The Paper reporter Zhuang An

  Hospital gynecological surgery was illegally broadcast live for people to watch in real time.

Such incidents have sparked public discussions on webcam security and privacy protection, and some netizens are worried that there may be a deeper industry chain behind them.

  A recent investigation by The Paper found that many domestic surveillance videos were disseminated on domestic and foreign online platforms, mainly on Twitter, Telegram and QQ.

There is a chain of interests behind this: some people install secret cameras or crack the permissions of other people's cameras, and then sell the camera IDs for real-time viewing, and some people specialize in offline agents for sellers.

  "If it doesn't make money, who is willing to sell this?" An agent said that the camera ID is also known as "Taiwan", and it only takes one day to sell the device to earn back the cost.

In addition to the gynecological operating table, there are also camera ID packages including toilets, dormitories, locker rooms, hotels, etc. The price ranges from one hundred to six hundred yuan, and some "boutique" IDs are fired to thousands of yuan.

  Some agents said that in order to maximize profits, the same ID will be resold to multiple people; and the nudity and pornographic scenes in the surveillance video will be recorded into videos, packaged and posted in group chats or websites, and can only be viewed by paying.

  The Paper's investigation found that the low cost of cracking and installing cameras, and the high prices of ID and related videos, stimulated many buyers to turn into agents.

Judgment documents show that a crime gang installed sneak camera in the hotel, and then resold it layer by layer, with more than 300 people offline.

  Behind the repeated black production, there are problems of supervision and accountability.

Some professionals dedicated to network security said that the "weak password" of the webcam leads to a low threshold for cracking, and even "undefended" in the Internet space.

And due to technical and historical reasons, manufacturers have difficulties in self-inspection, recall and accountability.

  Other professionals analyzed that the act of secretly filming the industry chain itself is flexible and concealed, and the qualitative and legal application of related acts often troubles case investigators; from the perspective of victims, due to psychological panic and time, money, money It costs a lot, and it may not be possible to cooperate with the collection of evidence or insist on accountability.

Toilets, bedrooms, operating tables may be peeped in real time

  "Only platforms with nudes will be sold. People who like to peep." On January 19, a seller advertised the camera ID they sold on Twitter.

  The surging news reporter consulted the seller as a buyer. The other party said that because his WeChat account would be blocked, he can only use Twitter and telegram group chats to divert traffic.

He said that spending 280 yuan to 480 yuan can buy the corresponding "package", and through the corresponding device ID, users can monitor other people's bedrooms, toilets, massage parlors, women's changing rooms, school women's dormitories, gynecological examination departments, love hotels, In places such as homestays, viewing software includes Cloud Vision, Green House, Le Orange, EZVIZ Cloud, and 360 Surveillance.

  In addition to one-to-one sales, there are also sellers who have set up group chats and websites dedicated to transactions.

  On the encrypted chat software Telegram, the reporter joined a group chat with more than 8,000 members, and found that the members were all banned. The group owner would share pornographic videos recorded through the camera. If you want to see more exciting pictures, you must submit Money "sponsorship".

  The group owner said that the surveillance video of the group came from a self-installed candid camera.

"It's a normal home camera sold online." The group owner said that the installer installed the camera in a hidden location in the hotel, and can watch real-time monitoring and cloud playback through the official software.

  The group owner said that each company's camera software is used in different ways. In the past, the mainstream cameras that could be used for sneak shots were 360 ​​cameras. At present, the mainstream ones are EZVIZ Cloud, Le Orange, and TP-LINK security. These three software are all in the application market. Can download.

  "In general, the people who come into contact with the real sellers are all agents, and the camera installers themselves will not come out to sell them. The owner will deliver the goods and the agents will sell the goods, so the price cannot be too cheap, plus the risk cost. , if it doesn't make money, who is willing to sell this?" the group owner said.

  In another video sharing group with more than 3,000 members, the group owner said that if you want to watch more surveillance videos, you need to buy an invitation code on the website, register as a member, select the "sponsorship" duration, and then send an email to a specific mailbox, and then receive daily Organize the online viewing address.

  In addition to the promotion and sale of surveillance videos on overseas platforms, some sellers are suspected to be active on QQ.

  Peng Mei News found that there were several group chats on QQ named "Yunshi EZVIZ Cloud Hotel Monitoring" and "Yunshi Family Crack ID", which can no longer be joined, but according to the introduction of the group chat, they can be linked to relevant customer service personnel or QQ No., the other party said that they could sell camera IDs or record and broadcast videos, and said they could sell pinhole equipment.

Weak Password Vulnerability for Easily Cracked Cameras

  In addition to privately installing cameras to take pictures, the seller will also use software to crack the viewing rights of other people's cameras, which is cheaper.

  "If you just buy monitoring and watch it yourself, you can just buy the cloud. If you want to sell Taiwan like me, you have to buy Taiwan sweeping software (that is, cracking software)." Agent Xiao Zhou told reporters.

  Xiao Zhou said that 610 yuan can buy a "sweeping platform" package, including sales channels and operation tutorials.

  "Taiwan-sweeping software can crack the surveillance cameras, and if it finds that there are 'boutiques' and interesting things, it can be sold with an ID." Xiao Zhou claimed that selling a table (ID) is a profitable business, and it doesn't take too much time. Do it part-time.

Selling an ID does not mean losing its authority, you can still resell it to others unlimited times.

  Xiaozhou showed his transfer records and said that on January 17, many people transferred money to him, with a total amount of more than 1,000 yuan; the chat records he showed showed that he also provided other sellers with the account number and password of the surveillance video.

  Another seller, Xiao Hong, claimed that he was the "top man" and that he taught other agents.

  The Paper found that Xiaohong's "Taiwan Sweeping Software" sold by Xiaohong contained download links for a series of toolkits such as scanners and weak password checking tools.

Xiaohong said that by installing these files, the weak password of the camera can be scanned and cracked, and the ID result can be obtained.

  An operation video released by Xiaohong shows that when you enter the corresponding device ID in the Yunshitong APP and click to connect, the interface immediately displays real-time monitoring in dozens of homes and hotels, and then clicks on another device ID to display the gynecological operating room. real time monitoring.

  Why can the so-called "sweeping software" easily crack other people's cameras?

Qu Zilong, a professional who has been devoted to network security for a long time and the founder of Network Jiandao, believes that this is related to the ecology of the Internet in its infancy.

  Qu Zilong explained to The Paper that, for the convenience of customers, early manufacturers set initial passwords when the cameras left the factory, such as "66666666" and "88888888".

But many customers are not strong on the concept of password reset, which leads to the existence of weak passwords.

And as long as you know the brand of the camera, you can find the initial password on the Internet to crack the camera, which is why most cameras are currently controlled by others by cracking the password.

  "The threshold for cracking is low." Qu Zilong said.

  He said that the principle of cracking of cameras in public places is the same as that of home cameras. There are about three ways: the first is to crack the computer by attacking the surveillance machine, and the second is to crack the new generation of networked cameras, most of which are It is cracked by matching the factory default password and weak password of the camera.

  "The third method is to debug the backdoor by sniffing the manufacturer or crack it through specific vulnerabilities. Compared with the first two methods, this kind of attack is not common in the candid camera industry, and relatively speaking, there is a certain technical threshold." Qu Zilong said.

Crazy blacks with kinky fetishes and voyeurism

  Qu Zilong said that in the current camera cracking business, one way is to connect the camera to a designated account and sell the rights, and the buyer can watch it in real time; the other way is to directly record a specific picture and sell it.

  Peng Mei News combed through a number of referee documents and found that from using software to crack cameras or privately install secret cameras, to shooting sex or nudity videos, to selling and developing offline, it is an important part of camera secret photography.

  According to a judgment published by China Judgment Documents Network in 2018, in early July 2017, Wang Moushuai, a man from Hebei, used software to crack the IP account and password information of other people's home cameras, and invaded and controlled the information systems of more than 30 home cameras.

  Wang Moushuai also set up 5 QQ groups on the Internet, packaged the cracking tutorials and IDs, and sold them to others at a price of 88 yuan per package.

The court held that Wang Moushuai constituted the crime of providing intrusion and illegal control of computer information system programs and tools, the crime of illegally controlling computer information systems, and the crime of selling pornographic materials for profit.

  Peng Mei News previously reported that a criminal ruling published by the Jining Intermediate Court in Shandong Province in February 2020 showed that Zhao and others had privately installed 360 cameras in hotel rooms in over 9 cities in China for the purpose of making illegal profits. , shoot obscene real-time videos of the sex of the guests, and sell the "invitation codes" for watching the above-mentioned obscene videos to more than ten people such as Shen and Cui through the Internet.

  Zhao and other 4 people promoted and developed more than 300 offline people through QQ and other software. One invitation code can be sold for more than 600 yuan, and each camera can generate up to 100 invitation codes for hundreds of people to watch online at the same time. Many agents Within a month or two, it made a profit of tens of thousands of dollars.

  Behind the low-cost and high-profit black production, there is a deformed voyeuristic desire.

  Xiao Lin, a buyer of Taiwan-sweeping software added by The Paper in the above group chat, said that he joined a lot of candid group chats, which contained very serious content.

He called himself "a good bite".

After discovering that the Taiwan sweeping software could not be used, he reported the group owner's Alipay account.

  "The psychological deformities and special hobbies of some groups make some specific videos more valuable." Qu Zilong said that camera cracking has formed a vertical black industry, which has transformed from traditional personal cracking to spy on privacy to purely commercial illegal Buying and selling, commercial operations based on invasion of personal privacy.

The dilemma of accountability and supervision

  In recent years, relevant departments have stepped up efforts to crack down on the chaos of illicit photography.

  For example, since May 2021, the Central Cyberspace Administration of China, together with the Ministry of Industry and Information Technology, the Ministry of Public Security, and the State Administration for Market Regulation, has further promoted the centralized governance of black products such as camera voyeurism.

The Central Network Information Office instructed the local network information offices to urge various platforms to clean up more than 22,000 pieces of relevant illegal and harmful information, dealt with more than 4,000 platform accounts and 132 groups, and removed more than 1,600 illegal products.

We interviewed 14 video surveillance APP manufacturers with potential leakage of private video information, and urged them to complete the rectification.

  But the black production of secret photography and voyeurism has not been eradicated.

  "The most difficult thing about cracking down on the candid photography industry chain is that the behavior itself is flexible and concealed. Suspects can engage in equipment modification, candid photography and secret recording activities at any time and place, which is really hard to prevent." Not long ago, Changzhou, Jiangsu Province Lu Yetao, deputy squadron leader of the Cyber ​​Security Brigade of the Wujin Branch of the Municipal Public Security Bureau, said in an interview with CCTV.

In addition, whether the equipment and equipment used by the suspect can be successfully seized and confiscated after the suspect arrives at the case, whether it can be identified as special equipment for eavesdropping and eavesdropping after the seizure, and how to fix the illegally obtained and illegally controlled camera account and other electronic evidence, and the details of secret photography and secret recording Questions such as how to characterize the behavior involved and how to apply the law are all perplexing the police handling the case.

  From the victim's point of view, defending rights is not easy.

  In an interview with CCTV, an associate professor at the School of Criminal Justice of China University of Political Science and Law said that many victims may have certain obstacles in cooperating with evidence collection due to privacy protection concerns or other reasons, and it is difficult to form a complete chain of evidence when and where they were secretly photographed. .

  Linlin (pseudonym), a Shanxi girl who was secretly photographed by the landlord, told The Paper that the landlord had a lot of private videos of herself in the rental house, and she hesitated to expose it.

After the landlord was detained, she still felt panic from time to time. She always felt that her normal life was affected, and she was not confident about the follow-up accountability.

  Xiao Tang, a woman who stayed at a hotel in Chenzhou, Hunan in October 2021, found a pinhole camera inside the hotel, and found a pinhole camera after changing rooms.

She then called the police.

  On January 21, 2022, Xiao Tang told The Paper that the police had recently caught the candid photographer and transferred him for prosecution.

However, the hotel involved has never contacted her, and it is more difficult to pursue civil liability.

"There is not much compensation for this kind of thing in law, and I am not a local person. I have to hire a lawyer and go to the local area. I really don't have time to do these things," she said.

  There are also difficulties in the supervision of camera manufacturers and their self-regulation.

  Qu Zilong said, first of all, due to technical reasons, the self-inspection of the merchant may not necessarily find that the camera has been cracked.

Secondly, the login method of account and password lacks multi-factor risk control.

Finally, the first generation of cameras has the characteristics of "non-networked, non-cloud".

"It's possible that a small company goes out of business, but the cameras it sold before are still in use in the market. Manufacturers can't supervise, and considering the cost of installation and removal, it's unlikely that the cameras will be recalled."

  Qu Zilong emphasized that it is difficult to legally define the responsibility of camera manufacturers. Before the promulgation of regulations such as the "Data Security Law", the two parties who bought and sold cameras only belonged to a sales contract, and now the law cannot be used to pursue historical responsibility.

  "For example, I bought a camera from you 5 years ago, and there is a 'three guarantees' clause between the two of us, that is, you have to ensure that the camera is available and not broken. You (the seller) need to provide the buyer with a complete warranty service. , but does not include non-disclosure of privacy, cannot be cracked by hackers, compliance with relevant privacy protection regulations, etc." Qu Zilong said that there was no requirement for non-disclosure of privacy in the product design of cameras in the past, so (at that time) companies were very There is little incentive to increase the cost of the product according to this specification.

  Qu Zilong suggested that whether it is cameras, social accounts, or website bills, in theory, passwords should be changed regularly, especially for commonly used accounts related to money and privacy.

For unused accounts or functions, you should log them out directly, or turn off the functions.