On Thanksgiving Day, infosec consultant Paul Moore and a hacker who goes by Wasabi both alleged that Anker’s Eufy cameras can stream encryption-free through the cloud — just by connecting to a unique address at Eufy’s cloud servers with the free VLC Media Player.Your camera’s 16-digit serial number — likely visible on the box — is the biggest part of the key But it also gets worse: Eufy’s best practices appear to be so shoddy that bad actors might be able to figure out the address of a camera’s feed — because that address largely consists of your camera’s serial number encoded in Base64, something you can easily reverse with a simple online calculator.The address also includes a Unix timestamp you can easily create, plus a token that Eufy’s servers don’t actually seem to be validating (we changed our token to “arbitrarypotato” and it still worked), and a four-digit random hex whose 65,536 combinations could easily be brute forced.When Georgia Tech security researcher and Ph.D. candidate Omar Alrawi was studying poor, smart home practices in 2018, he saw some devices substituting their own MAC address for security — even though a MAC address is only twelve characters long, and you can generally figure out the first six characters just by knowing which company made a gadget, he explains.Now that Anker has been caught in some big lies, it’s going to be hard to trust whatever the company says next — but for some, it may be important to know which cameras do and do not behave this way, whether anything will be changed, and when."