Devices Smart home and connected devices
Home cameras: keeping the feed away from everybody else
How camera feeds get exposed, the settings that prevent it, where cameras belong and do not, and the questions to ask before buying one.
The short answer
- Almost every exposed camera feed was reached through a reused or default password rather than through any clever attack on the camera.
- A unique password, a second factor and login alerts on the camera account do more than every other precaution combined.
- Cloud recording survives theft but puts a copy of your footage in someone else's hands, while local recording keeps control and makes backup your problem.
- Never forward a port to a camera, and keep cameras on a separate network from your computers and phones.
- Shared access is rarely revoked, so review the list of people and connected apps at least twice a year.
- Once a camera captures a public path or a neighbor's property, data protection duties can apply in the UK and the EU, and audio recording is the part most likely to cause trouble anywhere.
Almost every home camera that ends up watched by a stranger was reached through the account, not through the camera. The password was reused somewhere that later leaked, or it was the one printed in the manual, or somebody who was given access two years ago still has it. Exotic attacks on camera firmware exist, but they are rare next to an email address and password typed into a login page by software. That is good news, because the fixes are ordinary: a unique password, a second factor, updated firmware, and an honest list of who can see the feed.
How camera feeds actually get exposed
The routes are well understood and far from equally likely. Ranking them honestly matters, because effort spent on the rare ones is effort not spent on the common ones.
| Route in | How common | What stops it |
|---|---|---|
| Reused password taken from another site's breach | The most common by a wide margin | A unique generated password, plus a second factor |
| Default or printed password never changed | Common on cheap and secondhand cameras | Change it during setup, before mounting the camera |
| Shared access that was never revoked | Common, and usually invisible until you look | Review the list of people and linked apps twice a year |
| Camera exposed directly to the internet by port forwarding | Less common now, devastating when present | Never forward a port to a camera, use the vendor app or a VPN |
| Unpatched firmware with a published flaw | Occasional, and it stays open for years | Automatic firmware updates, and retiring unsupported models |
| Incident at the provider, or staff access to stored video | Rare, but entirely outside your control | Local recording, or end to end encryption where offered |
| Physical access to the memory card or the camera itself | Rare indoors, real for outdoor units | Mount out of reach, and keep a cloud or offsite copy of clips |
The first three rows account for most real incidents. A stranger scrolling through a nursery feed almost never broke anything: they logged in. Software takes username and password pairs from old breaches and tries them against camera services at scale, which works because the same password was used on a forum a decade ago. That is the whole reason reusing one password is the most expensive habit online, and a camera is where the consequences are most personal.
The account is the camera
Treat the camera login as one of the three or four accounts that deserve real protection, alongside your email and your bank. Three steps cover it.
Give it a long, unique password that exists nowhere else, generated and stored in a password manager rather than remembered. Turn on a second factor, preferring an authenticator app over text messages where the option exists, because a second factor stops a stolen password from being enough and that is precisely the attack these systems face. Then check whether the password you were using has already been exposed elsewhere, which takes a minute with a breach lookup on your email address.
One more habit that costs nothing: turn on login notifications and read them. A message about a sign in from an unfamiliar city is the earliest warning you will get, and it arrives long before anything visible happens in the app.
Cloud recording or local recording
This is the real design decision, and neither answer is simply better. It depends which failure you would rather have.
Cloud recording sends clips offsite. A thief who takes the camera cannot take the evidence, clips are available anywhere, and the detection that separates a person from a passing car usually runs on the provider's servers. The costs are a subscription, a copy of your footage held by a company, and staff access, provider side incidents and lawful requests all being outside your control.
Local recording keeps video on a memory card or a recorder in the house. Nobody else holds a copy, there is no subscription, and it works when the internet does not. The costs are that theft or fire takes the footage with the device, that remote viewing usually still travels through the vendor's relay service, and that the backup a cloud service quietly provided is now your job.
A middle path is worth asking about: some cameras offer end to end encryption, where clips are encrypted on the device with a key only your phone holds. It is the strongest option available, and the honest trade is that features needing the provider to look at the video, such as package or face detection, are reduced or unavailable. You cannot have both.
Firmware and the network around it
Cameras are computers nobody patches. Turn on automatic firmware updates during setup, and if the model does not offer them, put a twice yearly reminder in your calendar. When a maker stops issuing updates, every flaw found afterward stays open permanently, which is why firmware is the update category that leaves devices exposed for years.
Then three network habits. First, never set up port forwarding or leave automatic port opening enabled for a camera. It puts the device directly on the public internet, where scanners find it within hours. Remote viewing works through the vendor app without any of that.
Second, put cameras and other gadgets on a separate network from your computers and phones. On most home routers the guest network is the easy version of this. The point is containment: a compromised camera should not be able to see the laptop with your documents on it.
Third, if a camera records locally and you do not need remote access, block its internet access at the router entirely. A camera that cannot reach the internet cannot be reached from it either. The same separation is worth applying to everything else you have connected, and it is one of the steps in setting up a smart home so it keeps working.
Who else can see the feed
Shared access is the quiet failure. Over a few years a camera account collects a partner, a family member, a house sitter, a neighbor who watched the place during a holiday, an installer, and two apps you connected once and forgot. Each one is a live route to the video.
Open the sharing or members list today and remove anyone with no current reason to be there, then do the same for connected services and automation apps. Set a rule for the future: temporary access means temporary, and a housemate moving out is a prompt to check the list. If a household split was difficult, treat camera and smart lock access as urgently as the front door key.
Where cameras belong, and where they do not
Placement is partly a question of taste and partly a legal one, and the legal part differs by country. What follows is general information rather than advice about your particular situation.
Inside the home, bedrooms and bathrooms are not camera places, and that includes a device with a screen and a lens on a bedside table. Cameras aimed where someone would reasonably expect privacy cause problems in most legal systems, and in households regardless of the law. If an indoor camera is for an empty house, use the mode that disables it when someone is home.
Outside, the issue is what else is in the frame. In the UK and across the EU, a domestic camera is normally exempt from data protection rules, but once it captures a public pavement, a shared driveway or a neighbor's property, that household exemption stops applying and you take on responsibilities: recording no more than necessary, telling people that recording happens, keeping footage no longer than needed, and responding if someone asks for a copy of their own images. That last point catches people out, because a neighbor really can ask, and what people are entitled to ask about data held on them applies to your doorbell as much as to a company.
In the US there is no single national rule. Video of an area in public view is broadly permitted, recording where there is a reasonable expectation of privacy is not, and the details vary by state. Audio is the sharper issue: eavesdropping laws treat conversations differently from images, some states require the consent of one party and others of everyone, and a doorbell recording a conversation on the sidewalk can land on the wrong side of that line. The practical answer is the same everywhere: angle the camera down toward your own property, use privacy masking to black out a neighbor's window or a shared path, and turn audio off unless you need it.
The setup worth doing today
Half an hour, and most of the risk goes away.
- Change the camera account password to a long unique one from a password manager, and change any device level password too.
- Turn on two factor authentication and login alerts.
- Open the shared users and connected apps lists and remove everyone who should not be there.
- Enable automatic firmware updates, and check the model still receives them.
- Confirm no port forwarding or automatic port opening is enabled for the camera on your router.
- Move cameras onto the guest or device network, away from your computers.
- Decide cloud or local deliberately, and turn on end to end encryption if it is offered and you can live with the feature trade.
- Set the viewing angle and privacy zones so the frame covers your property, and switch audio off unless you need it.
Then tell the other people in your home what is recording and where the footage goes, which prevents most of the arguments a camera causes. The same conversation is worth having about anything else in the house with a microphone in it, since what a smart speaker hears and keeps raises the same questions in a quieter form.
Common questions
Can someone hack my home camera?
In practice they log in rather than hack in. Automated software takes email and password pairs from old breaches and tries them against camera services in bulk, so a password used anywhere else is the usual way in. Give the account a unique password and a second factor and that entire category of attack stops working against you.
Is local storage safer than cloud storage for camera footage?
Safer against one risk and worse against another. Local storage means nobody else holds a copy, but a thief who takes the camera or the recorder takes the footage too. Cloud storage survives theft and fire but places your video with a company. If a provider offers end to end encryption, that is the closest thing to both, at the cost of some detection features.
Is it legal to point a doorbell camera at the street?
This is general information rather than advice for your situation. In the UK and EU, capturing beyond your own property usually removes the household exemption from data protection rules and brings duties such as signage, limited retention and responding to requests for footage. In the US it varies by state, and audio is the part most likely to breach eavesdropping laws. Angling down and turning audio off avoids most of it.
Should I put a camera inside my home?
If you do, keep it out of bedrooms and bathrooms, and use a mode that disables recording while someone is home. Indoor cameras are most useful for an empty house, and least comfortable for the people who live there. Tell everyone in the household it exists, including visitors who stay overnight, because the surprise is what causes the conflict.
How do I know if someone else still has access to my camera?
Open the sharing or members section of the app, which lists the accounts that can view the feed, and check the connected apps or services list separately since automation tools often hold access of their own. Remove anything you do not recognize, then change the password so an old session cannot simply continue. Turn on login alerts afterward.