Skip to main content

Google shutting down Xiaomi access to Assistant following Nest Hub picking up strangers' camera feeds (Update: Xiaomi statement)

https://ift.tt/2tp2m3U So-called "smart" security cameras have had some pretty dumb security problems recently, but a recent report regarding a Xiaomi camera linked to a Google account is especially disturbing. One Xiaomi Mijia camera owner is getting still images from other random peoples' homes when trying to stream content from his camera to a Google Nest Hub. The images include stills of people sleeping and even an infant in a cradle. In the meantime, Google has entirely disabled Xiaomi integration for Google Home and the Assistant while it works out the issue with Xiaomi. This issue was first reported by user /u/Dio-V on Reddit and affects his Xiaomi Mijia 1080p Smart IP Security Camera, which can be linked to a Google account for use with Google/Nest devices through Xiaomi's Mi Home app/service. It isn't clear when Dio-V's feed first began showing these still images into random homes or how long the camera was connected to his account before this started happening. He does state that both the Nest Hub and the camera were purchased new. The camera was purchased from AliExpress and noted as running firmware version 3.5.1_00.66. Video Player 00:00 00:18 Video showing a random still image received when trying to stream content from the camera. When attempting to access a video feed from his connected camera (as depicted in the video above), instead of the expected local video feed, he's provided a random, occasionally partly corrupted black and white still image from another home. Among the eight or so examples initially provided to Reddit are a handful of disturbingly clear images showing a sleeping baby, a security camera's view of an enclosed porch, and a man seemingly asleep in a chair. Two more images showing a clear view inside a home, including someone asleep in a chair. Dio-V also believes the content of the random still images being fed to his Nest Hub, which contain Xiaomi/Mijia branded date/timestamps, depict a different time zone than his own. It's technically possible this could be an elaborate hoax, but the video evidence is pretty damning. Whatever feed is trying to be accessed is clearly something that is actually integrated with Google Home/Assistant, and the fact that it's intermittently corrupted and showing still images rather than the expected video is also pretty high-effort for a fake. It's also possible these could be some sort of test images and he's inadvertently accessing a debug mode/feed, among other potential explanations. Google isn't taking any chances, though. We reached out to the company and were provided with the following statement after our story was initially published: "We’re aware of the issue and are in contact with Xiaomi to work on a fix. In the meantime, we’re disabling Xiaomi integrations on our devices." We reached out for further confirmation that this would mean a blanket disabling of all Mi Home product integrations or commands for the Assistant, and we have confirmed that this is the case. Our own subsequent attempts to use Mi Home integrated devices through Google Home/Assistant show that Google has already disabled this functionality at the time of our update, and Dio-V (the Reddit user with the original report) has confirmed for us that his camera is no longer working on his Nest Hub. We've reached out to Xiaomi for comment, as well as additional details surrounding how an issue like this could occur, but the company did not immediately respond. This isn't the first time that smart home security cameras have has this sort of problem before. Memorably, some used Nest cameras would remain linked to an original owner's account, providing them a glimpse inside the new purchaser's home. More recently, Wyze, who makes smart security cameras, also recently suffered a "mistake," storing unsecured user data in a publicly accessible manner and requiring all customers to pair/set up devices again. UPDATE 1: 2020/01/02 10:49AM PST BY RYNE HAGER Google says it's disabling Xiaomi integrations A Google spokesperson has provided us with the following short statement: "We’re aware of the issue and are in contact with Xiaomi to work on a fix. In the meantime, we’re disabling Xiaomi integrations on our devices." We have further confirmed and verified that this is a blanket disabling of all Mi Home product integrations for Google Home and the Assistant. Our coverage above has been updated with this information. END OF UPDATE UPDATE 2: 2020/01/03 2:22AM PST BY SCOTT SCRIVENS Full statement from Xiaomi Overnight we've received the following statement from Xiaomi that confirms they have identified and fixed the problem. It appears that some sort of cache update is the root cause, and while Xiaomi devs work on ensuring this won't happen again, the service will remain suspended. Official statement "Xiaomi has always prioritized our users' privacy and information security. We are aware there was an issue of receiving stills while connecting Mi Home Security Camera Basic 1080p on Google Home hub. We apologize for the inconvenience this has caused to our users. Our team has since acted immediately to solve the issue and it is now fixed. Upon investigation, we have found out the issue was caused by a cache update on December 26, 2019, which was designed to improve camera streaming quality. This has only happened in extremely rare conditions. In this case, it happened during the integration between Mi Home Security Camera Basic 1080p and the Google Home Hub with a display screen under poor network conditions. We have also found 1044 users were with such integrations and only a few with extremely poor network conditions might be affected. This issue will not happen if the camera is linked to the Xiaomi’s Mi Home app. Xiaomi has communicated and fixed this issue with Google, and has also suspended this service until the root cause has been completely solved, to ensure that such issues will not happen again."

Comments

Popular posts from this blog

Friends in all the wrong places

https://ift.tt/2BVSIXZ Striding past the glistening rows of duty-free liquor, watches and perfume, the two international travellers moved like men who could fight. Richard ''Gelly'' Gelemanovic had broad shoulders and a confident gait, while his companion, convicted heroin trafficker Amad ''Jay'' Malkoun, had a physique honed during his 16-year stint in prison. It was July 3, 2003, and Malkoun was recently out of jail, having gained public notoriety after being charged in 1988 as a key player in the state's biggest drug syndicate, which had been busted with $5.5 million of heroin. Amad 'Jay' Malkoun was described by police as 'a powerful standover man'. The federal police who were secretly watching Malkoun at Melbourne's international airport described him in a report as ''a powerful stand-over man … actively involved in the Melbourne drug trade''. The profession of his travelling companion, the man Jay called '

Kim Constable – Irish leader of NXIVM – jokes about working out in prison; shows results of badass workouts

http://bit.ly/2WTRg0f Kim Constable, 39 – one of Sara Bronfman’s ‘girls’ – is the leader of NXIVM in Ireland. She lives in Belfast and is also the leader of Rainbow Cultural Garden there. According to a source, she recruited at least one underage teen girl who was almost shipped to the USA with Allison Mack for the branding iron of DOS. Fortunately, the teen girl – with her mother’s help – escaped at the last minute. But not before there was a little violence and the threat of something truly sinister – which frightened the girl. I will tell more of that story later. For now, let us say hello to Kim. In addition to her NXIVM work, she is a vegan body-builder and sells courses on how to look like her. Her husband is a famous ex-athlete, Ulster rugby player Ryan Constable (46) who owns a sports management company. They have four children: Corey (12), Kai (11), Miya (8) and Jack (6). At one time, they all slept in the same 18-foot bed together. I am not clear where the Rainbow nannies sle