top | item 22814960

(no title)

quit32 | 5 years ago

Great write up. I agree I do not trust them very much and would not use them on a network that has internet access.

They are a great cheap option when using their custom RTSP firmware with synology surveillance stations. I throw them on their own SSID that is isolated from other local networks and does not have internet access. The SS can reach into their network but they can't initiate connections out.

Still they briefly need internet when setting up to enable RTSP but I'm more concerned about them being remotely accessible at anytime and having access to anything else on my network. Even my setup would allow my email and the isolated network's topo to leak bc of brief internet access.

discuss

order

runnerup|5 years ago

I don't think that was a great write up. I'm no panda-hugger but I was hoping for evidence/walk-through for the following claims made in the article, and I didn't find any direct evidence in the article. Did I not read it closely enough? (Pretty sure the claims are made without support)

> Yi Camera is a front for the Chinese Ministry of State Security. Full stop.

> Yi Cameras send all customer data to Xiaomi as I have previously claimed with Wyze.

40four|5 years ago

To be fair, I updated the link to the the ‘tags’ page, since it includes the whole series, after @quit32 commented. They might have been referring to one of the first couple in the series , the link originally pointed to #1.

Honestly I’m not familiar with the Yi cameras, I haven’t read that newest post, I’ll have to look into it. But, 12 Security is credited with disclosing the 2nd Wyze security breach in December 2019 (the 1st one not even a full calendar year before).

Wyze reluctantly admitted the breach days later, but went into damage control mode, claiming the DB was only exposed for part of the month of December. 12 Security says otherwise, that it was exposed for the majority of the calendar year, and many parties across the globe accessed it according to logs.

https://web.archive.org/web/20200306023236/https://www.nytim...

40four|5 years ago

That’s interesting usage. I wasn’t aware of the Synology products, I’ll admit I’m not very knowledgeable about security systems. Sounds like you take proper precautions!