<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Encryption in Arlo</title>
    <link>https://community.arlo.com/t5/Arlo/Encryption/m-p/1037401#M13967</link>
    <description>&lt;P&gt;At the very least it's bizarre&amp;nbsp;that information uniquely identifying your hardware is available in plaintext, but what concerns me most is the rtsp link that shows up when you begin live streaming. &amp;nbsp;The link is of the form&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;rtsp://vzwow....netgear.com:443/vzmodule/CAMERAID_123456?ingressToken=HEXSTUFF?cameraId=CAMERAIDso fa&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So far, I've been unable to play this link from VLC, which is promising, but I haven't tried very hard. &amp;nbsp;Even if the link is unusable (e.g. the token is single-use and is showing up in the TCP stream only after it was used), I'd still like to know why it was sent at all.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 20 Jan 2016 23:35:22 GMT</pubDate>
    <dc:creator>platron</dc:creator>
    <dc:date>2016-01-20T23:35:22Z</dc:date>
    <item>
      <title>Encryption</title>
      <link>https://community.arlo.com/t5/Arlo/Encryption/m-p/1036645#M13965</link>
      <description>&lt;P&gt;I've noticed that, while traffic from the netgear base station to the cloud seem to be encrypted, there's quite of a bit of plaintext being sent back.&lt;/P&gt;&lt;P&gt;For example, I see stuff like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;[{"from":"123-1234567_web","to":"MYBASE","transId":"web!b0b0b0!12345678910","action":"set","resource":"subscriptions/123-1234567_web","responseUrl":"","publishResponse":false,"properties":{"devices":["MYBASE"],"url":"https://vzweb05-prod.vz.netgear.com/hmsweb/publish/123-1234567"}}]&lt;/PRE&gt;&lt;P&gt;where I've changed possibly identifying text to something like 123..., but MYBASE in the original transmission is the actual S/N of my base station. &amp;nbsp;What is this information used for and why isn't it encrypted?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2016 20:53:04 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Arlo/Encryption/m-p/1036645#M13965</guid>
      <dc:creator>platron</dc:creator>
      <dc:date>2016-09-28T20:53:04Z</dc:date>
    </item>
    <item>
      <title>Re: Encryption</title>
      <link>https://community.arlo.com/t5/Arlo/Encryption/m-p/1037085#M13966</link>
      <description>&lt;P&gt;Your right in that the video info needs a 'key' as for the some of the data, it is in plain text ...Ive noticed the same thing... on it's way to / from Amazon servers.&lt;/P&gt;&lt;P&gt;But I really don't worry about that, but more that someone can't tap into the vids to get an inside view of the home/layout ( which is keyed )&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2016 15:29:32 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Arlo/Encryption/m-p/1037085#M13966</guid>
      <dc:creator>TomMac</dc:creator>
      <dc:date>2016-01-20T15:29:32Z</dc:date>
    </item>
    <item>
      <title>Re: Encryption</title>
      <link>https://community.arlo.com/t5/Arlo/Encryption/m-p/1037401#M13967</link>
      <description>&lt;P&gt;At the very least it's bizarre&amp;nbsp;that information uniquely identifying your hardware is available in plaintext, but what concerns me most is the rtsp link that shows up when you begin live streaming. &amp;nbsp;The link is of the form&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;rtsp://vzwow....netgear.com:443/vzmodule/CAMERAID_123456?ingressToken=HEXSTUFF?cameraId=CAMERAIDso fa&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So far, I've been unable to play this link from VLC, which is promising, but I haven't tried very hard. &amp;nbsp;Even if the link is unusable (e.g. the token is single-use and is showing up in the TCP stream only after it was used), I'd still like to know why it was sent at all.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2016 23:35:22 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Arlo/Encryption/m-p/1037401#M13967</guid>
      <dc:creator>platron</dc:creator>
      <dc:date>2016-01-20T23:35:22Z</dc:date>
    </item>
    <item>
      <title>Re: Encryption - somebody listened</title>
      <link>https://community.arlo.com/t5/Arlo/Encryption/m-p/1038782#M13968</link>
      <description>&lt;P&gt;So this is interesting... &amp;nbsp;I ran a few captures today, and it appears that the entire dialog betwen base and netgear/aws is now encrypted &amp;nbsp;The strange "ingress tokens" and rtsp links are gone, or at least no longer in plaintext. &amp;nbsp;This is a tremendous improvement.&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jan 2016 16:19:51 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Arlo/Encryption/m-p/1038782#M13968</guid>
      <dc:creator>platron</dc:creator>
      <dc:date>2016-01-23T16:19:51Z</dc:date>
    </item>
    <item>
      <title>Re: Encryption</title>
      <link>https://community.arlo.com/t5/Arlo/Encryption/m-p/1040998#M13969</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For the record, no. &amp;nbsp;It would have been nice to get some official resoponse from Netgear on a topic this serious.&lt;/P&gt;&lt;P&gt;_____________&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;STRONG&gt;Hello platron,&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Your topic recently received a reply.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p3"&gt;&lt;SPAN class="s2"&gt;Topic: &lt;A href="https://community.arlo.com/t5/Arlo-Wire-Free-camera/Encryption/td-p/1036645" target="_blank"&gt;&lt;SPAN class="s3"&gt;Encryption&lt;/SPAN&gt;&lt;/A&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Date: 2016-01-19 02:15 PM&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Did it solve your problem?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s4"&gt;&lt;A href="https://community.arlo.com/t5/Arlo-Wire-Free-camera/Encryption/m-p/1037085#M7916" target="_blank"&gt;Click here to view the reply&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN class="s1"&gt; and mark one as an Accepted Solution.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;This helps others find helpful answers in the community too!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2016 14:45:02 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Arlo/Encryption/m-p/1040998#M13969</guid>
      <dc:creator>platron</dc:creator>
      <dc:date>2016-01-27T14:45:02Z</dc:date>
    </item>
    <item>
      <title>Re: Encryption</title>
      <link>https://community.arlo.com/t5/Arlo/Encryption/m-p/1287585#M35299</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.arlo.com/t5/user/viewprofilepage/user-id/254780"&gt;@platron&lt;/a&gt;, could you share with me how you are doing the sniffing?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'd like to do the same on &amp;nbsp;my own setup too. As I've posted before here (&lt;A href="https://community.netgear.com/t5/Features/Arlo-is-being-Blocked-by-Privoxy-What-server-address-should-I/m-p/1266950#M11566" target="_self"&gt;Arlo is being Blocked by Privoxy. What server address should I whitelist?&lt;/A&gt;), I can't use livestream because Privoxy in my DD-WRT modem is blocking it. I've tried whitelisting&amp;nbsp;&lt;EM&gt;.amazonaws.com&lt;/EM&gt; and&amp;nbsp;&lt;EM&gt;.netgear.com&lt;/EM&gt; without any luck, so I'd really love to know what other address it's trying to access when clicking the livestream in order to try to whitelist it too.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks and please let me know also if you already know what other address I should whitelist!&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Best&lt;/P&gt;</description>
      <pubDate>Sun, 21 May 2017 19:07:34 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Arlo/Encryption/m-p/1287585#M35299</guid>
      <dc:creator>Timmy256</dc:creator>
      <dc:date>2017-05-21T19:07:34Z</dc:date>
    </item>
    <item>
      <title>Re: Encryption</title>
      <link>https://community.arlo.com/t5/Arlo/Encryption/m-p/1287620#M35301</link>
      <description>Did you ever open a case with support to see what they might be able to suggest?</description>
      <pubDate>Sun, 21 May 2017 20:11:39 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Arlo/Encryption/m-p/1287620#M35301</guid>
      <dc:creator>jguerdat</dc:creator>
      <dc:date>2017-05-21T20:11:39Z</dc:date>
    </item>
    <item>
      <title>Re: Encryption</title>
      <link>https://community.arlo.com/t5/Arlo/Encryption/m-p/1287652#M35306</link>
      <description>&lt;P&gt;Wireshark, principally. &amp;nbsp;If your devices are connected over a modern ethernet&amp;nbsp;switch (as opposed to a hub) or via WPA2 with session-level encryption, then you may also need to use iptables on your router to redirect traffic to wherever you're running wireshark.&lt;/P&gt;</description>
      <pubDate>Sun, 21 May 2017 21:42:18 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Arlo/Encryption/m-p/1287652#M35306</guid>
      <dc:creator>platron</dc:creator>
      <dc:date>2017-05-21T21:42:18Z</dc:date>
    </item>
    <item>
      <title>Re: Encryption</title>
      <link>https://community.arlo.com/t5/Arlo/Encryption/m-p/1287662#M35308</link>
      <description>&lt;P&gt;No&amp;nbsp;&lt;a href="https://community.arlo.com/t5/user/viewprofilepage/user-id/378"&gt;@jguerdat&lt;/a&gt;, I didn't actually got to it. I'm pretty sure that they'll tell me (if they reply at all) that I have to troubleshoot which address I'm trying to access first and then allow that to be bypassed. But since it's installed in DD-WRT (an embedded system), I have no easy way to generate logs in my case (I'd have to add JFFS2 storage to a physical unaccesible modem), that's why I'm still trying to figure it out myself.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks for the suggestion, though. I'll certainly submit it after a couple of months, when I get more time, and if I haven't fixed it myself already.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Sun, 21 May 2017 22:02:04 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Arlo/Encryption/m-p/1287662#M35308</guid>
      <dc:creator>Timmy256</dc:creator>
      <dc:date>2017-05-21T22:02:04Z</dc:date>
    </item>
    <item>
      <title>Re: Encryption</title>
      <link>https://community.arlo.com/t5/Arlo/Encryption/m-p/1287664#M35309</link>
      <description>&lt;P&gt;Thanks for the reply&amp;nbsp;&lt;a href="https://community.arlo.com/t5/user/viewprofilepage/user-id/254780"&gt;@platron&lt;/a&gt;! You were just typing as I was posting my previous message!&amp;nbsp;&lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.arlo.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yeah, I've tried with Wireshark and had to install the special drivers, but I didn't have the time to mess with it and the DD-WRT configuration, so I left it there.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would you happen to have it installed or some logs from your previous tests? Could you confirm me if there are other address besides these two that are tryed to be reached when you click on of the "Live" icons on the desktop web UI (not the app):&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;.amazonaws.com
.netgear.com&lt;/PRE&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Sun, 21 May 2017 22:05:44 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Arlo/Encryption/m-p/1287664#M35309</guid>
      <dc:creator>Timmy256</dc:creator>
      <dc:date>2017-05-21T22:05:44Z</dc:date>
    </item>
  </channel>
</rss>

