Follow Slashdot blog updates by subscribing to our blog RSS feed

 



Forgot your password?
typodupeerror
The Internet

40,000 IoT Cameras Worldwide Stream Secrets To Anyone With a Browser 21

Connor Jones reports via The Register: Security researchers managed to access the live feeds of 40,000 internet-connected cameras worldwide and they may have only scratched the surface of what's possible. Supporting the bulletin issued by the Department of Homeland Security (DHS) earlier this year, which warned of exposed cameras potentially being used in Chinese espionage campaigns, the team at Bitsight was able to tap into feeds of sensitive locations. The US was the most affected region, with around 14,000 of the total feeds streaming from the country, allowing access to the inside of datacenters, healthcare facilities, factories, and more. Bitsight said these feeds could potentially be used for espionage, mapping blind spots, and gleaning trade secrets, among other things.

Aside from the potential national security implications, cameras were also accessed in hotels, gyms, construction sites, retail premises, and residential areas, which the researchers said could prove useful for petty criminals. Monitoring the typical patterns of activity in retail stores, for example, could inform robberies, while monitoring residences could be used for similar purposes, especially considering the privacy implications.
"It should be obvious to everyone that leaving a camera exposed on the internet is a bad idea, and yet thousands of them are still accessible," said Bitsight in a report. "Some don't even require sophisticated hacking techniques or special tools to access their live footage in unintended ways. In many cases, all it takes is opening a web browser and navigating to the exposed camera's interface."

HTTP-based cameras accounted for 78.5 percent of the total 40,000 sample, while RTSP feeds were comparatively less open, accounting for only 21.5 percent.

To protect yourself or your company, Bitsight says you should secure your surveillance cameras by changing default passwords, disabling unnecessary remote access, updating firmware, and restricting access with VPNs or firewalls. Regularly monitoring for unusual activity also helps to prevent your footage from being exposed online.

40,000 IoT Cameras Worldwide Stream Secrets To Anyone With a Browser

Comments Filter:
  • its not a secret (Score:5, Informative)

    by Vomitgod ( 6659552 ) on Tuesday June 10, 2025 @07:28PM (#65441245)

    https://www.shodan.io/ [shodan.io]

    has been available for years.....

    • by Hadlock ( 143607 )

      One of our engineers did this as a side project back in 2015 in an afternoon, setup a web scraper on aws and the next day we could visit all these things. I'm pretty sure the company did a new article on this... ten years ago.

    • Yeah, there's even been an aggregator website for a decade:

      http://insecam.org/ [insecam.org]

      It's often broken, but "security researchers"? Come on, now.

  • just say no to their existence
  • -in that stupid thriller and you were like "no way, security doesn't work like that!" but then it turns out the real world is as stupid as that show/movie is.
  • I wanted to replace an obsolete camera surveillance system a few months back with better cameras and a more capable NVR server so I learned what I could about the tech. You can buy a good POE camera for under $60. Hook several to a POE switch attached to your local network (which damn well better be behind your router firewall) and you can get to the feeds and record them with some open source software running on a cheap linux micro-pc; https://docs.shinobi.video/ [docs.shinobi.video]

    I tried several camera brands. Hikvision, Re

    • I think most of those open cameras are open to the Internet because their owners intentionally opened ports in their routers.

    • by tlhIngan ( 30335 )

      That's the problem with cheap Chinese cameras. Not singling out the Chinese, but they're well known to take a camera design and making dozens of models based on the same model and software, and making them really, really, really cheap.

      Meanwhile you can spend more money for cameras that can do local storage of video, some of which can optionally upload to the cloud, and there's plenty that do triple storage - local (on-camera), local NVR, and cloud storage. Recording in 3 places means if the camera is stolen

      • >> cheap Chinese cameras

        Yes, all the cameras I looked at appeared to be the derived from the same basic design. Rebranded with some minor UI changes.

        Are there better cameras that you recommend?

  • Surprised the number isn't larger. In 2012 the Carna Botnet used 420,000 nodes to perform the "Internet Census of 2012" and most of those nodes were cameras.
  • Back in the day, Yahoo's search engine used to work with categories, one of which was devices connected to the Internet. Used to be great fun logging into a random California broadwalk webcam to see some sunshine in glorious 1 FPS detail!
    • Along those lines and a long time ago, Stella Artois had webcams set up in bars in Belgium etc. Found it quite entertaining for a half hour or so.
  • https://en.wikipedia.org/wiki/... [wikipedia.org] is the anti-hero we need. I wish it was a government-run service -- bring your bricked device and you get a reembursement. Should be easy to check if it is was bricked by a brickerbot. Such a service should pay off easily compared to the cost of botnets.

  • Preaching to the converted here, but...

    If you've got some webcams somewhere, then consider running Frigate to 'consume' their feeds. Ideally, put all of the cameras on a private network which doesn't have any access to any other network, and then give your frigate server 2 network interfaces. If you need off-network access to the feeds, then use a VPN.

    My Frigate server has a £60 USB TPU attached - it makes that little NAS, which runs a handful of other things as well, able to do AI recognition on a wh

  • Just wait til AI can watch all 40k+ feeds and analyze the data in real time.

In the sciences, we are now uniquely priviledged to sit side by side with the giants on whose shoulders we stand. -- Gerald Holton

Working...