[HN Gopher] Hackers break into thousands of security cameras, ex...
___________________________________________________________________
Hackers break into thousands of security cameras, exposing Tesla,
jail, hospital
Author : f430
Score : 645 points
Date : 2021-03-09 22:11 UTC (1 days ago)
(HTM) web link (www.bnnbloomberg.ca)
(TXT) w3m dump (www.bnnbloomberg.ca)
| dhdhhdd wrote:
| I own reolink and amcrest cameras. I put them in a vlan with no
| outside connectivity (and frankly no inside either!). They try to
| call home constantly :-(
| irthomasthomas wrote:
| "Kottmann said their reasons for hacking are "lots of curiosity,
| fighting for freedom of information and against intellectual
| property, a huge dose of anti-capitalism, a hint of anarchism --
| and it's also just too much fun not to do it."" .... "Kottmann
| says they found a user name and password for an administrator
| account publicly exposed on the internet"
|
| Excuse me but finding a password that some idiot included in
| their public git project is not fucking hacking.
| cwkoss wrote:
| I wonder how much footage has been captured. Hackers could have
| produced a prison reality TV show with all that access.
| edoceo wrote:
| Never be as good as Oz, that show was amazing
| bredren wrote:
| Sequoia is mentioned prominently here. What is the role of
| venture funds in ensuring their startups operate or endure some
| basic regular external security audits?
| soheil wrote:
| Is there an archive of the raw photos/videos someone can link to?
| naebother wrote:
| If they've got nothing to hide, they've got nothing to fear.
| TobySKT wrote:
| "If you've ever searched for content and interacted with the
| results on a mobile device, you've probably encountered AMP, or
| Accelerated Mobile Pages. AMP is a good solution for websites
| that deal with huge volumes of data and need to retain fast
| performance. These can be informational websites, blogs, and news
| sites. For large projects, AMP can't substitute for responsive or
| adaptive web design.
|
| If you're interested in using AMP or If you want a free
| consultation from our team, feel free to contact us. We'd be
| happy to help." https://steelkiwi.com/blog/accelerated-mobile-
| pages-what-is-...
| jtsiskin wrote:
| Why would the footage not be E2E encrypted? Hospitals and police
| stations are installing cameras which store unencrypted footage
| remotely?? What is this madness
| ocdtrekkie wrote:
| End-to-end between the cloud provider and the cameras at the
| site, sure. But it's stored unencrypted, mostly because cloud
| providers provide the web interfaces and such to stream the
| video, provide services to analyze and classify the video, etc.
|
| Nobody encrypts their surveillance video storage, AFAIK.
| d110af5ccf wrote:
| > End-to-end between the cloud provider and the cameras at
| the site, sure
|
| That's TLS, not E2EE. E2EE means the provider never sees the
| unencrypted data. (Ex SMS is unencrypted, most internet
| services use TLS these days, Matrix and Signal use E2EE.)
|
| > Nobody encrypts their surveillance video storage, AFAIK.
|
| This is a serious problem.
| ocdtrekkie wrote:
| It's never going to change because of the performance
| implications. Most video surveillance systems have poor CPU
| to begin with.
| d110af5ccf wrote:
| What performance implication?! AES-NI has been standard
| for mainstream x86 hardware since ~2013 and ARMv8
| introduced optional crypto instructions in 2011!
|
| The issue is that manufacturers choose the cheapest
| possible SoC that lacks these abilities. Given the small
| cost savings and importance of basic security measures,
| that really needs to change.
|
| (A quick look at Amazon shows many of the top sellers
| advertising various "AI" features and streaming video at
| 4K or better. Given their apparent capabilities, I
| strongly suspect that such SoCs do in fact have hardware
| support for crypto.)
| philip1209 wrote:
| Isn't Cloudflare notorious for otherwise wanting only on-premise
| software?
| lima wrote:
| Yeah... I bet today was the security team's "told you so" day.
| ocdtrekkie wrote:
| Especially if https://twitter.com/nyancrimew/status/136943725
| 6193343496?s=... is true.
| mcv wrote:
| Tweet account has been suspended. Could you tell us what
| was in it?
| ocdtrekkie wrote:
| The person behind this claimed to have root shells on the
| networks of both Cloudflare and Okta. (FWIW, if the
| network is well segmented, this may have limited impact.)
| throwawaygulf wrote:
| Hilarious. Software development at Verkada is filled with "non-
| traditional backgrounds" leftist SJW types that spew neurotic
| delusional beliefs on Slack all day.
|
| I bet management wishes they would have hired some real devs with
| backgrounds in software development and security. You reap what
| you sow.
| hummel wrote:
| Note to HN. I know personally the attackers, and they send me
| proof of the attack before making it public. They are just two
| south america teens having fun cause they can't leave home. They
| were doing just for the lolz, there is no complex supply chain
| attack or state-actors involved. Just two kids pwning billions of
| VC money.
| 19h wrote:
| Not sure who contacted you but one of them is definitely from
| Switzerland.
| moosebear847 wrote:
| Idk anything, except that one of these ninjas is lying.
| adtac wrote:
| unless Switzerland happens to be in South America!
| rozab wrote:
| Cloudflare? Wonder if any were pointed at their lava lamps ;)
| jgrahamc wrote:
| No.
| ocdtrekkie wrote:
| Yeah, I wonder if the hackers had the same feed used to
| generate Cloudflare's randomness... that could be a vastly
| bigger security breach on top of this one.
| karlding wrote:
| If their blog posts are to be believed [0], lava lamps are
| not the only source of entropy available.
|
| _> Hopefully, the primary sources of randomness used by our
| production servers will remain secure, and LavaRand will
| serve little purpose beyond adding some flair to our office.
| But if it turns out that we're wrong, and that our randomness
| sources in production are actually flawed, then LavaRand will
| be our hedge, making it just a little bit harder to hack
| Cloudflare._
|
| [0] https://blog.cloudflare.com/randomness-101-lavarand-in-
| produ...
| walrus01 wrote:
| This is the same company that was in the news back in October
| related to harassing its own female employees with fratboy
| douchebag behavior:
|
| https://www.theverge.com/2020/10/26/21535089/surveillance-co...
| Hypocritelefty wrote:
| Tesla shills will find anything lol
| tartoran wrote:
| Good catch. I wonder if it's just kharma or they were targeted
| specifically in response to those behaviours
| walrus01 wrote:
| Or maybe companies run by sleazy people have less than
| stellar infosec/netsec practices, or are prone to sweeping
| gaping security holes under the rug rather than fixing them,
| which will inevitably result in something like this.
| Balgair wrote:
| It's talked a bit more downthread, but I mean if the sales
| director is making public slack channels featuring female
| employees alongside explicit jokes, then long-term thinking
| may not be a strongly selected for attribute at the
| company.
|
| https://news.ycombinator.com/item?id=24906940
| adolph wrote:
| To be fair, it was a specific person with a set of other
| employees who were all punished for the incident. It wasn't the
| company which includes the people were harassed.
| wavefunction wrote:
| Why is a sales employee enabled with access to the
| surveillance footage of the home office? It's not trust-
| inspiring.
| scubazealous wrote:
| You would be surprised the unrestrained access given to
| sales and support employees at most small SAAS companies.
| mcv wrote:
| Exactly. I'm not entirely surprised to see a company with a
| history of unprofessionalism and poor security policies,
| hacked.
| jhanschoo wrote:
| The headline oversells it but your comment undersells it.
|
| The specific person and set of other employees were "a group
| of men in leadership positions on the sales team", including
| the "sales director". When found out,
|
| > Verkada CEO Filip Kaliszan gave employees in the Slack
| channel [i.e. those involved] a choice: leave the company or
| have their stock options reduced. All of them chose to stay
| and take the stock option cut, according to Vice. "I was
| shocked. To me that's not just a fireable offense, that's a
| career-ending offense," one employee told IPVM.
| walrus01 wrote:
| It says a great deal about the CEO's character and judgment
| that he even considered for a moment _not_ firing everyone
| involved.
| guiriduro wrote:
| Even if the CEO is unshameable, the investors can be.
| Here they are[0]. Remind them publicly they invest in a
| broken company and make their association toxic as and
| until they distance, disinvest and hold the company and
| its officers fully accountable.
|
| [0] https://www.crunchbase.com/organization/verkada/compa
| ny_fina...
| baxtr wrote:
| You need a have subscription to see all investors...
| vermilingua wrote:
| I can see them all just fine.
|
| Sequoia Capital, First Round Capital, Felicis Ventures,
| Meritech Capital, and Next27 are the lead investors.
| HenryBemis wrote:
| 1. Sequoia Capital
|
| 2. First Round Capital
|
| 3. Felicis Ventures
|
| 4. Founder Collective
|
| 5. Meritech Capital Partners
|
| 6. Next47
|
| 7. Fifth Down Capital
|
| 8. Nick Candito
|
| 9. Hans Robertson
|
| 10. Idan Koren
|
| 11. Hector Garcia-Molina
|
| Edit:
|
| I used AdBlockPlus to block their pixel-filter, and then
| when I went back in they served me this nice message:
| Access to this page has been denied because we believe
| you are using automation tools to browse the website.
|
| Javascript is disabled or blocked by an extension (ad
| blockers for example)
|
| _wink_
| [deleted]
| bredren wrote:
| The video event annotations or filenames described in the
| article sound like what you might get out of a company
| culture that allowed the previous behavior to go largely
| unpunished.
| TedDoesntTalk wrote:
| It was not clear to me if the Arizona prison (the
| customer) chose those filenames or Verkada did. I could
| see prison guards doing the same thing... archiving clips
| that they find entertaining and naming them
| inappropriately. Not defending Verkada, I just wish the
| article made the culprit more clear.
| alexeldeib wrote:
| From a different article, seems like the staff
|
| > Inside Arizona's Graham County detention facility,
| which has 17 cameras, videos are given titles by the
| center's staff and saved to a Verkada account.
|
| https://www.bloomberg.com/news/articles/2021-03-09/hacker
| s-e...
| bredren wrote:
| My mistake. Would edit if possible.
| throwawayboise wrote:
| Never trust a man named Flip.
|
| Edit: Argh... it's Filip. HN's tiny font strikes back.
| A4ET8a8uTh0 wrote:
| So a real question.. was HIPAA violated or since they used a
| 'good' vendor, the check mark is on the compliance list and
| auditors will be happy?
| SilverRed wrote:
| I think anyone who has had to comply with those compliance
| lists knows how useless they are. Easy to make the minimum
| change that makes you compliant without being any more secure.
| bronson wrote:
| Also Verkada, 4 months ago: Surveillance company harassed female
| employees using its own facial recognition
|
| https://news.ycombinator.com/item?id=24906940
| f430 wrote:
| > Last year, the sales director accessed these cameras to take
| photos of female workers, then posted them in a Slack channel
| called #RawVerkadawgz alongside sexually explicit jokes. The
| incident was first reported by IPVM and independently verified
| by Vice.
|
| damn that is despicable but this sort of brogrammer behavior
| appears rampant. How would you address this as a manager? This
| is absolutely not okay.
| ALittleLight wrote:
| You think their sales director is also a programmer? What's
| the point of combining "programmer" and "bro" like this?
| vineyardmike wrote:
| > What's the point of combining "programmer" and "bro" like
| this
|
| This is a known (to some) phrase, with a known (to some)
| meaning... its about bro-y silicon valley culture more than
| actual programmers
| ALittleLight wrote:
| You use a portmanteau of programmer to refer to people
| who aren't programmers? Seems like this is just the wrong
| pejorative to use in this case.
| vineyardmike wrote:
| It could be a programmer. I think the origin comes from
| bro-y men around 2005 moving to silicon valley (eg zuck
| in that movie) but then having a very frat-culture vibe
| (eg. lots of booze, house parties but with programming,
| etc). It grew to be anyone silicon-valley and tech-
| adjacent that acted like this.
| stjohnswarts wrote:
| You're right, it "appears" rampant with quotes. It really
| isn't. The world is a big place and such solacious news
| because almost instantly popular (because internet) even
| though it's a 1 in a million thing.
| 46Bit wrote:
| fire for cause, file a police report depending on what the
| photos are, and support the victims
| mcv wrote:
| Not what they did, mind you. The culprits merely got their
| stock options reduced. And the fact that the sales manager
| could access the camera feed may have been a big hint that
| security was not their biggest priority.
| ck2 wrote:
| If only there was a way to keep an intranet inaccessible from the
| internet like not connecting the two.
|
| You think there are nuclear missiles somewhere on the internet?
| Someday some general will want to monitor them and order that.
| rapjr9 wrote:
| I'd like to see an overview of everything that has been hacked so
| far, arranged by both device/protocol and industry/gov/social
| structure. It would be interesting to see if there are any
| categories that have not yet been hacked and what their
| characteristics are and where in society they reside. Maybe
| secure internal networks at the DoD have not yet been hacked?
| (How would we know, aren't those networks the ones the state
| attackers really REALLY want to attack? Who would tell us if
| they'd been compromised? There have been some news reports on the
| use of insecure drone control wireless protocols.) Crypto
| protocols used for chemical plant SCADA? Have parts of Starlink
| been hacked yet? Which banking protocols and hardware security
| modules have been hacked and which have not (SWIFT? HSM's based
| on ASC X9 standards?) Might give us some clue as to what actually
| works, what needs to be abandoned, and what needs changes. At the
| moment this looks like a losing battle (possibly a loss of
| civilization?) with the number of big data thefts and compromises
| if something does not change. Does anyone know if such a
| comprehensive review exists in the literature?
| brk wrote:
| I started this list when I was part of IPVM:
| https://ipvm.com/reports/security-exploits
|
| It's probably missing some, and is specific to security
| cameras, but it is a start.
| heracles wrote:
| I'd like to add a bit of context to how security cameras most
| often are installed.
|
| In the industry in general you have producers of the equipment
| and you have buyers, but in between there you have integrators.
| The integrators plays a crucial role when installing big systems.
| They win the bid for an installation and carries out the work.
| This means that there is seldomly any direct path between camera
| producer and the customer. For the producer to get access to
| footage they must go through the integrator, so the friction is
| non-trivial.
|
| Direct contact producer <=> buyer might happen in the small case,
| like a store with a single camera or you placing one at home.
|
| My guess (!) is that verkada tries to pry away the integrators
| with a simpler model for installation.
|
| Most larger producers now have cloud offerings, which could have
| some similar vulnerabilities to those mentioned in the article.
| However, my impression is that security is taken VERY seriously.
| Not just lipservice, but in practice. This makes sense as it is a
| key selling point and the larger buyers are competent judges of
| this. This is in stark contrast to the "typical" hacked target,
| which seems to be autoshops and hospitals (I am generalising to
| get through a point, I am not sure what the most common victim
| is).
| DudeInBasement wrote:
| So, do they know what happened to Jeffery?
| cosmodisk wrote:
| You hardly need to be a hacker for this. I did some Google dorks
| out of boredom. In 15 min, I saw live feed from some CCTVs
| exposed to public internet. The most disturbing one was someone's
| living room...
| ak217 wrote:
| Earlier feature about the culture at the security camera company
| in question: https://www.vice.com/en/article/pkdyqm/surveillance-
| startup-...
| gibolt wrote:
| Quite comical that the image in the article is subtitled 'Madison
| County Jail', but is actually seemingly a Tesla service center.
|
| Other options are the reporting site got hacked or it is quite
| the experience at that jail.
| xiphias2 wrote:
| I thought that jail workers are used to fix Tesla cars. I have
| read that people in jail are used for work in the US.
| marshmallow_12 wrote:
| They do actually get pay from what i hear. It's not like its
| forced labour (labor).
| danaliv wrote:
| A whopping $0.14-$1.41 per hour.
|
| https://www.prisonpolicy.org/blog/2017/04/10/wages/
| [deleted]
| marshmallow_12 wrote:
| I still think it's better then sitting and staring at the
| walls, yet that option is open to them .
| to11mtm wrote:
| It's a worse option for everyone:
|
| - Pushes down wages for other workers doing similar
| labor, by taking demand out from the normal market
|
| - Because the prison itself (or, more likely, the prison-
| industrial-complex corporation running it) is seeing a
| huge profit from these ventures, it provides a perverse
| incentive to keep their labor pool 'strong', be it
| through lobbying for harsher sentences, or encouraging
| shot quotas amongst their guards/COs.
|
| - Conditions prisoners towards working less for equal
| work (we shouldn't encourage the idea that -any- class,
| race, or creed of human being is worth less for the same
| amount of work)
| SilverRed wrote:
| No its not, because that work generate value for
| companies at a very low cost. So it both builds a system
| that pushes for more people in prison and displaces
| workers who would have been paid higher.
|
| Prisoners should be given some kind of work / study /
| something. But it should't generate value for anyone but
| the prisoner or perhaps lower costs for the prison
| (cleaning/etc)
| klingon78 wrote:
| I wonder about Cloudflare. It seems like the Windows Vista of its
| genre. It's big, pretty, and possibly doomed to be replaced.
|
| Tesla is fine. It may as well have been a publicity stunt for
| them. "For a limited time, you can tour the Tesla facility, but
| please don't. (wink wink!)"
| robbyking wrote:
| A while ago there was a post on Reddit about something similar,
| and there wasn't even any "hacking" going on; the video feeds
| were just unsecured.
|
| Using Google, someone search for a proprietary video protocol
| (IIRC) and found tons of video streams that weren't even password
| protected. Some in schools, some in warehouses, and some just on
| the street as part of neighborhood surveillance. I think I have
| the link saved, I'll look for it.
| Mixtape wrote:
| Finding unprotected streams via Google Dorking like this is
| easy. Here's an article that doesn't cover this particular use
| case, but rather the broader practice:
|
| https://exposingtheinvisible.org/guides/google-dorking/
|
| I've personally dabbled with it a bit in the past, and while I
| didn't find anything particularly interesting, it did make me a
| bit more cautious about enabling anyone with a link to access a
| Google Doc. With a good enough scraper or even just a lot of
| patience, there are a lot (potentially sensitive) data out
| there for people to harvest. That's not to say there aren't a
| number of benefits to having access to advanced search tools
| though, just that individual mindfulness when making something
| completely open for anyone to access is all the more important.
| judge2020 wrote:
| https://www.shodan.io/explore/tag/webcam
| SilverRed wrote:
| Its horrible how common this is. I used to do work on local
| business sites and the security was horrific. Pages that
| contain sensitive data or even CRM management pages exposed to
| the public internet with no password at all. On some of the
| less sensitive ones I had a look I found details of family
| members in these exposed sites.
|
| Not only that, but it was all horribly outdated. Seen some
| things running on rails 1 pre release on a debian server about
| 6 years passed end of life.
|
| Its a wonder the world works at all.
| Teknoman117 wrote:
| Wasn't there a website along the lines of "camroulette" that
| showed you random unsecured IP camera feeds?
| d110af5ccf wrote:
| Yes. There also used to be a subreddit where every post was
| an unsecured camera IP address.
| TameAntelope wrote:
| These folks (the hacker group) are a hoot to follow on Twitter, I
| do recommend searching for and finding them there. Hacker demons,
| the lot of them. :)
| ocdtrekkie wrote:
| Putting surveillance video on the cloud is... kinda dumb. It's
| rarely viewed outside your network, and local drives cost
| drastically less than the bandwidth needs. Also it's incredibly
| sensitive data that shouldn't leave your network without really
| good reason anyways.
|
| The solution to this hack is simple: Shut this company down,
| because it's a bad idea.
| httpz wrote:
| When Microsoft Exchange servers were hacked a few days ago,
| people on hacker news were talking about how most companies are
| not capable of securing their own on-premise systems and they
| should have used Office 365. There really isn't a perfect
| solution. There are trade-offs.
| ocdtrekkie wrote:
| It's a lot easier to secure on-premise Exchange than Office
| 365. For one, having OWA exposed to the Internet is entirely
| optional for Exchange on-prem... but impossible for avoid for
| a cloud service. Most possible ways to secure access to
| Exchange on-prem are built into your firewall, and you can
| configure at leisure... most possible ways to secure access
| to Office 365 are billable add-ons to your subscription. Any
| side channels to that... you just have to trust Microsoft...
|
| I agree there are trade-offs, but especially for large
| enterprises with security teams, on-prem is definitely more
| secure.
| rapsey wrote:
| Unfortunately local storage is a problem. It is very vulnerable
| to arson or theft.
| Ensorceled wrote:
| There are actually plenty of reasons for remote storage of
| surveillance footage; not the least of which is that offsite
| storage of such video can be a regulatory or insurance
| requirement.
| quasirandom wrote:
| There's more information here as well. Cloudflare was
| apparently operating network connected facial recognition
| cameras in their offices.
|
| I'm not someone who's crazy about privacy, but this is a pretty
| dark indicator for a company housing DNS query records. Maybe
| its time for someone to build a proxy for tunneling Cloudflare
| DoH/DoT over tor or some other free mixing network.
| ocdtrekkie wrote:
| It really comes down to how it's used. As another commenter
| pointed out, any company using badges to swipe into doors can
| track your movements. Most cameras are positioned near entry
| doors, exteriors, or public areas as it is. The main
| difference here is the amount of information collected on an
| unauthorized entrant, and the fact that maybe badge-borrowing
| doesn't go unnoticed anymore.
|
| I really doubt Cloudflare is the type of company to be
| tracking where each employee is and whether they are taking
| too many bathroom breaks. It's definitely an area abuse is
| possible, but probably not an area it's likely in
| Cloudflare's case.
| quasirandom wrote:
| > It really comes down to how it's used
|
| I absolutely agree. The thing that concerns me is these
| cameras sitting on the internet. It says something about
| how overworked the security team is. I trust that they have
| good faith, but I don't know if they have the resources
| they need.
| adolph wrote:
| What is a specific credible concern about cameras with
| public API?
| Teknoman117 wrote:
| People other than the ones you agreed to let monitor you,
| well, monitoring you. Also, it's a major risk to the
| company itself, who knows what can be read off of
| employees screens if they're compromised.
| adolph wrote:
| Yeah, it seemed far fetched to me at first but I guess
| surveillance might be useful to a 3rd party. I read an
| article a while back on how people make equity trades
| based on data found through satellite images of refinery
| tanks and whatnot. I guess unsecured internal
| surveillance cameras could allow an outsider to find out
| if a company was really busy or just faking it.
| gostsamo wrote:
| Every IOT device is an attack vector against the network.
| adolph wrote:
| I wonder if there is a way to dumb down IOT devices so
| they can't be an attack vector like that.
| gostsamo wrote:
| Lock the memory so that update is physical only and
| restart regularly to avoid no-memory malware. Not 100%
| secure and very inconvenient, so people prefer to isolate
| IOT in its own network and preferably have a good network
| security like putting the devices behind
| VPN/firewall/other gatekeeper.
|
| Actually, if you want to have IOT access outside of the
| network, the best approach is to close all ports and for
| the device to initiate connection with a control server.
| The device is dark when scanned while a heartbeat signal
| will ensure connectivity. This will require a good
| security on the control server, but that is okay because
| server security is much better understood and does not
| suffer from the constraints of the embedded software.
| josefx wrote:
| Someone wanting to break in can check if anyone is there
| or see where easy to steal stuff is kept? Or on a larger
| scale you might leak when and how security guards make
| their rounds.
| [deleted]
| jgrahamc wrote:
| _Cloudflare was apparently operating network connected facial
| recognition cameras in their offices._
|
| We do not use that feature and do not intend to.
| robertlagrant wrote:
| But did you ever use it?
| jgrahamc wrote:
| No, this was never in active use.
| rattray wrote:
| If they did, wouldn't it be a _good_ sign if someone came
| along and said, hey, this doesn 't align with our values,
| and was able to get it removed?
| bradlys wrote:
| How is that something to be worried about? There are
| companies out there that try to monitor if employees are in
| rooms/areas that they're not supposed to be. You can do that
| with badges/RFID but then people can take a card or slide by
| in various ways. (Happens all the time at big companies -
| people just tailgate) If anything, they might be taking
| privacy more seriously by not letting people without
| authorized access into secure areas.
|
| I think you give up any sense of privacy as to where you're
| located in an office or where you've been in an office when
| you decide to work in an office owned by some employer. I
| don't know why there'd be any expectation there.
| [deleted]
| batty_alex wrote:
| I find it fascinating how okay you are with your employer
| tracking you. We aren't to the life contract part of the
| dystopia yet, quit trying to skip ahead and give away your
| freedom so easily
| Shank wrote:
| Cloudflare sells security to people. If you don't want to
| work at a company that has security requirements like
| that, don't work there. Lots of people choose to donate
| their fingerprints, facial data, life history, and
| polygraphs to work for the government. That's their
| choice to make.
| tartoran wrote:
| If that info is well taken care of is one think. If it
| ends up floating on the internet is another. Rfid badge
| data floating on the net creates is useless however other
| personal data could be very toxic in the wrong hands. And
| usually this info leaks thats why its not a great idea to
| let it outside the network let alone record it in the
| first place
| throwawayboise wrote:
| > If that info is well taken care of
|
| It isn't. https://en.wikipedia.org/wiki/United_States_Off
| ice_of_Person...
| neffy wrote:
| If you are in a secure area, like a server room for
| example, it's perfectly normal for there to be badged
| entry, cameras everywhere etc. There will also be signs
| everywhere telling you this.
|
| If it's really secure there will be monitoring of all
| entrances, including corridors. (And there will still
| occasionally be people successfully tailgating, usually
| for perfectly innocent reasons like forgetting their
| badges at their desks etc. Real security is all sorts of
| fun.)
| Teknoman117 wrote:
| I've gotten stuck in a datacenter because I forgot the
| correct badge-out process. Tripped an alarm and got stuck
| in a man-trap.
|
| For the uninformed - badge in to open the entrance door.
| The room then locks and you use your badge to open the
| exit.
| jackson1442 wrote:
| Interesting. Seems like that would be a fire hazard, or
| was there a hold-to-escape type crashbar?
| LinuxBender wrote:
| Some facilities get exceptions to fire policy and require
| employees to go through _training_ of sorts. Diablo
| Canyon Nuclear Power Plant is one place I visited that
| did not have emergency egress. No badge? Call the guards,
| that is the only way out.
| ravel-bar-foo wrote:
| Obviously not the same type of facility, but I have seen
| buildings where the closing of smoke shutters opens
| otherwise locked doors, revealing an alternate fire
| escape from the corridor to the stairwell.
| vermilingua wrote:
| In fire/hazard conditions, security systems are required
| (at least in Australia) to permit free handle egress from
| any point in the building to a fire escape.
|
| Any access control system has the capability to integrate
| with a fire system and allow this.
| jackson1442 wrote:
| I believe the general policy in the States is "one swift
| motion" to exit a room which is why you see mostly
| crashbars and lever handles as egress, mostly on push
| doors for the primary egress path.
|
| In secured areas where they want you to swipe out or
| places where they might get tripped accidentally, they
| sometimes have like a 15 second lockout before actually
| tripping the door.
|
| I've been in just one server room and they just had a
| motion-deactivated maglock tied to an electric strike so
| in the case of a power outage a simple mechanical lock
| could be opened but otherwise you need to badge in/out.
| datavirtue wrote:
| Fire hazard and false imprisonment. Ask walmart. You
| accidentally lock someone in the store and you are
| looking at a civil rights law suit. You cannot restrict
| another humans' movement without due process.
| acomjean wrote:
| I worked I the defense sector.
|
| We were tracked by contract (badge into building, badge
| into area). We couldn't leave the work area un-attended
| which was a pain, so there were "processes in place"
| (last person badge etc..).
|
| Generally we knew they left you alone unless you were
| cheating. (Having someone badge you in when you weren't
| there was a fire able offense).
|
| I don't miss it, but it wasn't that bad. Of course having
| the work network not on the internet what else could we
| do but work...
| wyqydsyq wrote:
| How is being recorded by your employer while on their
| premises giving away your freedom? It would be a
| different thing if they were tracking you out of work,
| but when you enter a premises owned by a business you
| kind of implicitly agree to be surveilled by them, as it
| is _their_ right and freedom to protect their assets.
| meowface wrote:
| I'm okay with my employer tracking me if I'm on their
| premises using their property that they've given me. I'm
| not okay with them knowing anything I do or where I am
| outside of work, but if I'm at work then I'd be confused
| if I _wasn 't_ being tracked in some way.
|
| Not at all in the paranoid "are you slacking off?!"
| sense, but just security information like knowing when
| I've been in a server room, or knowing if my work
| computer sent traffic to a known botnet C&C. If there's a
| security or theft incident and they don't know who's been
| in their building or what their computers are doing, it's
| pretty much impossible to investigate anything.
|
| I understand that in places like Europe there's a very
| different culture and workers have a lot of protections
| from things employers may want to do, but not everyone
| around the world feels that way. Basic record-keeping of
| when badge-restricted doors and computers are
| authenticated to doesn't feel invasive to me in the
| slightest, even if others may strongly feel it is
| invasive.
|
| There are many things I would find egregiously invasive,
| such as a manager inspecting all the websites someone
| visits to assess how productive they are, or timing
| people's bathroom breaks, but I just avoid such
| companies.
| laurent92 wrote:
| I don't understand why people think the employer cannot
| check whether the employee is slacking off.
|
| Maybe what we should prevent is employer keeping months
| of proof and only bringing it up as inappropriate later,
| but if the employer uses the camera to tell an employee
| within 24hrs that he needs to ramp up, it feels ok. Maybe
| we should impose rules like "24hrs max" and "can't be
| used legally, just orally."
| csharptwdec19 wrote:
| > I don't understand why people think the employer cannot
| check whether the employee is slacking off.
|
| On some level it depends on what 'slacking off' means.
|
| I've had employers where 'slacking off' meant actively
| doing some %mundane/repetitive/unnecessary% task with
| every moment of my free time. We were literally pulling
| the finish off the counters; there was no need to keep
| dusting them.
|
| I've had software shops where reading integration
| documentation was 'slacking off'.
|
| An interesting data point; In Germany, MS Office doesn't
| track how long you have been editing a document. My
| understanding is this is because the law there more or
| less says if you pay someone to do a task, you aren't
| supposed to (i.e. can't) care about how long it took them
| to actually do it as long as it was done on time.
|
| So I guess that's my problem. There's a very fine line
| between employers using surveillance to catch 'bad
| actors' and employers using surveillance as another tool
| to bully substandard work conditions onto people.
| ocdtrekkie wrote:
| My guess is that micromanagement actually decreases
| quality and productivity as well, just due to the
| disconnect between management opinions and real-world
| employee experience. If you are judging performance on
| the output correctly, the employee will, out of own self-
| interest, maximize the quality and quantity of the output
| while minimizing their own effort expended in creating
| it.
| stjohnswarts wrote:
| The day one says I'm "slacking off because we noticed
| inactivity on your laptop" is when I stand up and walk
| out the door. Hasn't happened yet but I suspect it will
| at some point.
| 6510 wrote:
| Its only natural really in this race to the bottom. If
| your zero hour contract doesn't have room to pay the
| bills you are not just not worried about tracking, you'd
| take anything that might show how hard you've tried.
| mc32 wrote:
| One of the biggest use cases presently is SARS-COV-2
| tracing to figure out who needs to be notified they were in
| proximity for X-time of someone with COVID-19.
| bsder wrote:
| > Putting surveillance video on the cloud is... kinda dumb.
|
| I tend to agree, but ...
|
| If you're a small business or manufacturer, IT is a pain in the
| ass. The "cloud" _is_ a benefit because you don 't need to
| maintain any servers yourself and can just get on with your
| business.
|
| The problem is that these companies don't face any consequence
| for claiming that they're secure and then not actually being
| ... you know ... _secure_.
|
| If this stuff was simply encrypted at rest, that would have
| mitigated most of this breach.
| ocdtrekkie wrote:
| Sure, but many of Verkada's customers are large enterprises
| with large IT teams just making a bad decision.
|
| Small businesses have either a box they bought at Costco or
| use something like Comcast's service which they just add on
| to their cable modem.
| leesalminen wrote:
| Those boxes from Costco come with WiFi built in and a
| mobile app paired to it. The small business owner
| invariably sets up port forwarding so they can watch from
| home and leaves the default password because it doesn't
| force you to change it. Not much better there either.
| ocdtrekkie wrote:
| My point was less that those were good solutions, but
| that a company I contend "shouldn't exist" likely has a
| different customer segment, like Tesla and Cloudflare.
| intrasight wrote:
| Oh, the places I've boldly gone - using default passcodes
| brundolf wrote:
| I don't think it would, because they leaked admin credentials
| (unless it was encrypted with a customer key and inaccessible
| to admin/support)
|
| Anyway, I think we're at the point with software/digital
| systems where food manufacturing was in 1900: there's been a
| gold-rush due to new technology, and we're reaching peak
| negligence in the pursuit of profit, and I think we'll soon
| get to a threshold where regulators will finally step in and
| lock down the wild-west and impose some real standards.
| Between SolarWinds, Exchange, and now this, it's to a point
| where it's dragging down our whole society. Something has to
| give.
| HarryHirsch wrote:
| I just had an aha moment reading your post. Food safety,
| drug safety, airline safety, all these regulations were
| implemented because manufacturers were operating with
| standards so lax that people suffered actual harm.
|
| Perhaps that's the real reason behind the anti-FDA lobbying
| we are seeing here. The FDA demonstrates that government-
| mandated safety standards work. We can't have those in the
| IT field because they would diminish profits!
| morlockabove wrote:
| The FDA also has massive associated costs and acts as a
| hurdle to innovation- which is partially by design
| (lobbyists like regulatory capture).
| HarryHirsch wrote:
| The Moderna and Biontech RNA vaccines got past the FDA in
| record time and are a massive innovation. What are you
| even talking about?
|
| Also: Hepatitis C antivirals. One pill and you are cured,
| whereas in the past you'd be looking at a liver
| transplant. If that's not innovation it's impossible to
| say what that would be.
| tomc1985 wrote:
| But then how will techbro wantrepreneurs build their unicorn
| business?!?!
| Hnaomyiph wrote:
| It's amazing how much security people and companies are willing
| to give up for a smidge of convenience. Properly deployed CCTV
| has little worry of hackers since, hence it's name, it is
| closed-circuit.
| lancesells wrote:
| This made me wonder if there's a place for a company to
| disrupt the video cloud industry by selling CCTV cameras and
| devices that would require physical updates sent on a usb
| drive.
| ocdtrekkie wrote:
| It's not actually hard to do that today with existing
| equipment: Put it all on a network switch and then just...
| don't plug it into the Internet. Plenty of on-premise
| solutions exist and work with or without remote
| connectivity.
| vel0city wrote:
| Get this: closed circuit television systems actually
| existed before updates could be delivered by the internet.
| Another crazy fact: there are still products sold which
| don't connect to the internet. You don't see nearly as many
| ads on these products though and don't seem to be as
| popular these days.
| pugworthy wrote:
| Trust me, it's not always about convenience for some of us
| remote camera users.
|
| In my case, I've got a camera in my elderly parent's back
| yard as there have been a few falls in the back yard, and one
| break-in some years back.
| stjohnswarts wrote:
| That seems like more trouble than it's worth though. Do you
| like just check every hour to see if someone has fallen or
| something? That seems like something that could become
| either an obsession or something you'd forget to do.
| ocdtrekkie wrote:
| Not the OP, but I have a significant amount of anxiety
| sometimes about if something bad has happened or if my
| pets are okay or whatever. It's an extreme version of
| "did I forget to turn the over off".
|
| Being able to remote in and go "ah, everything's fine"
| basically can instantly turn such anxieties off, rather
| than say, having to live with it until you finish out the
| work day and can head home.
| antihero wrote:
| Verkada has prioritized sales expansion over growing the
| engineering team, with 150% more salespeople than engineers and
| almost half the entire company in sales, per LinkedIn"
|
| Exactly the sort of people you want to trust with highly
| sensitive surveillance.
| philjohn wrote:
| Another take on this - I have google nest outdoor cameras.
| Recently, a car park company tried to claim I was in a car park
| for 7 hours. In reality, I had gone earlier in the day, come
| back home, and then gone back hours later - but their ANPR
| system must have had a glitch.
|
| I was able to send them links to the video clips on the Nest
| site, with embedded timestamps.
|
| If this was a local system there would be no way to prove I
| hadn't just faked the timestamps.
| listenallyall wrote:
| >> no way to prove I hadn't just faked the timestamps.
|
| Showing a ticket? Parking lots have been using them pretty
| successfully for 50+ years
| mattacular wrote:
| You not having to pay an unfair fee for parking one time
| hardly seems like a good tradeoff for massive surveillance
| overreach by truly incompetent companies but maybe that was
| one really expensive lot or something
| stjohnswarts wrote:
| Assuming one size fits all is dumb as well. This could be
| handled much better but it won't be cheap and that's what
| everyone is trying to do, "cheap". Other things are "on the
| web" and much less easily hacked.
| balfirevic wrote:
| > Shut this company down
|
| Who should shut it down?
| Black101 wrote:
| Pretty much all consumer security cameras do this by default
| nowadays... I had to disable it on mines and send it to my own
| server instead, as a backup.
| passivate wrote:
| Ouch! That's a bit harsh! Well, I suppose cloud archives could
| be encrypted? We use a cloud based system (but no cloud backup)
| and with multiple facilities, its nice to be able to launch the
| app and stream the camera's live feed using the cloud as a
| bounce.
|
| Also with the cloud being used as the de-facto off-site backup
| location, most data these days will end-up (hopefully
| encrypted) in some kind of cloud service or another.
| ocdtrekkie wrote:
| Remote access is fine, it can be reasonably managed:
| Generally the client sets it, and the manufacturer doesn't
| retain access. Usually you can geoblock and such as well. You
| have control of the hardware and can implement encrypted
| storage and better access controls, rather than trusting a
| third party to decide what is "secure".
| bredren wrote:
| This would be a much bigger hack if it were Wyze. Wyze cams are
| generally placed in residential interiors and contain a mic
| that can not be disconnected without physical removal.
|
| It wouldn't be as newsy, though because people put these in
| their own homes.
|
| The only way this group raises awareness instead of angering
| people is by targeting companies and institutions, rather than
| forcing people to confront their own compromises with
| technology, time and effort.
| tkinom wrote:
| Any known security issue with Wyze?
|
| I am very impress with their features. I am planning to buy
| couple of them, but I would never point them inside the
| house. Probably will put them in their own wifi network.
|
| I built a home grow solution with RPi + Webcam + Google Drive
| with some python script. But the performance to upload Pics
| to G Drive was slow and the way viewing the pics uploaded to
| G Drive was not very convenient.
| xvector wrote:
| Why not use an E2EE solution, like HomeKit for your camera?
| shakna wrote:
| A couple years back (2019) Wyze had a breach [0], which
| accidentally exposed another breach that they hadn't been
| aware of. This came just six months after a previous
| breach.
|
| But it suggested that Wyze can remotely disable all
| encryption and so on whenever they feel like it.
|
| And that for a "subset of users" they collected: "Height,
| Weight, Gender, Bone Density, Bone Mass, Daily Protein
| Intake, and other health information", which was included
| in the breached data.
|
| [0] https://www.nytimes.com/2019/12/30/business/wyze-
| security-ca...
| GloriousKoji wrote:
| If you're serious about security I recommend against wyze.
| You're locked into their platform and it isn't fully
| reliable.
|
| If you want something like a video of that opossum sneaking
| in the attic, coyote peeing in your rose bushes, that kid
| across in the street with the razer scooter and german
| shepard not cleaning up the poop off your lawn or what your
| iguana is up to when you're not home then it's great for
| that.
|
| The UI is probably worse than your gdrive setup. You have
| to use the wyze app to access it, which has a terribly slow
| scrubbing interface. The more convenient part is to check
| the motion/sound triggered 15 second clips which are upload
| to their cloud servers. Other than that I find myself
| frustrated and just take out the microSD card and browse it
| on my computer.
|
| Also don't buy the sense kit. It just doesn't work. I've
| even tried experiments with it right next to the camera and
| it's not consistent enough.
|
| If you want to use the wyze cams are generic IP cameras
| they offer unsupported firmware for that but then you'll
| need to roll your own DVR and I'm not sure if that supports
| all the new features the V3 offers or follows the genric
| protocol for remote pan control.
| [deleted]
| zucked wrote:
| Wyze cameras have open source firmware that can be loaded
| (DaFang Hacks) that works pretty well.
|
| I've never used (or trusted) the Wyze firmware anywhere
| on my network, but I use a couple of Wyze cameras pointed
| outwards from my house connected to a a DVR with motion
| detection.
| vineyardmike wrote:
| Not sure when you bought yours but i haven't been able to
| get DaFang working in at least 18 months (due to OTA
| firmware updates before attempting DaFang)
| dude3 wrote:
| I find the Wyze cams great! Cheap. They do have 2 factor
| auth support for apps like Authy. It doesn't sound like
| you have enabled the premium features. Person detection
| is really good for exterior facing cams. Hook it up to
| Alexa Show and you have person detected notifications
| also access to any cam. Premium also has longer clips.
| For the price it's kind of OK to be semi locked down. I
| believe the reason for not supporting RTSP is because of
| hardware limitations on V2.
| bredren wrote:
| I have used three wyze cams but only for pointing outside
| or to monitor plant growth. Here is an HD timelapse of a
| Monstera Deliciosa I made with one:
| https://youtube.com/watch?v=0NH2t1fJL9w&feature=emb_title
|
| The first thing I do with a wyze cam is physically remove
| the microphone, because it can only otherwise be turned
| off in software which is configured in the cloud.
|
| I'd consider using them with the OS firmware change, but
| hadn't thought of also running them on an independent
| network.
| bredren wrote:
| There were no "known" security issues with Verkada.
| Spooky23 wrote:
| For anything small, the local drives are obvious theft targets.
|
| For anything large or distributed, you're probably going to
| spend less for better security with a cloud system.
|
| It's sensitive data, but probably in a second tier of
| sensitivity. The integrity of the on-prem system depends in
| your remote access security and operational practices.
| Solutions like this often really suck.
| pugworthy wrote:
| > Putting surveillance video on the cloud is... kinda dumb
|
| It's a necessity for some cases. I commented on this elsewhere,
| but for me it's having an eye on my elderly parents back yard
| in case of falls. Past history of not knowing is precisely why
| we got the camera.
| ronnier wrote:
| You can still keep them local and use a VPN. That's what I
| do.
| contravariant wrote:
| People really should. It's pretty easy these days with
| wireguard or tailscale. Just plug a raspberry pi somewhere
| with network and power and you're set.
| pugworthy wrote:
| I spend my day doing the "tech shit" for work. I don't
| want to mess with stuff, I just want it to work. I'm
| willing to risk a bit of security for it to "just work",
| which it has now for multiple years. Without any security
| issues (so far).
| contravariant wrote:
| I completely agree, even though I do tinker around with
| stuff for fun. However in my experience so far wireguard
| and tailscale (which is based on wireguard) are the kind
| of solutions that just work with little to no oversight.
| SilverRed wrote:
| Its still on the internet though. Its just the VPN becomes
| the security barrier. Although if you keep it up to date,
| its going to be safer than iot crap
| _-david-_ wrote:
| I think the biggest selling point to cloud security cameras is
| to have a copy of the video not at the location. If your house
| / business is robbed or burns down you will possibly lose the
| video. This video could be used to find the theif or arsonist.
|
| Ideally it would store video locally, then encrypt it and
| upload the last minute to the cloud.
| brk wrote:
| The biggest selling point is really the OPEX sales model, and
| outsourcing of the general care-and-feeding of the
| recorders/servers. The tradeoff is that you tend to get
| lesser quality video and/or less scalability of the size of
| the system from bandwidth limitations.
|
| Theft of recorders/loss of recorded video is much much less
| of an issue than it is generally made out to be, and most
| systems have various means for auto backups, dual recording,
| etc. Many also have the ability to send select segments of
| video, based on motion or analytics, to cloud/FTP/email for
| free, which adds some extra resiliency if you are really
| worried about random arsonists :)
|
| (I work in the industry)
| ocdtrekkie wrote:
| I am still honestly confused by the whole "OpEx > CapEx"
| thing. Apparently for some people this is worth paying
| _over double_ the price when you look at things on an
| annualized basis, even for an established business that 's
| got a very stable environment?
| brk wrote:
| In short, yes it is.
|
| The concept of having a predictable recurring bill, and
| known costs can have a lot of value. In the opex hardware
| model, there is usually a hardware refresh built in (a
| lease of sorts) and also covered replacements for any
| failures before the refresh.
| ocdtrekkie wrote:
| > a predictable recurring bill
|
| This makes no sense to me, because almost no OpEx-based
| services operate on a predictable billing model. Usage
| based pricing means they are subject to change.
|
| If I buy a $5,000 server, and it lasts me five years, I
| can plan around needing $1,000 a year set aside to
| replace it. Meanwhile, my AWS bill can suddenly be
| $20,000 with no warning.
|
| The hardware refresh model you describe... I've actually
| only ever seen in a CapEx appliance, where paying for the
| support contract got you those refreshes regularly,
| replacement for failures, etc. but had an initial upfront
| purchase cost.
| HeyLaughingBoy wrote:
| Compare SaaS to COTS software: same thing, (somewhat)
| different industry.
| pdimitar wrote:
| > _(I work in the industry)_
|
| Ohhhh, you are so in trouble now! :P
|
| I am pondering moving to a rather remote estate with my
| wife but we're both city kids and have zero clue how to
| defend ourselves in such conditions (I am even thinking we
| should take shooting lessons and bring guns to the estate
| as well).
|
| Part of our plan is a surveillance system -- I planned to
| have an on-site ZFS storage cluster with several cameras
| that periodically encrypts the last 5 minutes and sends
| them off-site. Not sure how complex such a setup might turn
| out to be though... Maybe there's a way to make the storage
| cluster itself auto-replicate remotely often enough? I'm
| not that educated yet.
|
| Do you have any recommendations? I don't want to spend
| $5000 due to paranoia but I don't want to be defenseless in
| case of a robbery either. What's the middle ground?
| GrinningFool wrote:
| Would not a large dog suffice? They're more maintenance,
| but also come with other benefits.
| pdimitar wrote:
| Yep, we thought of buying two specially trained German
| shepherds (the kind of training that requires you to be
| there so the dog bonds with you and trusts nobody else).
|
| Still not sure about guns but the dogs would indeed be a
| very good investment.
| cacarr wrote:
| An Anatolian livestock guardian dog is a vastly superior
| natural guard dog, compared to a GSD. They can not be
| bribed with food, and they spend every second of their
| waking day looking for intruders to destroy. Very gentle
| with children and small dogs, though.
|
| Downsides include being extremely smart but not very
| trainable (smart like a wolf) -- they decide what's a
| threat and what isn't, and they don't care about your
| opinion. They guard naturally. Also, you may find
| yourself having to bury dead coyotes on occasion, as they
| will murder any that are stupid enough to intrude.
| pdimitar wrote:
| Very interesting, thanks a lot! I'll research more.
| d110af5ccf wrote:
| > specially trained
|
| I think you might be overthinking this. The dogs don't
| even need to be large. If the property is more than a few
| acres just get 2 or 3 herding dogs. They're upbeat,
| energetic, and above all very noisy if a stranger wanders
| into your yard. I very much doubt anyone will ever bother
| you.
|
| > Still not sure about guns
|
| How remote is it? What's the police response time? If
| it's really in the middle of nowhere then it seems like a
| good idea to have something on hand just in case.
| pdimitar wrote:
| > _How remote is it? What 's the police response time? If
| it's really in the middle of nowhere then it seems like a
| good idea to have something on hand just in case._
|
| Exactly because of that: remote and small country (Costa
| Rica is one idea so far), we would prefer a sea-side
| house which is NOT very close to a city (we think 20-30km
| away from a city is optimal) and we have no clue about
| police response time -- but I can't imagine they'll be
| there 2 minutes after I make a panicked call that I am
| tracking 3 armed burglars, especially if not in a city.
|
| > _I think you might be overthinking this._
|
| Very possible. Right now I don't even have the money for
| a down-payment, but me and my wife both share this dream
| and started brainstorming it and doing some preliminary
| planning.
|
| Above all, I really want the dogs to not be able to be
| bribed with food. Not a fan of dogs that bark at every
| single small disturbance but oh well, if that's the price
| you pay for living in a remote area and having good
| security then okay.
| d110af5ccf wrote:
| > Costa Rica is one idea so far
|
| Oh, I was imagining remote rural in the US or a similar
| country (Canada, Scandinavia, etc). I have absolutely no
| idea what public safety concerns might exist in less
| developed places.
|
| > want the dogs to not be able to be bribed with food
|
| It's more that a solid looking fence, a few dogs, and
| some visible security cameras are highly likely to deter
| any attempts in the first place. If someone is armed and
| willing to shoot your dogs then you have much larger
| problems to deal with (and probably don't want to be
| living there to begin with).
| omgJustTest wrote:
| Who are your enemies haha. "Don't want to spend 5k cause
| of paranoia but I'm planning on moving to a remote estate
| and... guns... and gun lessons.... cause I'm not
| paranoid"
| brk wrote:
| This isn't a short conversation, but you can contact me
| offline and I can give you some pointers.
| pdimitar wrote:
| Pinged you on twitter several hours ago, as I can't find
| any other accounts in your HN profile and don't want to
| stalk by looking you up online.
| lifeisstillgood wrote:
| Forgive me asking but which country do you live in.
|
| I often have debates with my wife about country vs city
| living, but I don't think buying a gun / attack dog / big
| security system ever comes into the equation. (UK based).
|
| Am I not paranoid enough, are you over paranoid? Is there
| a Bayesian equation we need here?
|
| Just to put up an alternative I just read this
| https://news.ycombinator.com/item?id=26411899
|
| The guy cycled through Europe and India, met some guy in
| a bar in Italy and ended up sleeping on his couch and
| eating home cooked Pasta lunch the next day. A different
| approach would be to drive with a gun under the seat. I
| think something is missing.
| pdimitar wrote:
| Me and my wife were thinking Costa Rica but got warned by
| an acquaintance that burglaries and home invasions in
| remote areas are a regular occurrence. And we want a sea-
| side house.
| 177tcca wrote:
| > Am I not paranoid enough
|
| Do you also forgo a fire extinguisher in your kitchen?
| cacarr wrote:
| > (UK based)
|
| Often what's "country" in the UK (outside of Scotland)
| would be considered exurban in the USA. You might
| possibly feel different about security at a truly remote
| home in N America.
| wcarron wrote:
| To be honest, the easiest way is to 1) Buy and install a
| bunch of ring cameras and 2) Buy and learn to use a
| Mossberg 500 with a 18" barrel. Maybe another gun, too.
| Total cost: Idk, $800-1800.
| bigbillheck wrote:
| Is it just me or does this seem kind of excessive?
| LinuxBender wrote:
| To me excessive would be automatic tracking turrets with
| really nasty things mounted on them. I recall someone
| made one that fits in a briefcase and uses paintballs. It
| had something like 90% accuracy on fast randomly moving
| targets. But for some people that might not be excessive,
| probably depends on the circumstances.
| at-fates-hands wrote:
| Reminds me of the hotel scene in the book "Altered
| Carbon". The Netflix series did a good job visually with
| this scene.
|
| https://www.youtube.com/watch?v=T6VaUPmaCcI
| LinuxBender wrote:
| That is a great show and I agree, that hotel is a perfect
| example. I really hope they keep the show going.
| pdimitar wrote:
| The area I want to move in is known for its heightened
| percent of home invasions and burglaries. So I don't
| know, maybe it is excessive. I just don't want my life
| savings to fall into the hands of a random burglar.
| Forbo wrote:
| Why keep your savings at home? For anything critical I
| use a safe deposit box.
| pdimitar wrote:
| My bad for using bad figure of speech. Of course most of
| my savings won't even be physical (bank / cryptocurrency
| / investments etc.) -- I meant that I'll have all my
| possessions there (expensive computers, TVs, furniture,
| kitchen tech, what have you) and I would like to avoid
| having them stolen while I am grocery shopping in the
| nearest city, you know.
| nielsbot wrote:
| Also, convenience: Buy this camera, get access to recordings
| anywhere over the internet with nearly zero setup time.
|
| If you have an on-site system (like I do) it's way more
| effort for the average consumer.
| andrewprock wrote:
| That's not security, that's voyeurism
| vincnetas wrote:
| Was also thinking the same. Security cameras should be
| used where there is an incident and additional
| information is needed to clarify what happened. Then you
| check the security camera footage to figure out what
| happened. If there were no incidents there is not
| reasonable need for anyone to look at that footage.
|
| edit: not talking here about active monitoring security
| cameras used by guards.
| ma2rten wrote:
| Another one is that you can run machine learning on it. For
| example to automatically detect unusual activity.
| ocdtrekkie wrote:
| You can absolutely run machine learning on-premise
| hardware.
| ocdtrekkie wrote:
| Plausibly, yes, though again, large enterprises should be
| able to handle this internally, especially some of the listed
| customers here.
| AmericanChopper wrote:
| I work in a large enterprise. If my employer were to decide
| to exclusively store security footage on our own
| infrastructure, then I would have access to every piece of
| hardware it's stored on. The risks associated with that is
| why every piece of mission critical data where I work is,
| at a minimum, backed up in a 3rd party facility.
| zerkten wrote:
| There are plenty of use cases, such as the various forms of
| analysis with ML, which are often only implemented outside
| the "company firewall" (this idea is antiquated.) Of
| course, this could and should be handled inside a trusted
| boundary (I can't think of a better term for today's
| networks), but in practice security here is fairly immature
| and people try things when there isn't good governance in
| place.
| TeMPOraL wrote:
| This sounds like general problem of enterprise security.
| There are no consequences.
|
| I can entirely get why a company would outsource IP
| cameras to a third party cloud, even with storing data
| on-site. Business runs on contracts. It's entirely normal
| to contract out everything except your core competencies,
| if it's cheaper this way. It's how you turn CAPEX,
| complex OPEX and high risk into simple OPEX and low risk.
| A contract is in big part a risk shifting tool. This
| works well in practice... outside IT.
|
| The problem is, with IT and data, there's a mismatch
| between expectations and reality. An enterprise _should_
| feel safe buying their video surveillance from Verkada,
| because between the contract and the legal framework,
| Verkada should be bankrupt now, and their management
| possibly facing jail time. That 's the part where
| contracts work as Cover-Your-Ass tool: if you shift risk
| and liability to outside party, the liability is not on
| you.
|
| However, this only works as long as the other party
| actually internalizes the risk and liability. Since there
| are no consequences for mishandling data, operating IT
| services you're not structurally competent to operate,
| and eventually having your crown jewels stolen - the
| contractor doesn't really internalize risk, has no
| incentive to mitigate it.
|
| All this to say: Verkada should go down after this, and
| their customers should be named and shamed widely - the
| latter is so that future customers of IT services put
| more care into vetting companies they contract IT out to.
| You shouldn't get to CYA with a contract where
| assumptions around contracting are broken.
| spoonjim wrote:
| Putting the surveillance video on-site is... kinda dumb. If
| someone breaches your facility and wants to take the evidence
| of them doing so, they just have to steal the video storage.
|
| Cloud security footage makes sure that you have at least the
| footage up until they disable your network.
| mike_d wrote:
| > It's rarely viewed outside your network
|
| The majority of real camera systems (100+ cameras, 10+
| locations) I have interacted with are monitored by outside
| vendors.
| figassis wrote:
| "Our internal security team and external security firm are
| investigating the scale and scope of this potential issue."
|
| Potential issue? Your house is on fire. When will these
| businesses just be straight rather than PR everything?
| heracles wrote:
| Nothing on blog or "What's new" either, just corporate
| newspeak.
| atum47 wrote:
| Back in college I was studying security and eventually I found
| out about shodan. I mean, when people don't even care to put
| passwords on their connected to the internet device, can you even
| call it hacking?
| atum47 wrote:
| Meaning no disrespect to the people who find the user and pass,
| but criticizing people who don't set passwords or leave the
| default ones
| Teknoman117 wrote:
| Are there any companies actually pushing a security-first IoT
| model?
| gostsamo wrote:
| In my experience - no. I've seen devices sold for thousands of
| dollars whose login screen could be bypassed with a magic
| cookie. Here and there you will find a device that will force
| you to change the default password upon activation, but this is
| as far as it goes and the cheaper models from the same vendor
| will be as shitty as anybody else's.
|
| The best that you can hope in consumer devices is something
| like Apple, Google or Amazon, because they can afford the
| support costs, but it comes at the price of privacy and
| funneling your money in many other ways. Enterprise stuff could
| be found, but you can never trust just the brand for every
| model.
|
| Edit: grammar.
| rickspencer3 wrote:
| Forget where I read it, but it always makes me laugh:
|
| The "S" in IoT stands for "Security"
| jrochkind1 wrote:
| This is the important part. NOT that their network was not
| secured, but that anyone with a super-user account can simply
| view archived and live video feeds of any of their customers????
|
| > The hackers' methods were unsophisticated: they gained access
| to Verkada through a "Super Admin" account, allowing them to peer
| into the cameras of all of its customers. Kottmann says they
| found a user name and password for an administrator account
| publicly exposed on the internet.
| heracles wrote:
| This really struck me also. I work in the relevant industry (we
| make cameras etc.) and there is always a bit of pain to get
| user footage. This is how it should be! To have everything from
| source code to customer material accessible to an admin is
| bottom-tier thinking. Why not just rename your "admin" to "GOD"
| and then ask yourself if you have any single point of failure?!
|
| I do NOT want to sound smug, but there is a little bit of
| amateur hour going on here both from buyer and seller. High
| value and large targets (like airports) and more established
| sellers usually don't work like this, and that's for a reason.
| jrochkind1 wrote:
| It's not just that it's a single point of failure, it's that
| as a customer I do not want any admin who is feeling curious
| to be able to snoop on my footage with a click.
|
| I don't know how "established" this company is, but their
| customers appear to include city governments, hospitals, and
| Tesla motors, which I would consider "high value and large
| targets".
|
| Makes me suspicious of the whole industry. If others in the
| industry dont' want that, time for some industry codes and
| audits and self-regulation.
| tyfon wrote:
| This would be illegal on so many levels in my country.
|
| It is also not compliant with GDPR but I suspect these are not
| selling in Europe.
|
| But this is in line with the general idea that anything you put
| online in some form will be public at some point. Internet Of
| Things to be hacked.
| floatingatoll wrote:
| Is that HIPAA-compliant? (Not sarcasm: I don't know HIPAA rules
| enough to assess myself in the cloud-vendor / medical-
| institution scenarios we're seeing here.)
| tanseydavid wrote:
| I cannot wait until the whole world is run by machines that do
| not work very well. </sarc>
| DoofusOfDeath wrote:
| In the U.S. legal system, is video footage exposed in this manner
| admissible in court?
|
| E.g., if a prison inmate was physically abused by staff, and his
| only corroborating evidence would be this video footage, can it
| be used to justify a civil or criminal complaint?
| dylan604 wrote:
| IANAL, but from all of the cop shows on TV, if the lawyer was
| provided the evidence and did not break laws themself OR as
| long as the lawyer did not entice someone else to commit the
| offense or provide instructions on what to do, then typically
| the judge allows the evidence.
| ocdtrekkie wrote:
| I think so? Law enforcement can't break into something without
| a warrant, but if someone brings them evidence of wrongdoing
| (especially a third party who didn't conduct the hack
| themselves), I believe they can act on it.
| skybrian wrote:
| It seems like someone would have to testify that it's
| authentic? Who is going to do that?
| dylan604 wrote:
| The guy receiving the beating?
| ocdtrekkie wrote:
| Under oath, presumably you compel the people in the
| footage. But I would imagine that the footage of
| questionable sourcing might count as the probable cause to
| go in and get the footage directly via warrant?
|
| I am not a lawyer.
| throwanem wrote:
| Whoever at Verkada gets subpoenaed by the inmate's counsel
| to do so, I'd assume. That said, I'm no more a lawyer than
| anyone else who's commented here so far.
| swiley wrote:
| To the surprise of _absolutely no one_ closed IP cameras that
| rely on a manufacturer run internet service are not secure.
|
| Consumer electronics really suck, I wish there was an alternative
| to the DIY approach of Linux SBCs with rsync over ssh.
| jtchang wrote:
| I'm making it -- https://github.com/openmiko/openmiko if you
| want to help!
| dylan604 wrote:
| Each of these security camera system/IoT companies are only
| offering you a bit of hardware to interact with their true
| purpose of making you a user of their SaaS product.
| bombcar wrote:
| Get cheap-ass wired camera (even PoE).
|
| Isolate the network they are on behind a Linux box that cannot
| route.
|
| Record on the box, display from another hardware port.
|
| Wrap all the above behind another firewall.
|
| Make it all IPv6 only.
| totony wrote:
| why ipv6?
| IncRnd wrote:
| Presumably for the larger address space that is more
| resistant to scans.
| SilverRed wrote:
| Its interesting that you can and people have scanned the
| entire ipv4 space in minutes on a fast VPS but it would
| take you forever to find your first ipv6 address that is
| even in use.
| lytfyre wrote:
| Shodan - a search tool for such things - had a pretty
| incredible approach to attacking this - they quietly
| provided most of the ipv6 hosts to pool.ntp.org, which is
| widely used as a linux default - and would queue a
| portscan up for any device that connected at startup for
| timesync.
|
| https://arstechnica.com/information-
| technology/2016/02/using...
| bombcar wrote:
| Ingenious - and all the more reason to run NTP on the
| border router/firewall and have that be the only device
| that communicates with the outside world.
| waz0wski wrote:
| Here's one project based on RPi & HomeKit integration -
| https://github.com/brutella/hkcam
| g00gler wrote:
| D-Link sells cameras that don't have cloud access. Look up a
| DCS-913L. I bought one on eBay around a year ago. It has wifi
| and you can set it up to record over SMB.
|
| It's not the best image quality but if you get another router,
| a raspberry pi and a large external HDD you can have a
| relatively cheap CCTV set up.
| judge2020 wrote:
| Dupe of https://news.ycombinator.com/item?id=26404799
| [deleted]
| rossdavidh wrote:
| Well, that looks bad. Thank goodness, though, that after a
| security lapse this awful, corporate and government bureaucracies
| will come to their senses and stop outsourcing critical functions
| to cloud companies they don't know all that much about. Oh,
| wait...
| modzu wrote:
| anyone else doing this in 1995??
| mavhc wrote:
| Why would anyone ever send their unencrypted cctv footage to a
| 3rd party?
| mensetmanusman wrote:
| This is amazing. If they would have added software to the cameras
| to mine bitcoin, it would've been absolute peak cyber punk.
|
| People that sell video cameras attached to the Internet should
| always have a disclaimer that the user should assume that the
| system will probably be accessible by anyone at some point in the
| future.
|
| I believe Samsung started doing this with their TVs in regards to
| audio.
|
| We are certainly building ourselves an interesting future.
| mcv wrote:
| > peak cyber punk.
|
| I'm running a Shadowrun campaign where the hacker of the group
| frequently hacks security cameras. But it's always just a
| single camera close to where he is. Clearly it would be more
| realistic if he hacked all cameras of a single company all over
| the world simultaneously.
|
| I'm going to stick with my current game balance, though.
| dylan604 wrote:
| Mining on a SoC that fits in a security camera must be the
| definition of futile. How in the world does one of these ever
| "win" to earn?
| jffry wrote:
| They could mine for a mining pool
| rtrdea wrote:
| Could maybe mine Monero
| TeMPOraL wrote:
| Distributed computing. Customer's electricity is free for
| you, so whatever you manage to mine, is pure profit (and
| invisible to IRS if you're clever). Making this work would
| also be an interesting Big Data Hyper Edge Cloud Computing
| project to keep the engineers occupied and further justify
| the need for the money they got from investors.
| belval wrote:
| Except there are no coins that could be mined with a camera
| CPU. Even with Monero (which is CPU based) you will not
| meet the RAM requirements or clock-in a "share" of work in
| any useful timespan.
|
| You statement is true in the wider sense, you can have
| mining botnets of computers and maybe some high-end phones,
| but IP cameras are really-really weak as far as compute
| power go.
| goliatone wrote:
| You're right, partially. In the sense that to mine
| bitcoin/etc you need something more powerful... but you
| could just create a new type of crypto to be mined
| specifically in low power/IoT devices. Something like [1]
|
| [1]https://www.helium.com
| dylan604 wrote:
| How does something that works on low pwered systems not
| get devoured by larger systems currently mining other
| coins?
| belval wrote:
| Not familiar with Helium, but it seems to be PoS more
| than PoW (at least for the IoT device part) so I guess
| that could work.
| TeMPOraL wrote:
| Depends on what hardware they put in their cameras? I
| assume they aren't just using random IP cams, but
| deploying their own design? They could sneak in a
| cryptocoin ASIC for good measure.
|
| Of course they most likely aren't doing that, but it's
| not out of the realm of possibility (and thus a missed
| opportunity to make this debacle peak cyberpunk).
| starky wrote:
| Most security cameras are PoE powered which gets you a
| whopping 13W of power that also has to run a sensor, IR
| LEDs, heaters, lens, RAM, etc. before you even choose the
| SoC and potentially your ASIC. How much computing power
| do you really think you can get with that?
| TeMPOraL wrote:
| > _a whopping 13W of power_
|
| So comparable to a smartphone under load. That's a pretty
| good power budget, given that most of the components you
| mentioned (except RAM/SoC) are going to be operated
| intermittently.
|
| > _sensor_
|
| Serious question: you mean image post-processing and
| encoding here? I thought CMOS sensors themselves have
| negligible power demands?
|
| > _heaters_
|
| A crypto miner is just that - an overcomplicated heater.
| If you include one, you don't need the other.
|
| > _How much computing power do you really think you can
| get with that?_
|
| Not much, though an ASIC would get a nice multiplier on
| it. I'd guesstimate it to be comparable to a cryptominer
| running in the browser of an unsuspecting regular person
| - who will typically have a cheap, underpowered machine
| that can barely lift the OS and the browser without
| hanging. In recent years, at least some people thought
| you can make a profit with it, because we've seen such
| web cryptominers deployed around the web.
|
| My point isn't that it's happening - I fully expect the
| cost of sourcing a miner ASIC and redesigning a camera
| around it to be much larger than the mining it would
| bring in any reasonable timeframe. But I think that on
| first look, it's _possible_ , if someone tried hard
| enough, to build a sneaky security camera like this, that
| would be able to eventually yield some profit if deployed
| wide enough.
| belval wrote:
| If they can do god tier supply chain attack, dissipate
| the heat from mining hardware, add 4GB of RAM and put it
| in a form-factor that looks reasonable for a camera while
| still turning a profit, they can dedicate their genius to
| legitimate business ventures instead.
| TeMPOraL wrote:
| It's not a "god tier supply chain attack" if you own the
| blueprints and put the ASIC and a heatsink on them on
| purpose.
| dylan604 wrote:
| Now that would be funny. However, would this not be
| fairly obvious to one of those sites doing tear downs?
| Then again, if found, would the PR one of those tear down
| sites could generate slow the sales down enough to make
| it a losing prospect for the manufacturer?
|
| Non-techy people are willing to look so so far the other
| way in trade of convenience. Showing them "facts" about
| how much electricity their cameras are using would not
| impact the vast majority of the users if they feel like
| the service they are receiving is good enough.
| downrightmike wrote:
| having a crypto asic in any product would be sold as a
| way to lower costs to consumers and would be deemed ok.
| dylan604 wrote:
| now that you put it like that, I'm surprised the
| selection of "smart" TVs, cable boxes, provider wifi
| boxes, etc are not doing that already.
| TeMPOraL wrote:
| Do we know that they don't? A dedicated ASIC would
| probably be spotted by some random person doing a
| teardown. But a DSP chip doubling as crypto miner when
| not in use, that could easily escape post-purchase
| hardware inspection.
|
| (Might be easier to discover it on the
| design/procurement/supply chain side. Perhaps stock
| players would find out when investigating their
| investments. A high-profile brand putting crypto miners
| on consumer hardware is newsworthy, and news move stocks,
| so there's incentive to leak the story.)
| tracedddd wrote:
| This isn't true, you could still mine (poorly) with
| reduced RAM by recomputing as needed. And I'm not sure
| what you mean by "clocking-in" a share in a useful
| timespan. Compromised devices aren't people, so they
| don't care if a particular machine can't get regular
| payouts. If the whole network can reliably find a low
| diff share solutions anywhere it can make money.
|
| It would be horribly inefficient however a network of
| tens or hundreds of thousands of low resource units can
| absolutely make money since the costs are zero.
| belval wrote:
| To run argon2 (monero) you would need a significant
| amount of time to compute even one hash that means that
| the synchronization overhead of your workers would trump
| any "hashing speed" an IP camera (even a good 4K one)
| would have. By the time you get any amount of work done,
| the block will be processed by a regular miner and you
| will not get a payout. Same goes for a pool, doing any
| "share" of work would take too long and you would be out
| of sync. Hell given a bad enough ping I get refused
| shares on a Ryzen 3800X.
|
| Also on top of all of that most IP cameras are designed
| with tightly defined specs. Trying to run a miner on them
| would absolutely requires stopping the video feed which
| would make the "attack" (which is still useless) easy to
| detect.
| ghayes wrote:
| You could run a SHA256 hash of random values and send it
| to a database in hopes of mining a Bitcoin block with it
| one day when the input (block hash) happens to match.
| It's only 2^256 times less efficient than standard mining
| techniques.
| deft wrote:
| monero mining botnets have been doing this for years. Every
| penny counts, as long as the SoC doesn't overheat and melt
| its a trickle faucet forever
| vanillax wrote:
| This is why I self host all my cameras.
| https://mitchross09.medium.com/how-i-self-host-my-own-sites-...
| SilverRed wrote:
| The sad part is the majority doesn't know how and why they
| should do this. They just get their personal lives broadcast to
| the web for all to see. There was or at least used to be a
| subreddit showing the more interesting exposed cams.
| antihero wrote:
| How likely is it that for someone who isn't technically as
| adept as a team at a (good) cloud NVR provider, the security is
| actually worse? Bit like rolling your own crypto.
| waz0wski wrote:
| Verkada set the bar awfully low:
|
| > The hackers gained access to Verkada through a "Super
| Admin" account, allowing them to peer into the cameras of all
| of its customers. They found the user name and password of
| the account publicly exposed on the internet
|
| Don't put your personal stuff directly on the internet, use
| separate admin accounts with 2FA, gg, you're doing better
| than Verkada - comically valued at $1.6B
| NiceWayToDoIT wrote:
| From some reason, all I am wondering is how huge is potential for
| industrial espionage this way?
| pmlnr wrote:
| And when you try to describe the problem with cloud connected
| "security" devices to your non techie neighbour, all you get is a
| "whaaa...?" expression.
___________________________________________________________________
(page generated 2021-03-10 23:02 UTC)