Category: IT|Dec 4, 2022 | Author: Admin

Cameras sold in Norway are a security disaster

Share on

"Server error" allowed Eufy owners to see into each other's homes,"

Such poor security that it is hard to fathom
At the time, customers of Anker's "security cameras" explained that they "could see every single camera, front door, back door, bedroom, living room, garage, kitchen, their recording started by motion, everything."

 

Furthermore, we reported that "Eufy has stated to Android Police that the error lasted for an hour and that it did not affect their baby-call products. On Reddit, a message is shared that should have been sent from Eufy to their customers.”

 

There should also be problems with content that should not be shared with the cloud being shared with the cloud regardless of whether the function is not activated - the security key should also be out of the way (Paul Moore has sued Anker):

 

 

Videos from Eufy cameras are not even encrypted
Now it is the winter of 2022 and the problem is not fixed but is so much worse than anyone could have imagined. According to The Verge, even the company has lied to them and said that what is happening now is not technically possible.

 

So what is happening now? Yes, it is possible via a hack to connect to any Anker Eufy camera via video apps such as VLC - that's right; there is no encryption of the video stream, despite Anker's advertising:

 

 

Supposedly lied to The Verge
The problems continue for Anker, for The Verge asked the company, which is mainly known for chargers if it is actually true that you can video stream other people's security cameras with VLC because nothing is encrypted. The advantage is that sleeping cameras will not be woken if you try.

 

“I can confirm that it is not possible to start a stream and watch live video with a third-party player like VLC,” Brett White explained to The Verge.

 

The newspaper can now confirm that this is not true:

 

This week we repeatedly watched live footage from two of our own Eufy cameras using the same VLC media player from across the US. It proves that Anker has a way to bypass encryption and access these supposedly secure cameras through the cloud.

 

“But it gets worse”
According to The Verge, it has not been proven that malicious actors have tried the trick before, which includes logging in with a username and password "before Eufy's website hosts the encryption-free stream."

 

Okay, that's good. It's also good that the cameras have to be active to peek, but there is an even bigger problem that follows this:

 

“Eufy's best practices appear to be so poor that malicious actors may be able to figure out the address of a camera stream. This is because the address largely consists of the camera's serial number coded in Base64, which you can easily reverse with a simple online calculator."

Sources: The Verge

Sponsored Ads:

Comments:


Google has a hidden collection of highly-addictive retro games

Category: Google|Apr 28, 2024 | Author: Admin

Google is officially a $2 trillion company

Category: Google|Apr 27, 2024 | Author: Admin

Snowden: “DO NOT use Reddit!”

Category: IT|Apr 26, 2024 | Author: Admin

Popular Google app used by millions set to close in a few weeks

Category: Google|Apr 25, 2024 | Author: Admin

Cheeky, YouTube!

Category: Google|Apr 24, 2024 | Author: Admin

This is the date Apple will reveal new iPads

Category: Apple|Apr 23, 2024 | Author: Admin

Only possible with VPN

Category: IT|Apr 22, 2024 | Author: Admin

Apple sidles into sideloading in the EU

Category: Apple|Apr 21, 2024 | Author: Admin

Report: Microsoft-OpenAI ownership might get conditional OK from EU regulators

Category: IT|Apr 20, 2024 | Author: Admin

Giant change at Google could change everything

Category: Google|Apr 19, 2024 | Author: Admin

Now Windows will be bothered about this too

Category: Microsoft|Apr 18, 2024 | Author: Admin

Test the new AI trick with Logitech

Category: IT|Apr 17, 2024 | Author: Admin

The US Government Has a Microsoft Problem

Category: Microsoft|Apr 16, 2024 | Author: Admin

Now comes the commercial

Category: Microsoft|Apr 15, 2024 | Author: Admin

Linux Foundation is leading fight against fauxpen source

Category: IT|Apr 14, 2024 | Author: Admin
more