Security camera recommendations, alternatives to Ring


Recommended Posts

3 minutes ago, BudMan said:

No that is not true at all.. Are the users to blame for many issues sure!!  But when the options are not even their for the educated to use if they wanted to.. Its not like the application asked hey do you want to exchange info in the clear or secure, etc..

When ring came up their security did they never once have a "Gibsonian response" to their practices?

3 minutes ago, BudMan said:

No that is not true at all.. Are the users to blame for many issues sure!!  But when the options are not even their for the educated to use if they wanted to.. Its not like the application asked hey do you want to exchange info in the clear or secure, etc..

 

These iot cameras sharing code without  proper security audits of their own - who do you blame for that?  back door logins, etc. etc.

 

These companies do need to be held accountable for the security of their products.. If the user reuses passwords, that is on the user.. But flaws in basic protocol use is not the users issue..

So would you say it is 50-50? The company is at fault for not providing a more secure product and the user is at fault for not understanding the basic concepts of security, and not using the same password?

Name one iot device that supports wpa2-enterprise?  Or 802.11w?  They do not have to be enabled out of the box - but JFC give the user the ability to turn such features on!!  Then if not in use the company can say - hey not our fault the idiot user did stupid ######!

 

edit:

Is it 50-50.. To be honest would lean more toward 60-40, 70-30... Company needs to provide documentation to why you need to enable 2fA, etc.  Why you should isolate your vlans.. I know for sure the general public is like herding cats when it comes to being secure.. But many of these companies don't even try, or even give the tools to the users to do better security if they want to... 

 

Take plex for example - how long have users been screaming for 2fa, yet to be an option... But F me if they didn't spend lots of development time on adding ###### to your library with ads in it!!  So they can make more money.. And is it opt in, no its default!! And the user has to turn it off if they don't want to see it..

 

The overall problem to be honest - is security sucks!  It makes it harder to do what we want!  And users want easy, and simple and they sure and the F do not want to be bothered with 2fa, etc..

 

What these companies should do is say look here - we offered every possible security protocol there is.. This is all the latest ###### that you can do, if the user didn't turn it on - that is not our problem!!  But not offering it as option is on them.. If user mistakes bring that to the spotlight, then I say good for user errors!

 

Its not like you have to hire top of the line security guys and spend millions on security issues... You can have people find holes in your ###### for pennies... Just have a bounty program... Hey point out where we F'd up and get X dollars.. You will have all kinds of people looking at your app trying to exploit it..

Just adding my $.02 here.  I’ve been using, https://www.amazon.com/dp/B07KWNMB8Z/ref=cm_sw_r_cp_tai_ORucEbGN9CZWZ with 365-day battery life with no issues.

That look interesting for sure... But that is a bold claim to be sure.. there has to be a like 365 days of 10 minutes a day sort of recording..   There is no freaking way that can stream video for 365 days on same battery without charge.

1 hour ago, BudMan said:

That look interesting for sure... But that is a bold claim to be sure.. there has to be a like 365 days of 10 minutes a day sort of recording..   There is no freaking way that can stream video for 365 days on same battery without charge.

I was just going to say the same thing. Even 10 mins a day for 365 days would be impressive. That would be 60 hours of video recording on a single battery.

1 hour ago, BudMan said:

What off the shelf wifi routers even support vlans for example?  Its not like it would cost them anything to have the option available - ###### ddwrt can enable actual vlan support on much of the soho hardware..  But why do all these high end mesh products not even support such basic features?  Why do iot devices not support enterprise or 802.11x, etc. etc.

Well, almost every router supports guest wifi, and assuming it's segregating devices properly put IOT on that.

3 hours ago, BudMan said:

That look interesting for sure... But that is a bold claim to be sure.. there has to be a like 365 days of 10 minutes a day sort of recording..   There is no freaking way that can stream video for 365 days on same battery without charge.

It’s all motion activated, not constant recording.  Yes, trees and bushes moving because of wind will trigger the camera for A 20 second recording but setting up “activity zones” limits the false-positives. Also the amount of time of live viewing will affect the battery life.  I have 2 cameras that last about 320 days before a recharge.

9 hours ago, primortal said:

Also the amount of time of live viewing will affect the battery life.

And how much live viewing do the batteries give you?  Have you tested that?  Curious..

11 hours ago, BudMan said:

NO guest network is NOT the same as vlans... Not even close!!

Never said it was the same same as vlans. But it is built into most routers and a guest network is better than nothing.

Sure but problem is while that lets billy bob your guest use the internet... It doesn't allow for you to actually isolate your iot stuff and allow for any sort of pinhole access... So for example your roku device to access your plex server... It might work via a nat reflection and using the public IP... But its going to cause all kinds of issues when your plex server is saying you can access me via IP X, and the roku is on that X network via ip and mask, but can not talk to it, etc etc..

 

While sure its better than nothing, its pretty useless if trying to allow for specific connectivity securely...

 

Why not just allow for vlans?  Users don't have to turn them on if they don't want to, etc.

18 hours ago, BudMan said:

Great point!!   But somethings you can blame them for - exchanging login info over clear.. This is just bonehead not thinking.. saving some money that they didn't think through..  If the only way you could set the device up was over a wire connected to the device.. Ok... But when your going to send it over wireless that could be sniffed.. And that can be forced to redo - that is not looking out for best of bread security or possible issues, etc.

 

In theory... I could sit out on the street.. deauth the ring, and wait for the owner to redo their wifi.. Now I have access to the wifi, etc. etc.

 

Do the rings support say 802.11w?  Do they support wpa2 enterprise vs just psk?

 

If you want to state your security is best of breed, then you should support all the latest and greatest protocols.. even if the user doesn't enable them and enabling them by default might cause problems... I just wish these companies would stop shaving pennies and allow the users that want to secure their ######, actually secure it.

 

What off the shelf wifi routers even support vlans for example?  Its not like it would cost them anything to have the option available - ###### ddwrt can enable actual vlan support on much of the soho hardware..  But why do all these high end mesh products not even support such basic features?  Why do iot devices not support enterprise or 802.11x, etc. etc.

I agree with you, especially about the login info and the need to add advanced security.

 

I also understand that the deauth situation chance is near zero for the average joe user and if someone is that dedicated to breaking in to your WiFi, you have much more to worry about. 

13 minutes ago, BudMan said:

deauth attacks or pretty freaking simple - for sure the 12 year old living next door can use google and accomplish it ;)

Have you seen the range on these doorbells? They usually can't make it to the living room. Only time I would worry would be in an apartment building.

 

9 hours ago, BudMan said:

And how much live viewing do the batteries give you?  Have you tested that?  Curious..

Not to the extent to measure how long the battery will last.    On average week I spend about 10-15 minutes of live streaming.

On 12/30/2019 at 1:08 PM, BudMan said:

deauth attacks or pretty freaking simple - for sure the 12 year old living next door can use google and accomplish it ;)

Just to clarify, Even with the range limitations, I'm not saying it isn't an issue, it's very much an issue and absolutely shouldn't have been there in the first place.  However, they did patch it, so that's better than many IoT companies.

 

  • 11 months later...

This topic was automatically locked because it did not receive any replies for a year. If you want to have this topic reopened

  • please contact any staff moderator or
  • report the first post of the topic with the reason why it should be reopened.

Thank you.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • But they will be the first asking for a bail out the moment crap goes sideways. Its just a matter of time with this AI thing unless skynet gets us first.
    • I'm so conflicted with the Google Search AI summaries. On one hand I don't like how it's harming smaller websites by greatly reducing traffic which will harm us all in the long run but on the other hand those AI summaries often give me the information I'm after. I have never once clicked on 'show me more' though and never will.
    • Not a single company as small or large it may be is obligated to subsidize its products and sell them at a loss. Your way of thinking is socialist and as a West German with a German brother state but impoverished by state dictatorship and a socialist command economy situated to the East i can tell you - this kind of thinking very quickly leads to products not being produced anymore at all. EDIT: That does not mean that I find state support for social needs unreasonable. Quite the contrary. Together with solid workers' rights we exactly had exactly that in Germany for decades in the form of the Sozialstaat which was as the scandinavian social democratic very successful - until the number of people who drew from those resources dramatically increased (ironically a project of social democrat and green proponents).
    • Apple reportedly has a second-generation iPhone Fold planned for 2027 by Hamid Ganji The iPhone Fold is one of the most anticipated tech products expected to debut this fall. It will be Apple’s first foldable iPhone, ushering in a new product category for the company. While the first generation has yet to hit the shelves, a new leak suggests Apple has already begun work on its successor. Chinese leaker Digital Chat Station claims that the second-generation iPhone Fold has already been confirmed, meaning Apple could launch a successor in fall 2027. The foldable iPhone is also reportedly referred to as the “iPhone Ultra,” though it remains unclear whether Apple will ultimately choose that branding, especially as Samsung is rumored to rename the Galaxy Z Fold 8 as the Galaxy Z Fold Ultra this year. The leaker also claims that the second-generation foldable will feature a wider folding display while reusing the same screen found in the first generation. Apple’s first foldable iPhone is expected to feature a 7.8-inch inner display and a 5.3-inch outer screen in a passport-style form factor. It has already been reported that Apple plans to change its iPhone release cycle in 2026 to spread launches throughout the year. Under this strategy, the iPhone Fold is expected to debut this fall alongside the iPhone 18 Pro and iPhone 18 Pro Max. The standard iPhone 18 and iPhone Air 2 are expected to arrive later in 2026 or in early 2027. Speaking of the iPhone Air, Digital Chat Station says Apple remains undecided about a third-generation model. The company is reportedly waiting to see how the iPhone Air 2 performs in the market, and if sales disappoint, a successor may never materialize. As we reported this week, the iPhone Air has not been scrapped from Apple’s plans. The second-generation model is reportedly scheduled for spring 2027 and could introduce upgrades such as an additional rear camera for ultrawide photography and improved battery life.
    • ahh yes the good old your opinion differs from mine so you are therefore insane lol destiny 1 had no agenda pushing and was a massive success of a game, if you clearly look online the team for some reason thought they had too many men on the team and went on a woman and dei recruitment drive and we all know how destiny 2 performed from then on in
  • Recent Achievements

    • One Year In
      Vistor earned a badge
      One Year In
    • First Post
      kinowa earned a badge
      First Post
    • Rookie
      krychek57 went up a rank
      Rookie
    • Grand Master
      Jaybonaut went up a rank
      Grand Master
    • One Year In
      Philsl earned a badge
      One Year In
  • Popular Contributors

    1. 1
      +primortal
      405
    2. 2
      +Edouard
      170
    3. 3
      PsYcHoKiLLa
      131
    4. 4
      Xenon
      72
    5. 5
      neufuse
      69
  • Tell a friend

    Love Neowin? Tell a friend!