News: 1708442112

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Wyze admits 13,000 users could have viewed strangers' camera feeds

(2024/02/20)


Smart home security camera slinger Wyze is telling customers that a cybersecurity "incident" allowed thousands of users to see other people's camera feeds.

Thanks to a helpful Reg reader who sent a customer email over to us, we know that around 13,000 Wyze users had the opportunity to view events captured by other users' cameras.

Wyze said of these 13,000, only 1,504 users actually looked at the feeds of others, willfully or not. This represented around 0.25 percent of all users.

[1]

The company explained that a Friday outage, which it attributed to "our partner [2]AWS , took down Wyze devices for several hours early Friday morning." Wyze said it then experienced a "security issue" when cameras came back online.

[3]

[4]

During the course of normal operation, Wyze cameras capture "Events" – clips of notable activity caught throughout the day which are stored in the Events section of the Wyze app for users to review at their leisure.

As cameras came back online, the circa 13,000 affected users were able to view Events from other users' cameras in their own app. Wyze said it immediately revoked users' access to the Events tab upon realizing the error.

[5]

"The incident was caused by a third-party caching client library that was recently integrated into our system," the email read.

"This client library received unprecedented load conditions caused by devices coming back online all at once. As a result of increased demand, it mixed up device ID and user ID mapping and connected some data to incorrect accounts."

The company introduced a number of measures to prevent the incident from recurring, including adding a new verification layer before users attempt to view Event videos.

[6]

It's also searching for new client libraries which, once chosen will be "thoroughly stress-tested for extreme events." Wyze's system will also bypass caching for checks on user-device relationships until those new client libraries are selected.

"We know this is very disappointing news," the email went to say. "It does not reflect our commitment to protect customers or mirror the other investments and actions we have taken in recent years to make security a top priority at Wyze. We built a security team, implemented multiple processes, created new dashboards, maintained a [7]bug bounty program , and were undergoing multiple third-party audits and penetration testing when this event occurred.

"We must do more and be better, and we will. We are so sorry for this incident and are dedicated to rebuilding your trust.

Online discussions held by Wyze customers have been mostly negative toward the company.

[8]Amazon Ring, Alexa accused of every nightmare IoT security fail you can imagine

[9]Ubiquiti blunder let some folks view others' security cameras, accounts

[10]Network died, hard, during company Christmas party, leaving lone techie to fix it

[11]Eufy security cams 'ignore cloud opt-out, store unique IDs' of anyone who walks by

One user, claiming to be a 23-year-old woman, received an email saying her camera was one of the minority that was accessed. She described the experience as one that left her feeling violated, and that she would no longer be using her cameras.

"I'm so disgusted and upset," she [12]wrote . "I've already deleted my account, but I'm feeling so violated."

Other incensed users have [13]suggested poisoning reviews on iOS and Android app stores, as well as the various Amazon shopping review sections. ®

Get our [14]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZdTavU-sXZ8HhC9tuKAXlQAAAYw&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://www.theregister.com/2023/12/13/aws_sees_direct_uk_government/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZdTavU-sXZ8HhC9tuKAXlQAAAYw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZdTavU-sXZ8HhC9tuKAXlQAAAYw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZdTavU-sXZ8HhC9tuKAXlQAAAYw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZdTavU-sXZ8HhC9tuKAXlQAAAYw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2023/10/27/google_ai_bounty_hackerone/

[8] https://www.theregister.com/2023/06/01/ftc_alexa_ring_amazon_settlement/

[9] https://www.theregister.com/2023/12/15/ubiquiti_camera_privacy/

[10] https://www.theregister.com/2023/07/17/who_me/

[11] https://www.theregister.com/2023/03/17/eufy_lawsuit/

[12] https://www.reddit.com/r/wyzecam/comments/1aulfw4/i_was_watched_by_someone/

[13] https://www.reddit.com/r/wyzecam/comments/1aukv1y/app_store_reviews_are_a_great_way_to_share_the/

[14] https://whitepapers.theregister.com/



usbac

People putting cloud based security cameras in their homes. Who would have thought something would go wrong?

Especially a company run by a bunch of tech-bros that probably runs on a bunch of frameworks stitched together with code from Stack Overflow and hosted on AWS.

Cloud-based security cameras in your home

Anonymous Coward

Do you really think that's Wyze, sir?

'This represented around 0.25 percent of all users'

BinkyTheMagicPaperclip

It may be 0.25% of all users, but 1504 users out of 13,000 is a not inconsiderable 8%, and you can safely bet the number would have been much higher if the access had been left open longer.

There's no sign of anyone following the sensible advice of :

Never buy an IoT device you can't host elsewhere or at home (To be fair, it appears possible to do this for Wyze)

Don't trust the vendor's cloud service. Especially if it's cheap.

If having the data inadvertently exposed is that important or distressing, don't expose it.

Re: 'This represented around 0.25 percent of all users'

pdh

> If having the data inadvertently exposed is that important or distressing, don't expose it.

I wish I could give more than one thumbs-up for that...

MOH

It mixed up the device ID and user ID because it was overloaded? That makes zero sense

"Your butt is mine."
-- Michael Jackson, Bad