martes, 13 de febrero de 2018

Baby Monitor - TC2027

To introduce you to the topic I'll be writing about, I'll first explain the context.

My father works and lives out of Jalisco, but he comes and visits us every two weekends or so.
My brothers and I (we're 3 male, young adults - this might be relevant) live with my mother, she went a few days ago to my place of birth, to take care of her parents. 

Why do I have to tell you this? Well... because before my mother left, my father set up two Baby Cameras to "watch the house", more like keeping an eye on their sons.
Some of you might ask what does this have to do with security, well, let me tell you some stories that came up in the news:

  • A couple's 3 year old son told their parents he was afraid of the man talking over the monitor at night. One day, the father heard “Wake up little boy, daddy’s looking for you,” coming from the monitor. (CBS)
  • A family in London was sleeping their child when they heard eerie music coming from the monitor and a voice that said "you're being watched". (CTV News)
These news are creepy, but we're not babies, so what could go wrong? Well, if someone gained access to the monitors, they could watch us everytime, see our movements, when do we go out, at what time do we come back, what do we do when we're at the house, etc. There is a webpage, insecam which has this on their webpage:

Welcome to Insecam project. The world biggest directory of online surveillance security cameras. Select a country to watch live street, traffic, parking, office, road, beach, earth online webcams. Now you can search live web cams around the world.



Meaning that they have access to many cameras all around the world that don't have passwords protecting them, or they have the default ones "root : password", etc.
This sure raises awareness, and I found a really good post and I will try to explain it, just not as in depth, for how hackers get access and how to protect yourself, I encourage you to read the full post here: https://www.groovypost.com/howto/secure-your-video-baby-monitor/

First, how do hackers get access to a monitor?

It can be by gaining administrative access to your router, unless you've enabled port forwarding or created a demilitarized zone, you're safe here. This is done by BitTorrent clients or high bandwidth online video games. They can also gain access if you have an open wireless network (no password), but, you wouldn't do this, right? (another tip for protecting your router is to update the firmare regularly, when there's an update)

After they gained access, they can access the baby monitor configuration, these monitors usually come with a default password (or no password at all), so be sure to put a strong password in place.

However, many parents (like mine) want to access that monitor via the internet, when they're not at home, but "the bandwidth and security implications of enabling this feature are too great if you don't know what you're doing", because instead of hackers first gaining access to your router, they just have to gain access to the monitor (a strong password is needed, please, and keep the firmware of the camera updated)

My father and I took the required measurements to secure the webcams, so for now, I can rest in peace knowing that only my parents are watching me...


Read more:
http://newyork.cbslocal.com/2015/04/21/seen-at-11-cyber-spies-could-target-your-child-through-a-baby-monitor/
https://london.ctvnews.ca/baby-monitor-camera-hacked-while-child-rocked-to-sleep-1.2483149

No hay comentarios:

Publicar un comentario