I’ve noticed that my Wyze Cam v4 is making public DNS queries over port 53.
Would it be more secure to use the Asus Merlin firmware’s DNS Director (DHCP) to force these queries back to the router using DNS-over-TLS (DoT)? Or is it much better to route all of the camera’s traffic through a dedicated VPN tunnel instead?
What do you guys recommend? How are you maximizing the security and protection for your cameras?
There is really no security needed on these DNS queries. Even if someone intercepted your DNS and redirected you, the cams use secure auth with the wyze servers.
Most home routers already proxy your DNS traffic. If you want to enforce DOT or DOH between the router and your DNS server of choice, you can, it really doesn’t buy anything in this scenario though.
You could also use a VPN for the camera traffic but if the wyze side of things were to get hacked or compromised, it wouldn’t offer you any extra protection.
Long story short, the cameras are relatively secure, but no “cloud cam” is immune and all the companies have had breaches and bugs at times. These cameras should not be in private places (including places that can pick up audio you wouldn’t want heard) and ideally should be on an isolated guest/IOT network when possible.