To pick another one from my own daily life, this time: what is the deal with cameras, really?
That may sound like a strange question. But more and more households have a Ring camera. An expensive doorbell. But there are plenty of other cameras in use as well. One person has one because they are a train enthusiast and live near the railway. They point a camera at the tracks and share the livestream 24/7 on YouTube. Someone else wants to keep an eye on the grounds of their farm. From an escaped lamb to a burglar. Yet another person recently got a kitten and has to be away from home for office work, while still wanting to keep an eye on the new member of the family.
Either way, there can be many reasons to use a camera.
But as a tech guy, I wondered: how safe and comfortable is all of this, really? That is quite a sobering thought in 2026.
Cameras are everywhere by now
Let me give you a concrete example. Over the course of the last 20 to 30 years, we have gone from 640x480 webcams to a world where an optical sensor has almost become a disposable component. Every smartphone has several of them. Cameras are used at barriers to recognise licence plates, and you even find cameras and other sensors in household appliances.
Interestingly enough, the police have a registration system where you can register your cameras. I personally find that rather amusing. On the one hand, there are clear rules about filming public spaces and your neighbours. On the other hand, you can voluntarily register your outdoor camera with Camera in Beeld. If something happens afterwards, the police know that there may be potentially useful camera footage available at that location.
That may sound contradictory. You cannot simply film the street, but at the same time the police are quite happy to know afterwards where cameras are located that may have captured a robbery, burglary or getaway car.
But what about that camera in your living room?
Let's dive a little deeper into that hypocrisy. What about that camera you use to keep an eye on your cat from the office? 1080p and sound. Connected to your network. 24/7.
For anyone working in information security, this is interesting.
Especially when you realise that, as a regular consumer, you can buy an "IP camera" for 9 euros at a local Action store. You put it somewhere in your home. You download an app. And voilà. You can check on your furry little friend from home, but also from the office, using the camera.
I saw one of those cameras sitting on the shelf. And I was curious.
What struck me was how incredibly user-friendly the whole thing is. You do not need to be a computer expert to use it. You put it somewhere, plug in a USB-C cable, download the app and enter your Wi-Fi name and password. The app turns that into a QR code. You hold that code in front of the camera lens. And boom. The camera is connected.
You can now open the app on your smartphone and immediately see and hear what your new camera can do for you. Super easy. Video and audio. You can now check your living room at any time.
But of course, that is not what I did.
Why does my camera need to know my Wi-Fi password?
My first questions already came up when I read the instructions. Download an app and enter your Wi-Fi password into that app? What? Why do I need an app? And why do I need to enter a highly sensitive piece of information into that app? And where does that app take it afterwards? I had questions. Burning questions.
The fact that I can look at the camera in my living room from the office through the smartphone app already tells me that there is at least an internet connection between my camera and the manufacturer's service. How else would I be able to view the footage through my app while away from home?
That already feels uncomfortable. But it got much more uncomfortable.
For 9 euros, you don't get miracles
Long story short: I stripped all the plastic off this 9-euro "IP camera" from the Action store and started looking at the hardware. What I found was a circuit board, or PCB as it is technically called, which, like many modern devices, relies primarily on one important SoC. That is a chip in which multiple functions are combined.
And that chip told me more or less what I already expected. If you are sitting on the shelves at Action with a retail price of 9 euros, the design primarily has to be cheap to manufacture. That does not automatically mean the hardware is insecure. Cheap hardware can function perfectly well and can also be designed securely. But it does make me particularly curious about the security choices the manufacturer has made.
A few things stood out. To connect the camera to your Wi-Fi, you have to, as mentioned, enter your Wi-Fi name and password through the manufacturer's app. Those details are turned into a QR code. You show that QR code to the camera after connecting it to power for the first time. The camera reads the QR code, extracts the details and uses them to connect to your Wi-Fi network.
After that, I saw the camera connecting to a computer on the internet. We call that a server. During my research, I saw connections to AWS infrastructure, Amazon's cloud service. When you open the app on your smartphone, it also connects to the service behind it. That is how the video can eventually reach your smartphone, whether you are at home or somewhere else.
Why does it have to go through the cloud?
Technically, I already find that interesting. Instead of a relatively short route, where your camera communicates with a device on the same network through your router, you have a longer route here: your smartphone connects to a service on the internet, and your camera does the same.
That does not in itself have to be a security problem. A cloud connection can actually be properly secured. But it does mean that the functioning of your camera depends on external infrastructure. And if video and audio travel through that infrastructure, you should ask yourself exactly what data is going there, how long it is stored, who can access it and how well that infrastructure is secured.
Even more interesting: when I soldered a wire onto certain connections of the SoC and used that to gain access to the software, I soon discovered, as expected, that the camera was simply running neatly on Linux. But when I dug further into the software, I discovered that the Wi-Fi credentials provided to the camera through the QR code were being stored by the manufacturer's software on the camera in readable form, on the /APP partition.
That is rather concerning.
Even if we assume that the store and the manufacturer of the camera have our best interests at heart, this is a setup that could make things very easy for a malicious user if they gain access to the camera or its storage.
A cheap camera is still a computer
I had to think back to Shodan. A sort of Google for technical experts. Both hackers and crackers. Or, as the media forces me to say: both benevolent and malicious hackers.
Long story short: through Shodan, you can find devices and services that are directly reachable from the internet. This can range from routers and cameras to industrial systems. Not everything Shodan finds is necessarily vulnerable or poorly secured. But if a device is directly reachable from the internet, it is at least interesting from an information security perspective.
You really don't want your desire to check on your cat during the day to end with a criminal group gaining access to an entire batch of cheap cameras that are being sold in large numbers and subsequently being able to watch video and listen to audio from people's living rooms.
So I did it differently
I immediately replaced all the software on this device with my own software. And now it does what I want. No app. No cloud. No AWS and no QR codes.
But that is me.
I sometimes genuinely worry about what is being sold in ordinary shops. Those shops are not deliberately doing anything wrong by selling these products. Quite the opposite, to the average consumer the product is attractive precisely because it is cheap and easy to use. But underneath that convenience, there is sometimes electronics that handles your security and privacy in ways that are at the very least questionable.
The average buyer will not know this and will not be able to fix it either. Without realising it, someone can therefore make data, video and audio available to systems they have very little visibility into. That cannot be the intention at a time when we are connecting more and more devices in our homes to the internet.
Whether for business or private use, keep an eye on what happens to your data. Do not take it too lightly. What you want is not wrong. But how you do it makes a world of difference.
And yes, that means that for ordinary people, relying on the advice of experts will sometimes be necessary. Unfortunately, there is no way around that.