HomeCII/OTWyze Cameras Enable Unintentional User Surveillance

Wyze Cameras Enable Unintentional User Surveillance

Published on

spot_img

Wyze, a company based in Seattle that offers smart home products such as cameras and doorbells, has experienced a cybersecurity “incident” that allowed many of its connected camera users to access other people’s camera feeds, unbeknownst to them.

This isn’t the first time that Wyze has faced a cybersecurity issue like this. In September 2023, users reported seeing camera feeds that were not theirs, which was attributed to a Web caching problem. Now, the issue has recurred, affecting even more users. Around 13,000 users received thumbnails from cameras that were not theirs, and 1,504 users enlarged the image. Some instances involved the thumbnail being attached to a video, which was then viewed.

Reports from users on platforms such as Reddit and the Wyze forum detailed the distressing experience of seeing strangers’ images and footage from other time zones. Several users expressed concerns about the security flaw and questioned whether their own camera notifications were being sent to other Wyze users due to the mix-up.

David Crosby, Wyze’s co-founder and chief marketing officer, has addressed the issue by implementing new security measures. These involve adding an extra layer of verification between users and event videos, requiring all users to log out of the Wyze app and reset tokens if they have been active. Additionally, the Events tab was temporarily taken down in response to the reports of privacy breaches.

The cybersecurity incident was initially attributed to an overloaded Wyze server following an Amazon Web Services (AWS) outage, which allegedly caused corruption of user data and led to the security issue. However, AWS did not report an outage during the time the problems with the Wyze cameras occurred.

In an email obtained by the media, Crosby expressed gratitude for the assistance provided by users in addressing the issue and apologized for the stressful experience. Despite Wyze’s apparent transparency in handling the situation compared to the previous incident, the company’s trust and reputation remain in question. As an investigation continues, it remains to be seen how Wyze will regain user trust and prevent similar incidents from occurring in the future.

Source link

Latest articles

5 IoT Vulnerabilities That Are Undermining Projects Before Launch

The Pitfalls of IoT Development: Identifying and Addressing Vulnerabilities In the rapidly evolving landscape of...

The Ongoing AI Agent Security Crisis

The Rise and Risks of OpenClaw: An Autonomous AI Agent OpenClaw, an open-source autonomous AI...

Week in Review: Self-Spreading npm Malware Targets Developers and Cisco SD-WAN 0-Day Exploited Since 2023

Weekly Review: Noteworthy Developments in Cybersecurity and Technology In the past week, the cybersecurity and...

Infostealers Fuel Significant Brute-Force Attacks on Corporate SSO Gateways Using Stolen Credentials

The cybersecurity landscape is currently facing a significant surge in credential-stuffing attacks specifically targeting...

More like this

5 IoT Vulnerabilities That Are Undermining Projects Before Launch

The Pitfalls of IoT Development: Identifying and Addressing Vulnerabilities In the rapidly evolving landscape of...

The Ongoing AI Agent Security Crisis

The Rise and Risks of OpenClaw: An Autonomous AI Agent OpenClaw, an open-source autonomous AI...

Week in Review: Self-Spreading npm Malware Targets Developers and Cisco SD-WAN 0-Day Exploited Since 2023

Weekly Review: Noteworthy Developments in Cybersecurity and Technology In the past week, the cybersecurity and...