Hikvision Critical Cloud Vulnerability

fenderman

Staff member
Joined
Mar 9, 2014
Messages
36,905
Reaction score
21,279
That is one bad article... I think whoever wrote it might be good at rewriting what he reads, but has probably never used a Hikvision device.
What specifically is "bad"...he simply explains the vulnerability and its a serious one. At least this time hikvision did something to fix the issue rather quickly.
 

Securame

Pulling my weight
Joined
Mar 25, 2014
Messages
664
Reaction score
214
Location
Barcelona, Spain
What specifically is "bad"...he simply explains the vulnerability and its a serious one. At least this time hikvision did something to fix the issue rather quickly.
Well, just saying that the post just seems to be written by someone who knows nothing or little about CCTV, Hikvision, etc. Two examples.

He mixes the Dahua DVR vulnerability on the article.
"Later on that same year, after details about exploiting Hikvision IP cameras were posted on Full Disclosure, some owners were seeing “HACKED” on camera displays instead of the live video feed they had expected to see."
He goes as far as posting a screenshot from a DVR... a Dahua unit.

He says that Hikvision "introduced the Hik-Connect cloud service in January 2017". Hik-connect has been around for maybe 3 years? Even longer under the EZVIZ name. The press release he links to from Jan/17 just points that users that migrate from HiDDNS now are "encouraged" to use Hik-connect, but Hik-connect had been functioning for a while.

Great job also on the random picture with several cameras from a random flickr user. Only one of the cameras on the pic is a Hikvision camera.

Yes, at least this time they got it fixed pretty quick.
 

fenderman

Staff member
Joined
Mar 9, 2014
Messages
36,905
Reaction score
21,279
The hacked issue was a Hikvision vulnerability...the image was for illustration...
 

Mike

Staff member
Joined
Mar 9, 2014
Messages
2,982
Reaction score
2,727
Location
New York
Thanks for sharing, interesting read. Glad it was "fixed". If you can't trust a surveillance company owned by the Chinese gov't, who can you trust?!
 
Top