Remote viewing lets you check the shop, the site or the house from anywhere. It also connects your cameras to the internet, and cameras have been a favourite target of attackers for years. Here is how it works and how to do it safely.
The two ways remote viewing works
1. The manufacturer's app (cloud or P2P). The recorder makes an outgoing connection to the manufacturer's service, and your phone app connects through it. You usually scan a QR code on the recorder to add it. Nothing on your network has to accept connections from the internet.
2. Port forwarding. Your router is set to pass traffic from the internet straight to the recorder, and you connect to your public IP address. This puts the recorder's login page on the open internet, where automated scanners look for exposed recorders around the clock.
For most businesses the manufacturer's app is the safer choice. If port forwarding is unavoidable, it should go through a VPN on the router rather than straight to the recorder.
Why this matters
- In 2016 the Mirai botnet took over hundreds of thousands of internet-connected devices, many of them cameras and video recorders, mostly by logging in with factory default passwords. It was then used for some of the largest denial-of-service attacks seen at the time.
- In 2021 a critical flaw (CVE-2021-36260) was found in the web server of many Hikvision cameras and recorders. It let an attacker take full control without a password. A fix was released, but the flaw was exploited on devices that were never updated, and the US cybersecurity agency CISA added it to its list of known exploited vulnerabilities in January 2022.
In both cases the devices at risk were the ones reachable from the internet with old firmware or default passwords.
The checklist
- Change the default password on the recorder and every camera during installation.
- Give each viewer their own account through the app's sharing feature, with view-only access where possible. Never share the admin login.
- Turn on two-step verification in the app if it offers it.
- Update the firmware on the recorder and cameras, and update the app on your phone.
- Turn off UPnP on the router and the recorder, so the recorder cannot open ports on its own.
- Turn off remote viewing entirely if nobody actually uses it.
- Install the app only from the official app store, published by the camera's manufacturer.
- Put cameras on their own network (a separate VLAN) so a compromised camera cannot reach your office computers.
Two practical points
- Phone apps normally show the lower-resolution sub stream by default to save data. Switch to the main stream only when you need detail.
- Remote viewing stops when the router or recorder loses power. See Keeping CCTV recording through dumsor for keeping both running.