{"id":11183,"date":"2022-12-16T18:58:24","date_gmt":"2022-12-16T15:58:24","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=11183"},"modified":"2022-12-16T18:58:24","modified_gmt":"2022-12-16T15:58:24","slug":"ip-cameras-unsecurity-eufy","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/ip-cameras-unsecurity-eufy\/11183\/","title":{"rendered":"IP kamera g\u00fcvenli\u011fi: k\u00f6t\u00fc, \u00e7irkin, felaket"},"content":{"rendered":"<p>Ak\u0131ll\u0131 evler, elektronik aletlerin yeni fakat \u00e7ok y\u00f6nl\u00fc bir kategorisidir. Web aray\u00fcz\u00fc olan su \u0131s\u0131t\u0131c\u0131lar, uzaktan kapat\u0131labilen \u00fct\u00fcler ve ak\u0131ll\u0131 ayd\u0131nlatma kontrol sistemleri: bunlar\u0131n t\u00fcm hayat\u0131m\u0131z\u0131 kolayla\u015ft\u0131rmak i\u00e7in tasarlanm\u0131\u015ft\u0131r. Peki ama bu \u00fcr\u00fcnler g\u00fcvenli mi? Nesnelerin interneti (IoT) cihazlar\u0131, sunduklar\u0131 kolayl\u0131\u011f\u0131n yan\u0131nda yeni g\u00fcvenlik ve gizlilik risklerini de beraberinde getirir. Herhangi bir ak\u0131ll\u0131 cihazda g\u00fcvenlik a\u00e7\u0131\u011f\u0131 vakas\u0131 ya\u015fanmadan ge\u00e7en tek bir hafta bile yok denebilir. Tek bir \u201cak\u0131ll\u0131 ampul\u201d bile <a target=\"_blank\" rel=\"nofollow noopener\" href=\"https:\/\/www.usatoday.com\/story\/tech\/2020\/02\/05\/how-to-avoid-smart-lights-getting-hacked\/4660430002\/\">ev a\u011f\u0131na s\u0131zmak<\/a> i\u00e7in kullan\u0131labiliyorken, daha ciddi ekipmanlarla neler yap\u0131labilece\u011fini siz hayal edin.<\/p>\n<p>Ev g\u00fcvenlik sistemlerinin temel unsurlar\u0131ndan birisi de internete ba\u011fl\u0131 g\u00fcvenlik kameras\u0131d\u0131r. Dad\u0131 kameralar\u0131, g\u00f6r\u00fcnt\u00fcl\u00fc diyafon sistemleri ve profesyonel g\u00fcvenlik sistemlerine y\u00f6nelik sofistike, motorlu kameralar gibi bir\u00e7ok kamera t\u00fcr\u00fc vard\u0131r.<\/p>\n<p>Ad\u0131ndan da anla\u015f\u0131laca\u011f\u0131 \u00fczere IP kameralar s\u00fcrekli olarak internete ba\u011fl\u0131d\u0131r ya da d\u00fczenli aral\u0131klarla ba\u011flan\u0131r. Bu kameralarla elde edilen g\u00f6r\u00fcnt\u00fcler ise genellikle sat\u0131c\u0131n\u0131n kendisine ait olan, \u00f6zelle\u015ftirilmi\u015f hizmet \u00fczerinden al\u0131nabilir. Bu hizmete giri\u015f yapt\u0131\u011f\u0131n\u0131zda, d\u00fcnyan\u0131n neresinde olursan\u0131z olun kameran\u0131n video ak\u0131\u015f\u0131na eri\u015fim sa\u011flayabilirsiniz. Kullan\u0131\u015fl\u0131 olmas\u0131n\u0131n yan\u0131 s\u0131ra, buna alternatif \u00fcr\u00fcnler (\u00f6rne\u011fin yaln\u0131zca yerel bir a\u011fdan eri\u015febilece\u011finiz kameralar) potansiyel m\u00fc\u015fterilerin ilgisini \u00e7ekmez.<\/p>\n<p>Fakat bu da bir\u00e7ok soruyu beraberinde getirmektedir. \u00d6rne\u011fin siber sald\u0131rganlar oturum a\u00e7ma bilgilerinizi \u00e7alarsa ne olur? Bulut video kamera sistemleri ne kadar g\u00fcvenli? Sald\u0131rganlar, hesab\u0131n\u0131z\u0131 ele ge\u00e7irmeden kamera g\u00f6r\u00fcnt\u00fclerine eri\u015fim sa\u011flayabilir mi? Ne de olsa i\u015fler k\u00f6t\u00fcye gitti\u011finde, evinizin foto\u011fraf ve videolar\u0131 da dahil olmak \u00fczere son derece hassas veriler yanl\u0131\u015f ki\u015filerin eline ge\u00e7ebilir.<\/p>\n<h2>Bozulan s\u00f6zler<\/h2>\n<p>Anker, kendi IP kameras\u0131 serisini Eufy markas\u0131 alt\u0131nda piyasaya s\u00fcrd\u00fc\u011f\u00fcnde t\u00fcm bu korkulara olduk\u00e7a a\u015finayd\u0131. 2011\u2019de kurulan Anker, elektronik sekt\u00f6r\u00fcnde yeni de\u011fil. Ak\u0131ll\u0131 telefon ve diz\u00fcst\u00fc bilgisayarlara y\u00f6nelik \u015farj aleti ve aksesuar \u00fcretimiyle sekt\u00f6re giri\u015f yapan \u015firket, her t\u00fcrl\u00fc zevk ve ihtiyaca hitap edecek ta\u015f\u0131nabilir elektronik cihazlardan olu\u015fan kapsaml\u0131 bir portf\u00f6y yaratt\u0131. G\u00f6r\u00fcnt\u00fcl\u00fc diyafon sistemleri ve g\u00fcvenlik kameralar\u0131 da buna dahil.<\/p>\n<div id=\"attachment_11185\" style=\"width: 1470px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2022\/12\/16185448\/ip-cameras-unsecurity-eufy-01.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-11185\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2022\/12\/16185448\/ip-cameras-unsecurity-eufy-01.jpg\" alt=\"Eufy'nin web sitesinden al\u0131nan ve kullan\u0131c\u0131 verilerinin tamamen korundu\u011funu belirten ekran g\u00f6r\u00fcnt\u00fcs\u00fc.\" width=\"1460\" height=\"777\" class=\"size-full wp-image-11185\"><\/a><p id=\"caption-attachment-11185\" class=\"wp-caption-text\">Eufy\u2019nin web sitesinden al\u0131nan ve kullan\u0131c\u0131 verilerinin tamamen korundu\u011funu belirten ekran g\u00f6r\u00fcnt\u00fcs\u00fc.<\/p><\/div>\n<p><a target=\"_blank\" rel=\"nofollow noopener\" href=\"https:\/\/us.eufy.com\/pages\/privacy-commitment\">Eufy\u2019nin web sitesinde<\/a> yer alan reklamda kamera geli\u015ftiriciler, maksimum g\u00fcvenlik sunulaca\u011f\u0131n\u0131 ve bulut sistemi kullan\u0131lmayaca\u011f\u0131n\u0131 garanti ediyor: T\u00fcm veriler g\u00fcvenli ve yerel bir depolama alan\u0131nda tutuluyor. Uzaktan video kamera fonksiyonu tamamen devre d\u0131\u015f\u0131 b\u0131rak\u0131labiliyor fakat evinizin i\u00e7inde olan biteni g\u00f6rmek isterseniz de, kameran\u0131z video ak\u0131\u015f\u0131n\u0131 \u015fifreliyor ve ak\u0131ll\u0131 telefonunuzdaki uygulamaya g\u00f6nderiyor. Bu uygulama, g\u00f6r\u00fcnt\u00fclerin de\u015fifre edilebilece\u011fi tek yer. Buna \u201cu\u00e7tan uca \u015fifreleme\u201d ad\u0131 veriliyor. Yani sat\u0131c\u0131 da dahil hi\u00e7 kimse verilere eri\u015femiyor.<\/p>\n<p>Ayr\u0131ca, alg\u0131lama sistemi do\u011frudan cihazda \u00e7al\u0131\u015f\u0131yor. Her kamerada bulunan entegre yapay zeka, \u015firketin sunucular\u0131na herhangi bir \u015fey g\u00f6ndermeksizin g\u00f6r\u00fcnt\u00fcy\u00fc analiz ediyor, karedeki ki\u015fileri tespit ediyor, hatta tan\u0131yor; \u00f6rne\u011fin ev sahibini ve kirac\u0131y\u0131 yabanc\u0131lardan ay\u0131rt edebiliyor. Bu sayede, bilinmeyen bir ki\u015fi kadraja girdi\u011finde kameran\u0131n kullan\u0131c\u0131s\u0131 bilgilendiriliyor.<\/p>\n<p>Mahremiyetiniz g\u00fcvence alt\u0131nda. Fakat kullan\u0131c\u0131lar, yak\u0131n zamanda ufak bir s\u00fcrprizle kar\u015f\u0131la\u015ft\u0131: Eufy kameralar, arka planda biraz farkl\u0131 \u00e7al\u0131\u015f\u0131yor. Britanyal\u0131 g\u00fcvenlik uzman\u0131 Paul Moore, 23 Kas\u0131m\u2019da att\u0131\u011f\u0131 bir <a target=\"_blank\" rel=\"nofollow noopener\" href=\"https:\/\/twitter.com\/Paul_Reviews\/status\/1595421705996042240\">tweet\u2019te<\/a> bir <a target=\"_blank\" rel=\"nofollow noopener\" href=\"https:\/\/www.youtube.com\/watch?v=qOjiCbxP5Lc\">videoya<\/a> yer vererek, Eufy\u2019yi, verileri buluta iletme se\u00e7ene\u011fi kapal\u0131yken bile bunu yapmakla su\u00e7lad\u0131.<\/p>\n<div id=\"attachment_11184\" style=\"width: 922px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2022\/12\/16185448\/ip-cameras-unsecurity-eufy-02.png\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-11184\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2022\/12\/16185448\/ip-cameras-unsecurity-eufy-02.png\" alt=\"Paul Moore'un Eufy kameralar\u0131n\u0131n veri g\u00fcvenli\u011fi sorunlar\u0131yla ilgili olarak att\u0131\u011f\u0131 tweet'lerden birisi.\" width=\"912\" height=\"752\" class=\"size-full wp-image-11184\"><\/a><p id=\"caption-attachment-11184\" class=\"wp-caption-text\">Paul Moore\u2019un Eufy kameralar\u0131n\u0131n veri g\u00fcvenli\u011fi sorunlar\u0131yla ilgili olarak att\u0131\u011f\u0131 tweet\u2019lerden birisi.<\/p><\/div>\n<p>Moore\u2019un videosunda sorun detayl\u0131 bir \u015fekilde g\u00f6steriliyor; Moore, bu durumu olduk\u00e7a kolay tespit etmi\u015f. Eufy g\u00f6r\u00fcnt\u00fcl\u00fc diyafon sistemlerinden birisini kuran Paul, cihaz\u0131n web aray\u00fcz\u00fcnde oturum a\u00e7arak kaynak kodu taray\u0131c\u0131da analiz ediyor ve kadrajda birinin g\u00f6r\u00fcnd\u00fc\u011f\u00fc her durumda, kameran\u0131n sat\u0131c\u0131n\u0131n sunucusuna bir foto\u011fraf g\u00f6nderdi\u011fini g\u00f6steriyor. Bu da Eufy\u2019nin taahh\u00fctlerinden en az bir tanesinin (\u201cbulut yok\u201d taahh\u00fcd\u00fc) ger\u00e7ek olmad\u0131\u011f\u0131 anlam\u0131na geliyor.<\/p>\n<p>Bu olaydan sonra Moore, veri korumayla ilgili \u00e7ok daha ciddi sorunlar hakk\u0131nda birka\u00e7 kez daha tweet att\u0131. G\u00f6r\u00fcn\u00fc\u015fe g\u00f6re Eufy\u2019nin \u201cg\u00fcvenilir\u201d \u015fifrelemesinde, t\u00fcm kullan\u0131c\u0131lar i\u00e7in ayn\u0131 sabit anahtar <a target=\"_blank\" rel=\"nofollow noopener\" href=\"https:\/\/twitter.com\/Paul_Reviews\/status\/1594725532062580737\">kullan\u0131l\u0131yor<\/a>. Daha da k\u00f6t\u00fcs\u00fc bu anahtar, bizzat \u015firket taraf\u0131ndan <a target=\"_blank\" rel=\"nofollow noopener\" href=\"https:\/\/github.com\/FuzzyMistborn\/python-eufy-security\/blob\/dev\/API.md\">GitHub<\/a>\u2018da payla\u015f\u0131lan Eufy kodunda g\u00f6r\u00fcn\u00fcyor. Sonras\u0131nda, teknoloji sitesi <em>The Verge<\/em>, Moore ve ba\u015fka bir g\u00fcvenlik uzman\u0131na at\u0131fta bulunarak en k\u00f6t\u00fc senaryoyu <a target=\"_blank\" rel=\"nofollow noopener\" href=\"https:\/\/www.theverge.com\/2022\/11\/30\/23486753\/anker-eufy-security-camera-cloud-private-encryption-authentication-storage\">do\u011frulad\u0131<\/a>: G\u00f6r\u00fcn\u00fc\u015fe g\u00f6re internete eri\u015fimi olan herkes, sadece cihaz\u0131n kendine ait adresine ba\u011flanarak g\u00f6r\u00fcnt\u00fc ak\u0131\u015f\u0131n\u0131 izleyebiliyordu.<\/p>\n<h2>Belirsiz a\u00e7\u0131klama<\/h2>\n<p>G\u00f6r\u00fcnt\u00fclerin buluta y\u00fcklenmesine ili\u015fkin ilk sorunla ilgili olarak tamamen mant\u0131kl\u0131 bir a\u00e7\u0131klama oldu\u011funun s\u00f6ylenmesi gerekir. Teoride Eufy kameralar\u0131 \u015f\u00f6yle \u00e7al\u0131\u015f\u0131yor: Kameray\u0131 evinize kuruyorsunuz ve ak\u0131ll\u0131 telefonunuz \u00fczerinden uygulamay\u0131 yap\u0131land\u0131r\u0131yorsunuz. Birisi Ak\u0131ll\u0131 Arama d\u00fc\u011fmesine bast\u0131\u011f\u0131nda veya alg\u0131lama sistemi kadraja birini alg\u0131lad\u0131\u011f\u0131nda, ak\u0131ll\u0131 telefonunuza foto\u011fraf i\u00e7eren bir bildirim geliyor. B\u00fcy\u00fck olas\u0131l\u0131kla bu bildirimleri g\u00f6ndermenin tek yolu bulut. \u00d6yleyse Eufy neden bulut kullan\u0131lmayan bir deneyim vadetti? G\u00fczel soru!<\/p>\n<p>Peki ya video g\u00f6r\u00fcnt\u00fclerine uzaktan eri\u015fim sa\u011flanabilmesi? <em>The Verge<\/em> ve kaynaklar\u0131, bu g\u00fcvenlik a\u00e7\u0131\u011f\u0131ndan toplu \u015fekilde faydalan\u0131lmas\u0131n\u0131 \u00f6nlemek i\u00e7in problemin t\u00fcm detaylar\u0131n\u0131 payla\u015fmad\u0131. Fakat yine de baz\u0131 sorunlar a\u015fikar: \u00d6ncelikle, video g\u00f6r\u00fcnt\u00fclerini iletmek i\u00e7in vadedilen \u015fifreleme kullan\u0131lm\u0131yor. Asl\u0131na bakarsan\u0131z g\u00f6r\u00fcnt\u00fcler hi\u00e7 \u015fifrelenmiyor ve VLC gibi s\u0131radan bir medya oynat\u0131c\u0131 kullan\u0131larak izlenebiliyor. \u0130kinci olarak, belirli bir kameraya eri\u015fmek i\u00e7in o kameraya ait URL\u2019yi, yani internetteki adresini bilmeniz gerekiyor. Fakat bu adresler tahmin edilebilir bir \u015fekilde olu\u015fturuluyor; do\u011frudan cihaz\u0131n kutusunun \u00fcst\u00fcnde yazan seri numaras\u0131 ile o an\u0131n tarih ve saati kullan\u0131l\u0131yor. Buna ek olarak (ekstra \u201cg\u00fcvenlik\u201d i\u00e7in) d\u00f6rt haneli rastgele bir say\u0131 kullan\u0131l\u0131yor. Bu say\u0131 da \u201ckaba kuvvet\u201d yakla\u015f\u0131m\u0131yla kolayca \u00e7\u00f6z\u00fclebiliyor. Kamera kullan\u0131c\u0131s\u0131n\u0131, cihaz\u0131n seri numaras\u0131n\u0131 bilen bir sald\u0131rgana kar\u015f\u0131 koruyan tek \u015fey, kameran\u0131n verileri internete s\u00fcrekli olarak y\u00fcklememesi. \u00d6rne\u011fin \u00f6ncelikle kap\u0131 ziline bas\u0131larak etkinle\u015ftirilmesi gerekiyor. Bu s\u0131rada da yabanc\u0131 birisinin ba\u011flant\u0131 kurmas\u0131 m\u00fcmk\u00fcn hale geliyor.<\/p>\n<p>Eufy\u2019nin sahibi Anker\u2019dan iddialar\u0131 do\u011frulamas\u0131 ya da yalanlamas\u0131 istendi, bu da i\u015flerin daha \u00e7ok kar\u0131\u015fmas\u0131na neden oldu. <em>The Verge<\/em> ve <a target=\"_blank\" rel=\"nofollow noopener\" href=\"https:\/\/arstechnica.com\/gadgets\/2022\/12\/more-eufy-camera-flaws-found-including-remote-unencrypted-feed-viewing\/\"><em>Ars Technica<\/em><\/a> taraf\u0131ndan belirtildi\u011fi \u00fczere geli\u015ftiriciler, herhangi bir g\u00fcvenlik sorunu oldu\u011funu kesin bir dille reddetti ve belirli problemler hakk\u0131ndaki sorular kar\u015f\u0131s\u0131nda da en az iki beyanda bulundu. Sonras\u0131nda ise bu beyanlar\u0131n ger\u00e7ek olmad\u0131\u011f\u0131 ortaya \u00e7\u0131kt\u0131.<\/p>\n<p>Birinci beyanda \u015firket, kameradan canl\u0131 g\u00f6r\u00fcnt\u00fc izlemenin m\u00fcmk\u00fcn olmad\u0131\u011f\u0131n\u0131 \u201cdo\u011frulad\u0131\u201d fakat <em>The Verge\u2019<\/em>\u00fcn, kendisine ait Eufy kameralardan ikisini kullanarak yapt\u0131\u011f\u0131 \u015fey tam olarak buydu. \u0130kinci beyanda ise \u015firket, g\u00f6r\u00fcnt\u00fcl\u00fc diyafonlardan al\u0131nan g\u00f6r\u00fcnt\u00fclerin \u015firket sunucular\u0131na g\u00f6nderildi\u011fini fakat bunun amac\u0131n\u0131n yaln\u0131zca ak\u0131ll\u0131 telefonlara bildirim g\u00f6ndermek oldu\u011funu, sonras\u0131nda ise s\u00f6z konusu g\u00f6r\u00fcnt\u00fclerin silindi\u011fini kabul etti. Fakat bu da Moore taraf\u0131ndan <a target=\"_blank\" rel=\"nofollow noopener\" href=\"https:\/\/www.youtube.com\/watch?v=etpbq_HH79c\">basit bir test<\/a> yap\u0131larak <a target=\"_blank\" rel=\"nofollow noopener\" href=\"https:\/\/twitter.com\/Paul_Reviews\/status\/1596169974091071493\">yalanland\u0131<\/a>: Moore, ki\u015fisel hesab\u0131ndan kameran\u0131n \u00e7ekti\u011fi foto\u011fraflar\u0131 g\u00f6r\u00fcnt\u00fcledikten sonra, bu foto\u011fraflar\u0131n URL\u2019lerini kaydetti ve foto\u011fraflar\u0131 telefonundan sildi. Foto\u011fraflar telefonundan silinmi\u015f olmas\u0131na ra\u011fmen Moore, sadece kaydetti\u011fi URL\u2019leri taray\u0131c\u0131n\u0131n adres \u00e7ubu\u011funa yazarak bu foto\u011fraflara eri\u015fmeyi ba\u015fard\u0131. Yukar\u0131da s\u00f6z\u00fc ge\u00e7en di\u011fer ara\u015ft\u0131rmac\u0131 <a target=\"_blank\" rel=\"nofollow noopener\" href=\"https:\/\/www.youtube.com\/watch?v=6TlQcg-_zoQ\">daha da ileri gitti<\/a>: Video kameray\u0131 tamamen s\u0131f\u0131rlad\u0131ktan, dolay\u0131s\u0131yla da hesab\u0131nda kay\u0131tl\u0131 t\u00fcm videolar\u0131 sildikten sonra, cihaz\u0131 hesab\u0131na tekrar ba\u011flad\u0131 ve silinmi\u015f olmas\u0131 gereken videolar\u0131 g\u00f6rd\u00fc!<\/p>\n<p>Genel olarak konu\u015fmak gerekirse g\u00fcvenlik sekt\u00f6r\u00fcnde belirli etik standartlar de\u011fi\u015fime u\u011frad\u0131. G\u00fcvenlik a\u00e7\u0131klar\u0131yla ilgili bilgilerin nas\u0131l a\u00e7\u0131klanaca\u011f\u0131 ve sat\u0131c\u0131lar\u0131n buna nas\u0131l yan\u0131t vermesi gerekti\u011fi konular\u0131 buna \u00f6rnek verilebilir. Fakat Eufy olay\u0131nda bu etik standartlar tamamen yok oldu: Ara\u015ft\u0131rmac\u0131lar, \u015firkete sorunlar\u0131 d\u00fczeltme \u015fans\u0131 vermek yerine g\u00fcvenlik a\u00e7\u0131klar\u0131n\u0131 do\u011frudan kamuyla payla\u015ft\u0131. Ard\u0131ndan \u015firket, g\u00fcn gibi ortada olan bu sorunlar\u0131 inkar ederek yang\u0131na k\u00f6r\u00fckle gitmi\u015f oldu. Eufy, ba\u011f\u0131ms\u0131z uzmanlar\u0131n iddialar\u0131n\u0131 \u00e7\u00fcr\u00fctmeye y\u00f6nelik hi\u00e7bir teknik kan\u0131t sunmazken, Moore\u2019un su\u00e7lay\u0131c\u0131 payla\u015f\u0131mlar\u0131ndan sonra fark etti\u011fi tek de\u011fi\u015fiklik, \u00f6nceden HTML\u2019de \u015fifresiz metin \u015feklinde g\u00f6sterilen ve kamera karelerine giden ba\u011flant\u0131lar\u0131n, art\u0131k bulan\u0131k \u015fekilde g\u00f6steriliyor olmas\u0131yd\u0131. Yani bilgiler yine de Eufy sunucusuna g\u00f6nderiliyor fakat bu i\u015flem sadece izlemesi daha zor \u015fekilde yap\u0131l\u0131yordu.<\/p>\n<p>G\u00f6r\u00fcn\u00fc\u015fe g\u00f6re sat\u0131c\u0131, hi\u00e7 kimsenin kontrol etmeyece\u011fini umarak web sitesindeki bir taahh\u00fcd\u00fcn\u00fc daha bozmu\u015ftu. Ancak Eufy\u2019nin bu eylemi kendi taahh\u00fctlerinin yan\u0131 s\u0131ra, AB\u2019deki GDPR gibi, kullan\u0131c\u0131 verilerinin korunmas\u0131na y\u00f6nelik b\u00f6lgesel kanunlar\u0131 da ihlal ediyor.<\/p>\n<h2>Koruma y\u00f6ntemleri<\/h2>\n<p>Eufy vakas\u0131 olduk\u00e7a yeni. Ayr\u0131ca yetkisiz ki\u015filerin, belirli veya rastgele bir kullan\u0131c\u0131n\u0131n IP kameras\u0131ndan g\u00f6r\u00fcnt\u00fc alabildi\u011finin kesin olarak kan\u0131tlanmas\u0131 i\u00e7in ba\u015fka ara\u015ft\u0131rmalar da yap\u0131lmas\u0131 gerekiyor. Ancak, daha da ciddi g\u00fcvenlik sorular\u0131na dair birtak\u0131m \u00f6rnekler mevcut. \u00d6rne\u011fin 2021\u2019de, \u00c7inli \u00fcretici Hikvision\u2019\u0131n IP kameralar\u0131n\u0131n kritik bir g\u00fcvenlik a\u00e7\u0131\u011f\u0131 <a target=\"_blank\" rel=\"nofollow noopener\" href=\"https:\/\/watchfulip.github.io\/2021\/09\/18\/Hikvision-IP-Camera-Unauthenticated-RCE.html\">i\u00e7erdi\u011fi<\/a> ve bu g\u00fcvenlik a\u00e7\u0131\u011f\u0131 sayesinde sald\u0131rganlar\u0131n, cihaz\u0131n kontrol\u00fcn\u00fc tamamen ele ge\u00e7irebilece\u011fi saptand\u0131. Bu durumu d\u00fczeltmek i\u00e7in bir yama yay\u0131mlanm\u0131\u015f olsa da, bir y\u0131l sonra bile on binlerce kamera h\u00e2l\u00e2 g\u00fcvenlik a\u00e7\u0131\u011f\u0131 i\u00e7eriyor ve merakl\u0131 \u00fc\u00e7\u00fcnc\u00fc taraflar bu kameralara eri\u015febiliyordu. Ne yaz\u0131k ki en k\u00f6t\u00fc senaryoda, bu kameralar\u0131n kullan\u0131c\u0131lar\u0131 s\u00f6z konusu g\u00fcvenlik a\u00e7\u0131\u011f\u0131n\u0131n fark\u0131nda bile olmayabiliyor.<\/p>\n<p>B\u00f6ylece s\u00fcrekli sorulan sorular, bir kez daha kar\u015f\u0131m\u0131za \u00e7\u0131km\u0131\u015f oluyor: Bu kimin su\u00e7u ve ne yap\u0131lmas\u0131 gerekiyor? Ne yaz\u0131k ki Nesnelerin \u0130nterneti sekt\u00f6r\u00fc pek standartla\u015fm\u0131\u015f bir sekt\u00f6r de\u011fil. En az\u0131ndan asgari g\u00fcvenlik sa\u011flayacak genel kabul g\u00f6rm\u00fc\u015f normlar yok. Sat\u0131c\u0131lar, cihazlar\u0131n\u0131 mevcut kaynaklarla ve kendi g\u00fcvenlik nosyonlar\u0131yla koruyor. Hangi sat\u0131c\u0131ya g\u00fcvenece\u011fine karar vermek de kullan\u0131c\u0131ya kal\u0131yor.<\/p>\n<p><a target=\"_blank\" href=\"https:\/\/arstechnica.com\/gadgets\/2022\/12\/more-eufy-camera-flaws-found-including-remote-unencrypted-feed-viewing\/\" rel=\"noopener nofollow\">Ars Technica<\/a>\u2018n\u0131n do\u011fru \u015fekilde belirtti\u011fi \u00fczere, cihaz\u0131n\u0131zda bir lens ve Wi-Fi \u00f6zelli\u011fi varsa nihayetinde birisi bu \u00fcr\u00fcnde bir g\u00fcvenlik a\u00e7\u0131\u011f\u0131 bulacakt\u0131r. \u0130lgin\u00e7tir ki tasar\u0131m bak\u0131m\u0131ndan benzer olan cihazlar (diz\u00fcst\u00fc bilgisayarlardaki ve ak\u0131ll\u0131 telefonlardaki web kameralar\u0131) \u00e7ok daha iyi korunuyor: Kamera kullan\u0131l\u0131yorken bir g\u00f6sterge \u0131\u015f\u0131\u011f\u0131 yan\u0131yor ve <a target=\"_blank\" rel=\"nofollow noopener\" href=\"https:\/\/support.kaspersky.com\/15408\">g\u00fcvenlik \u00e7\u00f6z\u00fcmleri<\/a>, uygulamalar\u0131 izleyerek cihaza yetkisiz eri\u015fimi engelliyor.<\/p>\n<p><input type=\"hidden\" class=\"category_for_banner\" value=\"kis-top3\"><br>\n\u00a0<br>\nIP g\u00fcvenlik kameralar\u0131 ise bazen 7\/24 otonom \u015fekilde \u00e7al\u0131\u015f\u0131yor. Ne yaz\u0131k ki, cihaz g\u00fcvenli\u011fini de\u011ferlendirmeye y\u00f6nelik genel kabul g\u00f6ren bir sistem geli\u015ftirilene kadar sat\u0131c\u0131lar\u0131n \u201cgarantilerine\u201d g\u00fcvenmemeli, gizlili\u011finizi korumak i\u00e7in kendi \u00f6nlemlerinizi almal\u0131s\u0131n\u0131z. Video kamera sistemi kullan\u0131c\u0131lar\u0131na, cihazlar\u0131 hakk\u0131ndaki g\u00fcvenlik sorunlar\u0131yla ilgili haberleri takip etmelerini, kamera ayarlar\u0131n\u0131 dikkatle g\u00f6den ge\u00e7irmelerini, kullanmad\u0131klar\u0131 bulut \u00f6zelliklerini devre d\u0131\u015f\u0131 b\u0131rakmalar\u0131n\u0131 ve g\u00fcncellemeleri d\u00fczenli olarak y\u00fcklemelerini \u00f6neririz. Evinize video kamera sistemi kurmaya karar verirken de t\u00fcm riskleri de\u011ferlendirin zira izinsiz eri\u015fimden kaynaklanabilecek zararlar ciddi anlamda b\u00fcy\u00fckt\u00fcr.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Evlere y\u00f6nelik g\u00fcvenlik kameras\u0131 sistemlerinin g\u00fcvenli oldu\u011fu s\u00f6ylenir. Peki ama fark\u0131nda olmadan reality show y\u0131ld\u0131z\u0131 olmaya haz\u0131r m\u0131s\u0131n\u0131z?<\/p>\n","protected":false},"author":665,"featured_media":11186,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1284],"tags":[1350,706,2524,2523,629,715,1063,851,537],"class_list":{"0":"post-11183","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tips","8":"tag-akilli-ev","9":"tag-cctv","10":"tag-gizli-kameralar","11":"tag-guvenlik-kamerasi","12":"tag-iot","13":"tag-kisisel-veriler","14":"tag-nesnelerin-interneti","15":"tag-sizinti","16":"tag-tehditler"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/ip-cameras-unsecurity-eufy\/11183\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/ip-cameras-unsecurity-eufy\/24970\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/ip-cameras-unsecurity-eufy\/20468\/"},{"hreflang":"ar","url":"https:\/\/me.kaspersky.com\/blog\/ip-cameras-unsecurity-eufy\/10338\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/ip-cameras-unsecurity-eufy\/27538\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/ip-cameras-unsecurity-eufy\/25302\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/ip-cameras-unsecurity-eufy\/25617\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/ip-cameras-unsecurity-eufy\/28175\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/ip-cameras-unsecurity-eufy\/27443\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/ip-cameras-unsecurity-eufy\/34368\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/ip-cameras-unsecurity-eufy\/46574\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/ip-cameras-unsecurity-eufy\/19887\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/ip-cameras-unsecurity-eufy\/20469\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/ip-cameras-unsecurity-eufy\/29594\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/ip-cameras-unsecurity-eufy\/33000\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/ip-cameras-unsecurity-eufy\/28677\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/ip-cameras-unsecurity-eufy\/25657\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/ip-cameras-unsecurity-eufy\/31349\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/ip-cameras-unsecurity-eufy\/31076\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/tehditler\/","name":"tehditler"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/11183","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/665"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=11183"}],"version-history":[{"count":3,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/11183\/revisions"}],"predecessor-version":[{"id":11189,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/11183\/revisions\/11189"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/11186"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=11183"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=11183"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=11183"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}