Allow turning on from anywhere
A second switch on the Hub, off by default. With it on, a paired phone away from home can turn on Watch away from home itself. It is turned on only at home, and while Watch away from home is off the line it keeps carries three requests and nothing else.
What it is
Watch away from home lets a paired phone watch the cameras from outside the house, through the SecureEyes relay at relay.secureeyes.app. Every frame is sealed between the app and the Hub, so the relay carries ciphertext it has no key for. Watch your cameras from outside the house has the main switch.
Allow turning on from anywhere is a second switch under it. It decides what the Hub does while Watch away from home is off.
- Watch away from home: off by default. On: the Hub keeps a line to the relay, and a paired phone away from home watches through it.
- Allow turning on from anywhere: off by default. On: while Watch away from home is off, the Hub still keeps an encrypted line to the relay, and that line answers only a request to turn Watch away from home on. Off: while Watch away from home is off, the Hub keeps no line to the relay.
- Both need a valid Pro licence on the Hub, and a relay. A Hub with no valid licence, or a blocked Hub, keeps no line whatever the switches say.
Where the switch is
- On the Hub's web page, Overview: a panel headed WATCH AWAY FROM HOME. It is always there, whatever the switches say. It shows whether Watch away from home is ON or OFF, and it holds the Allow turning on from anywhere switch.
- On the Hub's web page, Settings, Network: the same panel. Both places show the same state.
- In SecureEyes, More, then Hub, under SET ON THE HUB, below Watch away from home. Watch your cameras away from home in the App guide has the app's side.
- The switch's row says ON. or OFF. first. On: This Hub keeps an encrypted line to the relay. While Watch away from home is off, that line answers only a request to turn it on. Off: With Watch away from home off, this Hub keeps no line to the relay.
Turn it on
- At home, on the Hub's own network, open the Hub's web page. Or open SecureEyes, then More, then Hub.
- On the Overview, in the panel WATCH AWAY FROM HOME, turn on Allow turning on from anywhere. The same switch is on Settings, Network.
- The page says Your phone can now turn on Watch away from home from anywhere. and the row reads ON.
- It turns on only at home: on the Hub's own network, or on the Hub's own page. The Hub refuses it through the relay. The app does not offer it there: the switch is dimmed and the row adds Turned on only at home, on the Hub's own network or its own page.
- The Hub refuses the switch without a valid Pro licence (SE-STA-025), and without a relay. The page then says The Hub would not change it with the Hub's reason.
Use it away from home
The button shows only when the Hub says this device may use it. The Hub allows 5 asks in 10 minutes for each device. After that the app says The Hub was asked too often. Try again in a few minutes.
- Away from home, open SecureEyes. When it says Watch away from home is off for this Hub, choose Turn on.
- The Hub checks its licence again, turns Watch away from home on, and the app connects as usual.
Turn it off
It turns off from anywhere, the relay included. If Watch away from home is off, the Hub drops its line at once. If Watch away from home is on, the line stays for watching, and the Hub keeps no line once Watch away from home is turned off.
The Hub's page asks nothing before it turns the switch off. In the app, away from home, it asks first: Turn off from anywhere? Once it is off, nothing can turn Watch away from home on until someone is at home.
- On the Hub's web page, turn off Allow turning on from anywhere on the Overview or under Settings, Network. Or turn it off in SecureEyes, under SET ON THE HUB.
- The page says Turned off. While Watch away from home is off, the Hub keeps no line to the relay.
What crosses the relay while Watch away from home is off
While Watch away from home is off and Allow turning on from anywhere is on, the line to the relay carries only three requests, each from a paired device: whether Watch away from home is on and whether it may be turned on, turning it on, and turning Allow turning on from anywhere off. Nothing else crosses it: no video, no stills, no camera list, no events, no settings and no push messages. The relay also knows when your Hub is online, and nothing more.
The Hub refuses everything else before it is read, with SE-STA-036. The three requests, each from a paired device:
- Whether Watch away from home is on, and whether this device may turn it on. The answer is those two facts and nothing else.
- Turning Watch away from home on.
- Turning Allow turning on from anywhere off.
What the relay sees, and who can do what
- The relay, or anybody who runs it. It can see that a phone connects to a Hub, from which address, when, for how long and how many bytes. It cannot read a frame, and it cannot forge one. Frames are sealed end to end to the Hub's key, which the app learned on the home network at pairing. It could play back a recording of an earlier connection, and the Hub refuses it: the Hub adds a fresh random value of its own to every connection's key, so a recording opens under no later connection, a restart included.
- A browser's session. It can do nothing through the relay. A browser signs in on the Hub's own network only, and a session presented through the relay is read as no sign-in.
- Anybody on the internet. They can knock at the relay, which limits knocks for each address. Without the Hub's key they cannot speak to the Hub at all. With it, everything is refused without a paired device's token. The Hub signs a caller in exactly as on the home network: a paired device's token, checked against the Hub's own record.
- Guessing tokens. Turning Watch away from home on and turning Allow turning on from anywhere off share one limit for each caller: 5 asks in 10 minutes. Once 20 such asks in 10 minutes were made with tokens the Hub does not know, an unknown token waits at both doors too, while a known phone is not held back. A token the Hub does not know gets the same refusal at every door, the status included, so none of the three says whether a guess was close. Refusals are logged without tokens.
- A stolen phone. It can do everything that phone could do: watch while Watch away from home is on, and turn it on while Allow turning on from anywhere is on. Remove the phone from the Hub (Settings, Devices). Its token stops working at once, through the relay as at home. A phone that is not used for 30 days stops working by itself. To be sure nothing away from home can turn it on, turn Allow turning on from anywhere off.
- An unlicensed or blocked Hub. Nothing. It keeps no line to the relay, whatever the switches say. The relay also refuses a Hub without a valid Pro licence.
Check it from the terminal
- Read both switches and whether the line is up:
curl -sk https://127.0.0.1:8443/api/v1/system/remote | python3 -c "import json,sys; r=json.load(sys.stdin); print(r['enabled'], r['anywhere'], r['connected'])". It prints three words: Watch away from home, Allow turning on from anywhere, and whether the line is up. - See every change of either switch, with who asked and from where:
sudo journalctl -u sehub | grep -E 'remote: (switch|turn on from anywhere)' - See what was refused through the relay while Watch away from home was off:
sudo journalctl -u sehub | grep 'viewing away is off; refused'
If it still fails
- Away from home, the app says Watch away from home is off for this Hub: the Hub answered, and it is off. That is SE-STA-036. It is not the relay's “that hub is not connected to this relay”, which the relay says when the Hub keeps no line at all.
- The app cannot reach the Hub away from home, and the relay says that hub is not connected to it: both switches are off, the Hub has no valid Pro licence, or the Hub is blocked (SE-STA-028 to SE-STA-032). Turn the switch on at home, or fix the licence. How the Hub's licence works has the fix.
- Turning on is held: the app says The Hub was asked too often. Try again in a few minutes. Wait ten minutes and try again.