If you have home security cameras, assume that shyt is hacked :scust:

Geek Nasty

Brain Knowledgeably Whizzy
Supporter
Joined
Jan 30, 2015
Messages
31,987
Reputation
5,750
Daps
121,442
Reppin
South Kakalaka
Talked to this Asian dude at work, didn't say outright but implied Chinese have hacked all these systems. I'm setting up cameras around my house, a few security red flags had me :usure:

* The web interfaces seem to always be plain HTTP. So, if you're using 3rd party apps to access your home network, that shyt is all plain text communications; including your password. I did some research trying to find a camera system, and a lot of them have unsecured HTTP interfaces to the NVRs. Hmmmm...
* Their support team wants remote access to your PC every time you contact them
* I've got a Lorex system, looked up online how their app works. Called "Easy Viewer", a third party app written by a Chinese guy. People complaining in comments every time they use the app their home security gets hacked. Hmmmm...
* One of the EULA stipulations was agreeing to allow your camera footage to be streamed overseas if you opt in for cloud storage. Makes ZERO sense sending all that content to server banks overseas unless they have a good reason.

Working on locking mind down so all it can do is talk to the cameras or Lorex. Pisses me off too because if this is legit, this should be well reported by US intelligence services.
 

xXMASHERXx

Superstar
Joined
May 15, 2012
Messages
9,945
Reputation
1,750
Daps
36,624
Talked to this Asian dude at work, didn't say outright but implied Chinese have hacked all these systems. I'm setting up cameras around my house, a few security red flags had me :usure:

* The web interfaces seem to always be plain HTTP. So, if you're using 3rd party apps to access your home network, that shyt is all plain text communications; including your password. I did some research trying to find a camera system, and a lot of them have unsecured HTTP interfaces to the NVRs. Hmmmm...
* Their support team wants remote access to your PC every time you contact them
* I've got a Lorex system, looked up online how their app works. Called "Easy Viewer", a third party app written by a Chinese guy. People complaining in comments every time they use the app their home security gets hacked. Hmmmm...

Working on locking mind down so all it can do is talk to the cameras or Lorex. Pisses me off too because if this is legit, this should be well reported by US intelligence services.
US knows and probably does the same thing. Is it not possible to put the camera system behind a firewall and only allow traffic from the inside to it?
 

Geek Nasty

Brain Knowledgeably Whizzy
Supporter
Joined
Jan 30, 2015
Messages
31,987
Reputation
5,750
Daps
121,442
Reppin
South Kakalaka
US knows and probably does the same thing. Is it not possible to put the camera system behind a firewall and only allow traffic from the inside to it?

Yeah you can add any kinds of restrictions you want, but I only know how to do this at a low level. I don't know if typical wifi routers give you this level of setup.
 

Geek Nasty

Brain Knowledgeably Whizzy
Supporter
Joined
Jan 30, 2015
Messages
31,987
Reputation
5,750
Daps
121,442
Reppin
South Kakalaka
Any way to get around this? Or any brands you recommend?

I'm not security guy so I don't know. Even if I lock the camera system down to just communicating with Lorex, the system itself could be corrupt. Maybe someone else with security cred would know.

Lorex is Canadian which is what trips me out. You'd think they'd be safer.
 

xXMASHERXx

Superstar
Joined
May 15, 2012
Messages
9,945
Reputation
1,750
Daps
36,624
Not sure what kind of router you have but most home router you have but it should have some type of firewall or acl. You should be able to enter the ip addresses of the cameras into a list and then block all traffic outside the local network on those ips. This is one of the reason why I don't like any kind of smart devices around my living area.
 

Dorian Breh

Veteran
Joined
Jan 14, 2016
Messages
23,440
Reputation
14,099
Daps
115,125
I think you would sort of need to do it yourself using raspberry pi and open source softwares (with encryption key obviously) to get around these vulnerabilities

If any 6cert breh wanna come thru with a walk thru you can hold these reps
 

O.T.I.S.

Veteran
Joined
Sep 15, 2013
Messages
85,292
Reputation
18,515
Daps
328,571
Reppin
The Truth
Well honestly, this could be any device especially if you’re going with some cheap, off the wall, no name brand device that you connect to your computer systems.

They have phone charging cables with malicious software or rogue ap’s on then that could hack into your computer.
 

peppe

Superstar
Joined
Jan 7, 2015
Messages
9,224
Reputation
3,747
Daps
41,070
If your working with http instead of httpS then its your own fault.
 
Top