There are websites that list thousands of private cameras anyone can watch: living rooms, shop counters, baby monitors, backyards. None of those owners chose to share. Their cameras were found by automated scanning because they were reachable from the internet with a default password or an unpatched flaw. LiveLocation was built as the opposite: we list only cameras that owners and agencies publish on purpose, and our rules ban scanning, imports from such sites and raw camera addresses.
This page is the checklist we would give a friend. It is written for homes and small businesses, and it applies equally to a beach bar’s public webcam and a farm’s gate camera. It is also short on jargon: you do not need to be an IT expert to do any of it.
How cameras actually get broken into
Real-world camera compromises are rarely sophisticated. The pattern is almost always:
- The camera is reachable from the internet, usually because someone forwarded a port or UPnP did it automatically.
- A scanner finds it and tries default or common passwords, or a known flaw in old firmware.
- The attacker watches the feed, posts it publicly, or quietly adds the camera to a botnet.
The 2016 Mirai botnet is the textbook case. According to CISA, it scanned for devices including network cameras and video recorders, logged in over Telnet with a short list of 62 common default usernames and passwords, and used hundreds of thousands of them in massive attacks. In an earlier case, the FTC found that TRENDnet’s cameras sent login credentials in clear text and had faulty software that let anyone with a camera’s address view the feed; about 700 feeds were posted online. CISA’s later Secure by Design alert put it bluntly: default credentials are a top weakness that attackers exploit.
The camera security checklist
1. Keep the camera off the open internet
- No port forwarding to cameras or recorders, and no “DMZ” setting pointing at them.
- Turn off UPnP on the router and in the camera. CISA’s Mirai alert recommended disabling UPnP unless it is essential.
- For remote viewing, use the maker’s app with two-step login or a VPN. For a public stream, push it out to a platform over RTMPS. See port forwarding vs P2P.
2. Use long, unique passwords, and two-step login
- Change every default account on day one, including hidden “user” or “guest” accounts, on cameras, recorders and routers.
- Make passwords long. NIST’s current digital identity guidelines (SP 800-63B-4) require a minimum of 15 characters when a password is the only factor. A passphrase of four or five random words is easy to remember and hard to guess.
- Never reuse a password from another service. A password manager makes this painless.
- Turn on two-step verification for the camera app or cloud account. A stolen password alone then is not enough.
- Use separate accounts for family members, staff and installers, with only the rights they need. Remove them when they leave.
3. Keep firmware and apps updated
- Turn on automatic updates if the camera supports them; otherwise check monthly.
- Update only from the maker’s official site or app.
- Buy from makers that commit to updates. In the UK, the PSTI law in force since April 2024 requires makers of connected products, including security cameras, to publish how long they will provide security updates and to stop shipping guessable default passwords. That support period is worth checking wherever you live.
- Retire cameras that no longer get updates, or at least keep them strictly off the internet.
4. Put cameras on their own network
If a camera is ever compromised, a separate network stops it from reaching your laptops and phones. CISA recommends segmenting networks to limit how far an intruder can move. Options from easiest to most robust:
- Guest or IoT network on a home router, if it isolates devices from your main network.
- VLAN on a business router and managed PoE switch, with rules that block cameras from starting connections to other devices.
- Separate recorder network: cameras connect only to the recorder, and only the recorder talks to the internet (through the maker’s cloud or a VPN).
5. Turn off what you don’t use
- Old protocols: Telnet, FTP and plain HTTP admin pages; use HTTPS for the camera’s web interface where available.
- P2P / cloud if you only record locally.
- RTSP if nothing uses it, or use a dedicated low-privilege account for it. See RTSP explained.
- Audio, unless you need it and it is lawful where you are; see US filming and audio laws.
6. Secure the router and Wi-Fi
- Change the router’s admin password and keep its firmware updated.
- Use WPA2 or, better, WPA3 with a strong passphrase.
- Turn off remote administration of the router from the internet.
7. Think about physical security and privacy
- Mount cameras out of easy reach, so the SD card and reset button cannot be grabbed.
- Aim only at what is yours or at a wide public view; use privacy masks over neighbors’ windows. See cameras and neighbors and privacy by design.
- Delete recordings you do not need.
Choosing a camera that is secure from the box
Security starts at the checkout. Some cameras make the right thing easy; others fight you. Look for:
- Forced password setup: the camera makes you create your own password before it works, with no shared factory default.
- Published update policy: the maker says how long the model gets security updates, and has a page of firmware releases with dates.
- A way to report security problems: a vulnerability disclosure page shows the maker takes reports seriously.
- Two-step login in the app, and the option to turn cloud features off if you do not want them.
- Encrypted connections: HTTPS for the camera’s web interface and RTMPS for streaming.
CISA has urged manufacturers to take ownership of these outcomes, for example by eliminating default passwords altogether, because relying on thousands of customers to change them has not worked. Buying from makers that do is the easiest security decision you will make. For the rest of the buying decision, see how to choose a live camera.
Shared homes, rentals and staff
Cameras are often shared: family members, roommates, a hotel’s front desk, a ski patrol. Give each person their own login with only the rights they need, so you can remove one person without changing everything. When a staff member or installer leaves, remove their account the same day. If you sell or give away a camera, reset it to factory settings and remove it from your app account first, so the next owner cannot see your history and you cannot see theirs.
Risks and fixes at a glance
| Risk | What attackers do | Fix | Effort |
|---|---|---|---|
| Default or weak password | Log in with common passwords | 15+ character unique password, two-step login | 5 minutes |
| Port forward or UPnP | Find the camera by scanning | Remove forwards, turn off UPnP | 10 minutes |
| Old firmware | Use a known flaw | Update; enable auto-updates | 10 minutes, then automatic |
| Flat network | Jump from the camera to your computers | Guest/IoT network or VLAN | 30 to 60 minutes |
| Unused services (Telnet, P2P, RTSP) | Attack a door you forgot | Turn them off | 10 minutes |
| Leaked stream key | Broadcast on your channel | Reset key, keep it private | 2 minutes |
| Shared or old accounts | Use a former staffer’s login | Separate accounts, remove leavers | 15 minutes |
How to tell if a camera was compromised
Signs worth checking:
- The camera moves, talks or changes settings when nobody in your household did it.
- Unknown user accounts in the camera or app.
- Unexpected traffic: your router shows the camera uploading a lot when you are not watching.
- The app shows logins from places you have never been.
If you see these: disconnect the camera from the network, update its firmware, reset it to factory settings, then set it up again with new passwords, without any port forwards. Change the passwords of the app account and the router too. CISA’s Mirai guidance followed the same pattern: disconnect, reboot, change credentials before reconnecting.
Public webcams: extra steps
If your camera streams to the public, a few more habits help:
- Push, never pull. The public watches the platform’s copy; the camera stays private. See RTMP explained.
- Protect the stream key and the platform account with two-step login.
- Keep the camera’s admin interface on the local network or behind a VPN only.
- Review the frame regularly: no windows, yards, screens or close-ups of people.
- Do not allow public camera control.
When you are ready, submit your camera to LiveLocation. Our review checks that it is a public view published on purpose.
Do these next
- Check your router for port forwards and UPnP, and remove them.
- Change every camera, recorder and app password; turn on two-step login.
- Update firmware and move cameras to a guest/IoT network.
Questions people ask
How do security cameras get hacked?
Usually through default or weak passwords, old firmware with known flaws, and cameras exposed to the internet by port forwarding or UPnP. Automated scanners find exposed cameras and try common passwords.
How long should my camera password be?
Long. NIST’s current guidelines require at least 15 characters when a password is the only login factor. A passphrase of several random words works well, and two-step login adds a second layer.
Should I put my cameras on a separate network?
Yes, if you can. A guest or IoT network, or a VLAN in a business, keeps a compromised camera from reaching your computers and phones.
Is it safe to view my camera from my phone?
Yes, when you use the maker’s app with a strong password and two-step login, or a VPN. Avoid port forwarding, which exposes the camera to the whole internet.
What should I do if I think my camera was hacked?
Disconnect it, update its firmware, reset it to factory settings and set it up again with new passwords and no port forwards. Change your app account and router passwords too.
How do I keep my camera off insecure camera websites?
Do not expose it to the internet: no port forwards, UPnP off. Use a unique strong password, keep firmware updated and use the maker’s app, a VPN or a push to a platform for remote viewing.
Sources
- CISA: Heightened DDoS threat posed by Mirai and other botnets (checked 2026-10-07)
- CISA: Secure by Design alert urges manufacturers to eliminate default passwords (checked 2026-10-07)
- CISA: Securing network infrastructure devices (checked 2026-10-07)
- NIST SP 800-63B-4: Digital identity guidelines, authentication (checked 2026-10-07)
- FTC: TRENDnet settlement over internet-connected cameras (2013) (checked 2026-10-07)
- NCSC (UK): The smart devices law (PSTI) (checked 2026-10-07)
Last reviewed October 7, 2026 by the LiveLocation team. General information, not legal or electrical advice.
