Hacker News new | ask | show | jobs
by lostlogin 14 days ago
> What would the attack vector be?

The cameras. But quite how, I don’t know.

2 comments

My Insta360s have wifi builtin, you have to connect to it with their phone app to do some of the processing. It's kind of nice, especially away from home but I wouldn't know how you'd know if it connected to something else or something else connected to it.

I don't know how you'd get devices like that certified for certain higher security applications.

Any backdoored camera with wireless networking can take pictures remotely.
Cloud risks are very true - for both GoPro and DJI.

About a year ago, I was looking for an action camera. I found a good DJI product, but then I learned that you have to link the camera to an app in order to use it. I am fundamentally opposed to that idea, so I looked up the equivalent GoPro camera. Turns out GoPro also requires you to activate the camera with a smartphone app.

I don't want to send my data to a company for something as trivial as an action cam. I was surprised to find that the US model had such an evil requirement, mirroring the Chinese model.

In the end, I bought the DJI action cam (cheaper, better) and activated it in a public location using a burner phone. You only need to use the app once to free the device and take it offline, after which you can delete the surveillance app. I have found no fingerprinting in the created media yet.

GoPro would have made an easy sale with me, if they had been more privacy/power aware.