Sextortion warning: It’s masking tape time for webcams

“New worries for the always-connected crowd: Attackers may remotely activate your webcam — without tripping the warning light — and remotely record your every activity, public and private,” Mathew J. Schwartz reports for InformationWeek. “Is it time to invest in some masking tape?”

“For years, malware known as remote-access tools (RATs) have included the ability to surreptitiously activate microphones and webcams — dubbed ‘camjacking’ — amongst other nefarious activities, such as sucking up all of your bank account details,” Schwartz reports. “To avoid RAT attacks, security experts already recommend keeping all operating systems and installed applications up to date. But should everyday users — meaning people who aren’t information security experts or Syrian dissidents — be concerned about camjacking attacks? More to the point, should everyone cover up their webcams when not in use?”

Schwartz reports, “The FBI in 2010 accused Luis Mijangos of sextortion attacks against 230 people, including 44 minors, which involved his compromising their PCs and attempting to extort them into providing sexually explicit videos. Earlier this year, the bureau also arrested Karen ‘Gary’ Kazaryan, charging him with running a similar sextortion campaign against 350 women between 2009 and 2011.”

    1. Apple had the foresight to avoid this problem by hardwiring the LED camera activity indicator directly into the power circuit for the camera. If the camera is on, so is the LED. This feature cannot be bypassed by malware. Someone would have to physically disassemble your Apple device and rewire it to bypass the LED.

      Yet another example of the fundamental differences between Apple devices and ‘other’ devices. You get what you pay for…and, in this case, a little bit more.

      1. I’ve used the “Hidden App” on my MBP and the camera captures images of whoever is using the computer, without lighting up the green beacon. If Hidden App can do it, can’t other software?

    1. Yet another reason to say NO! to gooooogle chrome
      (as if the hundreds that already exist weren’t enough)

      Anybody know if chrome “ignores” the flash security settings in systems preferences (where you can deny all camera & mic access to all flash applets)

      (A good precaution to do BTW if you don’t actually use flash for video chat))

  1. If an attacker remotely turns on my iMac’s webcam and they caught sight of my tired old hide in the buff, it is they who will go looking for duct tape to cover their eyes or scream out “I’m blind!”

    To which I say to said hackers, “Bring it!”

    1. I have it on good authority (my cousin’s wife’s hairdresser) that the tinfoil being sold today actually contains embedded antennas that transmit your thoughts to the Gubmint.

  2. I don’t know. I think I’ll discard this one. If you activate my webcam and catch me doing anything interesting, and publish it, I’m pretty sure anyone who sees it will need therapy. Also, make sure you spell my name right.

  3. I thought there was mention in an iFixit teardown of the iMac that the green LED is hardwired to the power to the camera… with the implication that you can not operate the camera without the LED being lighted. Does anyone else remember that?

  4. To my knowledge it is NOT possible to remotely activate the webcam without also activating the notification LED next to it. This is a hardware design in which powering up the camera also powers up the LED, they’re on the same circuitry. It’d be pretty dramatic if it was possible – but the article merely claims so without providing any proof at all (not, someone band-aiding their webcam is no proof).

    Until they back their bold claim up with facts I’m calling FUD. That article is really not worth sharing.

