On the other hand, the following article is an example of the kind of constructive teachable moment Wyze could’ve employed when the vulnerability was first discovered and avoided the whole brouhaha that was caused by a lack of communication with their customers.
" But this story is still disturbing. Wyze was not transparent with its customers and sat on a concerning security flaw for three years—are there any other vulnerabilities that we need to know about?
Wyze didn’t even tell customers about this flaw when it was patched on January 29th. And when the company discontinued the Cam V1 two days earlier, it simply explained that the camera couldn’t “support a necessary update.” It’s very hard to trust Wyze after it knowingly kept us in the dark."
I mean the egalitarian thing to do was tell V1 owners there was an issue and they are sending them V2 camera for free but nope.
It’s tough to write a statement in this situation, since it’s 3 years too late. Yeah, you would always have the fluffy PR line, but back then you could have explained it and eliminated the panic. Put the big boy pants on and either fix it or replace them. I would imagine they might have been fixable back then, but after three years of upgrades and features, it would be tough to do.
Sometimes I walk around in just my jockey shorts. Serves them right for watching a 66 year old man. Hopefully the feed will require mental bleach to erase the image.
Yeah, wyze withholding the info from those using the v1 is unacceptable. They force use of their cloud by closing the ecosystem which demands customers rely on their cloud via wifi internet connection. Leaving vulnerable customers in the dark is irresponsible when they were obviously knew of the flaw. In the big picture, most users probably are average folk who fly under the radar making them less likely to be targeted by hackers. However, that’s not for wyze to decide for the user. It should be the users choice whether they want to continue to use a vulnerable device or not. If any V1s were under warranty at the time, they should have been replaced by V2s. Older V1 owners could have been offered a deep discount on the V2 at a minimum.
I believe wyze could have also made available a custom FW for the V1 that would allow both limited functionality such as direct to app connectivity plus RTSP so users would have the option to continue to use it via 3rd party software or use it like a webcam while also ability to setup, view and control via the app - I’m not a software engineer so maybe I’m wrong, but it seems like limited internal lan use ability would be sufficient for many users to continue getting some benefit out of their cams. Forcing usage via the wyze cloud basically makes these cams completely unusable now. Eventually most tech becomes orphaned, but not all become unusable - my old netbook could not upgrade to win10 but it’s now going on it’s second decade of life running Linux, my old iPhone 3GS has not been able to be updated in many yrs, but it still works fine playing music.
It really makes you wonder about the wyze leadership team that they’d rather face this type of blow back than face up to their failures. The first gen sensor failures keep coming to mind as how they choose to put blinders on rather than proactively face up to and rectify the problems. It once again shows a certain disregard for the customer, much like how they push out beta products on an unsuspecting public, fail to dig deep into testing before rollouts, offer social engagement to appear customer centric, etc.
Not really. it’s a wireless camera. you can’t connect it directly to your modem, there needs to be a wireless router in between them. and all home wireless routers have NAT turned on by default. So pretty much everyone was protected, assuming they used a wifi password. Even those with no password on their wifi were only vulnerable to people using their wifi, not the entire internet as a whole.
Back in 2015, it was pretty common for security cameras to have port 23 (telnet) open. Now most of them have gone to port 22 (ssh), which is better, but still, the username and password are hard coded in firmware. This is not seen as a huge security vulnerability, because these ports are not generally forwarded to the devices in question.
Yet in the absence of Wyze assertively pushing an email message to every customer giving the details and mechanics of the vulnerability, rather than a vaguely worded reference to discontinuing the cam v1 without full disclosure, there might very well be cam v1 owners out there who perhaps knowingly or unknowingly blundered into at-risk territory and are continuing to be deprived of the information and advice they could use to make an informed decision on whether and how to take the necessary steps to protect themselves.
Hence, the continued blowback over what some might perceive as Wyze’s seeming self-serving paternalistic stance of withholding information under a variety of self justifications vs demonstrating the kind of transparency one might hope and expect would be forthcoming from a company the espouses very different values in their public facing marketing claims.
Even if there was justification to assume the risk was infinitely minimal, it would’ve been a great opportunity to do some public education on how to avoid being the victim of such an exploit
I guess what I meant was if it were able to be serviceable off the internet. If I failed to mention, I apologize, I am not a software engineer so it’s my opinion not fact.
There are routers that are unsecured out there, some have default credentials, exploits, etc…
The WiFi credentials can be hacked locally with some determination then once in the network port forwards could be setup in NAT, etc… Then once locally hacked and the router can have ports open to the internet.
if your router has an exploit that allows people on the WAN side to forward ports to devices on your LAN, that’s a few orders of magnitude more important than a device on your network with an open port.
There is no security when someone has local access. Period.
Even I’m starting to agree the horse may just be dead. People will either get that it’s serious but not really a big deal for most, or they won’t get it. The lying screaming headlines don’t help though.
Yes, I thanked @Rareapple3 for it in another thread. Finally someone with a level of attention / reputation who gets it.
I’ve only watched a few minutes. Please let us know if he says anything novel (other than pointing out how irresponsible The Verge and Gizmodo and Bleeping Computer - and Wyze- have been about this).