Malware? Don't know if anyone else saw this article...

nayr

IPCT Contributor
Joined
Jul 16, 2014
Messages
9,329
Reaction score
5,325
Location
Denver, CO
Hint: Its everyone..

The Firmware on IPCameras, from anyone.. will completely fail any security audit shortly once a security researcher starts poking about.. its abysmal, thoroughly..

I put tighter restrictions on black boxes from china than I even do Windows.. I'll let a Windows VM connect to the internet to download updates, my security cameras cant communicate with anything I didn't explicitly allow, and thats only 2 IP's in the entire world.. my NVR and my Admin workstation.. the NVR can talk to a few more things but still cant reach the internets.
 

Ssayer

BIT Beta Team
Joined
Jan 5, 2016
Messages
19,607
Reaction score
70,925
Location
SE Michigan USA
True. I block all my cams and only let BI get out to the world. Nothing wrong with being paranoid. The first time you aren't, you'll wish that you would have been. :p
 

nayr

IPCT Contributor
Joined
Jul 16, 2014
Messages
9,329
Reaction score
5,325
Location
Denver, CO
China has a culture of ripping off, and thats the problem.. they rip off so much that they try to keep them selves from getting re-ripped off by obfuscating and hiding things and purposefully sabotaging things.. government offers no protection for copyright infringement.. hikvisions region locking is a symptom.. all these security issues are a symptom because they cant trust anyone enough to collaborate.

one of our members here I found one of his videos on aliexpress, and it had been watermarked by the seller so other people would not steal it from him..

The quality of software that comes out of China is abysmal as a result, its a bunch of plagiarized code they suck up from anywhere they can find it without ever bothering to understand how the code works.. no effort is put into security other than what seems to be required and the'll gladly trash 100 emails a day from security researchers finding problems.

Its the price for cheap cameras.. to hire talented western developers performing rigorous security testing all along the way would not get you an IPCamera for under a grand, let alone under $100.. Those of us with that ability are getting paid very well now days, and few of us work on anything consumers directly own.. because well consumers dont get any real security, ever.. your door locks are pathetic, your personal information is hardly safe, your passwords suck, your gun safe I can hit with a hammer hard enough to open.. its just feel good stuff for the masses, aka security theatre.
 

j4co

Pulling my weight
Joined
Jan 17, 2016
Messages
502
Reaction score
175
Location
The Netherlands
I also intend to put the hikvision units behind a firewall, just in case they have backdoors etc.
Having them hacked or whatever would put me through the password recovery once more and i would like to avoid that.
 

Q™

IPCT Contributor
Joined
Feb 16, 2015
Messages
4,990
Reaction score
3,989
Location
Megatroplis, USA
Not my gun safe. Not Butch Cassidy and not you.

My cameras? Errrrrr....wellll....
 
Top