Skip to main content

Morning Overview

A single flaw in a cheap home camera can let strangers watch the live feed inside a house

A camera bought to keep an eye on a front porch or a nursery can just as easily become a window a stranger looks through from the other side. Consumer IP cameras stream live audio and video over the internet by design, and a single weak link in how one is set up or built can turn that convenience into remote access for someone who was never supposed to see inside the house at all.

How an IP Camera Ends Up Exposed

Cameras marketed as smart, connected, or Wi-Fi cameras all work the same basic way: they capture video, send it over a home network, and make it available through an app so an owner can check in from anywhere. The Federal Trade Commission’s guidance on securing home cameras notes that this convenience is exactly what creates the risk, since the same remote-access pathway an owner uses is, in principle, the same one an attacker needs. A camera can be compromised through a weak password on the device itself, a vulnerability in the manufacturer’s cloud servers, an unsecured home Wi-Fi network, or a bug in the software that mixes up which video feed belongs to which account, and any one of those alone is enough.

The 2024 Wyze Mix-Up That Showed the Real-World Risk

The risk moved from theoretical to documented in February 2024, when camera maker Wyze disclosed that a caching error let roughly 13,000 users see event clips recorded by other customers’ cameras. According to reporting on the incident from The Register, the company said the problem began after a partner outage took its devices offline, and when cameras reconnected, a third-party caching library mixed up device and user identifiers, routing some customers’ recorded clips into the wrong accounts. Wyze reported that around 1,504 of those 13,000 exposed accounts actually had their footage viewed, whether accidentally or deliberately, before the company revoked access to the affected feature. Nothing about that failure involved a hacker breaking in; a routine software error was enough to hand strangers a look inside other people’s homes.

Default Passwords and the Cheapest Way In

Separate from backend software bugs, the far more common path into a camera is simply never changing its factory-set credentials. The FTC’s guidance is direct on this point: a camera’s default username and password, along with any password already reused on another account, are exactly what an attacker checks first, because those combinations are often published in manufacturer manuals or leaked online in bulk. Automated scanning tools can test thousands of internet-connected cameras against known default logins in a short span of time, meaning a camera that was never assigned its own unique password can be found and accessed without the owner’s device or network being individually targeted at all.

Why Encryption and HTTPS Logins Matter

Even a strong password does not fully close the gap if the connection carrying it is not encrypted. The FTC recommends checking that a camera’s login page begins with https rather than plain http, since that prefix indicates the username and password entered are scrambled in transit rather than sent in a form that could be intercepted on the same network. The same logic applies to the video stream itself: a camera that encrypts its livestream and stored recordings keeps that footage unreadable to anyone who intercepts it, while a camera without that protection can expose its feed to anyone positioned to capture the traffic, whether over an insecure Wi-Fi connection or a compromised router.

Building a Safer Setup Before Something Goes Wrong

Reducing the risk starts before a camera is even purchased, by checking whether it advertises built-in encryption and two-factor authentication for its companion app. Once installed, the device should sit on a properly secured home network, meaning a router with an updated password of its own, current firmware, and, ideally, a separate guest network reserved for cameras and other smart devices so that a breach of a laptop or printer does not automatically extend to the camera feed as well. The FTC’s companion guidance on securing a home Wi-Fi network recommends enabling WPA2 or WPA3 encryption and keeping router software current, both of which close off common paths attackers use to reach devices sitting on that same network. Camera software and its associated app also need periodic updates, since manufacturers routinely patch the exact kind of authentication and identifier bugs that led to incidents like the one Wyze disclosed, and a camera running outdated firmware keeps those old holes open long after a fix exists.

Who else has access to a livestream matters as much as how the camera itself is secured. A camera placed in a bedroom, a nursery, or another private space is a poor candidate for casual livestream sharing with a wide circle of family or friends, since every added viewer is another login that could be weak, reused, or eventually forgotten and left active after it should have been revoked. Cameras that support tiered permissions, letting an owner grant one contact view-only access during specific hours while reserving administrative control, such as the ability to add new accounts or change the camera’s direction, for a single person, cut down on that exposure considerably. Owners who no longer use a camera should also disable it entirely rather than leaving it connected and forgotten, since an idle camera still running old firmware on a home network is one more device a future vulnerability could reach.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview