Hacker News new | ask | show | jobs
by pkcsecurity 1537 days ago
What counts as “remote access”? Another device authenticated to Wi-Fi? Another device anywhere on the internet, with knowledge of the device ID? Another device anywhere on the internet with knowledge of email address?

These are vastly different criticality levels.

All the talk of IOCtl and assembly/bytes in the in the ButDefender report implies “another device on the Wi-Fi”, but I know wyze cams can be viewed over-the-Internet, ostensibly proxied via Wyze’s own servers, so maybe not?