How to Keep Your Home Security Cameras From Being Hacked
CR's digital privacy and security experts offer their best advice for protecting your privacy
Smart security cameras are a great tool for keeping an eye on your home, whether for package deliveries, critters rummaging through your garbage cans, or intruders snooping around your house. But their “all-seeing” abilities can also be co-opted by hackers to spy on you via the internet. No wonder, then, that according to the 2021 Statista Global Consumer Survey, 28 percent of U.S. respondents worried that people could spy on them through their smart home devices.
How Hacks Happen
One way security cameras are vulnerable to hacks is through a technique called “credential stuffing.” Hackers use usernames and passwords from other data breaches (that other hackers share online) to gain access to accounts. The combination of large data breaches, such as those at Equifax and Target, and consumers reusing the same passwords—52 percent of internet users reuse or modify the same passwords—make the work easy. In recent years hackers have made the log-in credentials for over 11.7 billion online accounts available on the internet.
This type of hack doesn’t require the breach of a security camera company’s system, so every brand is at risk. “These companies aren’t technically at fault,” says Fred Garcia, who oversees CR’s privacy and security testing for home security cameras. “Most companies offer a two-factor authentication system that acts as an extra deterrent against attacks like this. But there is more that these companies could do, like encouraging people to use that added security feature by default.”
How to Protect Yourself
Data breaches and subsequent credential-stuffing attacks won’t be going away anytime soon, but there are simple steps you can take to reduce the chances that your security camera will be hacked.
1. Keep Your Camera’s Firmware Up to Date
Manufacturers that are serious about protecting their cameras will routinely release firmware updates that fix software bugs and patch security vulnerabilities. Some cameras will automatically download and install these updates, while others require that you check for them on your own. (You’ll usually find an update button under the Settings menu in your camera’s app.)
2. Change Your Camera’s Password
In a nationally representative CR survey of 1,006 U.S. adults on data privacy conducted in May 2019, 13 percent of Americans with at least one online account said they used the same password for all their accounts. That makes it a cinch for hackers to gain access to multiple accounts. Always create a unique password for each account. Here’s the best way.
Do: Use something long and complex—like a random phrase or string of characters—with numbers, symbols, and uppercase and lowercase letters.
Don’t: Include any personally identifiable information, such as names, birthdates, etc. Hackers can often get this information from public social media profiles, such as those on Facebook and Instagram, and then use it to guess your passwords and gain access to your accounts. You also want to avoid simple, commonly used passwords, such as Nordpass’s 200 Most Common Passwords. For more tips on strengthening your passwords, read our tips for better passwords.
3. Set Up a Password Manager
These programs generate incredibly strong, random passwords for your digital accounts, securely store and remember them for you, and even automatically insert them into log-in prompts. Many password managers are free to use and available on an array of devices and web browsers.
4. Set Up Two-Factor Authentication
This is an extra layer of security. You opt to have your security camera company send you a single-use passcode via a text message, phone call, email, or authentication app that you use in addition to your username and password when you log in to the account. That way, if hackers crack your password, they still won’t be able to access your camera unless they also gain access to your passcode.
Many camera companies now offer two-factor authentication, and some even require you to use it, but there are still holdouts. That’s why we note whether cameras and doorbells offer two-factor authentication in our home security camera ratings.
All these methods can improve your chances of avoiding a hack, but they’re not foolproof. “None of these methods will work perfectly on their own,” Garcia says. “But right now, these measures are our best tools. Use them all!”
Top Cameras With Two-Factor Authentication
Consumer Reports conducts data privacy and security tests on wireless security cameras to help you find models that are as secure as possible. Cameras that include two-factor authentication receive a higher score. Our experts also inspect the user interface and network traffic from each camera and its companion smartphone app to make sure it’s using encryption, adhering to manufacturer policies, and not sharing your data. We evaluate each model’s public documentation (such as privacy policies) to see what claims the manufacturer makes about the way it handles your data.
Below are a few cameras that do well in our data privacy and security tests and offer the extra security of two-factor authentication. They’re listed in alphabetical order by brand.
Passwords & Firmware 101
Online privacy and security are huge issues facing a lot of people today. On the “Consumer 101” TV show, Consumer Reports expert Maria Rerecich explains why it’s not just phones and computers that people should be concerned about.