Tuesday, September 15, 2026

Difference Between Active vs. Passive PoE

Difference Between Active vs. Passive PoE 

Power over Ethernet or PoE for short can be a new and potentially confusing term to a lot of people searching for security cameras. PoE connectivity simplifies cabling needed to connect a device by allowing power and data delivery over a single network cable such as CAT5e or CAT6. It makes it easy to connect devices such as IP security cameras, or office phones; a separate power supply or electrical outlet for each device is not needed. However, it is important to know the nuances about PoE equipment to avoid damaging your equipment. There are two types of PoE connections - active and passive. While one may think active is with power and passive is without power, that's not correct.

Active Power over Ethernet (PoE) uses an automatic negotiation handshake to safely deliver dynamic power levels based on device requirements, whereas passive PoE sends a constant, fixed voltage without any communication or safety check.

Active PoE

802.3af/at Compliant PoE - Good for IP cameras

Active PoE means that a device is rated to be 802.3af or 802.3at compliant. These are regulated specifications that require a device and power supply to do a “handshake” or verification. The PoE power supply tests the connection to the device and ensures that the power is compatible. If it isn’t, then the device simply will not power up, preventing any potential damage.

Active PoE Standards (IEEE 802.3)

The IEEE defines several Active PoE standards that determine how much power can safely be delivered.

Standard

Name

Max Power

Voltage Range

802.3af

PoE

Up to 15.5W

44–57V DC

802.3at

PoE+

Up to 30W

50–57V DC

802.3bt

PoE++

60–90W

52–57V DC

Passive PoE

Raw unnegotiated power - Bad for IP cameras

Passive PoE refers to any device that does not follow the 802.3af or 802.3at specifications. Passive PoE does not do any sort of power check so it simply supplies power regardless of what it is plugged into. This can damage any equipment not rated to accept the passive PoE power input. It is extremely important to understand the requirements and specifications of your equipment before plugging anything in.

Unfortunately, we see it too often that a customer damages their newly purchased IP security cameras when using a PoE switch such as a Unifi Switch that can output Passive PoE Power. If you choose to use your own PoE switch, we recommend use of reputable manufacturers such as Cisco, Netgear, or TP-Link that manufacture 802.3af/at compliant PoE hardware.

Calculating Passive PoE Power

If a device requires 12W and supports 12–30V, and you are using a 24V Passive PoE injector, you will need at least 0.5A to meet the power requirement:

24V x 0.5A = 12W.

Practical Limits for Passive PoE

·        24V Systems: Typically limited to about 50 metres due to higher voltage drop at lower voltages.

·        48V Systems: More efficient for longer runs, as higher voltage reduces the current needed for the same power, thereby minimizing heat loss (I2R).

·        Wiring: Passive PoE often uses Mode B, sending power over the "spare" pairs: pins 4/5 (+) and pins 7/8 (-)

Now question is How to access a PoE Security Camera from a Computer

We’re often asked how to modify an IP camera’s video settings once you already have it up and running on your NVR. This process can be difficult without any knowledge of computer networking or setting up a standalone IP camera. In this article we explain the technical details of taking a camera from the back of your NVR and connecting to it with either a direct connection or through your network.

The first steps include understanding how a camera and PoE NVR work together, noting the IP address the camera is configured to and finally physically removing the camera from the NVR.

After having a grasp on the basics and noting the IP address of your camera you can then proceed to the next steps. There are two ways that you can connect to a camera’s web interface:

·       The first is through a direct connection into your Windows desktop or laptop that has an ethernet port.

·       The second involves going over your computer network by configuring the camera to communicate on the network.

Be sure to note the IP address of the camera before disconnecting it from the NVR, you will need it later.

A) Direct connection between IP camera and Computer

The easiest way to access an IP camera is by connecting to it directly from a computer. This method requires you have the following:

1.   The IP address of your camera from the NVR registration page

2.   PoE Injector or 12VDC 1A Power Adapter. It is very important to use a CCTV Camera World approved device or you risk frying the camera due to incorrect voltage

3.   Two Ethernet cables (one if using a power adapter)

4.   Windows 11 pro based PC

1. Use a PoE injector to supply power and data

A PoE injector will have two ports, one labeled for PoE or P+D/Out (power and data) and one labeled LAN or Data/In. Connect the PoE injector to a power outlet. Connect an ethernet cable from your PC's network port to the Data/In on the PoE injector. Connect a second ethernet cable from the network camera's RJ45 network jack to the port labeled PoE or P+D/Out. To check if everything is connected properly refer to the lights on the PoE injector and the port on your computer. If you do not see any indication lights you may have a bad cable or do not have the wires connected properly.

2. Use a 12VDC 1A power adapter

A correct power adapter will have a label stating it is 12VDC 1000mA. Connect an ethernet cable from the camera directly to your computer’s ethernet port. A good way to check if the camera is receiving power and communicating with your computer is to look at the lights on your computer’s port. If you have no lights it is important to test that your cable and power supply work with another device.

3. Configure your PC's network port to communicate with the camera

For your computer to "speak" to your camera, you need to set its network port to the same IP address scheme as the camera. Before we disconnected the camera from the back of the NVR, we noted what the IP address of the camera was.

Login to your Windows PC, change your computer's ethernet adapter to communicate with the camera. Use the Network & Internet settings which contains an Ethernet section. Using the change adapter settings set an IP address for your computer that matches the network for the camera. If you do not know how to do this refer to the video above for this step.

4. Test the connection with the Ping command

After powering the camera and configuring your computer to talk with it, it is good practice to test the connection using the Ping command. Simply open the Command Prompt and type Ping with the address of the camera. In our case we used the following command: ping 10.1.1.65 -t press enter key.

5. Access the camera using Internet Explorer

It is important to use Internet Explorer as it is the most compatible browser for accessing security cameras. Type the IP address of your camera into the address bar in Internet Explorer. Some cameras may require initialization and it is recommended to uncheck the Easy4IP and auto-update options when proceeding through the prompts. The password can be admin, or may be printed on the label found on the box of the camera. Note: the customer is responsible for any password change beyond the defaults. There is no master reset password.

After successfully logging into the camera you need to install a plugin to view the camera. Click the link in the center of the page to download the plugin. Make sure to Run and do not save the plugin download. Internet Explorer will prompt you to allow the plugin to run. Once the plugin is installed, you will be required to log back into the camera. You should now see video from your camera and can modify the settings of the camera in the Setting tab within your browser. Make sure when you are done modifying your camera(s) that you change your network settings back to “Obtain IP address automatically” in your network settings, this is demonstrated in the video above.

B) Accessing the camera over your network

Besides direct connection to a computer, the other method to connect to a PoE security camera is over the network. This method requires the following pre-requisites:

1.   A home or business network with router

2.   Windows PC with ConfigTool installed

3.   PoE Injector or 12VDC 1A power adapter

4.   A network cable to connect to your router

5.   The IP address of your camera

1. Power the camera

You can use a PoE injector or 12V DC 1amp power adapter to power the camera and connect to your network router or switch. The process is simple. It is very important to use a CCTV Camera World approved device or you risk frying the camera due to incorrect voltage.

2. Connect the camera to your network router

Instead of connecting the camera directly to your computer, you will connect it to your network router so the computer can communicate with the camera over the network. When following this guide, it is important to connect the camera and computer to the same router or switch. We suggest using a hardwired connection between the computer and the router to prevent a situation where your WiFi network is different from the wired network. If you are knowledgeable about your network setup, feel free to use a WiFi laptop.

3. Use the ConfigTool to find the camera and change its IP address

Using the ConfigTool to find the camera on your network is fairly easy. It is imperative that you turn off any firewall or antivirus program on your computer that may prevent the program from sniffing your network.

4. Access the camera's web interface using Internet Explorer

The steps are similar to method A because the web interface will be the same regardless of how you connect to the camera.

Method for Identifying a PoE Power Supply Failure Caused by High Network Cable Resistance

If network cables can be removed from the switch at the local site, use below method to measure the resistance.

·        Measurement tool: Multimeter

·        Measurement contents and procedure: Use the multimeter to measure the DC resistance of each cable wire and take down the measured values as R1, R2,…R8.

·        Measurement results:

Network cable resistance:

R = (R1 + R2 + R3 + R6)/4 (when the switch uses the wires 1, 2, 3, and 6 to supply power.)

Or:

R = (R4 + R5 + R7 + R8)/4 (when the switch uses the wires 4, 5, 7, and 8 to supply power.)

Usually, the AC and PoE switch use wires 1, 2, 3, and 6 for power supply, and the PoE adapter uses wires 4, 5, 7, and 8 for power supply.

Key Takeaways

The primary difference between Active and Passive Power over Ethernet (PoE) is how they deliver power: Active PoE communicates with a device to ensure it is safe to power, while Passive PoE sends electricity immediately without checking compatibility.

Active PoE (The "Smart" Choice)

Active PoE is the industry standard for most modern business networks.

·        Intelligent Handshake: The power source (PSE) sends a low-voltage signal to detect if the connected device is PoE-compatible and determines exactly how much power it needs.

·        Protection: If you plug in a laptop or a non-PoE device, the switch detects it and sends only data, preventing electrical damage.

·        Common Standards:

o   PoE (802.3af): Up to 15.4W per port.

o   PoE+ (802.3at): Up to 30W per port.

o   PoE++ (802.3bt): Up to 60W or 100W for high-power devices.

Passive PoE (The "Always-On" Choice)

Passive PoE is common in specific setups like outdoor wireless bridges or legacy equipment.

·        No Communication: It does not check the device's needs; it simply pushes a fixed voltage over specific pins in the Ethernet cable.

·        High Risk: If you plug a device into a passive port that doesn't match its required voltage (e.g., 48V into a 24V device), it can cause permanent electrical failure.

·        Manual Matching: You must manually verify that your injector or switch matches the exact voltage and pinout required by your device.

Which should you choose?

·        Choose Active PoE for almost all standard office or home office uses (IP cameras, VoIP phones, modern Access Points) to ensure safety and future-proofing.

·        Choose Passive PoE only if you have specific legacy hardware or budget-constrained outdoor installations where you are certain the power specs match perfectly

How to Find Your Model's Requirements

1.   Check the Physical Label: Look for a sticker on the back or bottom of the device. It will often list "802.3af," "802.3at," or a specific voltage like "24V DC".

2.   Consult the Datasheet: Search for your model number + "technical specs" online. Look specifically for the "Power Method" field.

3.   Check the Box: If you still have the original packaging, the required PoE standard is usually printed on the side near the serial number.

 

Tuesday, September 1, 2026

Drones and Data Privacy

Drones and Data Privacy 

Drones raise data privacy concerns due to their ability to collect vast amounts of personal data, including images, video, and geolocation, through advanced sensors and cameras. These concerns are amplified by potential for surveillance, the collection of data without consent, and security risks like hacking. Mitigation requires clear guidelines, responsible use, and the implementation of data protection principles like data minimization and secure storage.

 

For Indian business owners, a drone is no longer just an aerial tool; it is a mobile data harvester. Operating commercially means navigating the strict intersection of aviation mandates from the Directorate General of Civil Aviation (DGCA) and the stringent privacy liabilities of India’s Digital Personal Data Protection (DPDP) Act.

As drone adoption accelerates across Europe, privacy has become the new regulatory frontier. Enterprises must now prove not just safety, but also data sovereignty — where and how aerial data is stored, processed, and shared.

What is personal data? The term “personal data” is a very broad concept that covers any type of information relating to an identified or identifiable person. As a result, any use of a drone that captures images which identify an individual (such as a facial image) will fall within the scope of data protection legislations. But the same also applies if the drone collects any type of data (such as location, house fronts, phone number, vehicle registration plate, IR image, etc) that can be linked to an individual and therefore, this one becomes identifiable/identified.

Hidden Privacy Risks of Aerial Data

·       Surveillance: 

Drones can be used by governments, law enforcement, or private entities to monitor individuals, infringing on their right to privacy. 

·       Data collection: 

High-resolution cameras and sensors can capture images, video, audio, and location data that identify individuals, even without direct intention. 

·       Unauthorized access: 

The use of drones in public spaces can intrude on areas where people have a reasonable expectation of privacy, such as private properties. 

·       Function creep: 

The sophisticated technology on drones can lead to "function creep," where data is collected for one purpose and then used for other, more intrusive purposes later. 

·       Security vulnerabilities: 

Drones and their data can be vulnerable to hacking, which can lead to unauthorized access or the compromise of sensitive information.

Mitigation and best practices

·       Establish clear guidelines: 

Regulations are needed to define when and how drones can be used for data collection, particularly in residential or sensitive areas. 

·       Adopt data minimization: 

Data collection should be limited to what is necessary for a specific, stated purpose, and irrelevant data should not be retained or collected. 

·       Implement security measures: 

Manufacturers and users should implement robust data handling and storage mechanisms to protect collected data. 

·       Use privacy-by-design: 

Drones should be designed with privacy in mind, and hardware capabilities that pose risks should be carefully considered. 

·       Educate users: 

Recreational and commercial users need to be aware of privacy risks and practice responsible use, which may include following codes of conduct. 

Drone hardware (payloads and capabilities) and privacy

Drone payloads which include sensors and allow capturing data could give rise to privacy concerns among individuals on the ground. By capturing data, such as images, sound, geolocation and others, a drone could interfere with the privacy of individuals on the ground, especially if the captured data allows the identification of people (which in such case qualifies as the collection of personal data in terms of the GDPR). Blurring of faces of people is not always a guaranteed way to prevent such identification in contexts which contain other details, such as house or car numbers. Therefore, it is recommended that you, as a manufacturer, consider what kind of hardware features and capabilities a drone should be equipped with.

The question has shifted from “Can drones fly here?” to “Can this data legally live here?”

Why compliance is now a boardroom issue

For companies like UAVONIC, operating across the EU, every mission involves strict GDPR and local data protection checks. Each flight generates high-resolution video and telemetry that can include private property, people, or restricted infrastructure.

‍Traditional cloud workflows created friction: uploading footage to international servers risked compliance breaches. On-premise data handling, however, is limited in scalability. Enterprises needed both control and automation, a balance that most systems couldn’t offer.

How autonomy enables compliance

The solution came through FlytBase’s on-prem deployment model. UAVONIC adopted docked drones integrated with FlytBase’s local processing nodes, allowing missions to execute autonomously while keeping all captured data within sovereign infrastructure.

This approach provides:

·       Complete local data ownership — video and telemetry never leave the enterprise network

·       Automated audit trails for flight records and data access

·       Policy-based storage controls, aligning operations with GDPR and national regulations

By removing manual data handling and external transfers, UAVONIC reduced audit preparation time by 70% and achieved full compliance across multiple EU territories.

Beyond regulation toward accountability

Privacy compliance is evolving from a checkbox to a competitive advantage. Clients and partners now ask how enterprises manage drone data before granting access to sensitive sites.

By using FlytBase’s secure automation framework, organizations can demonstrate verifiable control over every mission, proving not only where data is stored, but how it’s governed.


The global shift to data sovereignty

Across industries, from utilities to logistics, more enterprises are adopting localized autonomy frameworks. Each FlytBase deployment ensures that sensitive operational data stays within defined boundaries while maintaining real-time collaboration for authorized teams.

The result is a new kind of compliance readiness — one that’s proactive, automated, and fully auditable.

Securing autonomy for the future

‍Data privacy is no longer an IT concern; it’s a business requirement. By combining autonomy with data governance, FlytBase enables organizations like UAVONIC to operate confidently in regulated environments while staying ready for future policy shifts.

Potential risk

Pontential safeguards

Overall information and IT security assurance

Malicious hardware or software could be used to attack both the drone and the ground control systems. Such vulnerabilities could lead to loss of sensitive data or to loss of control over drones while operational, both of which could raise potential privacy and security concerns.

The security of the entire supply chain of software and components you use to manufacture a drone should be ensured.

Ensure that the update or patching of software does not interfere with the operation of the drone, especially while in flight.

Using firewalls, antivirus systems and intrusion detection systems could be a fundamental step towards security the drone.

Drone navigation, both when operating autonomously and manually  

Information and IT security vulnerabilities in the ground control system for the drone or in the transmission of information and commands between the drone and its controlling point could allow unauthorised persons to take over control of the drone or disrupt its normal functioning. This could raise concerns about the privacy of people on the ground since this unauthorised controller would be unknown to them but could also raise security issues due to the physical damage and harm which drones could cause. 

Installing authorisation controls on the ground control system could help limit unauthorised access and control of the drone or unauthorised interference with drone features and settings.

Since Global Navigation Satellite

Systems (GNSS) like Galileo, GPS or GLONASS broadcasts are freely accessible, unencrypted and unauthorised signals, a drone could be fed misleading GNSS signals to alter its calculations of geographical coordinates. This could lead to a drone changing its flight path and could raise privacy and security concerns, particularly when the drone is operating autonomously.

Software features which are able to detect fake GNSS signals should be incorporated into the product.

A interface feature whereby manual control can easily be restored and override autonomous operation is recommended.

GNSS signals could also be jammed. This would disrupt the connection between the drone and external navigation, leading to the drone becoming disoriented and potentially crashing.

Alternative means of navigation could be considered, such as reliance on visual and inertia ques and requiring the attention of pilots and operators to begin manual operation. The use of GNSS receivers for more than one system can also mitigate the risk of GNSS jamming.

Data collection and processing

The operation and functioning of drones could be attacked by injecting false sensor data into the flight controller. This type of attack can impact all types of drone sensors, including radar, infrared and electrooptical sensors.

A drone could utilise alternative operational procedures to compare data received through different sensors and crosscheck readings. This could allow the drone to tolerate malfunctioning components or infected information.

Data transmission between the drone and other devices

(e.g. control system)

Real time data streams can be hacked and intercepted, especially if they are not encrypted or equally protected. This can jeopardise the privacy of people captured in the data, as well as the security of the drone operation itself by failing to control access to key data.

Incorporating continuous mutual authentication between the operator and the drone can help authenticate communication.

Encryption could help protect such data.

Utilising security keys to authenticate the connection and transmissions can ensure its security.

Data stored on drone 

By exploiting information and IT security vulnerabilities, unauthorised personnel could gain access to data stored on a drone. This could take place in the event of a drone accident or drone crash, as well as by exploiting vulnerabilities in the hardware and software of the drone. This could raise privacy concerns for individuals whose data is captured.

Use encryption to ensure the data stored on a drone is protected.

Implement access controls to the drone itself requiring authorisation for accessing data.

Build in capabilities to detect data breaches and alarm users to them.


The Dual Regulatory Burden on Indian Businesses

1. DGCA Airspace Compliance

All commercial drones operating above the Nano category (under 250 grams) must strictly follow the DGCA framework.

·       UIN Registration: Every drone must be registered on the eGCA Portal to receive a Unique Identification Number.

·       NPNT Mandate: India enforces No Permission, No Takeoff (NPNT). Drones must connect to the DigitalSky system; firmware locks will physically prevent the drone from taking off unless digital flight clearance is granted.

·       The Civil Drone Bill: Businesses should prepare for the stringent updates outlined in the Civil Drone Bill, which significantly escalates penalties for deviations—including steep fines up to ₹1 Lakh and authority powers to detain aerial hardware on mere suspicion.

2. The DPDP Act: Your Data Fiduciary Status

Under the Digital Personal Data Protection Act, commercial operators are legally classified as Data Fiduciaries. Aerial video files, LiDAR maps, or thermal scans that capture identifiable faces, residential interiors, or vehicle license plates are classified as digital personal data. If your drone inadvertently records individuals without explicit authorization, your business faces substantial financial liabilities.

Operational Blueprint for Privacy and Compliance

To protect your business from operational bans or multi-crore privacy penalties, integrate these localized practices into your standard operating procedures (SOPs):

Deploy Privacy Masking at the Source

·       Firmware Controls: Work with your tech teams to configure built-in "privacy masking" protocols.

·       AI Blurring: Use localized post-processing software to automatically blur faces and registration plates before sharing mapping data with third-party clients.

Establish Verifiable Consent & Notice Architecture

·       Public Advisories: When surveying non-public zones or semi-residential sites, provide clear, advanced notification to local communities.

·       Explicit Disclosures: State exactly why data is being collected, who will have access to it, and how long the video logs will be archived.

Localise Data Storage

·       Turn Off Auto-Sync: Many commercial drone suites default to overseas cloud servers. Restrict your hardware to Local Data Mode (LDM) to force the data to remain entirely within localized, offline servers.

·       On-Soil Infrastructure: Under the DPDP Act guidelines, any data transferred across borders must clear negative-country checklists. Keeping processing pipelines on Indian cloud infrastructure lowers compliance risks.

Encrypt and Log All Assets

·       Secure the Storage: Encrypt the physical SD cards inside your drone payloads. If a drone crashes or is retrieved by an unauthorized party, the raw surveillance footage must remain completely unreadable.

·       Maintain Flight Logs: Keep precise flight telemetry logs for at least one year to protect your business against data breach accusations or airspace violations.

Comparison of Liability: Recreational vs. Commercial In India

Compliance Vector

Recreational / Nano Drones (<250g)

Commercial Enterprise Drones (Micro to Large)

DGCA Registration

Not mandatory for most standard Nano models.

Mandatory via eGCA portal; must display physical UIN.

Pilot Licensing

No remote certificate needed for basic hobby flights.

Mandatory Remote Pilot Certificate via approved RPTO pathways.

Airspace Clearing

Restricted to basic green zones up to 50 feet.

Strict NPNT integration required before every single flight.

DPDP Accountability

Mostly exempt unless processing systemic data.

Full Data Fiduciary Liability with mandatory breach notifications.

The Outlook for Enterprise Aviation

The Indian commercial drone market is backed heavily by government growth models like the Production Linked Incentive (PLI) Scheme. However, this fast-tracked scaling requires operational maturity. Drone data security is no longer just a technical checkbox—it is a critical pillar of corporate compliance. Business leaders who proactively blend aviation safety with DPDP data privacy standards will gain a strong competitive advantage in India's expanding digital ecosystem.