Report Sparks Security Concerns About Meari Technology Baby Monitors
More than 1 million baby monitors worldwide may be vulnerable to a security breach. Here's what parents should know.
A recent discovery that more than 1 million baby monitors worldwide may be vulnerable to hacking and other security and privacy concerns has many parents worried—here’s what to know and how to protect yourself and your family.
According to reporting in The Verge, as many as 1.1 million WiFi baby monitors and security cameras produced by Meari Technology were found to be susceptible to a serious security breach, making users’ video feeds, stored photos, email addresses, and location data easily accessible.
When Consumer Reports contacted Meari Technology about the security concerns, a company spokesperson said via email that “We are currently conducting internal verification regarding relevant reports.” The spokesperson also told CR that in the company’s perspective, the products supplied to the U.S. market do not involve information security risks. “For U.S. clients, we mainly provide pure hardware solutions or non-network connected product solutions, which fundamentally avoid relevant network security concerns.” CR repeatedly requested a list of affected brands and products sold in the U.S., but did not receive a response in time for publication. Without that list, it’s impossible to verify the company’s claims.
What Parents Should Know About Baby Monitor Security
A video baby monitor lets you keep an eye on your little one while you’re in a different room, so you can get some rest or work done while they sleep—and be quickly alerted if they start fussing.
There are two main types of video baby monitors: those that send a live video and audio feed over proprietary radio frequencies and come with a display unit, and those that use WiFi to send data via the internet to your smartphone. There are also hybrid monitors that do both.
Baby monitors that use your smartphone are convenient because you can check on your baby not just from the kitchen in your house, but from anywhere. This kind of baby monitor can also let other caregivers check on your baby remotely via the app. But internet-connected baby monitors raise additional security and data privacy concerns. Without robust security, anyone could access the live feeds transmitted by your baby monitor or glean data like your location or email address.
In our on-site labs, CR’s product testing experts put every internet-connected baby monitor we test through evaluations for potential privacy and security risks. Most of the WiFi monitors tested by CR receive middling marks for security (safety against potential hacking) and privacy (how the companies collect and handle data from the devices).
Common security issues in WiFi baby monitors: The most common security problems we’ve found include unsecured servers that make sensitive customer information easily accessible, as seen in the Meari Technology breach. We’ve also seen issues in our tests where some devices don’t require complex passwords or multifactor authentication to keep your device safe if someone gains access to your password.
Common privacy issues in WiFi baby monitors: Only some manufacturers in our tests provide clear information in their user documentation about how they collect and use data, and how long they keep it.
How to Make Your WiFi Baby Monitor More Secure
If you do opt for the convenience of a smartphone-connected WiFi baby monitor, here are some steps CR’s experts recommend you take to make it more secure. “Your best bet is to put your WiFi-connected baby monitor on a separate network and keep the device firmware up to date,” says Higginbotham. “And whenever you buy a connected device, choose ones that offer multifactor authentication and require complex passwords.”
Use a complex password. Some baby monitors allow you to use a short, six-character password, but our privacy experts urge you to use at least 16 characters, with a mix of letters, numbers, and other characters.
Enable multifactor authentication. This feature should be standard on any important connected device or online account. It can prevent someone who gets your password from logging in to your account. Once you’ve set it up, you’ll also be alerted if someone with your credentials tries to log in from a new device.
Routinely update the device’s firmware. Some baby monitors push automatic updates, while other models require you to do it manually. If you buy a model without automatic updates, our experts suggest checking for and installing firmware updates once a month to stay on top of security fixes and enhancements.
Put smart home devices, such as a baby monitor, on a separate guest network. “This isn’t going to stop hackers from accessing a poorly secured microphone or camera and listening in on your baby monitor,” Higginbotham says, “but it can stop an attacker from using the baby monitor to attack other devices on your regular network.”
How to Shop for Safer WiFi Baby Monitors
It’s understandable to want a cute baby monitor that fits with your nursery decor, but remember to prioritize safety and security when it comes to internet-connected devices. Here’s what CR’s experts recommend keeping in mind when shopping for the best baby monitor.
- Shop from reputable and recognizable brands—and use CR’s baby monitor ratings as a tool in your research. If you can’t find a brand website, that’s a red flag.
- If you shop online, purchase directly from retailers rather than a third-party seller. On the retailer’s marketplace, look for the “Ships from” and “Sold by” labels to check.
- Be skeptical of designations like “Top Seller” or “Highly Rated”, which do not guarantee the quality or safety of a product.
- Read retailer site product reviews with a heavy dose of skepticism. Avoid products with negative reviews that offer real-life details and mention similar problems.
If you have a negative experience with a baby monitor or find something suspicious, report it to the retailer and alert the Consumer Product Safety Commission at SaferProducts.gov.
You can learn more about how Consumer Reports evaluates data privacy and security at The Digital Standard, an independent information site that is used by testing organizations, researchers, and product teams.