News: 1613649669

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Nurserycam horror show: 'Secure' daycare video monitoring product beamed DVR admin creds to all users

(2021/02/18)


Updated A parental webcam targeted at nursery schools was so poorly designed that anyone who downloaded its mobile app gained access to admin credentials, bypassing intended authentication, according to security pros – with one dad saying its creators brushed off his complaints about insecurities six years ago.

Anyone could have logged into Nurserycam's DVRs thanks to poor design choices – and a decision to "authenticate" logins by passing the device's admin username and password to parents, claimed a reverse engineer who looked into the matter.

[1]

Melissa Kao, a director of Footfallcam Ltd, the firm behind Nurserycam, insisted to The Register that what infosec researchers had found was "legacy non-functional codes" [sic] that were "there to distract hackers".

Footfallcam Ltd was recently seen on The Register after it threatened an infosec researcher with a baseless police report [2]unless he deleted a Twitter thread pointing out one of its products' shortcomings.

[3]

Internet of Things security prober Andrew "Cybergibbons" Tierney [4]published a warning to Nurserycam's users after realising how insecure the product was. He wrote: "These issues would allow any parent, past or present, to access the video feeds from the nursery. There is also the chance that anyone on the Internet could have accessed them."

Nurserycam is an internet-connected DVR with a port-forwarding firewall in front of it, taking its feed from CCTV cameras deployed inside nurseries and pointed at the children. The idea is to let parents monitor their children remotely. Several nurseries (daycare centres for preschool kids aged six months to five years) around the UK appear to have deployed the system, judging by search results for the Nurserycam name.

You get an admin password, you get an admin password, you too!

Tierney held that if a person knew the IP address for one of Nurserycam's DVRs, they could log into the device and view live camera feeds thanks to the system's poor design. They could even have viewed up to 18 months of footage featuring children and nursery workers, he added.

Tierney, who spoke extensively to The Register , explained in his blog: "For all parents connecting to a given nursery, they are given the same username and password for the DVR. In the examples I have been shown, the username is admin and the password are obvious words followed by 888. This means that the parents, past and present, have all been given the administrator password for the DVR."

We understand that the admin credentials were visible in the source of the webpage shown to parents using Nurserycam's web app to access the live camera feeds of children. Moreover, those admin passwords were not unique to each DVR.

Nurserycam's Kao insisted that the DVRs' default passwords were changed after installation. Tierney told El Reg that parent users of the app at different nurseries had confirmed to him this was not true.

Pattern of behaviour

A parent who spoke to The Register and asked not to be named said he had reported similar flaws to Nurserycam back in 2015 – and was brushed off by Kao. At the time, this father had realised that any Nurserycam video feed could be viewed by simply changing the URL in the web browser: a flaw known in infosec as an insecure direct object reference (IDOR) vulnerability.

While the vuln was eventually fixed, the dad recounted to us how Kao had phoned him after his initial report direct to the company – and had initially refused to identify herself.

El Reg has reviewed evidence showing the firm seemed more concerned with knowledge of the flaws being made public than with remediation, [5]similar to last week's Footfallcam debacle (where Kao's fellow Footfallcam Ltd director, Edward Wong, threatened an infosec bod with a police report unless he deleted Twitter criticism of another product's poor design). While there were no specific threats made, it appeared removing this criticism was of greater importance to the company than fixing its product's security shortcomings, which seemingly were still a problem six years later.

Controversies in the lively UK infosec world over insecure IoT products and poor responses by industry to security issues are not unusual. However, when live video feeds of young children are freely available online to anyone with just a little technical knowhow, the people behind that system have a moral imperative to act fast.

It is also important that end users of those products – nurseries and parents alike – are aware that Nurserycam's claims that its video streams were "safer than online banking" were simply not true.

While Footfallcam Ltd claims it has fixed the vulnerabilities Tierney (and others) highlighted, it [6]appears , at the time of writing, that these fixes apply only a basic level of security that ought to have been in place for years.

We have asked the Information Commissioner's Office for comment. ®

Bootnote

A [7]Twitter thread prompted by the controversies over this company's practices makes eye-opening reading, though The Register has not verified its contents.

Updated to add

An ICO spokesperson said: "Children's personal information – including images – requires specific protection under data protection law. Any company or organisation processing children's data must make sure they have appropriate security measures in place to protect this data, and should carry out a risk assessment beforehand.

[8]

"When an organisation buys in products or services that will be involved in the processing, they need to ensure that they choose ones that are designed with data protection in mind. This is part of a data protection by design approach and can help them to protect children's personal information. Organisations should consider these issues when doing their risk assessment."

Get our [9]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YC6dJyFSv60KSe7bkHzGcAAAANM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://www.theregister.com/2021/02/12/footfallcam_twitter_kerfuffle/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YC6dJyFSv60KSe7bkHzGcAAAANM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://cybergibbons.com/security-2/a-warning-to-users-of-nurserycam/

[5] https://www.theregister.com/2021/02/12/footfallcam_twitter_kerfuffle/

[6] https://twitter.com/cybergibbons/status/1361617789644070914

[7] https://twitter.com/_MG_/status/1359582075439882240

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YC6dJyFSv60KSe7bkHzGcAAAANM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://whitepapers.theregister.com/

Simple Answer.

IGotOut

Anything where "Think of the children" is concern, drop an email to the Daily Mail.

They love this shit, by the time the article is published, it will be Pedos (sic), the Chinese and ISIS watching naked children via online security cameras. Boris Johnson said to be fuming and asks for stricter border controls....except those that may have covid, then its ok, especially if it's a business trip, or you can afford the fine, or you're a MP, then just say sorry.

bought one webcam 2 years

Anonymous Coward

Reputable shop in Switzerland. All marks were ticked on the box. 200 CHF anyway.

When I read the config instructions, I couldn't believe what I was reading:

- USB cable was only for power, so no config here

- config guide:

- download an app for a smartphone (done by a chinses manufacturer)

- configure wifi just for the app (why it couldn't use my smartphone one was not said)

- wifi key could only be between 5 chars and 12. No idea why.

- then after press of buttons, the CAM would emit some sort sound, yes *morse* style then autoconfig, using the phone mic whatever that meant

Needless to say, the sound stuff never worked. One hour after, everything went back into parcel.

I did some research and this manufacturer, call Swisstel is known nowhere. And after looking again, I discovered the look and specs were *entirely* the same as some known reputable model.

Yup, counterfeit !

Went to the shop saying it doesn't work and they gave my money back.

I also told them they're fake, but they never wanted to believe me.

Shittest product I ever bought for 200CHF !

Re: bought one webcam 2 years

Alan Brown

" I discovered the look and specs were *entirely* the same as some known reputable model."

Because they're vitually ALL based on HiSilicon embedded DVR chips (used in both DVRs and IP cameras) using XiaongMai (XM Eye) monolithic block code

The stuff is a (badly encrypted) monolithic block embedded in a Linux system. The "moinolith" is full of GPL symbols, but XMEye have been screaming to all and sundry about "Piracy" and threatening researchers for a while

Neither Huawei, XiaongMai (or any of the reselelrs) respond to GPL requests and the only response I've had so far is the standard chinese fiction that GPL == Opensource ==public domain "therefore we can do what we want with it and we don't have to disclose anytning to YOU"

Incidentally I have virtually exactly the same response from local Chinese (PRC or Taiwan) researchers who are clearly using GPL complonents in their work.

It's clear that some kind of misinformation campaign has been going on about GPL which has taken root across chinese language countries. Remember all those GPL-violations cases in Europe against D-link, etc? These are exactly the same arguments as were raised back then.

FootfallCam

Oh Matron!

Makes the antics of Travis Kalanick, author of "How to nearly drive (sic) a buisness into the ground" look tame

A wretched hive of scum & villainy

KarMann

When I read the Footfallcam article the other day, and [1]some kindly AC posted a link to their Companies House listing, I got nosy & curious and looked at [2]their address on Google Maps , and lo and behold, also 'at this place' were a couple called Magic Mirror & NurseryWeb. I figured they probably had similar QC issues, and would be interesting to look into more deeply. Sure enough, here we are.

[1] https://forums.theregister.com/forum/all/2021/02/12/footfallcam_twitter_kerfuffle/#c_4204300

[2] https://goo.gl/maps/utu13465F9X5ZGDQ7

iron

> any Nurserycam video feed could be viewed by simply changing the URL in the web browser: a flaw known in infosec as sheer incompetent dumbassery

FTFY

I will be forwarding this article to all my relativces who have small children. Not that any of them will understand it or pay any attention but at least I will have tried.

heyrick

Forward it to the nurseries - don't they have some degree of liability for installing the system in the first place?

Alan Brown

Yes they do, and it's a _vicarious_ liability (which means they're liable even if they weren't aware of it)

Don't forward it to the nurseries, forward it to a few parenting groups and emphasise that the response of the company to being told they had a security problem was to go on the offensive against the reporter rather than fix it, so anyone using a nursery has an interest in knowing what's being used becausesome of the suppliers are in denial

Doctor Syntax

"Yes they do, and it's a _vicarious_ liability (which means they're liable even if they weren't aware of it)

Don't forward it to the nurseries"

The nurseries are the people to forward it to in the first instance, pointing out that they're using a product which opens them up to GDPR complaints from the parents. If they don't react then forward it to the parents. The probably non-technical but responsible nurseries will realise their problem and tackle it at stage one. It's the ones who don't who deserve a GDPR case against them at stage 2.

Anonymous Coward

There are different kinds of nurseries. A broad spectrum from the "daycare" kind that provides a couple of minimally trained year old girls to babysit a bunch of screaming toddlers for 8 hours a day, to the "Montessori school " kind which help the kids develop useful skills.

The thing that they all have in common is poor understanding of IT. Nursery staff generally do not have the skills to evaluate and test the security of IP cameras. So they buy in a system from companies who claim to be experts in that field. Unfortunately sometimes those companies are not really experts at all.

The whole IT industry is based upon vendors telling lies about their products and customers not really understanding what they are buying. As much as the buyer should beware, the responsibility for faulty products lies with the vendor.

Scary

Ben Tasker

> El Reg has reviewed evidence showing the firm seemed more concerned with knowledge of the flaws being made public than with remediation, similar to last week's Footfallcam debacle (where Kao's fellow Footfallcam Ltd director, Edward Wong, threatened an infosec bod with a police report unless he deleted Twitter criticism of another product's poor design).

This is the bit that's _really_ scary. All products have bugs (some serious, like this, others minor).

What really sets companies/products apart is how they handle this reality. Do they

- Actively look for bugs/weaknesses and/or fix quickly when issues are reported to them

- Yell "nananana can't hear you" and/or "I'll sue you" at anyone who points out flaws

It's not just the flaws in Nurserycam/Footfallcam that should put them out of business, but the fact that they were aware of significant and trivial flaws in their product, and did nothing, and then when they were told about it again, tried to confuse the issue so that they could - again - do nothing.

That kind of "fuck you, I'm not fixing it" mindset does not belong anywhere near *anything* that gets even remotely close to kids (or, adults really).

herman

So, people get all upset when a camera that is made to be watched, is watched? Or are they annoyed because nobody watches the watcher?

This is GDPR infose stage 2 - denial

0laf

Stage one was - ignore it

Most major vendors I've run into in the last 12-24 months have successfully completed GDPR stage 1 which was to completely ignore the legislation and pretend nothing was happening. This allowed them to avoid any additional costs for development work that would have been needed to actually be compliant with GDPR.

Since most existing customers were already in contracts the ICO allowed these to continue under the old DPA, so as far as the vendors were concerned all was well.

We're now well into stage 2 - Now that those old DPA 1998 contract are expiring savvy customers are now asking difficult questions about product compliance with GDPR (DPA 2018). Since those vendors did fuck all in the years they should have been getting ready for GDPR and preparing for the post DPA 2018 world their products now look woefully inadequate in terms of security. However not to worry, especially if you are a near monopoly provider. Just deny the insecurity in your products, state it's secure 'enough' safe in the knowledge your customer has nowhere to go and the ICO is pretty likely to do bugger all unless you get hacked. If you do get hacked don't forget your handy "Dido Harding" phrase book - sophisticated hack, personal data is our top priority yadda yadda yadda.

Personally I'm keenly awaiting stage 3 -blind panic.

This will come after a couple of major hacks when ministers feel they have to get of their arses and pass the blame onto someone. The ICO will pick a few juicy targets to take tro court and fall out should make enough waves in the market that someone might actually open the coffers enough to get things brought up to minimum standards.

BTW if you are a vendor and relying on username and password to protect a web exposed system processing personal or special category data it really isn't fucking good enough, and a PIN sent via email is not "taking consideration of the state of the art" under Article 32 of the Regulation.

If you don't really know what MFA is stop trying to bullshit the people who do know, you just look stupid

And for this bucch of muppets "Melissa Kao, a director of Footfallcam Ltd, the firm behind Nurserycam, insisted to The Register that what infosec researchers had found was "legacy non-functional codes" [sic] that were "there to distract hackers" '. I really wish I was there to hear to say that crap to the ICO

Re: This is GDPR infose stage 2 - denial

Alan Brown

" I really wish I was there to hear to say that crap to the ICO"

There's a real problem with the enforcement side though:

The ICO is (deliberately) not resourced to do much more than token enforcement, nor do ICO directors WANT enforcement taking place - particularly against any company which is part of the "chumocracy"

Various long-established people in the industy have been throwing thei rhands up in despair about dealing with the ICO - particularly under the current government where it's been clear for the last 8 years that the political appointees at the time are doing everything they can to _block_ most investigations, particularly if the company directors involved have "the right political contacts"

Such an ethical company

Alan Brown

I'm sure people are falling over themselves to do business with them....

After all, what could possibly go pearshaped?

Doctor Syntax

I wonder what they'd do if someone took "legacy non-functional codes" [sic] that were "there to distract hackers" literally and twiddled a few of these non-functional codes to not change the user IDs and passwords - which they obviously can't change if they're non-functional. At a guess scream that they've been hacked.

The greatest griefs are those we cause ourselves.
-- Sophocles