Arlo|Smart Home Security|Wireless HD Security Cameras

Shared Videos are accessible without password

Reply
Discussion stats
  • 3 Replies
  • 537 Views
  • 0 Likes
  • 2 In Conversation
maxim__s
Aspirant
Aspirant

The problem:

- turn on email notifications about the camera detected some movement

- emails arrive

- in the emails, there is an URL which allows you to watch the video WITHOUT ENTERING THE PASSWORD

- yes, the URL contains the long string of hex digits, but still NO PASSWORD IS REQUIRED

- the video on that webpage is called "Shared Media" or so

 

So, some hacker can just iterate over these hex strings and view ANY video ever saved by the Arlo camera.

 

Questions:

- isn't this a security problem? or is it considered to be safe due to the length of the hex string in the URL?

- if I switch email notifications off, will this kind of access to my saved videos be switched off?

- is there any possibility for me to tweak some options to switch this "Shared Media" feature off?

 

Model: VMB4500 | Arlo Pro/Pro2 Base Station
3 REPLIES 3
JamesC
Community Manager
Community Manager

maxim__s,

 

This email is only generated when you have email notifications turned on or you use the share option within the library. You can eliminate this by turning off email notifications.

 

How do I turn on/off email notifications?

 

JamesC

 

maxim__s
Aspirant
Aspirant

The problem is not in the email notifications by itself, which can be easily turned off.

 

The problem is that the cloud provides password-free access to the recordings, by using URLs with long hex strings.

 

If I turn emails off, are you absolutely sure that this access will also be terminated?

 

JamesC
Community Manager
Community Manager

maxim__s,

 

If you turn off emails, no URL is generated. This only happens when email notifications are turned on, or a clip is shared from the library manually.

 

JamesC

Discussion stats
  • 3 Replies
  • 538 Views
  • 0 Likes
  • 2 In Conversation