UK's National Cyber Security Centre sidles in to help firm behind hacked NurseryCam product secure itself
- Reference: 1614258463
- News link: https://www.theregister.co.uk/2021/02/25/ncsc_nurserycam_security/
- Source link:
Company director Melissa Kao confirmed to The Register that the NCSC, a sibling of UK spy agency GCHQ, was helping the company shore up security after [1]its NurseryCam product was hacked last week.
[2]
"We are aware of this incident and working to fully understand its impact," an NCSC spokesman told The Register .
FootfallCam Ltd is the operator of the NurseryCam brand of web-connected camera services. As its name suggests, NurseryCam is a product deployed in daycare centres so parents can have a look at how junior is getting on.
[3]
The company needs NCSC's help: although we previously reported that users' passwords were hashed in storage, emails from the company shown to The Register by horrified parents confirmed that they were, in fact, being stored without any encryption at all.
"It was a design decision to store passwords in plaintext, which was used for image decryption. The same practice is also made in platforms such as Facebook, Twitter and GitHub," said an email from the firm, adding: "Moving forward, we will be changing to using hashed passwords to improve security measures."
The Register was contacted last week by a hacker who said he had obtained copies of usernames, passwords, users' forenames and surnames, and registered email addresses. On top of that, he also claimed to have accessed the rest of FootfallCam Ltd's web services – including those of its sister company, Meta Technologies.
The point of access was, we were told, a poorly secured Odoo business apps server instance that used a default admin password for its web interface, seemingly relying on security through obscurity.
He told The Register : "Though operating the admin panel requires a password, that password is the same as the default password documented on the main page of the admin panel."
IoT infosec researcher Andrew Tierney, who [4]closely scrutinised the NurseryCam product, confirmed to The Register that the Odoo instance existed not long after we were tipped off about it, though it has since been made inaccessible.
Footfallcam first came to our attention [5]earlier this month after a spat between Laurens Leemans of SignIPS, who analysed a sample of the firm's Footfallcam 3D Plus product, and the firm itself, which had threatened him with a police report unless he deleted tweets he'd made criticising the product's design.
[6]
The NCSC has yet to respond to The Register 's request for additional comment. ®
Get our [7]Tech Resources
[1] https://www.theregister.com/2021/02/22/nurserycam_breach/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YDfXrOvvpcp0thJHgWFH@AAAABQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YDfXrOvvpcp0thJHgWFH@AAAABQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://www.theregister.com/2021/02/18/nurserycam_security_problems_footfallcam_ltd/
[5] https://www.theregister.com/2021/02/12/footfallcam_twitter_kerfuffle/
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YDfXrOvvpcp0thJHgWFH@AAAABQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://whitepapers.theregister.com/
> "It was a design decision to store passwords in plaintext, which was used for image decryption. The same practice is also made in platforms such as Facebook, Twitter and GitHub,"
Leaving aside whether FB, Twitter and Github do this....
There's absolutely no need for the plaintext password to be stored in order to achieve the same thing, you just use something derived from the password (*cough* the hash).
User has password: imaneasypassword
You salt it and hash it to: abcdefabcdef
The input to your encryption function is abcdefabcdef. At the client's end, it salts and hashes the password (it's got it because the user entered it) and uses that to decrypt the images.
It's still not ideal, because it means you're keeping the user's password in memory for longer at the clients end - but that's true of the approach they went with too.
Passwords in plaintext
I was going to post a comment in the spirit of "It should be an offence for anyone to sell a product that does not employ reasonable security including one way encryption for user credentials", but then we've got plenty in UK Govt who want to outlaw effective encryption.
It was a design stupid decision to store passwords in plaintext
FTFY.
Fits well. Indeed, you need a certain level of intelligence to be able to recognize you made a mistake.
"The company needs NCSC's help"
No, laws need to be put in place so that companies / directors can be prosecuted when "security" practices that are not considered to be "best practice" are used - in a similar way that a death due to faulty software will be considered to be due to negligence if evidence* cannot be provided to show that best practice was followed.
* created during development, not after-the-fact.
Re: "The company needs NCSC's help"
I’d prosecute them for the grievous brain damage they caused me banging my head on the table when I read their BS excuse.
"The same practice is also made in platforms such as Facebook, Twitter and GitHub"
Ah, the old "other people are doing it too" excuse.
I want to add "EPIC" to the icon!