Hikvision backdoor? (WSJ article)

Cljs

Young grasshopper
Joined
May 21, 2014
Messages
48
Reaction score
19
Link:
Surveillance Cameras Made by China Are Hanging All Over the U.S. - WSJ

In May, the Department of Homeland Security issued a cybersecurity warning saying some of Hikvision’s cameras contained a loophole making them easily exploitable by hackers. The department assigned its worst security rating to that vulnerability.

Also in the article: interesting description of technologies Hikvision is developing.
 

Mike A.

Known around here
Joined
May 6, 2017
Messages
3,828
Reaction score
6,384
Cameras are kind of the tip of the iceberg as far as that goes.
 

RyanODan

IPCT Vendor
Joined
Mar 10, 2014
Messages
626
Reaction score
266
Location
Tulsa
Also, @bp2008 made a program from the exploit that allowed you to easily change the password on the cameras that were dated earlier than version 5.4.5. You can find it here: Hikvision camera admin password reset tool

and I can personally vouch that his release of the password generator script and Password reset tool has saved me hours of waiting to get a password reset.
 

fenderman

Staff member
Joined
Mar 9, 2014
Messages
36,901
Reaction score
21,269
Neutrally-toned, paywalled article, outdated information, too much credit to DHS, no mentioning of researchers, published 6 months too late... Typical WSJ.
It amazes me that they can publish something like that and not give you credit.
 

fenderman

Staff member
Joined
Mar 9, 2014
Messages
36,901
Reaction score
21,269
I need no credit. I need to not be able to trust my cameras. :)
I understand that, but credit is due whether you need it or not....no one will be able to trust any camera ever....the true solution is open source verified firmware. There is no need for hikvision or any camera manufacturer to be in the firmware business....they suck at it.
 
Top