Cameras get installed to protect a home. What's rarely appreciated is that they're also the device most likely to open a way in, with nothing to indicate when that happens.
The reason isn't that cameras are built carelessly, but a combination of three things that rarely coincide on other devices.
Why cameras specifically
- They're always on. Twenty-four hours a day, for years, never switched off or inspected.
- They're designed to be reached remotely. That's the whole point, and every deliberately opened way in is a way others can try too.
- They're rarely updated. Phones nag about updates; cameras tell you almost nothing.
Plus one more thing: what leaks from a camera differs in kind from what leaks elsewhere. A password can be changed. Footage from inside your home cannot.
Automated scanning looks for cameras specifically. There are search engines that index internet-connected devices, including cameras left on default settings. Nobody is targeting you personally, your device simply happened to answer the knock.
Checking where your camera stands
Five minutes, and most people find at least one thing worth fixing.
Check whether the password is still the default
Including the device's own password, not just the app account. Many cameras have both, and the second is almost never touched. How to build a replacement is in the guide to strong passwords.
Look for port forwarding rules from the past
If you or an installer once opened external access, the rule is still in the router. This is the most direct way in, and the most often forgotten, see the guide to port forwarding.
Turn off UPnP on the router
This feature lets devices open their own ports without asking. Some cameras use it, so external access can be open even though you never configured it, see the guide to firewalls.
Check the firmware date
Open the app or camera panel and find the version and date. If it's more than two years old with no update available, that model has likely been abandoned by its maker.
Review the device list on your network
Confirm the number of cameras showing matches what you installed, see the guide to seeing who's on your Wi-Fi.
Remote access: two routes, one far safer
Viewing the camera while away is the main reason people install one. How you achieve it determines nearly all of the risk.
| Via the maker's app | Via port forwarding | |
|---|---|---|
| How it works | Camera calls out to a service, you meet it there | Camera is opened directly to the internet |
| Scannable address | None | Yes, and found within hours |
| Who can see footage | You and the manufacturer | You, and anyone who guesses the password |
| If the maker shuts down | Remote features stop | Keeps working |
For almost any home, the manufacturer's app is the more sensible choice, not because it's perfect, but because it leaves no address for anyone to knock on.
If you genuinely need direct access with no intermediary, the route isn't port forwarding but a VPN back to your own home. An introduction to the concept is in the guide to VPNs on public Wi-Fi.
Separating cameras from the main network
This is the single most effective step, and on most routers it needs no extra hardware.
The reasoning is simple: a compromised camera sits inside your network, alongside laptops, file storage, and work computers. The router's firewall doesn't stop traffic between them.
The easiest approach is to put all cameras on the guest network and leave personal devices on the main one. The steps are in the guide to separating guest networks, while a tidier separation is covered in the guide to VLANs.
One consequence to know about: features requiring camera and phone to be on the same network will stop working inside the house. For most people that's a worthwhile trade.
Placement matters more than expected
This isn't a technical matter, but it determines how bad the consequences are if something happens.
- Avoid bedrooms and bathrooms. No security setting is worth the risk of footage from those rooms.
- Point at doors and entry paths, rather than sweeping the whole living room.
- Watch what falls outside your boundary. A camera capturing the street or a neighbour's yard raises a different issue, see the guide to CCTV rules and privacy.
- Turn off the microphone if unused. Audio is rarely useful for home monitoring and adds weight to any leak.
Cameras and network load
Cameras uploading footage to the cloud run all day over the upload path, the narrowest part of most subscriptions. The symptom often shows up as video meetings stuttering for no obvious reason.
When that happens, lowering resolution or switching to local recording usually resolves it. The mechanism is explained in the guide to why upload is slower than download.
For stability, cameras within reach of a cable should use one. Besides saving wireless capacity, it removes a source of disruption, see the guide to choosing LAN cable.
If you're buying
What matters more than resolution:
- Clarity about update support. A manufacturer that states how long firmware is supported is a good sign.
- A local storage option. So you aren't tied to a cloud subscription permanently.
- Two-step verification on the account. A password alone isn't adequate for an account holding footage of your home.
- Clarity about where data is stored and for how long, if the service collects recordings.
The considerations applying to other smart devices are in the guide to smart home device security.
The bottom line
Cameras are exposed not because they're complicated, but because they're always on, built to be reached remotely, and seldom updated.
Three steps close most of the risk: change default passwords including the one on the device itself, close direct external access and disable UPnP, then move every camera onto a separate network. The rest is placement, and that's a decision no setting can correct afterwards.
Frequently asked questions
Can someone else access my Wi-Fi security camera?
Yes, and the usual cause isn't sophisticated hacking but something simple: a default password never changed, external access opened through port forwarding, or old firmware whose vulnerabilities are publicly documented.
How would I know if my camera is being accessed?
Reasonable warning signs: the indicator light on when nobody has the app open, the camera moving on its own if it pans, login history you don't recognise, and heavy upload traffic during quiet hours.
Is it safer to store recordings on a memory card or in the cloud?
Each has a different weakness. A memory card involves no third party but is lost if the camera is stolen. Cloud storage survives theft, but the footage sits on someone else's system. For indoor areas, local storage is usually the better trade.
Should cameras be separated from the main network?
Strongly recommended. Cameras rarely receive updates as well as phones or laptops, so if one is compromised, separation stops it reaching your computers and storage. A guest network is adequate for this.