Consumer PTZ's Compromised

nayr

IPCT Contributor
Joined
Jul 16, 2014
Messages
9,329
Reaction score
5,325
Location
Denver, CO
Joined
Jan 5, 2017
Messages
4
Reaction score
0
It's all very entertaining to (re)learn how ridiculously weak this whole industry is re: security, but what the heck are people supposed to do to deal with this silliness ?

Is there 'any' model camera under $200 that:
  • is network-enabled, with wifi support ideally (yes, I know I know I know...)
  • to be mounted outside and with IR support
  • and acceptable image quality day+night for a 30' distance and perhaps 60 degree range of view
  • that is known to be configurable enough to absolutely not phone home or expose itself to some network attack
  • that doesn't require you to be a professional computer+network person (with a comparable amount of time+money) to set up and run safely ?
All I'm looking for is an affordable network-enabled camera for LAN access only. Nothing out to Internet at all. Zero holes/protocols punched through the network gateway/firewall box inbound. Camera=>Internet blocked completely at both the DNS (pihole) and Internet gateway (firewall rules). LAN only.

I run either zoneminder/motion on Linux, or eyeSpy (didn't like BI at all) on Win10Pro if that matters.

I would 'really' prefer to not need to go old-school coax to a DVR kind of setup with all that wiring and power hell that results. A quality 'secure' wifi cam for LAN-only is what I'm looking for. But the whole industry just seems to be a house of cards for consumers.
 

hmjgriffon

Known around here
Joined
Mar 30, 2014
Messages
3,386
Reaction score
979
Location
North Florida
It's all very entertaining to (re)learn how ridiculously weak this whole industry is re: security, but what the heck are people supposed to do to deal with this silliness ?

Is there 'any' model camera under $200 that:
  • is network-enabled, with wifi support ideally (yes, I know I know I know...)
  • to be mounted outside and with IR support
  • and acceptable image quality day+night for a 30' distance and perhaps 60 degree range of view
  • that is known to be configurable enough to absolutely not phone home or expose itself to some network attack
  • that doesn't require you to be a professional computer+network person (with a comparable amount of time+money) to set up and run safely ?
All I'm looking for is an affordable network-enabled camera for LAN access only. Nothing out to Internet at all. Zero holes/protocols punched through the network gateway/firewall box inbound. Camera=>Internet blocked completely at both the DNS (pihole) and Internet gateway (firewall rules). LAN only.

I run either zoneminder/motion on Linux, or eyeSpy (didn't like BI at all) on Win10Pro if that matters.

I would 'really' prefer to not need to go old-school coax to a DVR kind of setup with all that wiring and power hell that results. A quality 'secure' wifi cam for LAN-only is what I'm looking for. But the whole industry just seems to be a house of cards for consumers.
If you don't care about seeing your cams from the internet then just keep then in there own physical hardware, what's the big deal.
 
Joined
Aug 3, 2015
Messages
3,823
Reaction score
12,279
Location
Charlotte
Is there 'any' model camera under $200 that:
  • is network-enabled, with wifi support ideally (yes, I know I know I know...)
  • to be mounted outside and with IR support
  • and acceptable image quality day+night for a 30' distance and perhaps 60 degree range of view
  • that is known to be configurable enough to absolutely not phone home or expose itself to some network attack
  • that doesn't require you to be a professional computer+network person (with a comparable amount of time+money) to set up and run safely ?
All I'm looking for is an affordable network-enabled camera for LAN access only. Nothing out to Internet at all. Zero holes/protocols punched through the network gateway/firewall box inbound. Camera=>Internet blocked completely at both the DNS (pihole) and Internet gateway (firewall rules). LAN only.
There are a bunch of no-name/off-brand cameras that easily fit these requirement, if you're willing to take the risk. Look at AliExpress.com for any 1080p IP cameras with wifi:
Shop 1080p IP camera wifi online Gallery - Buy 1080p IP camera wifi for unbeatable low prices on AliExpress.com

Here's one example:
wifi HD 1080P P2P onvif H.264 4IR metal outdoor lights night vision camera wireless network IP security-in Surveillance Cameras from Security & Protection on Aliexpress.com | Alibaba Group

Here's another:
Full HD 1080P IP Camera Wifi Ultra Low Illumination SONY IMX222 + HI3516C Sensor IP Camera Wireless 1080P Outdoor XMEYE-in Surveillance Cameras from Security & Protection on Aliexpress.com | Alibaba Group
 

fenderman

Staff member
Joined
Mar 9, 2014
Messages
36,903
Reaction score
21,274
It's all very entertaining to (re)learn how ridiculously weak this whole industry is re: security, but what the heck are people supposed to do to deal with this silliness ?

Is there 'any' model camera under $200 that:
  • is network-enabled, with wifi support ideally (yes, I know I know I know...)
  • to be mounted outside and with IR support
  • and acceptable image quality day+night for a 30' distance and perhaps 60 degree range of view
  • that is known to be configurable enough to absolutely not phone home or expose itself to some network attack
  • that doesn't require you to be a professional computer+network person (with a comparable amount of time+money) to set up and run safely ?
All I'm looking for is an affordable network-enabled camera for LAN access only. Nothing out to Internet at all. Zero holes/protocols punched through the network gateway/firewall box inbound. Camera=>Internet blocked completely at both the DNS (pihole) and Internet gateway (firewall rules). LAN only.

I run either zoneminder/motion on Linux, or eyeSpy (didn't like BI at all) on Win10Pro if that matters.

I would 'really' prefer to not need to go old-school coax to a DVR kind of setup with all that wiring and power hell that results. A quality 'secure' wifi cam for LAN-only is what I'm looking for. But the whole industry just seems to be a house of cards for consumers.
None of those off brands are secure..You are no more secure by using a DVR.... any cam can be made wifi...if you don't connect your cams I to the net they cannot be compromised since you are not willing to do any work pay the monthly stupid tax and use nestcam and pray their connection is secure...
Btw blue Iris blows both ispy and zoneminder out of the water....
...
 
Last edited:

hmjgriffon

Known around here
Joined
Mar 30, 2014
Messages
3,386
Reaction score
979
Location
North Florida
Zoneminder is ancient garbage, it was written by a guy who's shed got broken into for himself and then he abandoned it and some other people eventually took it over.
 
Joined
Jan 5, 2017
Messages
4
Reaction score
0
If you don't care about seeing your cams from the internet then just keep then in there own physical hardware, what's the big deal.
the big deal is these things phone home 'outbound' (my Hootoo knockoff-Foscam drives itself half crazy trying to phone home, with no configurability to tell it not to).
Zoneminder is ancient garbage, it was written by a guy who's shed got broken into for himself and then he abandoned it and some other people eventually took it over.
And that kind of ridiculous "I can post anything I want from Mom's basement" is why this site is so unpleasant to even read.

It gets a job done sufficiently for many many users. Sheesh.
 
Joined
Jan 5, 2017
Messages
4
Reaction score
0
Thanks.

Just to close the thread hopefully, I worked around the configuration on the camera I have (Hootoo knockoff Foscam with no 'off' switch for the phone behavior, and no firmware updates available) by the following:

  • set it to static ip
  • set its gateway to point to itself
  • set its DNS server to point to itself
  • so it can ping and try to connect to itself as often as it wants without sending any traffic outbound
  • (verified with a sniffer)
 

hmjgriffon

Known around here
Joined
Mar 30, 2014
Messages
3,386
Reaction score
979
Location
North Florida
the big deal is these things phone home 'outbound' (my Hootoo knockoff-Foscam drives itself half crazy trying to phone home, with no configurability to tell it not to).


And that kind of ridiculous "I can post anything I want from Mom's basement" is why this site is so unpleasant to even read.

It gets a job done sufficiently for many many users. Sheesh.
"knockoff-Foscam" I think I found your problem.
 
Top