Avast_Threat_ Research: We tested the security of top IP camera apps, and here’s what
#1
Bug 
Quote:
[Image: TVDumYE.png]

Of the 10 apps that we put to the test, the apps that accompany the Blink and Wyze smart cameras proved to provide the best account security measures

Recently, our research team looked into the account security of app companions belonging to ten IP cameras. Each of these cameras have been listed on Amazon’s “hot new releases” and “best seller” categories. 

Avast IoT researcher, Marko Zbirka, looked into whether the apps that accompany smart cameras include a two-factor authentication option, send the owner a notification that someone has attempted to log in or has successfully logged in from a new device, especially if the login attempts came from a device appearing to be on the opposite side of the world, and if the length of account passwords was restricted.  

The 10 different IP cameras, all of which have cloud functionality, are as follows:
  • Blink
  • Wyze
  • YI IOT
  • YI Home
  • Wansview Cloud
  • MIPC
  • Jawa
  • CloudEdge
  • Amcrest Cloud
  • iCSee
The apps accompanying these cameras have all been downloaded 50,000 times or more, and four of the ten have been downloaded more than one million times. 

Checking account security

Our team’s researcher downloaded the apps used to connect and control the cameras and created accounts for them. After successfully logging in, he checked for an option to change the accounts’ password and set up two-factor authentication for the accounts. He then used a second phone with a VPN app to connect to a server abroad, so that the communication from the second device would go through that server and thus anything being sent from the device would appear to be coming from a device located abroad. 

“I intentionally attempted to log in to my own account using wrong passwords more than 10 times to see if any kind of brute force attempts would be detected by the apps. After that, I used the correct login credentials to log in to see if I received a notification about a new login from a different device and location,” said Marko Zbirka, IoT researcher at Avast. “Following this, I checked if the traffic between the app and the manufacturer’s server was encrypted. Of the ten apps I looked at, only two had what I would consider an acceptable level of account security measures.”

The two apps that provided the best basic account security out of the ten, according to Zbirka, were Blink and Wyze. The Blink app requires users to enter a one-time password to add a new device, a one-time password to change the account password, and notifies users in case of brute force attempts or when a login is made using a new device. 
...
Continue Reading
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Windows 11 Reaches 72.78% Market Share a...
Windows 11 now run...harlan4096 — 12:58
QOwnNotes
26.3.1  Fixed tex...Kool — 12:26
AMD also launches Ryzen AI PRO 400 for m...
AMD intros Ryzen A...harlan4096 — 10:28
AMD launches Ryzen AI PRO 400G desktop A...
AMD brings Ryzen AI...harlan4096 — 10:26
F-Secure 26.2
Version 26.2​ R...harlan4096 — 08:11

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (44)gapedDow
avatar (38)snorydar
avatar (43)Hectorvot
avatar (51)knowhanPluts
avatar (39)Williamengiz
avatar (46)qaqapeti
avatar (44)battsourIonix
avatar (43)CedricSek
avatar (39)chasRex
avatar (43)slavrProck
avatar (45)Tyesharaike
avatar (49)TomeRerla
avatar (45)walllMIZ
avatar (41)oconyho
avatar (33)uteluxix
avatar (47)piafcflene
avatar (39)Matthewkah
avatar (51)tersfargum
avatar (50)alfreExept
avatar (38)Charlesfibre
avatar (42)napasvem
avatar (44)diploJeoca
avatar (38)francisnj3
avatar (43)artmaGoork
avatar (45)tukraNax
avatar (41)RichardCisee
avatar (40)ebenofit
avatar (38)ykazawu
avatar (41)ARYsahulatbazar

[-]
Online Staff
There are no staff members currently online.

>