• About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
Tech News, Magazine & Review
  • Home
  • Shop
  • Tech News
    You can replace DLSS with AMD FSR 2.0 in Cyberpunk 2077 with this mod

    You can replace DLSS with AMD FSR 2.0 in Cyberpunk 2077 with this mod

    The Sabrent Rocket 4 Plus Destroyer 2 SSD has up to 64 terabytes of speedy storage

    The Sabrent Rocket 4 Plus Destroyer 2 SSD has up to 64 terabytes of speedy storage

    Stadia

    Stadia code change hints Google is prepping Nvidia GPU support

    Intel Core i9-13900 engineering sample is 20% faster than Alder Lake in new benchmarks

    Intel Core i9-13900 engineering sample is 20% faster than Alder Lake in new benchmarks

    AMD Threadripper Pro 5000 to expand availability to more OEMs, hit retail eventually

    AMD Threadripper Pro 5000 to expand availability to more OEMs, hit retail eventually

    YouTube Music can now recommend songs when you connect to earbuds

    YouTube Music can now recommend songs when you connect to earbuds

    Meta logo on a smartphone

    Meta shuts down social media post tracking tool on Facebook

    TikTok is reportedly on pace to rake in $12 billion this year

    TikTok is reportedly on pace to rake in $12 billion this year

  • Review
    The best instant cameras you can buy right now

    The best instant cameras you can buy right now

    Google’s Pixel 5 was the last of its kind

    Google’s Pixel 5 was the last of its kind

    Starlink RV review: the dawn of space internet to go

    Starlink RV review: the dawn of space internet to go

    Poco F4 GT

    Poco F4 GT

    Toyota bZ4X electric SUV review: mediocre at best

    Toyota bZ4X electric SUV review: mediocre at best

    6 Cores vs. 8 Cores for Gaming: 24 Game Benchmark

    6 Cores vs. 8 Cores for Gaming: 24 Game Benchmark

    Edifier MP230

    Edifier MP230

    Amazon Basics Rechargeable AAA 800mAh

    Amazon Basics Rechargeable AAA 800mAh

  • Gear
    Apple TV Siri Remote hinted in iOS 16 beta

    Apple TV Siri Remote hinted in iOS 16 beta

    amazon echo

    Amazon shows off Alexa’s new in-development ability to mimic anyone dead or alive

    Samsung Pay no longer functioning on smartphones from other manufacturers

    Samsung Pay no longer functioning on smartphones from other manufacturers

    Apple

    Apple’s AR glasses are currently in the design development stage: report

    Meta is working on several VR prototypes that aim to pass the Visual Turing test

    Meta is working on several VR prototypes that aim to pass the Visual Turing test

    Sony's Walkman is making a pricey digital comeback

    Sony’s Walkman is making a pricey digital comeback

  • Gaming
    AMD Engineer Confirms RDNA3 GPU Power Consumption Will Increase - ExtremeTech

    AMD Engineer Confirms RDNA3 GPU Power Consumption Will Increase – ExtremeTech

    Cyberpunk 2077 is getting a board game

    Cyberpunk 2077 is getting a board game

    The best tech and gadget gifts for less than $25

    The best tech and gadget gifts for less than $25

    Games Done Quick’s summer marathon kicks off Sunday, and there’s a lot to look forward to

    Games Done Quick’s summer marathon kicks off Sunday, and there’s a lot to look forward to

    Microsoft Adds a Ton of New Gaming Features to Edge - ExtremeTech

    Microsoft Adds a Ton of New Gaming Features to Edge – ExtremeTech

    Legendary designer Yu Suzuki returns with a wild arcade shooter

    Legendary designer Yu Suzuki returns with a wild arcade shooter

    Amazon Offering Fire TV Stick With a Wireless Game Controller in India to Attract Casual Gamers

    Amazon Offering Fire TV Stick With a Wireless Game Controller in India

    Chris Pratt says his Mario voice is ‘unlike anything you’ve heard’

    Chris Pratt says his Mario voice is ‘unlike anything you’ve heard’

  • Smart Phones
    OnePlus logo

    OnePlus 11 Pro: Everything we know so far and what we want to see

    VPN

    ClearVPN is so pretty that it doesn’t feel like a VPN. But it works like one — and it’s 80% off

    article thumbnail

    Harber Leather Desk Mat review: a comfortable, desirable Mac accessory | AppleInsider

    Asus ROG Phone 5/5S problems and how to fix them

    Asus ROG Phone 5/5S problems and how to fix them

    article thumbnail

    How to download Xcode faster | AppleInsider

    article thumbnail

    Daily deals June 25: $175 AirPods Pro, $40 Amazon Kindle, $30 OtterBox MagSafe Power Bank, more | AppleInsider

    Apple iPhone logo macro

    Should Apple M2 iPads worry the Pixel Tablet crowd?

    Google Pixel 7

    Pixel 7 Pro prototype reveals some details about second-gen Tensor

  • More
    • Apps & Software
    • Computing
    • Security
No Result
View All Result
  • Home
  • Shop
  • Tech News
    You can replace DLSS with AMD FSR 2.0 in Cyberpunk 2077 with this mod

    You can replace DLSS with AMD FSR 2.0 in Cyberpunk 2077 with this mod

    The Sabrent Rocket 4 Plus Destroyer 2 SSD has up to 64 terabytes of speedy storage

    The Sabrent Rocket 4 Plus Destroyer 2 SSD has up to 64 terabytes of speedy storage

    Stadia

    Stadia code change hints Google is prepping Nvidia GPU support

    Intel Core i9-13900 engineering sample is 20% faster than Alder Lake in new benchmarks

    Intel Core i9-13900 engineering sample is 20% faster than Alder Lake in new benchmarks

    AMD Threadripper Pro 5000 to expand availability to more OEMs, hit retail eventually

    AMD Threadripper Pro 5000 to expand availability to more OEMs, hit retail eventually

    YouTube Music can now recommend songs when you connect to earbuds

    YouTube Music can now recommend songs when you connect to earbuds

    Meta logo on a smartphone

    Meta shuts down social media post tracking tool on Facebook

    TikTok is reportedly on pace to rake in $12 billion this year

    TikTok is reportedly on pace to rake in $12 billion this year

  • Review
    The best instant cameras you can buy right now

    The best instant cameras you can buy right now

    Google’s Pixel 5 was the last of its kind

    Google’s Pixel 5 was the last of its kind

    Starlink RV review: the dawn of space internet to go

    Starlink RV review: the dawn of space internet to go

    Poco F4 GT

    Poco F4 GT

    Toyota bZ4X electric SUV review: mediocre at best

    Toyota bZ4X electric SUV review: mediocre at best

    6 Cores vs. 8 Cores for Gaming: 24 Game Benchmark

    6 Cores vs. 8 Cores for Gaming: 24 Game Benchmark

    Edifier MP230

    Edifier MP230

    Amazon Basics Rechargeable AAA 800mAh

    Amazon Basics Rechargeable AAA 800mAh

  • Gear
    Apple TV Siri Remote hinted in iOS 16 beta

    Apple TV Siri Remote hinted in iOS 16 beta

    amazon echo

    Amazon shows off Alexa’s new in-development ability to mimic anyone dead or alive

    Samsung Pay no longer functioning on smartphones from other manufacturers

    Samsung Pay no longer functioning on smartphones from other manufacturers

    Apple

    Apple’s AR glasses are currently in the design development stage: report

    Meta is working on several VR prototypes that aim to pass the Visual Turing test

    Meta is working on several VR prototypes that aim to pass the Visual Turing test

    Sony's Walkman is making a pricey digital comeback

    Sony’s Walkman is making a pricey digital comeback

  • Gaming
    AMD Engineer Confirms RDNA3 GPU Power Consumption Will Increase - ExtremeTech

    AMD Engineer Confirms RDNA3 GPU Power Consumption Will Increase – ExtremeTech

    Cyberpunk 2077 is getting a board game

    Cyberpunk 2077 is getting a board game

    The best tech and gadget gifts for less than $25

    The best tech and gadget gifts for less than $25

    Games Done Quick’s summer marathon kicks off Sunday, and there’s a lot to look forward to

    Games Done Quick’s summer marathon kicks off Sunday, and there’s a lot to look forward to

    Microsoft Adds a Ton of New Gaming Features to Edge - ExtremeTech

    Microsoft Adds a Ton of New Gaming Features to Edge – ExtremeTech

    Legendary designer Yu Suzuki returns with a wild arcade shooter

    Legendary designer Yu Suzuki returns with a wild arcade shooter

    Amazon Offering Fire TV Stick With a Wireless Game Controller in India to Attract Casual Gamers

    Amazon Offering Fire TV Stick With a Wireless Game Controller in India

    Chris Pratt says his Mario voice is ‘unlike anything you’ve heard’

    Chris Pratt says his Mario voice is ‘unlike anything you’ve heard’

  • Smart Phones
    OnePlus logo

    OnePlus 11 Pro: Everything we know so far and what we want to see

    VPN

    ClearVPN is so pretty that it doesn’t feel like a VPN. But it works like one — and it’s 80% off

    article thumbnail

    Harber Leather Desk Mat review: a comfortable, desirable Mac accessory | AppleInsider

    Asus ROG Phone 5/5S problems and how to fix them

    Asus ROG Phone 5/5S problems and how to fix them

    article thumbnail

    How to download Xcode faster | AppleInsider

    article thumbnail

    Daily deals June 25: $175 AirPods Pro, $40 Amazon Kindle, $30 OtterBox MagSafe Power Bank, more | AppleInsider

    Apple iPhone logo macro

    Should Apple M2 iPads worry the Pixel Tablet crowd?

    Google Pixel 7

    Pixel 7 Pro prototype reveals some details about second-gen Tensor

  • More
    • Apps & Software
    • Computing
    • Security
No Result
View All Result
No Result
View All Result
Home Security

Wyze Left Security Cameras Open to Hacking for Three Years – ExtremeTech

admin by admin
April 1, 2022
Wyze Left Security Cameras Open to Hacking for Three Years - ExtremeTech
Share on FacebookShare on Twitter


This site may earn affiliate commissions from the links on this page. Terms of use.

Wyze has made its name offering capable home security products for startlingly low prices. Whereas you might pay $200 for a Google Nest security camera, Wyze offers devices that are almost as good for literally one-tenth the price. It turns out that $20 security camera on your shelf might not be such a good deal. A new disclosure from security firm Bitdefender reveals that the company’s cameras had a major security vulnerability that could allow an attacker to remotely access your video, and Wyze has known about it for three years. Plus, the Wyze V1 is still broken and will not be fixed.  It almost goes without saying, but if you’ve got a Wyze V1 around, get rid of it. 

Unlike Google, Ring, or the other makers of popular security cameras, Wyze does not make its own hardware. It re-badges products from China with new firmware and app support. It offers cheap security cameras, but also robot vacuums, headphones, smart scales, smartwatches, and more. They’re all priced below competing products and generally are not quite as good. But hey, a $20 security camera? Wyze sold a boatload of them. 

The issue lies in how the cameras use their internal microSD card storage. The camera creates a symlink in the www directory, giving the webserver direct access to the videos stored on the camera so you can stream them to your app. However, Wyze implemented no access restrictions in this system, and that means an attacker can use a pair of vulnerabilities to collect the UID (unique identification number) and the ENR (AES encryption key). At that point, they can access your camera as if they were you. 

Wyze’s response to this was insufficient. It quietly discontinued the V1 camera early this year, and it patched the newer versions. It said that continuing to use the original cam carried “increased risk.” It didn’t say anything about the risk of using it for the last three years with a gaping security hole. The newer V2 and V3 cameras were patched to block the exploit. 

This email from January is the only official communication from Wyze on the security issue.

We’re used to security flaws being patched and/or disclosed in relatively short order, usually measured in weeks or months. But three years? Bitdefender initially reached out to Wyze in March 2019, and it didn’t hear back until November 2020. According to The Verge, Bitdefender gave Wyze some leeway because of the severity of the bug and Wyze’s slow progress toward fixing it. Wyze didn’t even have a security framework in place to address bugs like this until 2021. 

But at the end of the day, this is a $20 security camera — not a major investment. It’s one that I have actually used in the past, and I would have appreciated knowing that it was wide open to remote exploitation. I would have happily chucked it in the recycling without a moment’s hesitation. As for newer Wyze products that are supposedly safe, I’m skeptical enough that I won’t plug them in at all. Wyze owes its customers an apology.

Now Read:





Source link

admin

admin

Related Posts

Google says attackers worked with ISPs to deploy Hermit spyware on Android and iOS

Google says attackers worked with ISPs to deploy Hermit spyware on Android and iOS

June 25, 2022
Majority of Americans fear some form of cyberwarfare

Why we need to take the threat of cyberwarfare seriously [Q&A]

June 24, 2022
Tips for securing Windows with PowerShell... courtesy of the NSA

Tips for securing Windows with PowerShell… courtesy of the NSA

June 24, 2022
Weekend at Johnny's: McAfee's body remains at morgue one year after his death

Weekend at Johnny’s: McAfee’s body remains at morgue one year after his death

June 23, 2022
Next Post
MacBook Air (2020)

LG reportedly producing displays for Apple's rumoured foldable notebook

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • Trending
  • Comments
  • Latest
Alienware x17 R2 (2022)

Alienware x17 R2 (2022)

June 2, 2022
Toshiba 65UK3163DB

Toshiba 65UK3163DB

April 18, 2022
article thumbnail

Compared: Amazon Fire 7 2022 vs iPad mini & 10.2-inch iPad | AppleInsider

May 22, 2022
How to deactivate your Twitter account

How to deactivate your Twitter account

April 14, 2022
Intel Arc A770 desktop GPU debuts in the Geekbench database

Intel Arc A770 desktop GPU debuts in the Geekbench database

0
New evidence supporting the existence of the Google Pixel Watch emerges

New evidence supporting the existence of the Google Pixel Watch emerges

0
Microsoft is developing an in-game advertising system for free-to-play games

Microsoft is developing an in-game advertising system for free-to-play games

0
WhatsApp testing ability to hide ‘Last Seen’ status from specific contacts on iOS

WhatsApp testing ability to hide ‘Last Seen’ status from specific contacts on iOS

0
OnePlus logo

OnePlus 11 Pro: Everything we know so far and what we want to see

June 26, 2022
VPN

ClearVPN is so pretty that it doesn’t feel like a VPN. But it works like one — and it’s 80% off

June 26, 2022
Google says attackers worked with ISPs to deploy Hermit spyware on Android and iOS

Google says attackers worked with ISPs to deploy Hermit spyware on Android and iOS

June 25, 2022
article thumbnail

Harber Leather Desk Mat review: a comfortable, desirable Mac accessory | AppleInsider

June 25, 2022

Don't Miss.

Shadow IT is top security concern around SaaS adoption

Shadow IT is top security concern around SaaS adoption

April 20, 2022
Apple Inches Closer to Launching Its Mixed Reality Headset - ExtremeTech

Apple Inches Closer to Launching Its Mixed Reality Headset – ExtremeTech

May 23, 2022
Microsoft announces Xbox and Bethesda Games Showcase

Microsoft announces Xbox and Bethesda Games Showcase

April 28, 2022
GTA 5, GTA Online PS5 Xbox Series S/X Price in India Revealed, No Free Upgrade for Existing Users

GTA 5, GTA Online PS5 Xbox Series S/X Price in India Revealed

March 9, 2022

GIZMOZOD

Gizmozod is dedicated to providing you the latest news and other information about the tech world that you just need to know. It publishes news related to various tech fields like smartphones, computing, smart home, automotive, gaming, cybersecurity and so on.

Follow Us

Categories

  • Apps & Software
  • Computing
  • Gaming
  • Gear
  • Review
  • Security
  • Smart Phones
  • Tech News

Recent News

OnePlus logo

OnePlus 11 Pro: Everything we know so far and what we want to see

June 26, 2022
VPN

ClearVPN is so pretty that it doesn’t feel like a VPN. But it works like one — and it’s 80% off

June 26, 2022

Join Our Newsletter!


    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions

    gizmozod © 2022| All rights reserved.

    No Result
    View All Result
    • Home
    • Shop
    • Tech News
    • Review
    • Gear
    • Gaming
    • Smart Phones
    • More
      • Apps & Software
      • Computing
      • Security

    gizmozod © 2022| All rights reserved.