Saturday, August 23, 2025
  • Login
Euro Times
No Result
View All Result
  • Home
  • Finance
  • Business
  • World
  • Politics
  • Markets
  • Stock Market
  • Cryptocurrency
  • Investing
  • Health
  • Technology
  • Home
  • Finance
  • Business
  • World
  • Politics
  • Markets
  • Stock Market
  • Cryptocurrency
  • Investing
  • Health
  • Technology
Euro Times
No Result
View All Result

Anker’s Eufy lied to us about the security of its security cameras

by Sean Hollister
December 1, 2022
in Technology
Reading Time: 10 mins read
A A
0
Home Technology
Share on FacebookShare on Twitter


Anker has built a remarkable reputation for quality over the past decade, building its phone charger business into an empire spanning all sorts of portable electronics — including the Eufy home security cameras we’ve recommended over the years. Eufy’s commitment to privacy is remarkable: it promises your data will be stored locally, that it “never leaves the safety of your home,” that its footage only gets transmitted with “end-to-end” military-grade encryption, and that it will only send that footage “straight to your phone.”

So you can imagine our surprise to learn you can stream video from a Eufy camera, from the other side of the country, with no encryption at all.

Part of Anker’s Eufy “privacy commitment”.
Screenshot by Sean Hollister / The Verge

Worse, it’s not yet clear how widespread this might be — because instead of addressing it head-on, the company falsely claimed to The Verge that it wasn’t even possible.

On Thanksgiving Day, infosec consultant Paul Moore and a hacker who goes by Wasabi both alleged that Anker’s Eufy cameras can stream encryption-free through the cloud — just by connecting to a unique address at Eufy’s cloud servers with the free VLC Media Player.

When we asked Anker point-blank to confirm or deny that, the company categorically denied it. “I can confirm that it is not possible to start a stream and watch live footage using a third-party player such as VLC,” Brett White, a senior PR manager at Anker, told me via email.

But The Verge can now confirm that’s not true. This week, we repeatedly watched live footage from two of our own Eufy cameras using that very same VLC media player, from across the United States — proving that Anker has a way to bypass encryption and access these supposedly secure cameras through the cloud.

There is some good news: there’s no proof yet that this has been exploited in the wild, and the way we initially obtained the address required logging in with a username and password before Eufy’s website will cough up the encryption-free stream. (We’re not sharing the exact technique here.)

Also, it seems like it only works on cameras that are awake. We had to wait until our floodlight camera detected a passing car, or its owner pressed a button, before the VLC stream came to life.

Your camera’s 16-digit serial number — likely visible on the box — is the biggest part of the key

But it also gets worse: Eufy’s best practices appear to be so shoddy that bad actors might be able to figure out the address of a camera’s feed — because that address largely consists of your camera’s serial number encoded in Base64, something you can easily reverse with a simple online calculator.

The address also includes a Unix timestamp you can easily create, a token that Eufy’s servers don’t actually seem to be validating (we changed our token to “arbitrarypotato” and it still worked), and a four-digit random hex whose 65,536 combinations could easily be brute forced.

“This is definitely not how it should be designed,” Mandiant vulnerability engineer Jacob Thompson tells The Verge. For one thing, serial numbers don’t change, so a bad actor could give or sell or donate a camera to Goodwill and quietly keep watching the feeds. But also, he points out that companies don’t tend to keep their serial numbers secret. Some stick them right on the box they sell at Best Buy — yes, including Eufy.

On the plus side, Eufy’s serial numbers are long at 16 characters and aren’t just an increasing number. “You’re not going to be able to just guess at IDs and begin hitting them,” says Mandiant Red Team consultant Dillon Franke, calling it a possible “saving grace” of this disclosure. “It doesn’t sound quite as bad as if it’s UserID 1000, then you try 1001, 1002, 1003.”

It could be worse. When Georgia Tech security researcher and Ph.D. candidate Omar Alrawi was studying poor, smart home practices in 2018, he saw some devices substituting their own MAC address for security — even though a MAC address is only twelve characters long, and you can generally figure out the first six characters just by knowing which company made a gadget, he explains.

“The serial number now becomes critical to keep secret.”

But we also don’t know how else these serial numbers might leak, or if Eufy might even unwittingly provide them to anyone who asks. “Sometimes there are APIs that will return some of that unique ID information,” says Franke. “The serial number now becomes critical to keep secret, and I don’t think they’d treat it that way.”

Thompson also wonders whether there are other potential attack vectors now that we know Eufy’s cameras aren’t wholly encrypted: “If the architecture is such that they can order the camera to start streaming at any time, anyone with admin access has the ability to access the IT infrastructure and watch your camera,” he warns. That’s a far cry from Anker’s claim that footage is “sent straight to your phone—and only you have the key.”

By the way, there are other worrying signs that Anker’s security practices may be much, much poorer than it has let on. This whole saga started when infosec consultant Moore started tweeting accusations that Eufy had violated other security promises, including uploading thumbnail images (including faces) to the cloud without permission and failing to delete stored private data. Anker reportedly admitted to the former, but called it a misunderstanding.

Most worrying if true, he also claims that Eufy’s encryption key for its video footage is literally just the plaintext string “ZXSecurity17Cam@”. That phrase also appears in a GitHub repo from 2019, too.

Anker didn’t answer The Verge’s straightforward yes-or-no question about whether “ZXSecurity17Cam@” is the encryption key.

We couldn’t get more details from Moore, either; he told The Verge he can’t comment further now that he’s started legal proceedings against Anker.

Now that Anker has been caught in some big lies, it’s going to be hard to trust whatever the company says next — but for some, it may be important to know which cameras do and do not behave this way, whether anything will be changed, and when. When Wyze had a vaguely similar vulnerability, it swept it under the rug for three years; hopefully, Anker will do far, far better.

Some may not be willing to wait or trust anymore. “If I came across this news and had this camera inside my home, I’d immediately turn it off and not use it, because I don’t know who can view it and who cannot,” Alrawi tells me.

Wasabi, the security engineer who showed us how to get a Eufy camera’s network address, says he’s ripping all of his out. “I bought these because I was trying to be security conscious!” he exclaims.

With some specific Eufy cams, you could perhaps try switching them to use Apple’s HomeKit Secure Video instead.

With reporting and testing by Jen Tuohy and Nathan Edwards





Source link

Tags: AnkerscamerasEufyliedsecurity
Previous Post

Hackers dump more customer data from Australian insurer Medibank By Reuters

Next Post

Blade Air Mobility: Set For Urban Air Mobility Future (NASDAQ:BLDE)

Related Posts

The Trump administration’s big Intel investment comes from already awarded grants

The Trump administration’s big Intel investment comes from already awarded grants

by Anthony Ha
August 23, 2025
0

Intel formally introduced an settlement with President Donald Trump’s administration on Friday afternoon, following Trump’s assertion that the federal government...

Q&A with David Luan, head of Amazon’s AGI research lab, on leaving Adept in a reverse acquihire deal, why he believes progress on AI models has slowed, and more (Alex Heath/The Verge)

Q&A with David Luan, head of Amazon’s AGI research lab, on leaving Adept in a reverse acquihire deal, why he believes progress on AI models has slowed, and more (Alex Heath/The Verge)

by Euro Times
August 23, 2025
0

Featured Podcasts Large Know-how Podcast: The Large GPT-5 Debate, Sam Altman's AI Bubble, OnlyFans Chatbots The Large Know-how Podcast takes...

This 9-in-1 off-grid portable power station has a 17-year lifespan – and it’s over 50% off

This 9-in-1 off-grid portable power station has a 17-year lifespan – and it’s over 50% off

by Adrian Kingsley-Hughes
July 6, 2025
0

ZDNET's key takeaways The Bluetti Elite 200 V2 is a strong but compact transportable energy station, about half the scale...

Netflix explains how it’s quietly upgraded the image quality of your favorite movies and TV shows – and it’s all about film grain

Netflix explains how it’s quietly upgraded the image quality of your favorite movies and TV shows – and it’s all about film grain

by Sam Kieldsen
July 6, 2025
0

Netflix's new AV1 Movie Grain Synthesis tech boosts picture high qualityIt additionally reduces file measurement and improves streaming efficiencyThe tech...

How to Watch Palmeiras vs. Chelsea From Anywhere for Free: Stream FIFA Club World Cup Soccer

How to Watch Palmeiras vs. Chelsea From Anywhere for Free: Stream FIFA Club World Cup Soccer

by Kevin Lynch
July 6, 2025
0

See at DAZN Watch the FIFA Membership World Cup free of charge DAZN 61% off with 2yr plan (+4 free...

Hubble Observations Give Forgotten Globular Cluster Its Moment to Shine

Hubble Observations Give Forgotten Globular Cluster Its Moment to Shine

by Gadgets 360 Staff
July 6, 2025
0

A hanging new picture captured by NASA's Hubble House Telescope has make clear an underexplored gatekeeper of our galactic neighbours'...

Next Post
Blade Air Mobility: Set For Urban Air Mobility Future (NASDAQ:BLDE)

Blade Air Mobility: Set For Urban Air Mobility Future (NASDAQ:BLDE)

Sam Bankman-Fried to New York Times: “I Wasn’t Running Alameda”

Sam Bankman-Fried to New York Times: "I Wasn't Running Alameda"

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Jewish people hit with paint during clash at German protest camp

Jewish people hit with paint during clash at German protest camp

August 23, 2025
The Trump administration’s big Intel investment comes from already awarded grants

The Trump administration’s big Intel investment comes from already awarded grants

August 23, 2025
Bitcoin On-Chain Model Reveals Critical Support At 4,000-8,000

Bitcoin On-Chain Model Reveals Critical Support At $104,000-$108,000

August 23, 2025
Foxconn Recalls Over 300 Chinese Engineers In Latest Setback For Apple’s India Expansion

Foxconn Recalls Over 300 Chinese Engineers In Latest Setback For Apple’s India Expansion

August 23, 2025
Bitcoin Price Watch: Momentum Wavers at 5K—What Comes Next?

Bitcoin Price Watch: Momentum Wavers at $115K—What Comes Next?

August 23, 2025
Medtronic makes two key additions to its board. How activist Elliott can build shareholder value

Medtronic makes two key additions to its board. How activist Elliott can build shareholder value

August 23, 2025
Euro Times

Get the latest news and follow the coverage of Business & Financial News, Stock Market Updates, Analysis, and more from the trusted sources.

CATEGORIES

  • Business
  • Cryptocurrency
  • Finance
  • Health
  • Investing
  • Markets
  • Politics
  • Stock Market
  • Technology
  • Uncategorized
  • World

LATEST UPDATES

Jewish people hit with paint during clash at German protest camp

The Trump administration’s big Intel investment comes from already awarded grants

  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2022 - Euro Times.
Euro Times is not responsible for the content of external sites.

No Result
View All Result
  • Home
  • Finance
  • Business
  • World
  • Politics
  • Markets
  • Stock Market
  • Cryptocurrency
  • Investing
  • Health
  • Technology

Copyright © 2022 - Euro Times.
Euro Times is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In