{"id":4317,"date":"2014-11-21T11:00:38","date_gmt":"2014-11-21T16:00:38","guid":{"rendered":"http:\/\/me-en.kaspersky.com\/blog\/?p=4317"},"modified":"2020-02-26T18:59:19","modified_gmt":"2020-02-26T14:59:19","slug":"massive-webcam-breach","status":"publish","type":"post","link":"https:\/\/me-en.kaspersky.com\/blog\/massive-webcam-breach\/4317\/","title":{"rendered":"Who is to blame for &#8220;hacked&#8221; private cameras?"},"content":{"rendered":"<p>Recent news about \u201chacked webcams,\u201d \u201cbreached baby monitors\u201d and even a \u201cRussian website monitoring British citizens appears to be <a href=\"http:\/\/www.bbc.com\/news\/technology-30121159\" target=\"_blank\" rel=\"noopener nofollow\">all<\/a> <a href=\"http:\/\/edition.cnn.com\/2014\/11\/20\/world\/europe\/uk-web-cam-hacking-explainer\/index.html?hpt=hp_t4\" target=\"_blank\" rel=\"noopener nofollow\">over<\/a> the <a href=\"http:\/\/www.businessinsider.com\/russia-hacked-webcam-scandal-2014-11\" target=\"_blank\" rel=\"noopener nofollow\">place<\/a>. Judging by comments from all of the affected parties, the situation is indeed serious. Why is that?<\/p>\n<p><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/37\/2014\/11\/05111741\/eye_SQ-1.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-6835\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/37\/2014\/11\/05111741\/eye_SQ-1.png\" alt=\"eye_SQ\" width=\"800\" height=\"800\"><\/a><\/p>\n<p>For starters, everyone from users to officials and webcam manufacturers is blaming each other instead of trying to find a solution to the problem. Ultimately, one major take away from this story is that if you own a device that is connected to the Internet, you should certainly follow security news. Otherwise, your private life may, at some point, surface online and you won\u2019t even know about it.<\/p>\n<h3>So what happened?<\/h3>\n<p>Say you buy a webcam. Not a common one with a USB port that plugs into your computer, but a fancy wireless camera that streams video and allows you to observe your baby, your car in a garage or a sidewalk near your home, from another room, another town or even another country. You plug it in, follow the simple steps outlined in that \u201cQuick launch\u201d leaflet and it works just like that! It is a brilliant piece of technology and a true example of the modern digital world.<\/p>\n<p>Not exactly. The problem lies in the \u201cit works just like that\u201d part. As it turns out, many users, satisfied solely by the fact that the device was operational, did not bother to change the default password or, maybe, did not even know that such a thing was possible or recommended.<\/p>\n<p>A failure to change the password means that everyone who knows the exact address of the camera and the default password (you know, the \u20181234\u2019 type), could access your very private data. So, how could one know the exact address of a camera? One can enter a tricky search term into Google and access links to thousands of cameras online.<\/p>\n<p>It didn\u2019t take long for someone else to set up a website that seeks out unprotected webcams and sorts them by country and region (based on the IP address) for all of the bad guys out there to enjoy. There is even a thread in a limited-access forum where people can discuss the screenshots taken from webcams with the most \u2018remarkable\u2019 content. Yikes!<\/p>\n<h3>Who is to blame?<\/h3>\n<p>Both everyone and no one. First, let\u2019s consider cybercriminals. The people who established the website did not actually <em>hack<\/em> anything using sophisticated technology. They did not <em>exploit vulnerabilities<\/em>\u00a0in a camera\u2019s software or set up a phishing website to steal your private passwords. They simply took advantage of a <em>misconfiguration<\/em>.<\/p>\n<p>These cybercriminals broke into a device that was not designed with security in mind. One could compare it to taking a wallet that was forgotten in a cafe. The owner of the wallet should not have left it in a public place to begin with. While stealing it is not comparable to breaking into somebody\u2019s home, it is still considered a bad thing to do.<\/p>\n<p>Now let\u2019s consider the users. They failed to change the default password, though it was likely recommended somewhere in the manual (page 57, in small print, or something like that). However, do people really read the manual for a device that \u201cjust works\u201d? Webcam manufacturers design them to be as easy to operate as possible. Sometimes they may overlook security issues for the sake of simplicity. If a camera <em>required<\/em> a user to change the default password before starting to use it (a very simple thing to do), the entire incident would be preventable.<\/p>\n<p>How about the vendors? They tend to blame \u201chackers\u201d and their own clients that fail to change a default password. Our choice is to side with consumers. We believe that everything with an internet connection should be designed with security in mind. We also believe that the vendors should explain security, in the simplest terms possible, to their clients and do their best to secure their clients\u2019 private lives.<\/p>\n<h3>Welcome to the amazing world of computers!<\/h3>\n<p>In general, we contribute to the incidents that occur because we think of many devices as simple utility gadgets that merely do one or two simple tasks (like stream videos or provide WiFi access).<\/p>\n<p>In reality, it is way more complicated than that. Many cameras, home routers, smart TVs, set-top boxes and music players are actually <strong>real computers\u00a0<\/strong>capable of doing a lot more than they usually do. Actually, most of them tend to have these capabilities because manufacturers use standard, general-purpose hardware and software, as it is the cheapest method. Your home router provides WiFi, but it is powerful and sophisticated enough to control a space vehicle. That is what cybercriminals take advantage of.<\/p>\n<blockquote class=\"twitter-pullquote\"><p>If you own a device that is connected to the Internet, you should certainly follow security news.<\/p><a href=\"https:\/\/twitter.com\/share?url=https%3A%2F%2Fkas.pr%2F96wd&amp;text=If+you+own+a+device+that+is+connected+to+the+Internet%2C+you+should+certainly+follow+security+news.\" class=\"btn btn-twhite\" data-lang=\"en\" data-count=\"0\" target=\"_blank\" rel=\"noopener nofollow\">Tweet<\/a><\/blockquote>\n<h3>Advice<\/h3>\n<p>Since not all providers of hardware, software and web services are thinking enough about security, we have to take care of it ourselves. There are two ways to do so. The first way is to learn about computers, software, programming, networks, analyzing vulnerabilities and communication protocols, and modify your own system to be protected from all kinds of threats.<\/p>\n<p>The second way is to rely on professionals. For computers, smartphones and tablets this is not a problem (take a look at <a href=\"https:\/\/www.kaspersky.com\/total-security-multi-device\" target=\"_blank\" rel=\"noopener nofollow\">Kaspersky Total Security<\/a>). However, devices such as webcams, routers and smart TVs are very diverse and deliberately closed by vendors for external reviews, making it nearly impossible to come up with a single security solution. So read the manual and call your IT guy to take care of security settings (but type the passwords yourself).<\/p>\n<p>To learn more about similar \u201chacks\u201d, take a look at this brilliant research by Kaspersky Lab\u2019s expert, David Jacoby, titled\u00a0<a href=\"https:\/\/securelist.com\/analysis\/publications\/66207\/iot-how-i-hacked-my-home\/\" target=\"_blank\" rel=\"noopener\">\u201cHow I hacked my home.\u201d<\/a><\/p>\n<p>There is good news. Two days after the news broke, the website in question was shut down. But the bad news is that before the shut down, it was operational for at least six months. Even worse news: the misconfiguration that made the whole thing possible was revealed on one Russian technology website as early as August 2013 (not to mention that real cybercriminals could have used it long before that).<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">BBC News \u2013 Breached webcam and baby monitor site flagged by watchdogs <a href=\"http:\/\/t.co\/YnICwbMzvm\" target=\"_blank\" rel=\"noopener nofollow\">http:\/\/t.co\/YnICwbMzvm<\/a><\/p>\n<p>\u2014 Foscam UK (@FoscamUK) <a href=\"https:\/\/twitter.com\/FoscamUK\/status\/535717722869350400?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">November 21, 2014<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>The fact that the website is gone does not mean that the affected cameras are secure. One could still find and access them using simple tools like a Google search. The only definite solution is to change the webcam default password. The devices produced by at least one manufacturer (<a href=\"http:\/\/www.foscam.com\" target=\"_blank\" rel=\"noopener nofollow\">Foscam<\/a>) are known to be affected.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Recent news concerning \u201chacked webcams\u201d or \u201cbreached baby monitors\u201d appears to be all over the place. Let&#8217;s take a closer look at the situation.<\/p>\n","protected":false},"author":53,"featured_media":4318,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5],"tags":[848,543,97,712,847],"class_list":{"0":"post-4317","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-news","8":"tag-misconfiguration","9":"tag-news-2","10":"tag-security-2","11":"tag-webcam","12":"tag-webcam-hack"},"hreflang":[{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/massive-webcam-breach\/4317\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/massive-webcam-breach\/4388\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/massive-webcam-breach\/4854\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/massive-webcam-breach\/6273\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/massive-webcam-breach\/6833\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/massive-webcam-breach\/5585\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/massive-webcam-breach\/6273\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/massive-webcam-breach\/6833\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/massive-webcam-breach\/6833\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/me-en.kaspersky.com\/blog\/tag\/misconfiguration\/","name":"misconfiguration"},"_links":{"self":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/4317","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/53"}],"replies":[{"embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=4317"}],"version-history":[{"count":2,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/4317\/revisions"}],"predecessor-version":[{"id":15950,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/4317\/revisions\/15950"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/4318"}],"wp:attachment":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=4317"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=4317"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=4317"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}