Shared Videos are accessible without password
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The problem:
- turn on email notifications about the camera detected some movement
- emails arrive
- in the emails, there is an URL which allows you to watch the video WITHOUT ENTERING THE PASSWORD
- yes, the URL contains the long string of hex digits, but still NO PASSWORD IS REQUIRED
- the video on that webpage is called "Shared Media" or so
So, some hacker can just iterate over these hex strings and view ANY video ever saved by the Arlo camera.
Questions:
- isn't this a security problem? or is it considered to be safe due to the length of the hex string in the URL?
- if I switch email notifications off, will this kind of access to my saved videos be switched off?
- is there any possibility for me to tweak some options to switch this "Shared Media" feature off?
- Related Labels:
-
Service and Storage
-
Troubleshooting
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
maxim__s,
This email is only generated when you have email notifications turned on or you use the share option within the library. You can eliminate this by turning off email notifications.
How do I turn on/off email notifications?
JamesC
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The problem is not in the email notifications by itself, which can be easily turned off.
The problem is that the cloud provides password-free access to the recordings, by using URLs with long hex strings.
If I turn emails off, are you absolutely sure that this access will also be terminated?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
maxim__s,
If you turn off emails, no URL is generated. This only happens when email notifications are turned on, or a clip is shared from the library manually.
JamesC
-
Arlo Mobile App
564 -
Arlo Pro 2
11 -
Arlo Smart
167 -
Before You Buy
972 -
Features
409 -
Firmware Release Notes
57 -
Google Assistant
1 -
IFTTT (If This Then That)
24 -
Installation
1,122 -
Online and Mobile Apps
865 -
Service and Storage
317 -
SmartThings
37 -
Troubleshooting
6,122