A baby monitor, a pet cam and the camera over the front door share one weakness the Federal Trade Commission has put in writing, saying many IP cameras are “vulnerable to digital snooping”. The agency’s consumer-advice page on securing connected devices lists that line under its camera guidance, and the fix it describes starts with habits most owners never form, such as reading the camera’s own access log.
The FTC does not put a number on “many,” and the page was last modified on November 15, 2024. What it does provide is a concrete picture of how a camera ends up shared with a stranger and what an owner can check in an evening.
The FTC’s camera warning and what it covers
The FTC’s page on securing internet-connected devices at home groups baby, pet and security cams together as IP cameras, meaning devices that stream video over a network to an app. Its advice is to change the factory username and password, keep firmware and the companion app updated, and turn off unused features, remote management above all, because each open feature is another way in.
The page adds a step that few consumer guides mention: check the camera’s access logs in its admin settings. The FTC tells owners to watch for IP addresses they do not recognize or for access at odd times. A login from a network the household has never used, or at three in the morning when everyone is asleep, is the signature of someone else watching.
Unencrypted logins and the home network behind a camera
A second FTC page, Using IP Cameras Safely, states the risk plainly: “these cameras can be hacked.” If a login page is not encrypted, someone watching the traffic could capture the username and password, and if an attacker reaches the main home network, the cameras become easier to reach. The FTC says the address on the login page should begin with “https” and stay that way after sign-in, or the livestream may not be encrypted.
The agency also points to the network behind the camera. It recommends a strong router password, the router’s firewall left on, router updates installed, and WPA3 or WPA2 encryption. Cameras should sit on a separate network from computers and printers, so that a breach of a laptop does not hand over the video feed. The FTC’s guide to home Wi-Fi calls WPA3 “the newer and best” encryption and tells owners to disable remote management, WPS and UPnP, which it says can make a network less secure.
Before buying, the FTC says to look for built-in encryption that protects account data, livestreams and recordings, and to check the manufacturer’s website or the box label for what a camera already in use actually does. Owners of older cameras can ask the maker directly. The advice amounts to treating the camera as a computer with a lens: it needs updates, a unique password and a network that does not trust every other device in the house.
The Ring case and 55,000 hijacked accounts
The FTC has described what is at stake in an enforcement action. In its May 31, 2023 announcement about Ring, the agency alleged that hackers accessed roughly 55,000 U.S. customers’ accounts, viewing videos and harassing users, including children and elderly people, through two-way audio. It said Ring lacked basic protections against credential-stuffing and brute-force attacks despite multiple attacks in 2017 and 2018, and did not add multi-factor authentication until 2019.
Ring agreed to a proposed order that included $5.8 million in consumer refunds and required security controls, among them multi-factor authentication for employee and customer accounts. “Ring’s disregard for privacy and security exposed consumers to spying and harassment,” said Samuel Levine, then director of the FTC’s Bureau of Consumer Protection. The allegations concerned one company, but the mechanism, reused or guessed passwords on an internet-facing account, is the one the consumer pages warn about.
The FTC’s device advice carries the same point for any brand. Passwords should never be reused from other accounts, because attackers try credentials stolen in data breaches against other services, and two-factor authentication should be switched on wherever the camera’s cloud account offers it.
The warning is not confined to the United States. The UK’s National Cyber Security Centre issued an advisory on internet-connected cameras that CISA pointed administrators to in March 2020. It tells owners to replace any default password with a strong, unique one, install updates promptly and turn off remote access that is not used.
For rooms such as bedrooms, the FTC suggests a camera that lets the owner disable remote viewing entirely, a feature that removes the livestream from the internet rather than trusting a password to guard it. The agency also advises choosing cameras with permission controls, including some that let a designated administrator change settings or decide who can watch and when, which matters in homes where several relatives share one app.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- Long use of a common prostate pill is tied to a higher chance of glaucoma
- Ford is recalling 223,472 F-150 pickups because the fuel tank can leak or detach
- Hybrids have 15% fewer problems than gas cars, while EVs and plug-in hybrids have about 80% more, Consumer Reports finds
- Regulators cleared the first U.S. small modular reactor, 4 months early