Open Menu
AllLocalCommunitiesAbout
lotide
AllLocalCommunitiesAbout
Login

40,000 Security Cameras Found Compromised Online.

⁨154⁩ ⁨likes⁩

Submitted ⁨⁨5⁩ ⁨days⁩ ago⁩ by ⁨Pro@programming.dev⁩ to ⁨technology@lemmy.world⁩

https://www.bitsight.com/blog/bitsight-identifies-thousands-of-compromised-security-cameras

source

Comments

Sort:hotnewtop
  • hansolo@lemmy.today ⁨5⁩ ⁨days⁩ ago

    Shodan.io is the searchable index of open IoT devices.

    Change the default password, people!

    source
    • dan@upvote.au ⁨5⁩ ⁨days⁩ ago

      Hard-coded default passwords have been illegal in California since 2020, so it shouldn’t be as much of an issue with newer devices. Companies aren’t going to make California-specific versions of their devices, so they’ll follow the standards everywhere.

      To be legal in California, the device either needs to have a randomly-generated password unique to that device (can be listed on a sticker on the bottom of the device, or in the manual), or it needs to prompt to set a password the first time you use it.

      source
      • hansolo@lemmy.today ⁨5⁩ ⁨days⁩ ago

        Yes, but no one checks the legality of cheap Chinese devices from Amazon.

        source
        • -> View More Comments
      • Creat@discuss.tchncs.de ⁨5⁩ ⁨days⁩ ago

        Can’t remember when it came into effect, but randomized device specific passwords are also mandatory in the EU now. This was relatively recently though. It means they single device (item, not model type or class) has to have an individual password (also usually it’s on a sticker or something).

        And yes, connecting any ip camera to the Internet is just dumb.

        source
  • Ensign_Crab@lemmy.world ⁨5⁩ ⁨days⁩ ago

    40k? Impressive resolution.

    source
    • Tangent5280@lemmy.world ⁨4⁩ ⁨days⁩ ago

      For the Emperor!

      source
  • vane@lemmy.world ⁨5⁩ ⁨days⁩ ago

    Those cameras are there since 90s I remember watching them in ActiveX in real media player plugin in IE. Nothing changed.

    source
  • Emptiness@lemmy.world ⁨5⁩ ⁨days⁩ ago

    40K?

    Praise the Omnissaiah!

    source
  • Zarxrax@lemmy.world ⁨5⁩ ⁨days⁩ ago

    It would be nice to know what brands or models are most vulnerable.

    source
    • priapus@piefed.social ⁨5⁩ ⁨days⁩ ago

      What this is talking about is not really about the brand or model, its just about them being misconfigured. These cameras were exposed to the internet with either default credentials or no authentication.

      Theres very few good reasons to expose a camera to the internet at all, but if you need to, put some proper authentication in front of it.

      source
      • cmnybo@discuss.tchncs.de ⁨5⁩ ⁨days⁩ ago

        An IP camera may stay in use for a decade or more without any firmware updates. You shouldn’t trust any sort of authentication that’s built into the camera to be secure. Keep them on an isolated LAN and only allow access from the server that’s running the DVR software.

        source
    • dan@upvote.au ⁨5⁩ ⁨days⁩ ago

      Any camera you expose to the internet with no protection is vulnerable.

      Follow best practices by keeping your cameras on a separate VLAN that’s isolated from the internet, and you’ll be fine. Use a VPN like Tailscale to view your cameras while away.

      source
  • dan@upvote.au ⁨5⁩ ⁨days⁩ ago

    There’s a site that lists all the insecure cameras: www.insecam.org

    source
  • Zenlix@lemmy.ml ⁨5⁩ ⁨days⁩ ago

    Even when they are protected, when did they receive the last update? There are probably so much more vulnerable IoT devices.

    source