days ago,
         | people on hacker news were talking about how most companies are
         | not capable of securing their own on-premise systems and they
         | should have used Office 365. There really isn't a perfect
         | solution. There are trade-offs.
        
           | ocdtrekkie wrote:
           | It's a lot easier to secure on-premise Exchange than Office
           | 365. For one, having OWA exposed to the Internet is entirely
           | optional for Exchange on-prem... but impossible for avoid for
           | a cloud service. Most possible ways to secure access to
           | Exchange on-prem are built into your firewall, and you can
           | configure at leisure... most possible ways to secure access
           | to Office 365 are billable add-ons to your subscription. Any
           | side channels to that... you just have to trust Microsoft...
           | 
           | I agree there are trade-offs, but especially for large
           | enterprises with security teams, on-prem is definitely more
           | secure.
        
         | rapsey wrote:
         | Unfortunately local storage is a problem. It is very vulnerable
         | to arson or theft.
        
         | Ensorceled wrote:
         | There are actually plenty of reasons for remote storage of
         | surveillance footage; not the least of which is that offsite
         | storage of such video can be a regulatory or insurance
         | requirement.
        
         | quasirandom wrote:
         | There's more information here as well. Cloudflare was
         | apparently operating network connected facial recognition
         | cameras in their offices.
         | 
         | I'm not someone who's crazy about privacy, but this is a pretty
         | dark indicator for a company housing DNS query records. Maybe
         | its time for someone to build a proxy for tunneling Cloudflare
         | DoH/DoT over tor or some other free mixing network.
        
           | ocdtrekkie wrote:
           | It really comes down to how it's used. As another commenter
           | pointed out, any company using badges to swipe into doors can
           | track your movements. Most cameras are positioned near entry
           | doors, exteriors, or public areas as it is. The main
           | difference here is the amount of information collected on an
           | unauthorized entrant, and the fact that maybe badge-borrowing
           | doesn't go unnoticed anymore.
           | 
           | I really doubt Cloudflare is the type of company to be
           | tracking where each employee is and whether they are taking
           | too many bathroom breaks. It's definitely an area abuse is
           | possible, but probably not an area it's likely in
           | Cloudflare's case.
        
             | quasirandom wrote:
             | > It really comes down to how it's used
             | 
             | I absolutely agree. The thing that concerns me is these
             | cameras sitting on the internet. It says something about
             | how overworked the security team is. I trust that they have
             | good faith, but I don't know if they have the resources
             | they need.
        
               | adolph wrote:
               | What is a specific credible concern about cameras with
               | public API?
        
               | Teknoman117 wrote:
               | People other than the ones you agreed to let monitor you,
               | well, monitoring you. Also, it's a major risk to the
               | company itself, who knows what can be read off of
               | employees screens if they're compromised.
        
               | adolph wrote:
               | Yeah, it seemed far fetched to me at first but I guess
               | surveillance might be useful to a 3rd party. I read an
               | article a while back on how people make equity trades
               | based on data found through satellite images of refinery
               | tanks and whatnot. I guess unsecured internal
               | surveillance cameras could allow an outsider to find out
               | if a company was really busy or just faking it.
        
               | gostsamo wrote:
               | Every IOT device is an attack vector against the network.
        
               | adolph wrote:
               | I wonder if there is a way to dumb down IOT devices so
               | they can't be an attack vector like that.
        
               | gostsamo wrote:
               | Lock the memory so that update is physical only and
               | restart regularly to avoid no-memory malware. Not 100%
               | secure and very inconvenient, so people prefer to isolate
               | IOT in its own network and preferably have a good network
               | security like putting the devices behind
               | VPN/firewall/other gatekeeper.
               | 
               | Actually, if you want to have IOT access outside of the
               | network, the best approach is to close all ports and for
               | the device to initiate connection with a control server.
               | The device is dark when scanned while a heartbeat signal
               | will ensure connectivity. This will require a good
               | security on the control server, but that is okay because
               | server security is much better understood and does not
               | suffer from the constraints of the embedded software.
        
               | josefx wrote:
               | Someone wanting to break in can check if anyone is there
               | or see where easy to steal stuff is kept? Or on a larger
               | scale you might leak when and how security guards make
               | their rounds.
        
             | [deleted]
        
           | jgrahamc wrote:
           | _Cloudflare was apparently operating network connected facial
           | recognition cameras in their offices._
           | 
           | We do not use that feature and do not intend to.
        
             | robertlagrant wrote:
             | But did you ever use it?
        
               | jgrahamc wrote:
               | No, this was never in active use.
        
               | rattray wrote:
               | If they did, wouldn't it be a _good_ sign if someone came
               | along and said, hey, this doesn 't align with our values,
               | and was able to get it removed?
        
           | bradlys wrote:
           | How is that something to be worried about? There are
           | companies out there that try to monitor if employees are in
           | rooms/areas that they're not supposed to be. You can do that
           | with badges/RFID but then people can take a card or slide by
           | in various ways. (Happens all the time at big companies -
           | people just tailgate) If anything, they might be taking
           | privacy more seriously by not letting people without
           | authorized access into secure areas.
           | 
           | I think you give up any sense of privacy as to where you're
           | located in an office or where you've been in an office when
           | you decide to work in an office owned by some employer. I
           | don't know why there'd be any expectation there.
        
             | [deleted]
        
             | batty_alex wrote:
             | I find it fascinating how okay you are with your employer
             | tracking you. We aren't to the life contract part of the
             | dystopia yet, quit trying to skip ahead and give away your
             | freedom so easily
        
               | Shank wrote:
               | Cloudflare sells security to people. If you don't want to
               | work at a company that has security requirements like
               | that, don't work there. Lots of people choose to donate
               | their fingerprints, facial data, life history, and
               | polygraphs to work for the government. That's their
               | choice to make.
        
               | tartoran wrote:
               | If that info is well taken care of is one think. If it
               | ends up floating on the internet is another. Rfid badge
               | data floating on the net creates is useless however other
               | personal data could be very toxic in the wrong hands. And
               | usually this info leaks thats why its not a great idea to
               | let it outside the network let alone record it in the
               | first place
        
               | throwawayboise wrote:
               | > If that info is well taken care of
               | 
               | It isn't. https://en.wikipedia.org/wiki/United_States_Off
               | ice_of_Person...
        
               | neffy wrote:
               | If you are in a secure area, like a server room for
               | example, it's perfectly normal for there to be badged
               | entry, cameras everywhere etc. There will also be signs
               | everywhere telling you this.
               | 
               | If it's really secure there will be monitoring of all
               | entrances, including corridors. (And there will still
               | occasionally be people successfully tailgating, usually
               | for perfectly innocent reasons like forgetting their
               | badges at their desks etc. Real security is all sorts of
               | fun.)
        
               | Teknoman117 wrote:
               | I've gotten stuck in a datacenter because I forgot the
               | correct badge-out process. Tripped an alarm and got stuck
               | in a man-trap.
               | 
               | For the uninformed - badge in to open the entrance door.
               | The room then locks and you use your badge to open the
               | exit.
        
               | jackson1442 wrote:
               | Interesting. Seems like that would be a fire hazard, or
               | was there a hold-to-escape type crashbar?
        
               | LinuxBender wrote:
               | Some facilities get exceptions to fire policy and require
               | employees to go through _training_ of sorts. Diablo
               | Canyon Nuclear Power Plant is one place I visited that
               | did not have emergency egress. No badge? Call the guards,
               | that is the only way out.
        
               | ravel-bar-foo wrote:
               | Obviously not the same type of facility, but I have seen
               | buildings where the closing of smoke shutters opens
               | otherwise locked doors, revealing an alternate fire
               | escape from the corridor to the stairwell.
        
               | vermilingua wrote:
               | In fire/hazard conditions, security systems are required
               | (at least in Australia) to permit free handle egress from
               | any point in the building to a fire escape.
               | 
               | Any access control system has the capability to integrate
               | with a fire system and allow this.
        
               | jackson1442 wrote:
               | I believe the general policy in the States is "one swift
               | motion" to exit a room which is why you see mostly
               | crashbars and lever handles as egress, mostly on push
               | doors for the primary egress path.
               | 
               | In secured areas where they want you to swipe out or
               | places where they might get tripped accidentally, they
               | sometimes have like a 15 second lockout before actually
               | tripping the door.
               | 
               | I've been in just one server room and they just had a
               | motion-deactivated maglock tied to an electric strike so
               | in the case of a power outage a simple mechanical lock
               | could be opened but otherwise you need to badge in/out.
        
               | datavirtue wrote:
               | Fire hazard and false imprisonment. Ask walmart. You
               | accidentally lock someone in the store and you are
               | looking at a civil rights law suit. You cannot restrict
               | another humans' movement without due process.
        
               | acomjean wrote:
               | I worked I the defense sector.
               | 
               | We were tracked by contract (badge into building, badge
               | into area). We couldn't leave the work area un-attended
               | which was a pain, so there were "processes in place"
               | (last person badge etc..).
               | 
               | Generally we knew they left you alone unless you were
               | cheating. (Having someone badge you in when you weren't
               | there was a fire able offense).
               | 
               | I don't miss it, but it wasn't that bad. Of course having
               | the work network not on the internet what else could we
               | do but work...
        
               | wyqydsyq wrote:
               | How is being recorded by your employer while on their
               | premises giving away your freedom? It would be a
               | different thing if they were tracking you out of work,
               | but when you enter a premises owned by a business you
               | kind of implicitly agree to be surveilled by them, as it
               | is _their_ right and freedom to protect their assets.
        
               | meowface wrote:
               | I'm okay with my employer tracking me if I'm on their
               | premises using their property that they've given me. I'm
               | not okay with them knowing anything I do or where I am
               | outside of work, but if I'm at work then I'd be confused
               | if I _wasn 't_ being tracked in some way.
               | 
               | Not at all in the paranoid "are you slacking off?!"
               | sense, but just security information like knowing when
               | I've been in a server room, or knowing if my work
               | computer sent traffic to a known botnet C&C. If there's a
               | security or theft incident and they don't know who's been
               | in their building or what their computers are doing, it's
               | pretty much impossible to investigate anything.
               | 
               | I understand that in places like Europe there's a very
               | different culture and workers have a lot of protections
               | from things employers may want to do, but not everyone
               | around the world feels that way. Basic record-keeping of
               | when badge-restricted doors and computers are
               | authenticated to doesn't feel invasive to me in the
               | slightest, even if others may strongly feel it is
               | invasive.
               | 
               | There are many things I would find egregiously invasive,
               | such as a manager inspecting all the websites someone
               | visits to assess how productive they are, or timing
               | people's bathroom breaks, but I just avoid such
               | companies.
        
               | laurent92 wrote:
               | I don't understand why people think the employer cannot
               | check whether the employee is slacking off.
               | 
               | Maybe what we should prevent is employer keeping months
               | of proof and only bringing it up as inappropriate later,
               | but if the employer uses the camera to tell an employee
               | within 24hrs that he needs to ramp up, it feels ok. Maybe
               | we should impose rules like "24hrs max" and "can't be
               | used legally, just orally."
        
               | csharptwdec19 wrote:
               | > I don't understand why people think the employer cannot
               | check whether the employee is slacking off.
               | 
               | On some level it depends on what 'slacking off' means.
               | 
               | I've had employers where 'slacking off' meant actively
               | doing some %mundane/repetitive/unnecessary% task with
               | every moment of my free time. We were literally pulling
               | the finish off the counters; there was no need to keep
               | dusting them.
               | 
               | I've had software shops where reading integration
               | documentation was 'slacking off'.
               | 
               | An interesting data point; In Germany, MS Office doesn't
               | track how long you have been editing a document. My
               | understanding is this is because the law there more or
               | less says if you pay someone to do a task, you aren't
               | supposed to (i.e. can't) care about how long it took them
               | to actually do it as long as it was done on time.
               | 
               | So I guess that's my problem. There's a very fine line
               | between employers using surveillance to catch 'bad
               | actors' and employers using surveillance as another tool
               | to bully substandard work conditions onto people.
        
               | ocdtrekkie wrote:
               | My guess is that micromanagement actually decreases
               | quality and productivity as well, just due to the
               | disconnect between management opinions and real-world
               | employee experience. If you are judging performance on
               | the output correctly, the employee will, out of own self-
               | interest, maximize the quality and quantity of the output
               | while minimizing their own effort expended in creating
               | it.
        
               | stjohnswarts wrote:
               | The day one says I'm "slacking off because we noticed
               | inactivity on your laptop" is when I stand up and walk
               | out the door. Hasn't happened yet but I suspect it will
               | at some point.
        
               | 6510 wrote:
               | Its only natural really in this race to the bottom. If
               | your zero hour contract doesn't have room to pay the
               | bills you are not just not worried about tracking, you'd
               | take anything that might show how hard you've tried.
        
             | mc32 wrote:
             | One of the biggest use cases presently is SARS-COV-2
             | tracing to figure out who needs to be notified they were in
             | proximity for X-time of someone with COVID-19.
        
         | bsder wrote:
         | > Putting surveillance video on the cloud is... kinda dumb.
         | 
         | I tend to agree, but ...
         | 
         | If you're a small business or manufacturer, IT is a pain in the
         | ass. The "cloud" _is_ a benefit because you don 't need to
         | maintain any servers yourself and can just get on with your
         | business.
         | 
         | The problem is that these companies don't face any consequence
         | for claiming that they're secure and then not actually being
         | ... you know ... _secure_.
         | 
         | If this stuff was simply encrypted at rest, that would have
         | mitigated most of this breach.
        
           | ocdtrekkie wrote:
           | Sure, but many of Verkada's customers are large enterprises
           | with large IT teams just making a bad decision.
           | 
           | Small businesses have either a box they bought at Costco or
           | use something like Comcast's service which they just add on
           | to their cable modem.
        
             | leesalminen wrote:
             | Those boxes from Costco come with WiFi built in and a
             | mobile app paired to it. The small business owner
             | invariably sets up port forwarding so they can watch from
             | home and leaves the default password because it doesn't
             | force you to change it. Not much better there either.
        
               | ocdtrekkie wrote:
               | My point was less that those were good solutions, but
               | that a company I contend "shouldn't exist" likely has a
               | different customer segment, like Tesla and Cloudflare.
        
               | intrasight wrote:
               | Oh, the places I've boldly gone - using default passcodes
        
           | brundolf wrote:
           | I don't think it would, because they leaked admin credentials
           | (unless it was encrypted with a customer key and inaccessible
           | to admin/support)
           | 
           | Anyway, I think we're at the point with software/digital
           | systems where food manufacturing was in 1900: there's been a
           | gold-rush due to new technology, and we're reaching peak
           | negligence in the pursuit of profit, and I think we'll soon
           | get to a threshold where regulators will finally step in and
           | lock down the wild-west and impose some real standards.
           | Between SolarWinds, Exchange, and now this, it's to a point
           | where it's dragging down our whole society. Something has to
           | give.
        
             | HarryHirsch wrote:
             | I just had an aha moment reading your post. Food safety,
             | drug safety, airline safety, all these regulations were
             | implemented because manufacturers were operating with
             | standards so lax that people suffered actual harm.
             | 
             | Perhaps that's the real reason behind the anti-FDA lobbying
             | we are seeing here. The FDA demonstrates that government-
             | mandated safety standards work. We can't have those in the
             | IT field because they would diminish profits!
        
               | morlockabove wrote:
               | The FDA also has massive associated costs and acts as a
               | hurdle to innovation- which is partially by design
               | (lobbyists like regulatory capture).
        
               | HarryHirsch wrote:
               | The Moderna and Biontech RNA vaccines got past the FDA in
               | record time and are a massive innovation. What are you
               | even talking about?
               | 
               | Also: Hepatitis C antivirals. One pill and you are cured,
               | whereas in the past you'd be looking at a liver
               | transplant. If that's not innovation it's impossible to
               | say what that would be.
        
         | tomc1985 wrote:
         | But then how will techbro wantrepreneurs build their unicorn
         | business?!?!
        
         | Hnaomyiph wrote:
         | It's amazing how much security people and companies are willing
         | to give up for a smidge of convenience. Properly deployed CCTV
         | has little worry of hackers since, hence it's name, it is
         | closed-circuit.
        
           | lancesells wrote:
           | This made me wonder if there's a place for a company to
           | disrupt the video cloud industry by selling CCTV cameras and
           | devices that would require physical updates sent on a usb
           | drive.
        
             | ocdtrekkie wrote:
             | It's not actually hard to do that today with existing
             | equipment: Put it all on a network switch and then just...
             | don't plug it into the Internet. Plenty of on-premise
             | solutions exist and work with or without remote
             | connectivity.
        
             | vel0city wrote:
             | Get this: closed circuit television systems actually
             | existed before updates could be delivered by the internet.
             | Another crazy fact: there are still products sold which
             | don't connect to the internet. You don't see nearly as many
             | ads on these products though and don't seem to be as
             | popular these days.
        
           | pugworthy wrote:
           | Trust me, it's not always about convenience for some of us
           | remote camera users.
           | 
           | In my case, I've got a camera in my elderly parent's back
           | yard as there have been a few falls in the back yard, and one
           | break-in some years back.
        
             | stjohnswarts wrote:
             | That seems like more trouble than it's worth though. Do you
             | like just check every hour to see if someone has fallen or
             | something? That seems like something that could become
             | either an obsession or something you'd forget to do.
        
               | ocdtrekkie wrote:
               | Not the OP, but I have a significant amount of anxiety
               | sometimes about if something bad has happened or if my
               | pets are okay or whatever. It's an extreme version of
               | "did I forget to turn the over off".
               | 
               | Being able to remote in and go "ah, everything's fine"
               | basically can instantly turn such anxieties off, rather
               | than say, having to live with it until you finish out the
               | work day and can head home.
        
         | antihero wrote:
         | Verkada has prioritized sales expansion over growing the
         | engineering team, with 150% more salespeople than engineers and
         | almost half the entire company in sales, per LinkedIn"
         | 
         | Exactly the sort of people you want to trust with highly
         | sensitive surveillance.
        
         | philjohn wrote:
         | Another take on this - I have google nest outdoor cameras.
         | Recently, a car park company tried to claim I was in a car park
         | for 7 hours. In reality, I had gone earlier in the day, come
         | back home, and then gone back hours later - but their ANPR
         | system must have had a glitch.
         | 
         | I was able to send them links to the video clips on the Nest
         | site, with embedded timestamps.
         | 
         | If this was a local system there would be no way to prove I
         | hadn't just faked the timestamps.
        
           | listenallyall wrote:
           | >> no way to prove I hadn't just faked the timestamps.
           | 
           | Showing a ticket? Parking lots have been using them pretty
           | successfully for 50+ years
        
           | mattacular wrote:
           | You not having to pay an unfair fee for parking one time
           | hardly seems like a good tradeoff for massive surveillance
           | overreach by truly incompetent companies but maybe that was
           | one really expensive lot or something
        
         | stjohnswarts wrote:
         | Assuming one size fits all is dumb as well. This could be
         | handled much better but it won't be cheap and that's what
         | everyone is trying to do, "cheap". Other things are "on the
         | web" and much less easily hacked.
        
         | balfirevic wrote:
         | > Shut this company down
         | 
         | Who should shut it down?
        
         | Black101 wrote:
         | Pretty much all consumer security cameras do this by default
         | nowadays... I had to disable it on mines and send it to my own
         | server instead, as a backup.
        
         | passivate wrote:
         | Ouch! That's a bit harsh! Well, I suppose cloud archives could
         | be encrypted? We use a cloud based system (but no cloud backup)
         | and with multiple facilities, its nice to be able to launch the
         | app and stream the camera's live feed using the cloud as a
         | bounce.
         | 
         | Also with the cloud being used as the de-facto off-site backup
         | location, most data these days will end-up (hopefully
         | encrypted) in some kind of cloud service or another.
        
           | ocdtrekkie wrote:
           | Remote access is fine, it can be reasonably managed:
           | Generally the client sets it, and the manufacturer doesn't
           | retain access. Usually you can geoblock and such as well. You
           | have control of the hardware and can implement encrypted
           | storage and better access controls, rather than trusting a
           | third party to decide what is "secure".
        
         | bredren wrote:
         | This would be a much bigger hack if it were Wyze. Wyze cams are
         | generally placed in residential interiors and contain a mic
         | that can not be disconnected without physical removal.
         | 
         | It wouldn't be as newsy, though because people put these in
         | their own homes.
         | 
         | The only way this group raises awareness instead of angering
         | people is by targeting companies and institutions, rather than
         | forcing people to confront their own compromises with
         | technology, time and effort.
        
           | tkinom wrote:
           | Any known security issue with Wyze?
           | 
           | I am very impress with their features. I am planning to buy
           | couple of them, but I would never point them inside the
           | house. Probably will put them in their own wifi network.
           | 
           | I built a home grow solution with RPi + Webcam + Google Drive
           | with some python script. But the performance to upload Pics
           | to G Drive was slow and the way viewing the pics uploaded to
           | G Drive was not very convenient.
        
             | xvector wrote:
             | Why not use an E2EE solution, like HomeKit for your camera?
        
             | shakna wrote:
             | A couple years back (2019) Wyze had a breach [0], which
             | accidentally exposed another breach that they hadn't been
             | aware of. This came just six months after a previous
             | breach.
             | 
             | But it suggested that Wyze can remotely disable all
             | encryption and so on whenever they feel like it.
             | 
             | And that for a "subset of users" they collected: "Height,
             | Weight, Gender, Bone Density, Bone Mass, Daily Protein
             | Intake, and other health information", which was included
             | in the breached data.
             | 
             | [0] https://www.nytimes.com/2019/12/30/business/wyze-
             | security-ca...
        
             | GloriousKoji wrote:
             | If you're serious about security I recommend against wyze.
             | You're locked into their platform and it isn't fully
             | reliable.
             | 
             | If you want something like a video of that opossum sneaking
             | in the attic, coyote peeing in your rose bushes, that kid
             | across in the street with the razer scooter and german
             | shepard not cleaning up the poop off your lawn or what your
             | iguana is up to when you're not home then it's great for
             | that.
             | 
             | The UI is probably worse than your gdrive setup. You have
             | to use the wyze app to access it, which has a terribly slow
             | scrubbing interface. The more convenient part is to check
             | the motion/sound triggered 15 second clips which are upload
             | to their cloud servers. Other than that I find myself
             | frustrated and just take out the microSD card and browse it
             | on my computer.
             | 
             | Also don't buy the sense kit. It just doesn't work. I've
             | even tried experiments with it right next to the camera and
             | it's not consistent enough.
             | 
             | If you want to use the wyze cams are generic IP cameras
             | they offer unsupported firmware for that but then you'll
             | need to roll your own DVR and I'm not sure if that supports
             | all the new features the V3 offers or follows the genric
             | protocol for remote pan control.
        
               | [deleted]
        
               | zucked wrote:
               | Wyze cameras have open source firmware that can be loaded
               | (DaFang Hacks) that works pretty well.
               | 
               | I've never used (or trusted) the Wyze firmware anywhere
               | on my network, but I use a couple of Wyze cameras pointed
               | outwards from my house connected to a a DVR with motion
               | detection.
        
               | vineyardmike wrote:
               | Not sure when you bought yours but i haven't been able to
               | get DaFang working in at least 18 months (due to OTA
               | firmware updates before attempting DaFang)
        
               | dude3 wrote:
               | I find the Wyze cams great! Cheap. They do have 2 factor
               | auth support for apps like Authy. It doesn't sound like
               | you have enabled the premium features. Person detection
               | is really good for exterior facing cams. Hook it up to
               | Alexa Show and you have person detected notifications
               | also access to any cam. Premium also has longer clips.
               | For the price it's kind of OK to be semi locked down. I
               | believe the reason for not supporting RTSP is because of
               | hardware limitations on V2.
        
               | bredren wrote:
               | I have used three wyze cams but only for pointing outside
               | or to monitor plant growth. Here is an HD timelapse of a
               | Monstera Deliciosa I made with one:
               | https://youtube.com/watch?v=0NH2t1fJL9w&feature=emb_title
               | 
               | The first thing I do with a wyze cam is physically remove
               | the microphone, because it can only otherwise be turned
               | off in software which is configured in the cloud.
               | 
               | I'd consider using them with the OS firmware change, but
               | hadn't thought of also running them on an independent
               | network.
        
             | bredren wrote:
             | There were no "known" security issues with Verkada.
        
         | Spooky23 wrote:
         | For anything small, the local drives are obvious theft targets.
         | 
         | For anything large or distributed, you're probably going to
         | spend less for better security with a cloud system.
         | 
         | It's sensitive data, but probably in a second tier of
         | sensitivity. The integrity of the on-prem system depends in
         | your remote access security and operational practices.
         | Solutions like this often really suck.
        
         | pugworthy wrote:
         | > Putting surveillance video on the cloud is... kinda dumb
         | 
         | It's a necessity for some cases. I commented on this elsewhere,
         | but for me it's having an eye on my elderly parents back yard
         | in case of falls. Past history of not knowing is precisely why
         | we got the camera.
        
           | ronnier wrote:
           | You can still keep them local and use a VPN. That's what I
           | do.
        
             | contravariant wrote:
             | People really should. It's pretty easy these days with
             | wireguard or tailscale. Just plug a raspberry pi somewhere
             | with network and power and you're set.
        
               | pugworthy wrote:
               | I spend my day doing the "tech shit" for work. I don't
               | want to mess with stuff, I just want it to work. I'm
               | willing to risk a bit of security for it to "just work",
               | which it has now for multiple years. Without any security
               | issues (so far).
        
               | contravariant wrote:
               | I completely agree, even though I do tinker around with
               | stuff for fun. However in my experience so far wireguard
               | and tailscale (which is based on wireguard) are the kind
               | of solutions that just work with little to no oversight.
        
             | SilverRed wrote:
             | Its still on the internet though. Its just the VPN becomes
             | the security barrier. Although if you keep it up to date,
             | its going to be safer than iot crap
        
         | _-david-_ wrote:
         | I think the biggest selling point to cloud security cameras is
         | to have a copy of the video not at the location. If your house
         | / business is robbed or burns down you will possibly lose the
         | video. This video could be used to find the theif or arsonist.
         | 
         | Ideally it would store video locally, then encrypt it and
         | upload the last minute to the cloud.
        
           | brk wrote:
           | The biggest selling point is really the OPEX sales model, and
           | outsourcing of the general care-and-feeding of the
           | recorders/servers. The tradeoff is that you tend to get
           | lesser quality video and/or less scalability of the size of
           | the system from bandwidth limitations.
           | 
           | Theft of recorders/loss of recorded video is much much less
           | of an issue than it is generally made out to be, and most
           | systems have various means for auto backups, dual recording,
           | etc. Many also have the ability to send select segments of
           | video, based on motion or analytics, to cloud/FTP/email for
           | free, which adds some extra resiliency if you are really
           | worried about random arsonists :)
           | 
           | (I work in the industry)
        
             | ocdtrekkie wrote:
             | I am still honestly confused by the whole "OpEx > CapEx"
             | thing. Apparently for some people this is worth paying
             | _over double_ the price when you look at things on an
             | annualized basis, even for an established business that 's
             | got a very stable environment?
        
               | brk wrote:
               | In short, yes it is.
               | 
               | The concept of having a predictable recurring bill, and
               | known costs can have a lot of value. In the opex hardware
               | model, there is usually a hardware refresh built in (a
               | lease of sorts) and also covered replacements for any
               | failures before the refresh.
        
               | ocdtrekkie wrote:
               | > a predictable recurring bill
               | 
               | This makes no sense to me, because almost no OpEx-based
               | services operate on a predictable billing model. Usage
               | based pricing means they are subject to change.
               | 
               | If I buy a $5,000 server, and it lasts me five years, I
               | can plan around needing $1,000 a year set aside to
               | replace it. Meanwhile, my AWS bill can suddenly be
               | $20,000 with no warning.
               | 
               | The hardware refresh model you describe... I've actually
               | only ever seen in a CapEx appliance, where paying for the
               | support contract got you those refreshes regularly,
               | replacement for failures, etc. but had an initial upfront
               | purchase cost.
        
               | HeyLaughingBoy wrote:
               | Compare SaaS to COTS software: same thing, (somewhat)
               | different industry.
        
             | pdimitar wrote:
             | > _(I work in the industry)_
             | 
             | Ohhhh, you are so in trouble now! :P
             | 
             | I am pondering moving to a rather remote estate with my
             | wife but we're both city kids and have zero clue how to
             | defend ourselves in such conditions (I am even thinking we
             | should take shooting lessons and bring guns to the estate
             | as well).
             | 
             | Part of our plan is a surveillance system -- I planned to
             | have an on-site ZFS storage cluster with several cameras
             | that periodically encrypts the last 5 minutes and sends
             | them off-site. Not sure how complex such a setup might turn
             | out to be though... Maybe there's a way to make the storage
             | cluster itself auto-replicate remotely often enough? I'm
             | not that educated yet.
             | 
             | Do you have any recommendations? I don't want to spend
             | $5000 due to paranoia but I don't want to be defenseless in
             | case of a robbery either. What's the middle ground?
        
               | GrinningFool wrote:
               | Would not a large dog suffice? They're more maintenance,
               | but also come with other benefits.
        
               | pdimitar wrote:
               | Yep, we thought of buying two specially trained German
               | shepherds (the kind of training that requires you to be
               | there so the dog bonds with you and trusts nobody else).
               | 
               | Still not sure about guns but the dogs would indeed be a
               | very good investment.
        
               | cacarr wrote:
               | An Anatolian livestock guardian dog is a vastly superior
               | natural guard dog, compared to a GSD. They can not be
               | bribed with food, and they spend every second of their
               | waking day looking for intruders to destroy. Very gentle
               | with children and small dogs, though.
               | 
               | Downsides include being extremely smart but not very
               | trainable (smart like a wolf) -- they decide what's a
               | threat and what isn't, and they don't care about your
               | opinion. They guard naturally. Also, you may find
               | yourself having to bury dead coyotes on occasion, as they
               | will murder any that are stupid enough to intrude.
        
               | pdimitar wrote:
               | Very interesting, thanks a lot! I'll research more.
        
               | d110af5ccf wrote:
               | > specially trained
               | 
               | I think you might be overthinking this. The dogs don't
               | even need to be large. If the property is more than a few
               | acres just get 2 or 3 herding dogs. They're upbeat,
               | energetic, and above all very noisy if a stranger wanders
               | into your yard. I very much doubt anyone will ever bother
               | you.
               | 
               | > Still not sure about guns
               | 
               | How remote is it? What's the police response time? If
               | it's really in the middle of nowhere then it seems like a
               | good idea to have something on hand just in case.
        
               | pdimitar wrote:
               | > _How remote is it? What 's the police response time? If
               | it's really in the middle of nowhere then it seems like a
               | good idea to have something on hand just in case._
               | 
               | Exactly because of that: remote and small country (Costa
               | Rica is one idea so far), we would prefer a sea-side
               | house which is NOT very close to a city (we think 20-30km
               | away from a city is optimal) and we have no clue about
               | police response time -- but I can't imagine they'll be
               | there 2 minutes after I make a panicked call that I am
               | tracking 3 armed burglars, especially if not in a city.
               | 
               | > _I think you might be overthinking this._
               | 
               | Very possible. Right now I don't even have the money for
               | a down-payment, but me and my wife both share this dream
               | and started brainstorming it and doing some preliminary
               | planning.
               | 
               | Above all, I really want the dogs to not be able to be
               | bribed with food. Not a fan of dogs that bark at every
               | single small disturbance but oh well, if that's the price
               | you pay for living in a remote area and having good
               | security then okay.
        
               | d110af5ccf wrote:
               | > Costa Rica is one idea so far
               | 
               | Oh, I was imagining remote rural in the US or a similar
               | country (Canada, Scandinavia, etc). I have absolutely no
               | idea what public safety concerns might exist in less
               | developed places.
               | 
               | > want the dogs to not be able to be bribed with food
               | 
               | It's more that a solid looking fence, a few dogs, and
               | some visible security cameras are highly likely to deter
               | any attempts in the first place. If someone is armed and
               | willing to shoot your dogs then you have much larger
               | problems to deal with (and probably don't want to be
               | living there to begin with).
        
               | omgJustTest wrote:
               | Who are your enemies haha. "Don't want to spend 5k cause
               | of paranoia but I'm planning on moving to a remote estate
               | and... guns... and gun lessons.... cause I'm not
               | paranoid"
        
               | brk wrote:
               | This isn't a short conversation, but you can contact me
               | offline and I can give you some pointers.
        
               | pdimitar wrote:
               | Pinged you on twitter several hours ago, as I can't find
               | any other accounts in your HN profile and don't want to
               | stalk by looking you up online.
        
               | lifeisstillgood wrote:
               | Forgive me asking but which country do you live in.
               | 
               | I often have debates with my wife about country vs city
               | living, but I don't think buying a gun / attack dog / big
               | security system ever comes into the equation. (UK based).
               | 
               | Am I not paranoid enough, are you over paranoid? Is there
               | a Bayesian equation we need here?
               | 
               | Just to put up an alternative I just read this
               | https://news.ycombinator.com/item?id=26411899
               | 
               | The guy cycled through Europe and India, met some guy in
               | a bar in Italy and ended up sleeping on his couch and
               | eating home cooked Pasta lunch the next day. A different
               | approach would be to drive with a gun under the seat. I
               | think something is missing.
        
               | pdimitar wrote:
               | Me and my wife were thinking Costa Rica but got warned by
               | an acquaintance that burglaries and home invasions in
               | remote areas are a regular occurrence. And we want a sea-
               | side house.
        
               | 177tcca wrote:
               | > Am I not paranoid enough
               | 
               | Do you also forgo a fire extinguisher in your kitchen?
        
               | cacarr wrote:
               | > (UK based)
               | 
               | Often what's "country" in the UK (outside of Scotland)
               | would be considered exurban in the USA. You might
               | possibly feel different about security at a truly remote
               | home in N America.
        
               | wcarron wrote:
               | To be honest, the easiest way is to 1) Buy and install a
               | bunch of ring cameras and 2) Buy and learn to use a
               | Mossberg 500 with a 18" barrel. Maybe another gun, too.
               | Total cost: Idk, $800-1800.
        
               | bigbillheck wrote:
               | Is it just me or does this seem kind of excessive?
        
               | LinuxBender wrote:
               | To me excessive would be automatic tracking turrets with
               | really nasty things mounted on them. I recall someone
               | made one that fits in a briefcase and uses paintballs. It
               | had something like 90% accuracy on fast randomly moving
               | targets. But for some people that might not be excessive,
               | probably depends on the circumstances.
        
               | at-fates-hands wrote:
               | Reminds me of the hotel scene in the book "Altered
               | Carbon". The Netflix series did a good job visually with
               | this scene.
               | 
               | https://www.youtube.com/watch?v=T6VaUPmaCcI
        
               | LinuxBender wrote:
               | That is a great show and I agree, that hotel is a perfect
               | example. I really hope they keep the show going.
        
               | pdimitar wrote:
               | The area I want to move in is known for its heightened
               | percent of home invasions and burglaries. So I don't
               | know, maybe it is excessive. I just don't want my life
               | savings to fall into the hands of a random burglar.
        
               | Forbo wrote:
               | Why keep your savings at home? For anything critical I
               | use a safe deposit box.
        
               | pdimitar wrote:
               | My bad for using bad figure of speech. Of course most of
               | my savings won't even be physical (bank / cryptocurrency
               | / investments etc.) -- I meant that I'll have all my
               | possessions there (expensive computers, TVs, furniture,
               | kitchen tech, what have you) and I would like to avoid
               | having them stolen while I am grocery shopping in the
               | nearest city, you know.
        
           | nielsbot wrote:
           | Also, convenience: Buy this camera, get access to recordings
           | anywhere over the internet with nearly zero setup time.
           | 
           | If you have an on-site system (like I do) it's way more
           | effort for the average consumer.
        
             | andrewprock wrote:
             | That's not security, that's voyeurism
        
               | vincnetas wrote:
               | Was also thinking the same. Security cameras should be
               | used where there is an incident and additional
               | information is needed to clarify what happened. Then you
               | check the security camera footage to figure out what
               | happened. If there were no incidents there is not
               | reasonable need for anyone to look at that footage.
               | 
               | edit: not talking here about active monitoring security
               | cameras used by guards.
        
           | ma2rten wrote:
           | Another one is that you can run machine learning on it. For
           | example to automatically detect unusual activity.
        
             | ocdtrekkie wrote:
             | You can absolutely run machine learning on-premise
             | hardware.
        
           | ocdtrekkie wrote:
           | Plausibly, yes, though again, large enterprises should be
           | able to handle this internally, especially some of the listed
           | customers here.
        
             | AmericanChopper wrote:
             | I work in a large enterprise. If my employer were to decide
             | to exclusively store security footage on our own
             | infrastructure, then I would have access to every piece of
             | hardware it's stored on. The risks associated with that is
             | why every piece of mission critical data where I work is,
             | at a minimum, backed up in a 3rd party facility.
        
             | zerkten wrote:
             | There are plenty of use cases, such as the various forms of
             | analysis with ML, which are often only implemented outside
             | the "company firewall" (this idea is antiquated.) Of
             | course, this could and should be handled inside a trusted
             | boundary (I can't think of a better term for today's
             | networks), but in practice security here is fairly immature
             | and people try things when there isn't good governance in
             | place.
        
               | TeMPOraL wrote:
               | This sounds like general problem of enterprise security.
               | There are no consequences.
               | 
               | I can entirely get why a company would outsource IP
               | cameras to a third party cloud, even with storing data
               | on-site. Business runs on contracts. It's entirely normal
               | to contract out everything except your core competencies,
               | if it's cheaper this way. It's how you turn CAPEX,
               | complex OPEX and high risk into simple OPEX and low risk.
               | A contract is in big part a risk shifting tool. This
               | works well in practice... outside IT.
               | 
               | The problem is, with IT and data, there's a mismatch
               | between expectations and reality. An enterprise _should_
               | feel safe buying their video surveillance from Verkada,
               | because between the contract and the legal framework,
               | Verkada should be bankrupt now, and their management
               | possibly facing jail time. That 's the part where
               | contracts work as Cover-Your-Ass tool: if you shift risk
               | and liability to outside party, the liability is not on
               | you.
               | 
               | However, this only works as long as the other party
               | actually internalizes the risk and liability. Since there
               | are no consequences for mishandling data, operating IT
               | services you're not structurally competent to operate,
               | and eventually having your crown jewels stolen - the
               | contractor doesn't really internalize risk, has no
               | incentive to mitigate it.
               | 
               | All this to say: Verkada should go down after this, and
               | their customers should be named and shamed widely - the
               | latter is so that future customers of IT services put
               | more care into vetting companies they contract IT out to.
               | You shouldn't get to CYA with a contract where
               | assumptions around contracting are broken.
        
         | spoonjim wrote:
         | Putting the surveillance video on-site is... kinda dumb. If
         | someone breaches your facility and wants to take the evidence
         | of them doing so, they just have to steal the video storage.
         | 
         | Cloud security footage makes sure that you have at least the
         | footage up until they disable your network.
        
         | mike_d wrote:
         | > It's rarely viewed outside your network
         | 
         | The majority of real camera systems (100+ cameras, 10+
         | locations) I have interacted with are monitored by outside
         | vendors.
        
       | figassis wrote:
       | "Our internal security team and external security firm are
       | investigating the scale and scope of this potential issue."
       | 
       | Potential issue? Your house is on fire. When will these
       | businesses just be straight rather than PR everything?
        
         | heracles wrote:
         | Nothing on blog or "What's new" either, just corporate
         | newspeak.
        
       | atum47 wrote:
       | Back in college I was studying security and eventually I found
       | out about shodan. I mean, when people don't even care to put
       | passwords on their connected to the internet device, can you even
       | call it hacking?
        
         | atum47 wrote:
         | Meaning no disrespect to the people who find the user and pass,
         | but criticizing people who don't set passwords or leave the
         | default ones
        
       | Teknoman117 wrote:
       | Are there any companies actually pushing a security-first IoT
       | model?
        
         | gostsamo wrote:
         | In my experience - no. I've seen devices sold for thousands of
         | dollars whose login screen could be bypassed with a magic
         | cookie. Here and there you will find a device that will force
         | you to change the default password upon activation, but this is
         | as far as it goes and the cheaper models from the same vendor
         | will be as shitty as anybody else's.
         | 
         | The best that you can hope in consumer devices is something
         | like Apple, Google or Amazon, because they can afford the
         | support costs, but it comes at the price of privacy and
         | funneling your money in many other ways. Enterprise stuff could
         | be found, but you can never trust just the brand for every
         | model.
         | 
         | Edit: grammar.
        
         | rickspencer3 wrote:
         | Forget where I read it, but it always makes me laugh:
         | 
         | The "S" in IoT stands for "Security"
        
       | jrochkind1 wrote:
       | This is the important part. NOT that their network was not
       | secured, but that anyone with a super-user account can simply
       | view archived and live video feeds of any of their customers????
       | 
       | > The hackers' methods were unsophisticated: they gained access
       | to Verkada through a "Super Admin" account, allowing them to peer
       | into the cameras of all of its customers. Kottmann says they
       | found a user name and password for an administrator account
       | publicly exposed on the internet.
        
         | heracles wrote:
         | This really struck me also. I work in the relevant industry (we
         | make cameras etc.) and there is always a bit of pain to get
         | user footage. This is how it should be! To have everything from
         | source code to customer material accessible to an admin is
         | bottom-tier thinking. Why not just rename your "admin" to "GOD"
         | and then ask yourself if you have any single point of failure?!
         | 
         | I do NOT want to sound smug, but there is a little bit of
         | amateur hour going on here both from buyer and seller. High
         | value and large targets (like airports) and more established
         | sellers usually don't work like this, and that's for a reason.
        
           | jrochkind1 wrote:
           | It's not just that it's a single point of failure, it's that
           | as a customer I do not want any admin who is feeling curious
           | to be able to snoop on my footage with a click.
           | 
           | I don't know how "established" this company is, but their
           | customers appear to include city governments, hospitals, and
           | Tesla motors, which I would consider "high value and large
           | targets".
           | 
           | Makes me suspicious of the whole industry. If others in the
           | industry dont' want that, time for some industry codes and
           | audits and self-regulation.
        
         | tyfon wrote:
         | This would be illegal on so many levels in my country.
         | 
         | It is also not compliant with GDPR but I suspect these are not
         | selling in Europe.
         | 
         | But this is in line with the general idea that anything you put
         | online in some form will be public at some point. Internet Of
         | Things to be hacked.
        
         | floatingatoll wrote:
         | Is that HIPAA-compliant? (Not sarcasm: I don't know HIPAA rules
         | enough to assess myself in the cloud-vendor / medical-
         | institution scenarios we're seeing here.)
        
       | tanseydavid wrote:
       | I cannot wait until the whole world is run by machines that do
       | not work very well. </sarc>
        
       | DoofusOfDeath wrote:
       | In the U.S. legal system, is video footage exposed in this manner
       | admissible in court?
       | 
       | E.g., if a prison inmate was physically abused by staff, and his
       | only corroborating evidence would be this video footage, can it
       | be used to justify a civil or criminal complaint?
        
         | dylan604 wrote:
         | IANAL, but from all of the cop shows on TV, if the lawyer was
         | provided the evidence and did not break laws themself OR as
         | long as the lawyer did not entice someone else to commit the
         | offense or provide instructions on what to do, then typically
         | the judge allows the evidence.
        
         | ocdtrekkie wrote:
         | I think so? Law enforcement can't break into something without
         | a warrant, but if someone brings them evidence of wrongdoing
         | (especially a third party who didn't conduct the hack
         | themselves), I believe they can act on it.
        
           | skybrian wrote:
           | It seems like someone would have to testify that it's
           | authentic? Who is going to do that?
        
             | dylan604 wrote:
             | The guy receiving the beating?
        
             | ocdtrekkie wrote:
             | Under oath, presumably you compel the people in the
             | footage. But I would imagine that the footage of
             | questionable sourcing might count as the probable cause to
             | go in and get the footage directly via warrant?
             | 
             | I am not a lawyer.
        
             | throwanem wrote:
             | Whoever at Verkada gets subpoenaed by the inmate's counsel
             | to do so, I'd assume. That said, I'm no more a lawyer than
             | anyone else who's commented here so far.
        
       | swiley wrote:
       | To the surprise of _absolutely no one_ closed IP cameras that
       | rely on a manufacturer run internet service are not secure.
       | 
       | Consumer electronics really suck, I wish there was an alternative
       | to the DIY approach of Linux SBCs with rsync over ssh.
        
         | jtchang wrote:
         | I'm making it -- https://github.com/openmiko/openmiko if you
         | want to help!
        
         | dylan604 wrote:
         | Each of these security camera system/IoT companies are only
         | offering you a bit of hardware to interact with their true
         | purpose of making you a user of their SaaS product.
        
         | bombcar wrote:
         | Get cheap-ass wired camera (even PoE).
         | 
         | Isolate the network they are on behind a Linux box that cannot
         | route.
         | 
         | Record on the box, display from another hardware port.
         | 
         | Wrap all the above behind another firewall.
         | 
         | Make it all IPv6 only.
        
           | totony wrote:
           | why ipv6?
        
             | IncRnd wrote:
             | Presumably for the larger address space that is more
             | resistant to scans.
        
               | SilverRed wrote:
               | Its interesting that you can and people have scanned the
               | entire ipv4 space in minutes on a fast VPS but it would
               | take you forever to find your first ipv6 address that is
               | even in use.
        
               | lytfyre wrote:
               | Shodan - a search tool for such things - had a pretty
               | incredible approach to attacking this - they quietly
               | provided most of the ipv6 hosts to pool.ntp.org, which is
               | widely used as a linux default - and would queue a
               | portscan up for any device that connected at startup for
               | timesync.
               | 
               | https://arstechnica.com/information-
               | technology/2016/02/using...
        
               | bombcar wrote:
               | Ingenious - and all the more reason to run NTP on the
               | border router/firewall and have that be the only device
               | that communicates with the outside world.
        
         | waz0wski wrote:
         | Here's one project based on RPi & HomeKit integration -
         | https://github.com/brutella/hkcam
        
         | g00gler wrote:
         | D-Link sells cameras that don't have cloud access. Look up a
         | DCS-913L. I bought one on eBay around a year ago. It has wifi
         | and you can set it up to record over SMB.
         | 
         | It's not the best image quality but if you get another router,
         | a raspberry pi and a large external HDD you can have a
         | relatively cheap CCTV set up.
        
       | judge2020 wrote:
       | Dupe of https://news.ycombinator.com/item?id=26404799
        
       | [deleted]
        
       | rossdavidh wrote:
       | Well, that looks bad. Thank goodness, though, that after a
       | security lapse this awful, corporate and government bureaucracies
       | will come to their senses and stop outsourcing critical functions
       | to cloud companies they don't know all that much about. Oh,
       | wait...
        
       | modzu wrote:
       | anyone else doing this in 1995??
        
       | mavhc wrote:
       | Why would anyone ever send their unencrypted cctv footage to a
       | 3rd party?
        
       | mensetmanusman wrote:
       | This is amazing. If they would have added software to the cameras
       | to mine bitcoin, it would've been absolute peak cyber punk.
       | 
       | People that sell video cameras attached to the Internet should
       | always have a disclaimer that the user should assume that the
       | system will probably be accessible by anyone at some point in the
       | future.
       | 
       | I believe Samsung started doing this with their TVs in regards to
       | audio.
       | 
       | We are certainly building ourselves an interesting future.
        
         | mcv wrote:
         | > peak cyber punk.
         | 
         | I'm running a Shadowrun campaign where the hacker of the group
         | frequently hacks security cameras. But it's always just a
         | single camera close to where he is. Clearly it would be more
         | realistic if he hacked all cameras of a single company all over
         | the world simultaneously.
         | 
         | I'm going to stick with my current game balance, though.
        
         | dylan604 wrote:
         | Mining on a SoC that fits in a security camera must be the
         | definition of futile. How in the world does one of these ever
         | "win" to earn?
        
           | jffry wrote:
           | They could mine for a mining pool
        
           | rtrdea wrote:
           | Could maybe mine Monero
        
           | TeMPOraL wrote:
           | Distributed computing. Customer's electricity is free for
           | you, so whatever you manage to mine, is pure profit (and
           | invisible to IRS if you're clever). Making this work would
           | also be an interesting Big Data Hyper Edge Cloud Computing
           | project to keep the engineers occupied and further justify
           | the need for the money they got from investors.
        
             | belval wrote:
             | Except there are no coins that could be mined with a camera
             | CPU. Even with Monero (which is CPU based) you will not
             | meet the RAM requirements or clock-in a "share" of work in
             | any useful timespan.
             | 
             | You statement is true in the wider sense, you can have
             | mining botnets of computers and maybe some high-end phones,
             | but IP cameras are really-really weak as far as compute
             | power go.
        
               | goliatone wrote:
               | You're right, partially. In the sense that to mine
               | bitcoin/etc you need something more powerful... but you
               | could just create a new type of crypto to be mined
               | specifically in low power/IoT devices. Something like [1]
               | 
               | [1]https://www.helium.com
        
               | dylan604 wrote:
               | How does something that works on low pwered systems not
               | get devoured by larger systems currently mining other
               | coins?
        
               | belval wrote:
               | Not familiar with Helium, but it seems to be PoS more
               | than PoW (at least for the IoT device part) so I guess
               | that could work.
        
               | TeMPOraL wrote:
               | Depends on what hardware they put in their cameras? I
               | assume they aren't just using random IP cams, but
               | deploying their own design? They could sneak in a
               | cryptocoin ASIC for good measure.
               | 
               | Of course they most likely aren't doing that, but it's
               | not out of the realm of possibility (and thus a missed
               | opportunity to make this debacle peak cyberpunk).
        
               | starky wrote:
               | Most security cameras are PoE powered which gets you a
               | whopping 13W of power that also has to run a sensor, IR
               | LEDs, heaters, lens, RAM, etc. before you even choose the
               | SoC and potentially your ASIC. How much computing power
               | do you really think you can get with that?
        
               | TeMPOraL wrote:
               | > _a whopping 13W of power_
               | 
               | So comparable to a smartphone under load. That's a pretty
               | good power budget, given that most of the components you
               | mentioned (except RAM/SoC) are going to be operated
               | intermittently.
               | 
               | > _sensor_
               | 
               | Serious question: you mean image post-processing and
               | encoding here? I thought CMOS sensors themselves have
               | negligible power demands?
               | 
               | > _heaters_
               | 
               | A crypto miner is just that - an overcomplicated heater.
               | If you include one, you don't need the other.
               | 
               | > _How much computing power do you really think you can
               | get with that?_
               | 
               | Not much, though an ASIC would get a nice multiplier on
               | it. I'd guesstimate it to be comparable to a cryptominer
               | running in the browser of an unsuspecting regular person
               | - who will typically have a cheap, underpowered machine
               | that can barely lift the OS and the browser without
               | hanging. In recent years, at least some people thought
               | you can make a profit with it, because we've seen such
               | web cryptominers deployed around the web.
               | 
               | My point isn't that it's happening - I fully expect the
               | cost of sourcing a miner ASIC and redesigning a camera
               | around it to be much larger than the mining it would
               | bring in any reasonable timeframe. But I think that on
               | first look, it's _possible_ , if someone tried hard
               | enough, to build a sneaky security camera like this, that
               | would be able to eventually yield some profit if deployed
               | wide enough.
        
               | belval wrote:
               | If they can do god tier supply chain attack, dissipate
               | the heat from mining hardware, add 4GB of RAM and put it
               | in a form-factor that looks reasonable for a camera while
               | still turning a profit, they can dedicate their genius to
               | legitimate business ventures instead.
        
               | TeMPOraL wrote:
               | It's not a "god tier supply chain attack" if you own the
               | blueprints and put the ASIC and a heatsink on them on
               | purpose.
        
               | dylan604 wrote:
               | Now that would be funny. However, would this not be
               | fairly obvious to one of those sites doing tear downs?
               | Then again, if found, would the PR one of those tear down
               | sites could generate slow the sales down enough to make
               | it a losing prospect for the manufacturer?
               | 
               | Non-techy people are willing to look so so far the other
               | way in trade of convenience. Showing them "facts" about
               | how much electricity their cameras are using would not
               | impact the vast majority of the users if they feel like
               | the service they are receiving is good enough.
        
               | downrightmike wrote:
               | having a crypto asic in any product would be sold as a
               | way to lower costs to consumers and would be deemed ok.
        
               | dylan604 wrote:
               | now that you put it like that, I'm surprised the
               | selection of "smart" TVs, cable boxes, provider wifi
               | boxes, etc are not doing that already.
        
               | TeMPOraL wrote:
               | Do we know that they don't? A dedicated ASIC would
               | probably be spotted by some random person doing a
               | teardown. But a DSP chip doubling as crypto miner when
               | not in use, that could easily escape post-purchase
               | hardware inspection.
               | 
               | (Might be easier to discover it on the
               | design/procurement/supply chain side. Perhaps stock
               | players would find out when investigating their
               | investments. A high-profile brand putting crypto miners
               | on consumer hardware is newsworthy, and news move stocks,
               | so there's incentive to leak the story.)
        
               | tracedddd wrote:
               | This isn't true, you could still mine (poorly) with
               | reduced RAM by recomputing as needed. And I'm not sure
               | what you mean by "clocking-in" a share in a useful
               | timespan. Compromised devices aren't people, so they
               | don't care if a particular machine can't get regular
               | payouts. If the whole network can reliably find a low
               | diff share solutions anywhere it can make money.
               | 
               | It would be horribly inefficient however a network of
               | tens or hundreds of thousands of low resource units can
               | absolutely make money since the costs are zero.
        
               | belval wrote:
               | To run argon2 (monero) you would need a significant
               | amount of time to compute even one hash that means that
               | the synchronization overhead of your workers would trump
               | any "hashing speed" an IP camera (even a good 4K one)
               | would have. By the time you get any amount of work done,
               | the block will be processed by a regular miner and you
               | will not get a payout. Same goes for a pool, doing any
               | "share" of work would take too long and you would be out
               | of sync. Hell given a bad enough ping I get refused
               | shares on a Ryzen 3800X.
               | 
               | Also on top of all of that most IP cameras are designed
               | with tightly defined specs. Trying to run a miner on them
               | would absolutely requires stopping the video feed which
               | would make the "attack" (which is still useless) easy to
               | detect.
        
               | ghayes wrote:
               | You could run a SHA256 hash of random values and send it
               | to a database in hopes of mining a Bitcoin block with it
               | one day when the input (block hash) happens to match.
               | It's only 2^256 times less efficient than standard mining
               | techniques.
        
           | deft wrote:
           | monero mining botnets have been doing this for years. Every
           | penny counts, as long as the SoC doesn't overheat and melt
           | its a trickle faucet forever
        
       | vanillax wrote:
       | This is why I self host all my cameras.
       | https://mitchross09.medium.com/how-i-self-host-my-own-sites-...
        
         | SilverRed wrote:
         | The sad part is the majority doesn't know how and why they
         | should do this. They just get their personal lives broadcast to
         | the web for all to see. There was or at least used to be a
         | subreddit showing the more interesting exposed cams.
        
         | antihero wrote:
         | How likely is it that for someone who isn't technically as
         | adept as a team at a (good) cloud NVR provider, the security is
         | actually worse? Bit like rolling your own crypto.
        
           | waz0wski wrote:
           | Verkada set the bar awfully low:
           | 
           | > The hackers gained access to Verkada through a "Super
           | Admin" account, allowing them to peer into the cameras of all
           | of its customers. They found the user name and password of
           | the account publicly exposed on the internet
           | 
           | Don't put your personal stuff directly on the internet, use
           | separate admin accounts with 2FA, gg, you're doing better
           | than Verkada - comically valued at $1.6B
        
       | NiceWayToDoIT wrote:
       | From some reason, all I am wondering is how huge is potential for
       | industrial espionage this way?
        
       | pmlnr wrote:
       | And when you try to describe the problem with cloud connected
       | "security" devices to your non techie neighbour, all you get is a
       | "whaaa...?" expression.
        
       ___________________________________________________________________
       (page generated 2021-03-10 23:02 UTC)