Close Menu
Ztoog
    What's Hot
    AI

    Researchers From ETH Zurich and Microsoft Introduce LightGlue: A Deep Neural Network That Learns To Match Local Features Across Images

    Crypto

    Steve Cohen-backed NFT Platform Recur to Close Doors After Raising $50M Just 2 Years Ago

    Technology

    How to activate auto scroll on TikTok

    Important Pages:
    • About Us
    • Contact us
    • Privacy Policy
    • Terms & Conditions
    Facebook X (Twitter) Instagram Pinterest
    Facebook X (Twitter) Instagram Pinterest
    Ztoog
    • Home
    • The Future

      How to Get Bot Lobbies in Fortnite? (2025 Guide)

      Can work-life balance tracking improve well-being?

      Any wall can be turned into a camera to see around corners

      JD Vance and President Trump’s Sons Hype Bitcoin at Las Vegas Conference

      AI may already be shrinking entry-level jobs in tech, new research suggests

    • Technology

      What does a millennial midlife crisis look like?

      Elon Musk tries to stick to spaceships

      A Replit employee details a critical security flaw in web apps created using AI-powered app builder Lovable that exposes API keys and personal info of app users (Reed Albergotti/Semafor)

      Gemini in Google Drive can now help you skip watching that painfully long Zoom meeting

      Apple iPhone exports from China to the US fall 76% as India output surges

    • Gadgets

      Watch Apple’s WWDC 2025 keynote right here

      Future-proof your career by mastering AI skills for just $20

      8 Best Vegan Meal Delivery Services and Kits (2025), Tested and Reviewed

      Google Home is getting deeper Gemini integration and a new widget

      Google Announces AI Ultra Subscription Plan With Premium Features

    • Mobile

      YouTube is testing a leaderboard to show off top live stream fans

      Deals: the Galaxy S25 series comes with a free tablet, Google Pixels heavily discounted

      Microsoft is done being subtle – this new tool screams “upgrade now”

      Wallpaper Wednesday: Android wallpapers 2025-05-28

      Google can make smart glasses accessible with Warby Parker, Gentle Monster deals

    • Science

      Some parts of Trump’s proposed budget for NASA are literally draconian

      June skygazing: A strawberry moon, the summer solstice… and Asteroid Day!

      Analysts Say Trump Trade Wars Would Harm the Entire US Energy Sector, From Oil to Solar

      Do we have free will? Quantum experiments may soon reveal the answer

      Was Planet Nine exiled from the solar system as a baby?

    • AI

      Fueling seamless AI at scale

      Rationale engineering generates a compact new tool for gene therapy | Ztoog

      The AI Hype Index: College students are hooked on ChatGPT

      Learning how to predict rare kinds of failures | Ztoog

      Anthropic’s new hybrid AI model can work on tasks autonomously for hours at a time

    • Crypto

      Bitcoin Maxi Isn’t Buying Hype Around New Crypto Holding Firms

      GameStop bought $500 million of bitcoin

      CoinW Teams Up with Superteam Europe to Conclude Solana Hackathon and Accelerate Web3 Innovation in Europe

      Ethereum Net Flows Turn Negative As Bulls Push For $3,500

      Bitcoin’s Power Compared To Nuclear Reactor By Brazilian Business Leader

    Ztoog
    Home » $30 doorbell cameras have multiple serious security flaws, says Consumer Reports
    Gadgets

    $30 doorbell cameras have multiple serious security flaws, says Consumer Reports

    Facebook Twitter Pinterest WhatsApp
     doorbell cameras have multiple serious security flaws, says Consumer Reports
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp

    Enlarge / Consumer Reports’ investigation means that, ought to this supply particular person press and maintain the bell button after which pair utilizing Eken’s app, he might see if different supply individuals get such a perfunctory response.

    Eken

    Video doorbell cameras have been commoditized to the purpose the place they’re out there for $30–$40 on marketplaces like Amazon, Walmart, Temu, and Shein. The true value of proudly owning one could be a lot better, nonetheless.

    Consumer Reports (CR) has launched the findings of a security investigation into two budget-minded doorbell manufacturers, Eken and Tuck, that are largely the identical {hardware} produced by the Eken Group in China, in response to CR. The cameras are additional resold underneath at the least 10 extra manufacturers. The cameras are arrange via a standard cell app, Aiwit. And the cameras share one thing else, CR claims: “troubling security vulnerabilities.”

    The pairing procedure for one of Eken's doorbell cameras, which offers a malicious actor quite a bit of leeway.
    Enlarge / The pairing process for one in all Eken’s doorbell cameras, which provides a malicious actor fairly a little bit of leeway.

    Eken

    Among the digicam’s vulnerabilities cited by CR:

    • Sending public IP addresses and Wi-Fi SSIDs (names) over the Internet with out encryption
    • Takeover of the cameras by placing them into pairing mode (which you are able to do from a front-facing button on some fashions) and connecting via the Aiwit app
    • Access to nonetheless photos from the video feed and different data by realizing the digicam’s serial quantity.

    CR additionally famous that Eken cameras lacked an FCC license plate. More than 4,200 had been bought in January 2024, in response to CR, and infrequently held an Amazon “Overall Pick” label (as one mannequin did when an Ars author appeared on Wednesday).

    “These video doorbells from little identified producers have serious security and privateness vulnerabilities, and now they’ve discovered their manner onto main digital marketplaces reminiscent of Amazon and Walmart,” stated Justin Brookman, director of tech coverage at Consumer Reports, in a press release. “Both the producers and platforms that promote the doorbells have a accountability to make sure that these merchandise are usually not placing customers in hurt’s manner.”

    Advertisement

    CR famous that it contacted distributors the place it discovered the doorbells on the market. Temu instructed CR that it will halt gross sales of the doorbells, however “similar-looking if not equivalent doorbells remained on the location,” CR famous.

    A Walmart consultant instructed Ars that each one cameras talked about by Consumer Reports, bought by third events, have been faraway from Walmart by now. The consultant added that prospects could also be eligible for refunds, and that Walmart prohibits the promoting of units that require an FCC ID and lack one.

    Ars contacted Amazon for remark and can replace this publish with new data. An e mail despatched to the only deal with that might be discovered on Eken’s web site was returned undeliverable. The firm’s social media accounts had been final up to date at the least three years prior.

    Consumer Reports' researchers claim to have found JPEG file references passed in plaintext over the network, which could later be viewed without authentication in a browser.

    Consumer Reports’ researchers declare to have discovered JPEG file references handed in plaintext over the community, which might later be seen with out authentication in a browser.

    Consumer Reports

    CR issued vulnerability disclosures to Eken and Tuck relating to its findings. The disclosures notice the quantity of knowledge that’s despatched over the community with out authentication, together with JPEG recordsdata, the native SSID, and exterior IP deal with. It notes that after a malicious person has re-paired a doorbell with a QR code generated by the Aiwit app, they have full management over the machine till a person sees an e mail from Eken and reclaims the doorbell.

    With just a few exceptions, video doorbells and different IoT cameras are inclined to depend on cloud connections to stream and retailer footage, in addition to notify their homeowners about occasions. This has led to some notable privateness and security considerations. Ring doorbells had been discovered to be pushing Wi-Fi credentials in plaintext in late 2019. Eufy, an organization that marketed its “No clouds” choices, was discovered to be importing facial thumbnails to cloud servers to ship push alerts, and later apologized for that and different vulnerabilities. Camera supplier Wyze just lately disclosed that, for the second time in 5 months, photos and video feeds had been by chance out there to the incorrect prospects following a prolonged outage.

    Listing picture by Amazon/Eken

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp

    Related Posts

    Gadgets

    Watch Apple’s WWDC 2025 keynote right here

    Gadgets

    Future-proof your career by mastering AI skills for just $20

    Gadgets

    8 Best Vegan Meal Delivery Services and Kits (2025), Tested and Reviewed

    Gadgets

    Google Home is getting deeper Gemini integration and a new widget

    Gadgets

    Google Announces AI Ultra Subscription Plan With Premium Features

    Gadgets

    Google shows off Android XR-based glasses, announces Warby Parker team-up

    Gadgets

    The market’s down, but this OpenAI for the stock market can help you trade up

    Gadgets

    We Hand-Picked the 24 Best Deals From the 2025 REI Anniversary Sale

    Leave A Reply Cancel Reply

    Follow Us
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    Top Posts
    Gadgets

    CD-indexing cue files are the core of a serious Linux remote code exploit

    Enlarge / Cue files was a lot better-known, again once we all used CD-Rs to…

    Mobile

    JCB Toughphone and Toughphone Max announced

    JCB – the British heavy gear producer – is again on the smartphone scene with…

    Crypto

    Bitcoin Set To Lead A New Crypto Surge As Downside Factors Get Exhausted

    Bitcoin may at present be buying and selling under a $43,500 resistance stage, however analysts…

    Technology

    Google says the vast majority of AI Overviews provide high-quality information and many of the viral examples have been uncommon queries or have been doctored (Peter Kafka/Business Insider)

    Peter Kafka / Business Insider: Google says the vast majority of AI Overviews provide high-quality…

    AI

    Eric Evans receives Department of Defense Medal for Distinguished Public Service | Ztoog

    On May 31, the U.S. Department of Defense’s chief know-how officer, Under Secretary of Defense…

    Our Picks
    The Future

    Google Pixel 8 Pro vs. iPhone 15 Pro Max, Galaxy S23 Ultra: Top-End Phones Compared

    Crypto

    NFT Marketplaces Witness Dramatic Reduction in Ethereum Fees

    Mobile

    Snapdragon 8 Gen 3 vs Dimensity 9300 benchmarked

    Categories
    • AI (1,494)
    • Crypto (1,754)
    • Gadgets (1,806)
    • Mobile (1,852)
    • Science (1,868)
    • Technology (1,804)
    • The Future (1,650)
    Most Popular
    Gadgets

    First wave of AAA iPhone games sees a big new release—and a notable delay

    The Future

    You can now enjoy BINGE and Kayo Sports on Fire TV

    Technology

    Canada’s Online News Act Targets Facebook and Google

    Ztoog
    Facebook X (Twitter) Instagram Pinterest
    • Home
    • About Us
    • Contact us
    • Privacy Policy
    • Terms & Conditions
    © 2025 Ztoog.

    Type above and press Enter to search. Press Esc to cancel.