Anker’s Eufy Admits Unencrypted Video Can Be Accessed, Plans to Improve


Enlarge / Anchor’s Eufy division has stated that its web portal was not designed for end-to-end encryption and may allow outside access with the correct URL.

Eufy

After two months of debating back and forth with critics over how many aspects of its “no clouds” security cameras can be accessed online by security researchers, Anker smart home division Eufy has provided a lengthy explanation and a promise to do better. Have done

In several responses to The Verge, which has repeatedly called out Eufy for failing to address key aspects of its security model, Eufy has categorically stated that despite messaging the video streams produced by its cameras, Eufy Can be accessed through web portal. Marketing that suggests otherwise. Eufy also said it would bring on penetration testers, commission a report from an independent security researcher, create a bug bounty program, and better detail its security protocols.

Before the end of November 2022, Eufy has achieved a unique position among smart home security providers. For those willing to trust any company with video feeds and other home data, Eufy marketed itself as offering “no clouds or costs”, encrypted feeds streamed only to local storage.


Then came the first tragic revelation of Eufy. Security Consultant and Researcher Paul Moore asked Eufy on Twitter He found out about many anomalies. Images from his doorbell camera, seemingly tagged with facial recognition data, were accessible from a public URL. The camera feed, when activated, appears to be without authentication from VLC media player (something later confirmed by The Verge). Eufy issued a statement saying that, essentially, it had not fully explained how it uses cloud servers to provide mobile notifications and pledged to update its language . Moore went silent after tweeting about “a long discussion” with Eufy’s legal team.

Advertisement

A few days later, a different security researcher confirmed that, given a URL from inside a Eufy user’s web portal, it could be streamed. The encryption scheme on the URL also appears to lack sophistication; As the same researcher told Ars, it only took 65,535 combinations to brute-force it, “which is pretty fast a computer can run.” Anchor later increased the number of random characters required to guess the URL stream and stated that this removed the ability of media players to play a user’s stream even if they had the URL.

Eufy released a statement to The Verge, Ars and other publications at the time, noting that it “strongly disagrees” with the allegations made against the company concerning the safety of our products. After sustained pressure by The Verge, the anchor released a lengthy statement detailing his past errors and plans for the future.

Among the notable statements from Anchor/Ufey:

  • Its web portal now prevents users from entering “debug mode”.
  • The video stream content is encrypted and is not accessible outside the portal.
  • While “only 0.1 percent” of current daily users use the portal, it “had some issues,” which have been resolved.
  • Eufy is pushing WebRTC as the go-to end-to-end encrypted stream protocol for all of its security devices.
  • Facial recognition images were uploaded to the cloud to help replace/reset/associate the doorbell with existing image sets, but have been turned off. No identifying data was included with the images sent to the cloud.
  • Outside of “Recent Problem with the Web Portal”, all other videos use end-to-end encryption.
  • A “leading and well-known security expert” will prepare a report about Eufy’s systems.
  • “Several new security consulting, certification and penetration testing” firms will be brought in for risk assessment.
  • A “Ufee Security Bounty Program” will be set up.
  • The company promises to provide “more timely updates to our community (and the media!).”

Source


Related News

And the miracle was done: editing tweets is now possible on Twitter, we have tested it

Altering an already published tweet was impossible without modifying a screenshot with a photo editor. But, with the introduction of the edit button, Twitter

RatMilad: this new malware can completely monitor your Android mobile

Zimperium cybersecurity experts have warned about a new spyware Aimed at the Android platform, it hid behind a supposed verification tool of a social network

The directors of the Dungeons and Dragons film guests at Lucca Comics and Games 2022

More and more fantasy, more and more international: other important guests are added to the list of the now imminent Lucca event, in fact it has recently been

Android 13 beta 2 rotates media player and hides lockscreen

Android 13 beta 2 replaces the media player, hides the squiggle lockscreen

List of Android phones that will no longer have WhatsApp on October 31

WhatsApp It continues to update itself to add more features for the benefit of its subscribers and also to remove some possible bugs that may slow down its