A Wi-Fi security camera is a small computer with a lens. The sensor captures frames, an onboard chip compresses them into H.264 or H.265 video, and the camera’s radio pushes that stream over your 2.4GHz network to a microSD card, a recorder in your house, or a company’s cloud. Subscription fees, false alerts, and who else can watch are all decided at that last step.
Most explainers stop at “it connects to your Wi-Fi and sends video to an app.” True, and useless. It does not tell you why the camera refuses to join your 5GHz network, why the live view looks softer than the saved clip, why a moth sets off an alert at 2am, or whether anyone at the company can pull up your kitchen.
Here is the whole chain instead, one link at a time. Two links carry almost all the weight: where the video gets stored, and who holds the keys.
What happens between the lens and your phone?

Light hits an image sensor, which produces raw frames far too fat to send anywhere. The camera’s own chip fixes that before the video leaves the housing. Reolink, which builds these things, describes the step plainly: “the images are then processed by the camera’s onboard chipset, which encodes the video into a compressed digital format like H.264 or H.265 to conserve bandwidth and storage space while maintaining quality.” Without that compression, nothing downstream fits through a home internet connection.
What comes out of the chip is usually more than one stream. On the IPVM forum, where working surveillance integrators argue about this stuff, Matt Transue notes that “it is very easy (and common) to have multiple streams going to multiple places. Think high-res stream for storage and low-res stream for mobile.” So your phone preview is not the recording. They are separate streams off one sensor, and the phone gets the cheap one.
The transport underneath is nearly always the same protocol regardless of whose logo is on the box. Josh Hendricks, a backline support manager at the video management software company Milestone Systems, answered that in the same thread in January 2017: RTSP “is almost always how the camera streams are transported, regardless of whether you’re using an ONVIF driver, universal driver, or a dedicated device driver.” A camera that seems to speak only its manufacturer’s app is usually speaking RTSP underneath and not telling you the address.
Which means a working camera has to talk. It grabs an address, announces itself, and pushes traffic all day. That noisiness is what makes an unwanted one findable, and it is the whole basis of sweeping a room and a network for a hidden camera.
How much internet does one camera actually use?
Less than people fear at 1080p, more than people expect once there are four of them. Reolink publishes its own bandwidth math, so read these as a representative range rather than a rule covering every camera sold.
| Resolution | H.264 | MJPEG |
|---|---|---|
| 1MP (1280×720) | About 2 Mbps per camera | About 6 Mbps per camera |
| 2MP (1920×1080) | About 4 Mbps per camera | About 12 Mbps per camera |
| 4MP (2560×1440) | About 8 Mbps per camera | About 24 Mbps per camera |
Three to one at every resolution, which is why the codec line on a spec sheet matters more than the megapixel line. The same source puts a 1080p camera running H.264 at 30 frames per second at “around 2-4 Mbps” in practice, and a 1080p camera recording continuously at 15 frames per second with moderate compression at “around 60-100 GB of data per month.” That monthly figure is per camera too, which is worth knowing before four of them start recording around the clock on a metered plan.
Why your camera insists on 2.4GHz Wi-Fi

Buyers keep reading the 2.4GHz-only line as cheapness. Wyze, which sells cameras on both bands, gives the reasoning in its own support documentation: “All Wi-Fi connected Wyze devices support 2.4 GHz networks, as they work better over long distances and have better wall penetration.” Only a short list of newer models, the Cam Pan v4, Battery Cam Pro, Floodlight Pro, Video Doorbell Pro, Duo Cam Doorbell and Mesh Router, support 5GHz at all. A camera bolted to the back of a detached garage is exactly the device you want on the slower, longer-reaching band.
The requirement that actually strands people is narrower than the band. Wyze’s network page says “almost all Wyze devices must be connected to a 2.4 GHz Wi-Fi network with a WPA/WPA2 protocol,” and that they “will not work with enterprise Wi-Fi networks that have a landing page, sign in portal or require a browser to complete the connection.” If your Wi-Fi makes you click Accept in a browser, which covers hotels, plenty of campus housing and some managed apartment buildings, the camera cannot join it, and no setting in the app fixes that.
The guest network question is where the advice openly contradicts itself. In an r/Ring thread on using guest Wi-Fi just for cameras, one owner reports “on the IoT band the reception was hot garbage. Moved them to the main network and reception is MUCH better,” while others in the same thread say guest works fine for them. The fix that keeps surfacing is blunter: a cheap dedicated 2.4GHz router doing nothing but cameras. As one owner in those threads put it, “I added a dedicated 2.4G router just for my ring network… it works outstanding ever since.” And before blaming the camera for a mass outage, Wyze owners on Xfinity have pinned their offline mornings on the ISP pushing router firmware without notice.
Where does the video actually go?
| Storage path | Where the video lives | Who can reach it | The catch |
|---|---|---|---|
| Vendor cloud with a subscription | The company’s servers | You, and anyone holding your account password | Free tier is motion and sound alerts plus image-only cloud storage. Person, pet, vehicle and package detection and 14 days of rollover video sit behind the paid plan |
| microSD card in the camera | Inside the camera housing | Whoever can physically reach the camera and pull the card | While the camera is offline, recording to the card is all it can do. No live view, no notifications |
| Local recorder or NVR over RTSP | A box in your house | Whatever is on your local network | Cabling and setup, plus ONVIF support that is claimed more often than it is verified |
| HomeKit Secure Video | Encrypted in iCloud | End to end encrypted, and the motion analysis runs on your own home hub first | Camera count is capped by plan tier: one on 50GB, up to five on 200GB, unlimited at 2TB and above. Needs compatible hardware |
The offline question is the one people ask first. Wyze’s answer for the Cam v3 is that with a card inserted and local recording on, “the camera will continuously record to that microSD card, even if offline.” The next sentence matters more: “when Wyze Cam v3 is offline, the camera can only record to a microSD card.” Footage keeps accumulating. Nobody gets told anything.
The people who have lived with this longest tend to land in the wired camp. In an r/homeautomation thread on local storage, the top reply is short: “PoE with an NVR. Running cable is a little annoying but worth it. You have complete control and can keep it entirely closed circuit if needed.” Another commenter makes the point most buying guides skip, that clever detection and a monthly bill are not the same purchase: “You don’t need a ‘smart camera’ to do the image recognition processing as long as you have a device that can.”
What I would not do is treat local as automatically safe. A detailed Eufy HomeBase S1 writeup lists among its cons that playback “sometimes it will fail to decrypt, requiring you to try again,” which is the local encryption pipeline failing, not the cloud. On r/wyzecam, owners describe cards going unreadable after firmware updates: “Keeps saying non supported sd card, format? Then format fails.” A card you never test is not a backup. It is a hope.
How does the camera decide that something moved?

Three different things get sold under the word detection, and they are nowhere near equivalent.
The cheapest is pixel comparison, which is exactly what it sounds like. Wyze describes it this way: “Wyze Cam detects motion by comparing pixels changing between video frames. ‘Motion’ is recorded when large clusters of pixels change over time.” A cloud shadow crossing the driveway is a large cluster of pixels changing over time. So is a branch in wind, a headlight sweep, a moth working the infrared lamp at 2am. The camera cannot tell you which, because it does not know.
Add a PIR sensor and you get a heat trigger in front of that stage, not instead of it. On the Wyze Cam Outdoor, the PIR sensor “detects heat, which triggers the pixel comparison algorithm that compares key frames from the stream, and looks for differences between frames.” It also has a geometry quirk worth knowing before you mount anything: “Due to the PIR sensor’s placement, it is optimized to detect side-to-side motion, as opposed to movement from the top-down.” Aim a camera straight down a narrow walkway and people approach along its weakest axis.
Only the third tier separates a person from a shadow, and on Wyze’s platform that tier is a purchase. The free plan covers “Motion and Sound Alerts” and 24/7 local recording to a card. Person, pet, vehicle and package detection ship as “Smart AI Detections” inside Cam Plus, alongside 14 days of rollover cloud video. That is the pattern running through this whole category: the hardware in your hand is capable, and the useful half of it bills monthly.
Is any of this actually encrypted?

Start with the sentence nobody puts on a box: no mainstream consumer camera brand ships full end to end encryption switched on by default. Not one.
Ring does offer real end to end encryption, and its own documentation is unusually clear about the terms. The feature “is an optional security feature that protects your video and audio recordings with a passphrase you create. Only your enrolled mobile device can enter this passphrase to view recordings from end-to-end-enabled devices. No one else, including Ring, can access your encrypted content.” Genuine, and expensive in features. Switching it on disables Person Detection, Motion Verification, Live View from multiple mobile devices at once, and 24/7 Video Recording, and older hardware including the first-generation Video Doorbell and first-generation Spotlight Cam cannot use it at all.
Eufy is the cautionary half. Anker sold the cameras on an always-encrypted promise, then, after a reporter spent months pulling live feeds “using an ordinary media player,” the company “finally admitted its Eufy security cameras are not natively end-to-end encrypted,” as The Verge reported on January 31, 2023. Anker’s own account was that the cameras “can and did produce unencrypted video streams for Eufy’s web portal, like the ones we accessed from across the United States.” The fix was moving web portal streaming to WebRTC, “which is encrypted by default.” The marketing claim came first. The architecture caught up afterward, under press pressure.
The one meaningfully different design here is Apple’s. With HomeKit Secure Video, the motion analysis happens on hardware you own before footage reaches Apple: “the video is privately analyzed by your home hub using on-device intelligence to determine if people, pets, or cars are present,” and “it’s all end-to-end encrypted, and none of the video counts toward your iCloud storage.” The limits are real too. Camera count is set by your iCloud+ tier, one on the 50GB plan and up to five on 200GB, and it needs compatible hardware.
Who has already seen other people’s footage
| Case | What the primary record says | What it was not |
|---|---|---|
| Ring employee access, in the FTC complaint settled May 31, 2023 | “One employee over several months viewed thousands of video recordings belonging to female users of Ring cameras that surveilled intimate spaces in their homes such as their bathrooms or bedrooms.” Ring paid “$5.8 million, which will be used for consumer refunds” | Not an outside intruder. This was ordinary internal access to stored video |
| Ring credential stuffing, 2017 through 2019, same complaint | Ring “failed, according to the complaint, to implement common tactics” such as requiring multi-factor authentication until 2019, and attackers reached “stored videos, live video streams, and account profiles of approximately 55,000 U.S. customers” | Not a break in the video encryption. Passwords reused from other breaches were the door |
| Wyze thumbnail mix-up, February 2024 | Wyze’s own note to customers: “about 13,000 Wyze users received thumbnails from cameras that were not their own and 1,504 users tapped on them,” caused by “a third-party caching client library that was recently integrated into our system” | Not a hack, and not 13,000 leaked videos. What most affected people saw was a thumbnail |
Both Ring findings come from the FTC’s May 2023 press release on the case, and they are the failure modes that actually happen. Somebody inside the company looked at stored video. Somebody outside logged in with a recycled password. Encrypting a stream in flight stops neither, which is why “military grade encryption” on a product page tells you close to nothing about either risk.
The Wyze case matters for the opposite reason: it gets inflated every retelling. A caching library brought in from outside mixed up which device belonged to which account as cameras came back online after an outage, and The Verge published the company’s customer email in full on February 19, 2024. A boring bug with an ugly result. Calling it a hack trains people to worry about the wrong thing, because the real lesson is that the plumbing between a camera and an app is software written by humans on a deadline, same as the plumbing in a robot vacuum that maps your floor plan.
Four things to check before you buy

Check the band and the network type first, because that is the only failure that stops you before setup finishes. A 2.4GHz-only camera plus a router that hides its 2.4GHz band, or a building Wi-Fi that wants a browser login, and you are done before you start.
Check what the free tier does, specifically. Recording to a card and getting a motion alert is usually free. Telling a person from a shadow usually is not, and that gap is the actual product being sold.
Treat ONVIF support as a claim rather than a guarantee. ONVIF is a real standards body that describes itself narrowly, as “an open industry forum that provides and promotes standardized interfaces for effective interoperability of IP-based physical security products and services.” It is a discovery and control layer, not a codec: an ONVIF call asks a device for its settings and streams, and, as Hendricks put it, “the device should return the RTSP address to retrieve the video via RTSP.” The group warns buyers on its own homepage that “there are companies improperly claiming to have ONVIF conformant products,” and points at its Conformant Products database as “the only authoritative source.” Installers argue endlessly about which popular brands implement the spec faithfully, and that argument is not settled. Check the database, not the box.
If the camera runs on a battery, read the runtime as a condition rather than a number. Wyze rates the Battery Cam Pro removable 6200mAh pack at “Up to 6 Months” with an “Approximately 9 hours” recharge, and the same page notes that continuous microSD recording “may greatly shorten battery life.” Those two claims sit on one product page for a reason. Six months is what you get when the camera mostly sleeps.
None of this resolves into one right answer, and the most honest framing I found came from a commenter in that home automation thread: “Security cameras are basically a triangle: convenience, privacy, and subscription pain. Most products let you pick two, sometimes only one.” Cloud cameras are cheap to start and someone else holds your footage. Local setups keep the footage in the building and hand you the work. Neither settles where you are allowed to point the thing, which runs on state law and gets its own treatment in our guide to the rules on recording around your own property. And if the job is watching your own land rather than recording it, a pair of binoculars beats a camera for a fraction of the setup. The rest of the chain sits in the Learning Center.
Sources
- FTC: “FTC Says Ring Employees Illegally Surveilled Customers, Failed to Stop Hackers from Taking Control of Users’ Cameras”, press release, May 31, 2023.
- The Verge: Anker finally comes clean about its Eufy security cameras, January 31, 2023.
- The Verge: Wyze says camera breach let 13,000 customers briefly see into other people’s homes, February 19, 2024.
- Ring: Using video end-to-end encryption (E2EE).
- Apple: Store encrypted security camera footage in iCloud with HomeKit Secure Video.
- ONVIF: organization homepage and conformant products warning.
- IPVM: “Very Confused About ONVIF / RTSP” discussion, with answers from Josh Hendricks of Milestone Systems and Matt Transue, January 2017.
- Reolink: IP camera bandwidth calculation.
- Reolink: How does a wireless security camera work.
- Wyze support: Which Wyze devices work with 5 GHz networks.
- Wyze support: What kind of Wi-Fi network or router do I need.
- Wyze support: Motion detection and PIR effective area.
- Wyze support: Detection settings and zones.
- Wyze support: About Cam Plus.
- Wyze support: Can I use Wyze Cam v3 without Wi-Fi.
- Wyze: Battery Cam Pro product page, battery and solar panel specifications.
- r/homeautomation: local storage cameras or smart security cameras.
- r/Ring: using guest WiFi just for Ring devices.
- r/EufyCam: HomeBase S1 Professional owner writeup.
- r/wyzecam: SD cards not recognized thread.