How did consumer cameras and DVRs end up disrupting major internet services, and what made them so easy to recruit?
Weak and easily guessable default usernames and passwords let malware infect them at scale, and the resulting botnet flooded targets with requests — taking Netflix, PayPal, Twitter, Spotify and UK government sites offline.
* Weak credentials recruit cameras and DVRs into a botnet whose combined traffic exhausts a target’s capacity, harming third parties. *
The mechanics of the compromise were unremarkable, which is the point:
- Internet-connected camera products carried weak default usernames and passwords, and easily guessable passwords where they had been changed at all.
- A security flaw allowed the IP cameras to be infected with malware — no exploit chain required, just credentials that were the same on every unit and published in the manual.
- Around 4.3 million of the affected camera products were recalled from the US market afterwards.
The attack the botnet then performed was an ordinary distributed denial-of-service: multiple systems or devices flood a target with requests until legitimate ones cannot get through. What was new was not the technique but the supply — tens of thousands of always-on, always-connected devices with no user watching them, no update mechanism worth the name, and bandwidth sitting idle.
The reason this case is quoted so often is the asymmetry it exposes. The camera owner suffers almost nothing: the device keeps working. The damage lands entirely on third parties who never bought the product. That is a textbook negative externality, and it is why IoT security is increasingly treated as a regulatory matter rather than a purchasing decision — the party best placed to fix it has the least incentive to.
Tip: the defensive lesson is unglamorous and complete: unique credentials per device, forced change on first use, and no working default. Nearly every large IoT botnet traces back to that one missing control.
Go deeper:
Wikipedia — Mirai (malware) — the best-documented botnet of this kind: a table of sixty-odd factory credentials, and the 2016 attacks on Krebs, OVH and Dyn.
Wikipedia — Default password — why shipped credentials keep causing this, with cases beyond cameras.
Wikipedia — Denial-of-service attack — the mechanics of the flood itself, including other IoT-sourced cases such as a botnet of CCTV cameras.