Family traumatized after Nest system hacked by stranger(fox4kc.com)
fox4kc.com
Family traumatized after Nest system hacked by stranger
https://fox4kc.com/2018/10/31/family-traumatized-after-home-monitoring-system-hacked-by-stranger/
74 comments
Article text:
LONG ISLAND, N.Y. -- A mother in Long Island says a stranger hacked her family’s Nest camera and tried having a conversation with her five-year-old son, according to WPIX.
Nest ads will show you beautiful images of mother nature captured on their outdoor cameras, life’s silly moments and even those moments when your child is up to no good. But for this Long Island mother, the Nest cam she and her husband set up around their home to act as a nanny cam became a full-on nightmare.
“My son came running out of the playroom and found me in the kitchen and said 'it’s not daddy talking to me. It’s not daddy.'”
Nearly every day, after school, this mother, who asked PIX11 to hide her identity, said her 5-year-old son chats with her husband through the Nest cam, a home monitoring system users can connect through their cell phones. This time, however, it was a complete stranger on the other end.
“He asked my son if he took the school bus home and he was asking him about the toys he was playing with and when my son said 'mommy, mommy,' he told him to shut up,” she recalled.
When she walked into her child’s playroom, the ominous voice addressed her directly.
Now she is frightened and wonders how long a complete stranger was watching her family. Since this frightening violation, this mother called police, who, while sympathetic, said there was little they could do.
As for Nest? She was simply told to change her password and switch to a two-factor verification when logging on, but for this mom it’s not enough. She wants to speak out to warn others about this potential danger lurking in their home.
A Nest spokesperson responded to our request for comment and issued this statement:
"We have seen instances where a small number of Nest customers have re-used passwords that were previously exposed through breaches on other websites, and made public. None of these breaches involved Nest. This exposes these customers to other people using the credentials to log into their Nest account. We are proactively alerting affected customers to reset their passwords and set up two-factor authentication, which adds another layer of account security. Customers can reach out to Nest customer support with questions or report anything suspicious to [email protected]."
LONG ISLAND, N.Y. -- A mother in Long Island says a stranger hacked her family’s Nest camera and tried having a conversation with her five-year-old son, according to WPIX.
Nest ads will show you beautiful images of mother nature captured on their outdoor cameras, life’s silly moments and even those moments when your child is up to no good. But for this Long Island mother, the Nest cam she and her husband set up around their home to act as a nanny cam became a full-on nightmare.
“My son came running out of the playroom and found me in the kitchen and said 'it’s not daddy talking to me. It’s not daddy.'”
Nearly every day, after school, this mother, who asked PIX11 to hide her identity, said her 5-year-old son chats with her husband through the Nest cam, a home monitoring system users can connect through their cell phones. This time, however, it was a complete stranger on the other end.
“He asked my son if he took the school bus home and he was asking him about the toys he was playing with and when my son said 'mommy, mommy,' he told him to shut up,” she recalled.
When she walked into her child’s playroom, the ominous voice addressed her directly.
Now she is frightened and wonders how long a complete stranger was watching her family. Since this frightening violation, this mother called police, who, while sympathetic, said there was little they could do.
As for Nest? She was simply told to change her password and switch to a two-factor verification when logging on, but for this mom it’s not enough. She wants to speak out to warn others about this potential danger lurking in their home.
A Nest spokesperson responded to our request for comment and issued this statement:
"We have seen instances where a small number of Nest customers have re-used passwords that were previously exposed through breaches on other websites, and made public. None of these breaches involved Nest. This exposes these customers to other people using the credentials to log into their Nest account. We are proactively alerting affected customers to reset their passwords and set up two-factor authentication, which adds another layer of account security. Customers can reach out to Nest customer support with questions or report anything suspicious to [email protected]."
For the most part it forms a clear statement that the site operator does not wish to deal with EU clients.
So, yeah, if the odd EU-based client like me decides to VPN/Tor their way in, then legal action against the site operators for not dealing with my data appropriately shouldn't stand up.
Just a guess. IANAL.
So, yeah, if the odd EU-based client like me decides to VPN/Tor their way in, then legal action against the site operators for not dealing with my data appropriately shouldn't stand up.
Just a guess. IANAL.
> But what happens with the GDPR if I, a European citizen in Europe, access this website (blocking EU IP addresses) using a VPN?
Then everyone involved (except the lawyers, who will make out quite well) can risk getting wiped out as the EU’s extraterritorial application of privacy regulation and the US’s civil and criminal laws on unauthorized access combine into a firestorm of transatlantic litigation.
Then everyone involved (except the lawyers, who will make out quite well) can risk getting wiped out as the EU’s extraterritorial application of privacy regulation and the US’s civil and criminal laws on unauthorized access combine into a firestorm of transatlantic litigation.
They're being considerate by using your IP. They're not a EU company. They have no obligation or requirement to respect the EU laws, so them adding that feature is them at least acknowledging the EU has regulations they do not follow. If you want to circumvent that by using a VPN and deceive their servers, go ahead. While sure, under the GDPR that would still hold them liable, they're not located in the EU and therefore have no reason to spend the extra effort to find extra ways to try and prevent you from accessing their content.
> I guess Fox 4 KC didn't want to implement the GDPR
I think the content you're seeing, "Sorry, this content is not available in your region." is an implementation of GDPR compliance, no?
I think the content you're seeing, "Sorry, this content is not available in your region." is an implementation of GDPR compliance, no?
It's not an implementation of GDPR because the website doesn't have the right to exclude you from accessing the content even if you have not opted-in to trackers. It's a refusal to implement GDPR and having any business with European citizens (which for a local network affiliate is not a hard choice to make).
Refusal to do business in the EU certainly is an implementation of GDPR. The GDPR only applies to EU citizens, so not serving them means you meet all the compliance mandates.
> because the website doesn't have the right to exclude you from accessing the content even if you have not opted-in to trackers
Of course it does! It's their website. You don't have some god-given right to view fox4kc.com on your own terms.
Of course it does! It's their website. You don't have some god-given right to view fox4kc.com on your own terms.
[deleted]
Is there a better heuristic they could use? Outside of of using HTML5 Geolocation APIs, there's not much else they could do.
Easier than vpn: prefix the website with outline.com/
> But what happens with the GDPR if I, a European citizen in Europe, access this website (blocking EU IP addresses) using a VPN?
WDAF Kansas City, is a Fox affiliate located out of Missouri state.
GDPR is an EU regulation, not a global regulation, nor a US regulation. The EU and GDPR has no legal standing over most media companies in the US and very few US Web sites, because they do no business in the EU and are not bound by EU laws. It does not matter if you're an European citizen in Europe or not, if GDPR does not apply to the owner of the server you're accessing.
If I - an American citizen - access a server in China, US laws are not what govern what they can do with my information. That is governed by Chinese law.
WDAF Kansas City, is a Fox affiliate located out of Missouri state.
GDPR is an EU regulation, not a global regulation, nor a US regulation. The EU and GDPR has no legal standing over most media companies in the US and very few US Web sites, because they do no business in the EU and are not bound by EU laws. It does not matter if you're an European citizen in Europe or not, if GDPR does not apply to the owner of the server you're accessing.
If I - an American citizen - access a server in China, US laws are not what govern what they can do with my information. That is governed by Chinese law.
If I - an American citizen - access a server in China, US laws are not what govern what they can do with my information. That is governed by Chinese law.
The US government apparently has a different interpretation. For example, they asked Microsoft for the information of a user from the servers in Ireland.
The US government apparently has a different interpretation. For example, they asked Microsoft for the information of a user from the servers in Ireland.
Tribune Media would be subject to fines if they ever tried to do business in Europe.
Strangely, it does not work using archive.is either.
But I think this is the same event: https://www.dailymail.co.uk/news/article-6338113/Familys-Nes...
But I think this is the same event: https://www.dailymail.co.uk/news/article-6338113/Familys-Nes...
> Strangely, it does not work using archive.is either.
That’s because archive.is crawlers are hosted in Netherlands, Europe.
That’s because archive.is crawlers are hosted in Netherlands, Europe.
How is poor password security "hacking"? If you choose to use the same password on all of your devices then that is solely on you.
I think we’re long past the point where “hacking” in this sense has any sort of connotation of skill (and that is probably for the best). “Hack” is just a more colloquial synonym for “compromise”.
Nah, Nest could enforce 2FA, just as a basic example of how they could take responsibility for the safety of their consumers.
People seem to have adopted the term "hacking" to imply any and all unwanted access to a device or system. As far as I recall it meant that a device or system was modified in a way that was not originally intended. Logging in with the password is an intended use-case of the device, therefore not hacking in my opinion.
It's true, maintaining proper password hygiene is easy! See https://jasonlefkowitz.net/2015/09/ask-mr-science-how-to-sec... for details.
Legally, it is hacking.
I remember a story about someone getting an absurdly long prison sentence for guessing a simple password to a secure system.
Hacking only specifies the knowing and intentional circumvention of an authorization system. It doesn't place a value on how easy it was to do it.
I remember a story about someone getting an absurdly long prison sentence for guessing a simple password to a secure system.
Hacking only specifies the knowing and intentional circumvention of an authorization system. It doesn't place a value on how easy it was to do it.
Years ago a teenager was arrested for "hacking" because he just Google'd the answers to Sarah Palin's security questions to gain access to her Yahoo account.
The big takeaway here is that grown humans are mindlessly putting technology they don't understand in front of their children, and then they're blaming the technology for their own ignorance.
Alright, maybe I'm being a little extreme or cynical, and my goal here isn't victim blaming, clearly this sort of thing should not have to be a concern for people, but still... Don't they have a duty to understand what they're exposing their children to? Then again I've been tech savvy since I was like 11 years old (23 now) so maybe it's just easy for me to say. I just can't comprehend simultaneously having children and not understanding technology.
Alright, maybe I'm being a little extreme or cynical, and my goal here isn't victim blaming, clearly this sort of thing should not have to be a concern for people, but still... Don't they have a duty to understand what they're exposing their children to? Then again I've been tech savvy since I was like 11 years old (23 now) so maybe it's just easy for me to say. I just can't comprehend simultaneously having children and not understanding technology.
I must have missed the part in the Nest manual where they told you to expect complete strangers to be able to watch you and speak to you through it.
Actually, that is in the manual. That's a feature of the product. You can watch and speak through it. Just because a stranger got your password from an unrelated security breach to Nest, doesn't make it Nest's fault. They have the tools available, and even encourage you in the setup process to setup 2-factor (I just recently set one up). Outside of that, this is user error, in my opinion. Nothing was "hacked" on Nest's end.
[deleted]
A camera pointing at your face should be assumed to be turned on and recording you.
A camera pointing at your face hooked up to the Internet should be assumed to be broadcasting that information to the world.
We know this intuitively. Humans dislike eye contact from strangers because of what it implies. Cameras don't hit the same basic reflexes (likely because we've optimized them that way).
If we haven't done a good enough job of educating users on that, we need to address it. The UK Government run cybersecurity adverts occasionally. I don't think they go far enough.
I tell everyone I encounter to assume the worst case unless proven otherwise.
The purveyors of a commercial product aren't going to detail these things unless forced. See 'everything else ever' - food, drink, medicine, ...
A camera pointing at your face hooked up to the Internet should be assumed to be broadcasting that information to the world.
We know this intuitively. Humans dislike eye contact from strangers because of what it implies. Cameras don't hit the same basic reflexes (likely because we've optimized them that way).
If we haven't done a good enough job of educating users on that, we need to address it. The UK Government run cybersecurity adverts occasionally. I don't think they go far enough.
I tell everyone I encounter to assume the worst case unless proven otherwise.
The purveyors of a commercial product aren't going to detail these things unless forced. See 'everything else ever' - food, drink, medicine, ...
I wonder if this is a generational thing. I'm gen x and cameras absolutely hit the 'same basic reflexes' for me. When someone has their camera/phone out I sense where it is looking at least as much as I sense where people's eyes are looking.
My millenial girlfriend, my youngest siblings and cousins, etc., don't seem to be aware; nor do they have the same ideas of rudeness/politeness with camera use that I have.
My millenial girlfriend, my youngest siblings and cousins, etc., don't seem to be aware; nor do they have the same ideas of rudeness/politeness with camera use that I have.
My wife and I are both millennials and all the time she'll be playing with a Snapchat filter holding her phone straight out, and I'll ask her why she's filming me. From the back of the phone, it's completely indistinguishable.
It's the part that talks about how there's a camera and a speaker on an IoT device that's connected to the internet.
Seriously, though, my neighbor's entire house is wired up. His lights, his camera / security system, his shades, his music player, his TV... just about everything is integrated into Alexa. It boggles my mind why an otherwise intelligent person would do this.
Seriously, though, my neighbor's entire house is wired up. His lights, his camera / security system, his shades, his music player, his TV... just about everything is integrated into Alexa. It boggles my mind why an otherwise intelligent person would do this.
It's crazy to me that this is the way things are, and that a lot of these companies charge a service fee for remote access. A better way would be VPN offerings for the home from ISPs, and the devices working only locally.
I also missed that in the Facetime manual.
Tech is still in wild-west mode. I can buy food and eat it without testing it for poisons first. I can put my money in a bank without doing my own routine audits of their security. Like nutritional labels on food or a "Schumer box" on a credit card app, maybe we could list some risks and mitigations that the user needs to keep in mind when using the product.
Just because food is poison free doesn't mean it's consequence free. Most people just have a better understanding of food and it's consequences (feeding babies Burger King is a bad idea) when compared to tech and its consequences.
If a company forces two factor authentication, people will go to a product without it, because it's easier. It's easier to blame the product than bad security practices because no one is getting trained on these.
I think the real solution will be for Android and iOS to eventually have 2FA so integrated that any app can use OS APIs to implement it.
I think the real solution will be for Android and iOS to eventually have 2FA so integrated that any app can use OS APIs to implement it.
Authy is pretty impressive in that regard, I used it for the first time with twilio the other day and was impressed.
Not affiliated with either company.
Not affiliated with either company.
> I just can't comprehend simultaneously having children and not understanding technology.
Are your parents tech wizards? How about your grandparents?
Generational differences aside, pretty much everyone is clueless about some aspects of technology. You call yourself tech savvy, and I don't doubt you're correct, but I do doubt that your knowledge has no holes. Mine has plenty. And of course the general population's knowledge skews much thinner than HN readers. Many are on the Internet nearly every day of their lives, but ask them about something outside of the few select apps they use, and you're greeted with blank stares. Whether or not they have children is pretty much irrelevant. Giving birth may trigger some instinctive behaviors that come with a certain functional knowledge, but the layers in the OSI model aren't generally included.
Are your parents tech wizards? How about your grandparents?
Generational differences aside, pretty much everyone is clueless about some aspects of technology. You call yourself tech savvy, and I don't doubt you're correct, but I do doubt that your knowledge has no holes. Mine has plenty. And of course the general population's knowledge skews much thinner than HN readers. Many are on the Internet nearly every day of their lives, but ask them about something outside of the few select apps they use, and you're greeted with blank stares. Whether or not they have children is pretty much irrelevant. Giving birth may trigger some instinctive behaviors that come with a certain functional knowledge, but the layers in the OSI model aren't generally included.
Company lied to consumer that this wouldn't happen. Then it happened. And you're blaming the consumer?
Really? Google promised these people that if someone else used their correct username and their correct password, that other person wouldn't be able to log into the Nest camera?
I didn't see anywhere in the article that says Google promised that, and from what I know of security that's impossible. The article did say Google offered a way of increased security, an answer the consumer neglected to use and says isn't enough. (edit - says with absolutely no knowledge on the subject that 2FA isn't enough)
In your opinion, what should Google have done differently here? And where did you see that Google promised no one would be able to log in if that person had the correct username and password and 2FA wasn't enabled?
I didn't see anywhere in the article that says Google promised that, and from what I know of security that's impossible. The article did say Google offered a way of increased security, an answer the consumer neglected to use and says isn't enough. (edit - says with absolutely no knowledge on the subject that 2FA isn't enough)
In your opinion, what should Google have done differently here? And where did you see that Google promised no one would be able to log in if that person had the correct username and password and 2FA wasn't enabled?
Huh? Where do you see anything about Nest telling the consumer this wouldn't happen? They even encourage 2-factor in the setup process of the camera. I've never seen Nest say anywhere that the camera is 100% secure.
There was a security breach. The product was operating outside of the behavior range that the parents were told about. If I tell you that my toaster will not catch on fire and then it burns your house down while you use it as instructed, I can't argue that you "didn't understand" its behavior - sure, you didn't predict that it would self-immolate, but is it really your job to reverse-engineer my product to check for poor design?
My understanding is that the password was compromised. It is well within expected behavior for Nest to allow someone with the right credentials to access the connected cameras etc. This isn't a matter of expecting the consumer to reverse-engineer their product and perform a security audit before allowing themselves to trust it, it's a matter of expecting the consumer to understand what credentials are.
Being able to access the camera remotely given the correct password is absolutely within the behaviour range that users are told about. It's the entire point of the product. Do they want remote access or not? If so, then it's the user's responsibility to provision that access appropriately. Passwords and 2-factor might be too complicated for some, but what else do we have?
>We have seen instances where a small number of Nest customers have re-used passwords that were previously exposed through breaches on other websites, and made public. None of these breaches involved Nest. This exposes these customers to other people using the credentials to log into their Nest account.
Subtly, Nest did not actually claim that the attacker had a correct password. For all we know this instance was a breach.
Subtly, Nest did not actually claim that the attacker had a correct password. For all we know this instance was a breach.
Of course they are not going to give specific details about a particular customer's security incidents in a public statement. And of course they can not publicly claim that they've never had a security breach because it's impossible to know that for sure. I'm not sure how they could make the statement any more specific than they already have.
It is not the toaster company's responsibility to make sure no one gets in your house and puts a fork in your toaster and leaves it running.
Your analogy implies that compromised IoT devices are some rare statistical anomaly that nobody could possibly predict ever happening.
Your reply implies that consumers have a deep understanding of an industry that's outside of their areas of expertise.
If they think this is scary, wait till they find out what these "hackers" can do with their weak email passwords.
> A Nest spokesperson responded to our request for comment and issued this statement:
> "We have seen instances where a small number of Nest customers have re-used passwords that were previously exposed through breaches on other websites, and made public. None of these breaches involved Nest.
It's surprising how many people reuse their password or use unsafe passwords. Including my own family.
> "We have seen instances where a small number of Nest customers have re-used passwords that were previously exposed through breaches on other websites, and made public. None of these breaches involved Nest.
It's surprising how many people reuse their password or use unsafe passwords. Including my own family.
It's frustrating, isn't it? "We" spend a lot of time warning people about the dangers of phishing and to not give away their credentials. Then they give those same credentials away to random site operators who through malice or incompetence may end up giving those credentials to bad actors. I think most people don't grok the problem. They think 'this will never happen to me' and when it happens to them, they blame someone else. Reading the article, I don't get the sense that the family in the article learned anything. They seem to still be blaming the devices.
Not really. I have unique passwords everywhere, but I basically only have two PINs.
Is there a sensible way to log IoT traffic? I'm paranoid not just of who may be trying to access IP cameras, but what they may be sending back to their manufacturer.
Why is this low quality fear mongering Fox news post on the top page of HN? There is no evidence of "hacking" here, and Nest's official response was that the person had a poor or breached password. I get that this would be a nightmare situation, but it has nothing to do with Nest (at least with the current info)?
How is two-factor authentication not a prerequisite for using Nest in the first place?
I know we've moved as a society fairly quickly from expecting users to generate entropy to something that is actually secure. So it's understandable that some companies lag behind.
But Google is attempting to connect everything they can to the internet. If the bar for them isn't to at least prevent the easiest, most obvious hack from causing catastrophes then we're living in an idiocracy.
A user reusing passwords is bad. But in a civilized technological society the consequences for doing that cannot be a disembodied voice appearing communicating with one's child to give them nightmares.
Google's security teams surely know you can't "educate the user" to stop reusing passwords. If their official response is, "We did the right thing by suggesting two-factor authentication," then it doesn't matter how many engineers they throw at the problem.
Evil is afoot.
I know we've moved as a society fairly quickly from expecting users to generate entropy to something that is actually secure. So it's understandable that some companies lag behind.
But Google is attempting to connect everything they can to the internet. If the bar for them isn't to at least prevent the easiest, most obvious hack from causing catastrophes then we're living in an idiocracy.
A user reusing passwords is bad. But in a civilized technological society the consequences for doing that cannot be a disembodied voice appearing communicating with one's child to give them nightmares.
Google's security teams surely know you can't "educate the user" to stop reusing passwords. If their official response is, "We did the right thing by suggesting two-factor authentication," then it doesn't matter how many engineers they throw at the problem.
Evil is afoot.
Hacker News is not just about "hacking". I posted it here as a reflection of the status quo about what people (don't) know about the implications of connecting home services to a centralized network.
The article itself is very low quality. This isn’t even news. Stuff like this happens to thousands of people every day.
I wasn't referring to "hacking" the way you took it. I meant it in terms of how the article used it, I totally agree and understand Hacker News is not just about hacking, in the context you mean. I just meant like this article, in general, is pretty low quality and just about poor password usage from the person they interviewed. No data breach or anything in terms of Nest.
Local Fox affiliates != Fox News
Still low quality, but for different reasons.
Still low quality, but for different reasons.
So it seems that the nest itself was secured with a repeated password, and there was no 2FA on their account (which they could, and were encouraged, to add).
On one hand, it's easy to dismiss this as the nest owners being naive with internet security. This is incident was easily avoidable if the owners had put in the tiniest more effort. I think it's _fair_ to expect people who own these devices to know the basics about how to not get exploited from it.
On the flip side, although I think that knowing the basics is a _fair_ expectation, I don't think it's _pragmatic_. These devices are only going to get more powerful in their abilities, only going to get more ubiquitous in their distribution, and only going to get more opaque as to their inner workings. I don't think it's unreasonable that manufactures _force_ a higher level of security on such devices.
On one hand, it's easy to dismiss this as the nest owners being naive with internet security. This is incident was easily avoidable if the owners had put in the tiniest more effort. I think it's _fair_ to expect people who own these devices to know the basics about how to not get exploited from it.
On the flip side, although I think that knowing the basics is a _fair_ expectation, I don't think it's _pragmatic_. These devices are only going to get more powerful in their abilities, only going to get more ubiquitous in their distribution, and only going to get more opaque as to their inner workings. I don't think it's unreasonable that manufactures _force_ a higher level of security on such devices.
This story is pretty creepy, but at this point, people need to own up to the idea that weak passwords and passwords that are re-used across sites are going to be compromised at some point [1]. There's nothing Nest can really do about this, other than to mandate two-factor auth, which most people don't seem to like [2].
[1] I'm happy to see in my personal experience that even my non-technical friends are starting to use password managers. [2] According to https://hackernoon.com/why-do-most-people-ignore-two-factor-..., "less than 10 percent of active Google accounts use two-factor authentication. Furthermore, as per findings of the Pew Research Center, password managers are only used by approximately 12 percent of Americans." If people aren't using 2FA for their gmail account, which is arguably the most important account to protect, then they probably aren't using it anywhere else.
[1] I'm happy to see in my personal experience that even my non-technical friends are starting to use password managers. [2] According to https://hackernoon.com/why-do-most-people-ignore-two-factor-..., "less than 10 percent of active Google accounts use two-factor authentication. Furthermore, as per findings of the Pew Research Center, password managers are only used by approximately 12 percent of Americans." If people aren't using 2FA for their gmail account, which is arguably the most important account to protect, then they probably aren't using it anywhere else.
They could check the user's password against the HIBP database - many users aren't aware of these data breaches and this would prevent them using one of those passwords as well as making them aware of the problem.
Unfortunately the only additional authentication Nest offers is SMS base 2-step auth. You would think being owned by Google they would allow for 2FA.
Doesn’t appear to have been hacked like all the hacks we hear about rather, the user probably reused their password on another service that was hacked and they didn’t change their passwords as hopefully instructed when that occurred. Enabling 2 factor would resolve this in most alll cases easily for the user. Versus the user having to use a password management app and constantly monitor their security and update accordingly. 1Password helps a lot but the average person won’t use that so it’s on companies like Apple to continue to improve their keychain software to help automate this for users and on companies like nest to push 2 factor more. But until Apple and other natively support 2 factor seamlessly it won’t gain massive traction for non tech users. So while this was the users fault technically it’s ultimately tech companies fault for not making security for users more fool proof. Though if everyone uses 2 factor hackers will probably find another way.
> Enabling 2 factor
Unfortunately, they do not provide "true" 2fa, only through text message.
Unfortunately, they do not provide "true" 2fa, only through text message.
I guess Fox 4 KC didn't want to implement the GDPR… But what happens with the GDPR if I, a European citizen in Europe, access this website (blocking EU IP addresses) using a VPN?
The heuristic they use (IP address = country on which the user lives) is not a perfect method to assess whether they need to apply the GDPR regulation.