Security Researchers Find Several Bugs in Nest Security Cameras

PoohPooh Member Posts: 675 ✭✭✭✭✭
edited August 23 in Devices & Security

Yet again we find how easy it is to circumnavigate IoT security: this time it's Google's own Nest Cam IQ camera's.


Researchers found eight vulnerabilities in these cameras that Google said have been fixed in the current available firmware.


Whilst kudos some be given for getting the issues fixed, it's scary how much privacy we are giving up.


Do you know who's watching you through your cameras?



People say nothing is impossible, but I do nothing every day.
Tagged:
VioletChepil

Comments

  • VioletChepilVioletChepil London, UKAdministrator Posts: 2,018 admin

    Community Manager at Fing

  • adamadam Member Posts: 48 ✭✭✭

    Nearly all these kinds of attack are directly at the camera (as apposed to via the cloud portal that manages it) which means that to be vulnerable the camera has to be exposed on the Internet. Normally a vpn on a home network with no other ports open on the router can stop such issues.

    VioletChepil
  • PoohPooh Member Posts: 675 ✭✭✭✭✭
    edited August 23
    I wish that were true, but we've had copious situations where routers have been exposed to allow ingress, other IoT devices that allow backwards traversal, WiFi networks using easy to crack WEP keys or even WPA2 (now that's been shown to be compromised), malware on PC's open up tunnels etc. Heck, there's now even a Lightening cable you can buy that, when connected to an iOS device, will allow remote connectivity - a cable!

    So, whilst these vulnerabilities may be local to the network, it's still a serious risk because it's THAT easy for hackers to get inside your average home network with a proliferation of badly written 'thing' firmware and lazy users.

    Way way way too many folk have horribly insecure networks which makes these things relatively easy to exploit.
    People say nothing is impossible, but I do nothing every day.
    VioletChepil
  • MarcMarc Member Posts: 405 ✭✭✭✭
    I can’t stress this enough when it comes to home routers, keep the firmware updated to the latest and use a strong password for the admin account. No router is completely secure but these two steps go along way.  
    Thats Daphnee, she's a good dog...
    PoohVioletChepil
  • kltaylorkltaylor Member Posts: 546 ✭✭✭✭✭
    Pooh said:

    Yet again we find how easy it is to circumnavigate IoT security: this time it's Google's own Nest Cam IQ camera's.


    Researchers found eight vulnerabilities in these cameras that Google said have been fixed in the current available firmware.


    Whilst kudos some be given for getting the issues fixed, it's scary how much privacy we are giving up.


    Do you know who's watching you through your cameras?



    I've considered Nest cameras, but through research on issues like this, I've stayed away from them for now.
    The fact is that nearly any camera that could be used in a consumer or professional environment can be hacked, or have vulnerabilities in a firmware update that was recently pushed out.
    I expect more from Google, though ... how could independent researchers find the things that Google's own QA process should have discovered.
    Nonetheless, those individuals that want more security for their investment in a lot of cases, either forget to secure access to those tools or simply don't know how to.
    This is why a device like Fing is important for home automation and monitoring.  Bad guys need to first obtain access to the network before they can view your cameras.  If you don't know how to secure your network and access pathways, seek a geek!
    "There's a fine line between audacity and idiocy."
    -Warden Anastasia Luccio, Captain
    HronosVioletChepil
  • Lee_BoLee_Bo Member Posts: 98 ✭✭✭
    I don't think it matters WHAT product you use, if someone wants to hack into it, they will.
    VioletChepil
  • PoohPooh Member Posts: 675 ✭✭✭✭✭
    edited August 27
    @Lee_Bo whilst true, there are some items that do apparently make it horribly easy for any script kiddie armed with tools such as Metasploit and access to Shodan to break into folks networks...
    People say nothing is impossible, but I do nothing every day.
    VioletChepil
  • TheCustomCaveTheCustomCave Member Posts: 47 ✭✭✭
    As with all of these things it's a numbers vs. knowledge thing. The more you know about it, the more you can prevent it. For the numbers, statistics would generally tend toward the average punter not being in any real danger. Yes, a hacker could want to access accounts, but as these are mostly directly at the device, they'd generally want/need a reason to target you specifically.

    I generally take the view of keeping everything up to date, firmware, software etc. Nothing is every truly secure, especially in this day and age - but you take the same choice with things like having a Facebook or Google account. The average hacker isn't too interested in looking at what Joe Bloggs is doing, but while the vulnerability is present in the hardware they may target someone higher profile specifically.
    VioletChepil
Sign In or Register to comment.