2 min read

NurseryCam has serious security issues, claims researcher

Graham CLULEY

February 15, 2021

NurseryCam has serious security issues, claims researcher

* System widely used by nurseries to allow parents to watch their children playing.
* Claims made that NurseryCam was first informed of issues six years ago, but they still remain.

Security consultant Andrew Tierney, perhaps better known by the moniker “Cybergibbons”, has found disturbing security holes in a widely-used CCTV service designed to let parents remotely watch their children playing at nursery.

The NurseryCam service, which is promoted as “safer than online banking”, appears – according to Tierney – to suffer from some serious vulnerabilities.

Tierney claims that the system is not protected with TLS to encrypt the nursery’s video streams (opening them to eavesdropping by unauthorised parties), that parents of children who are no longer at the nursery are still able to access video feeds, that cameras parents are not entitled to view video from (such as rooms which their child does not use) are accessible.

Furthermore, the sharing of administrator usernames and passwords to parents – credentials that are used across multiple nurseries – opens opportunities for anyone on the internet to access the live video streams of children.

“This is analogous to your local bank giving you the keys to their vault and just trusting that you will only take your money,” says Tierney.

Tierney says that he informed NurseryCam about the security issues on 6 February 2021, and last week blogged about his initial concerns.

The researcher called upon NurseryCam to take down its service, and ensure that nurseries either changed their passwords to something more secure or stopped them from being exposed to the internet. In addition, Tierney said that nurseries, as well as current and former parents with children at exposed nurseries should be informed of the issues.

There is no indication that anything like this has yet happened.

To make matters worse, Tierney says that he was contacted by one parent who had found “almost identical issues” in NurseryCam in 2015, but they had clearly not been resolved in the years since.

At the time of writing there is no warning published on the NurseryCam website. Tierney, who believes that the NurseryCam system needs to be “almost completely redesigned” to resolve the security issues, has stark advice for affected nurseries:

  • Unplug the network connection from the DVR.
  • Contact NurseryCam and ask that they inform all impacted nurseries immediately.
  • Ask why the system you have been paying for isn’t the one that is described on the NurseryCam site.

tags


Author



Right now

Top posts

Ultimate Privacy Guide for Your Facebook Account

Ultimate Privacy Guide for Your Facebook Account

August 31, 2021

6 min read
7 Signs It’s Time to Use Parental Controls On Your Family’s Devices

7 Signs It’s Time to Use Parental Controls On Your Family’s Devices

August 27, 2021

2 min read
Your Netflix Account May Be on Sale on Darkweb. Protect It

Your Netflix Account May Be on Sale on Darkweb. Protect It

August 13, 2021

3 min read
E-mails claiming your computer was hacked and your privacy exposed - what you need to know (spoiler: you can relax - they’re bluffing)

E-mails claiming your computer was hacked and your privacy exposed - what you need to know (spoiler: you can relax - they’re bluffing)

July 29, 2021

5 min read
Watch Out for These Ongoing Bank of America Phishing Campaigns Targeting Customers in the US

Watch Out for These Ongoing Bank of America Phishing Campaigns Targeting Customers in the US

July 16, 2021

3 min read
How to protect yourself against cyberstalking

How to protect yourself against cyberstalking

July 06, 2021

2 min read

FOLLOW US ON

SOCIAL MEDIA


You might also like

New Malware Campaign Targets Linux and Web Apps to Install Crypto-Mining Software New Malware Campaign Targets Linux and Web Apps to Install Crypto-Mining Software
Silviu STAHIE

September 23, 2021

1 min read
What Is a VPN, How Does It Protect Me, and What Cool Perks Does it Offer? What Is a VPN, How Does It Protect Me, and What Cool Perks Does it Offer?
Filip TRUȚĂ

September 23, 2021

2 min read
Security Researcher Publishes Lock Screen Bypass for iOS 15 on Launch Day Security Researcher Publishes Lock Screen Bypass for iOS 15 on Launch Day
Silviu STAHIE

September 22, 2021

1 min read