Help! Linux in my Webcam!

Mickey Shkatov, Jesse Michael

DEF CON 33 · Day 1 · Main Stage

Most people think of a webcam as a simple optical sensor with a USB cable. Plug it in, the operating system loads a driver, and a video stream appears. The security model, implicitly, is that the webc

AI review

Mickey Shkatov and Jesse Michael tear apart a commercially available USB webcam and find a full embedded Linux OS, a UART debug interface with unauthenticated root access, and a firmware update path that accepts arbitrary unsigned firmware via SCSI pass-through commands. The persistent implant capability — surviving host OS reinstall, BitLocker, and EDR — is the lede.

Watch on YouTube