Thread Rating:
  • 1 Vote(s) - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Avast Blog_Security News: What is credential stuffing, and why is my smart security c
#1
Information 
Quote:
[Image: TVDumYE.png]

Protect yourself from one of today’s top threats and keep hackers from your security camera accounts

Imagine that the very security tool you put in place to keep intruders out of your home is suddenly being used as a doorway in. This nightmare is a reality for an increasing number of victims.

As reported by The Washington Post, the California mom of a toddler was horrified by this type of discovery. After hearing her daughter repeatedly talk about “a monster” in her room, the woman uncovered something more disturbing. Hackers had somehow taken over the family’s security cam account and started using the intercom feature to transmit pornographic audio into her 2-year-old’s room.

Unfortunately, this experience is not unique. Hackers hoping to exploit weak security features will try to open the metaphoric doors of consumer products like security cams every chance they can. Also, a technique called “credential stuffing” has evolved into an effortless hack for even a novice cybercriminal.

Why are security cams easy to hack?

Security installed on Nest security cams and other IoT consumer devices can create what Silicon Valley insiders call “friction” – barriers that keep a user from having a smooth and successful experience with the product. Examples of friction include too many screens to tap through, too complicated an assembly instruction, too inconvenient a security procedure, and so on. The less friction a product has, the wider its appeal.

Because IoT tech can intimidate anyone who is not digitally well-versed, new products have to seem easy to set up and easy to use. To draw the most customers, some IoT developers choose not to add even basic security setup features like prompting a default password change or 2-factor authentication (2FA). Weak security like this leaves your home network vulnerable to cyberattacks, including one of today’s most popular exploits — credential stuffing.

What is credential stuffing?

Credential stuffing is one of the simplest cybercriminal exploits, a favorite among hackers. Using this technique, the criminal collects your leaked credentials (usually stolen in a data breach) and then applies them to a host of other accounts, hoping they unlock more.

For example, let’s say you shop online at Target, and hackers breach the company’s database. Using your stolen credentials, they can then use credential stuffing to attempt logins on bank sites, social media sites, email servers, and more. If you’re like the majority of users out there, you reuse credentials. Hackers count on it.

Advancements in technology have made it easier than ever to launch a credential stuffing exploit. As TWP reports:

A new breed of credential-stuffing software programs allows people with little to no computer skills to check the log-in credentials of millions of users against hundreds of websites and online services such as Netflix and Spotify in a matter of minutes.

How do I make sure nobody hacks my security cam?

Check out our 5 tips for protecting your security camera from cybercriminals. Critically, make sure you always use a unique, complex password for logging into accounts, such as for IoT devices.
Continue Reading
[-] The following 1 user says Thank You to harlan4096 for this post:
  • ismail
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
F-Secure 19.4
What's new in the ...harlan4096 — 09:44
Thunderbird Supernova 115.10.1
Thunderbird Supern...harlan4096 — 09:41
Microsoft Edge 124.0.2478.51
Version 124.0.2478...harlan4096 — 09:40
Rogue Anti-Malware 15.16.1
V15.16.1 04/12/202...harlan4096 — 09:39
Intel Xeon 6 6980P “Granite Rapids-AP” C...
Intel Xeon 6 specs...harlan4096 — 09:37

[-]
Birthdays
Today's Birthdays
avatar (36)RobertUtelt
Upcoming Birthdays
avatar (43)wapedDow
avatar (42)techlignub
avatar (41)Stevenmam
avatar (48)onlinbah
avatar (49)steakelask
avatar (43)Termoplenka
avatar (41)bycoPaist
avatar (47)pieloKat
avatar (41)ilyagNeexy
avatar (49)donitascene
avatar (49)Toligo

[-]
Online Staff
There are no staff members currently online.

>