Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Unless that camera uses UPnP and has no auth configured by default.


Or admin/1234 which is about 90% of them


You’re saying f the camera will talk to the firewall using a username and password and open a hole/port forward?


I don't think the username as password is required.

Open a Bittorrent client and it will try and port forward port 6881 using UPnP.


Which doesn’t matter about the password. If you have a faulty router which allows unauthorised inbound connections then you have a bigger problem than weak credentials


huh? The camera pokes the hole in the "firewall" (NAT in 99% of cases, which isn't a firewall, hence why it's so easy for bits of software to poke holes in it.

You don't even need to do UPnP, if you're okay with a random port, you can just do STUN.


No, I mean the cameras have these settings.

Some cameras do also open ports with UPnP but it's rare in my experience. I think these cams are more users who are a bit technical but not too much to realise the implications.


Ok so aside from some malware running inside your security perimeter what’s the threat?

Yes weak passwords are bad, but if nobody can access it it’s not the end of the world.


Well this very site is why it's bad. And things like Shodan.

It's the swiss cheese model. I'm sure most of these people didn't mean to make their cam accessible to the internet. If there had been a unique username/pw they wouldn't have got exposed.


which cameras do this?




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: