Security camera installer reuses passwords

techguy505

n3wb
Joined
Jun 23, 2024
Messages
6
Reaction score
9
Location
Canada
So I recently discovered the outside contractor who installs and manages our security cameras and alarm systems has been reusing the same username "admin" and the same password on all of his NVR/DVR systems across all of his clients for years now. We have 7 NVR systems with him. Typically Dahua units and cams. Is this as bad as I think it is?
 

TonyR

IPCT Contributor
Joined
Jul 15, 2014
Messages
17,595
Reaction score
40,940
Location
Alabama
So I recently discovered the outside contractor who installs and manages our security cameras and alarm systems has been reusing the same username "admin" and the same password on all of his NVR/DVR systems across all of his clients for years now. We have 7 NVR systems with him. Typically Dahua units and cams. Is this as bad as I think it is?
Definitely not good.....although it could be worse if you find out even more similar no-no's......:wtf:
 

techguy505

n3wb
Joined
Jun 23, 2024
Messages
6
Reaction score
9
Location
Canada
Techguy, why don't you change the passwords?
I just figured out it was happening. The contracter and I are having an unrelated dispute and I came to the realization while reviewing past conversations. He'll likely be removed and upper management has been made aware of it but my hands are currently tied.
 
Joined
Aug 8, 2018
Messages
7,624
Reaction score
26,913
Location
Spring, Texas
He did that because he is lazy. He does not need to keep track of different credentials for each installation. This goes against the first rule of cyber security that has been told to everyone for decades.

This is almost like installing a back door. He or anyone working for him can access your system without your consent. This also means that any of his other clients can know your password to your system, and anyone that those clients share the password with can know your password also.
 

Oneup

Getting the hang of it
Joined
Apr 24, 2024
Messages
18
Reaction score
35
Location
32789
What is worse, is that the installer, that is Pissed Off at you, has access to your system. That would be my first thing to correct.
 

techguy505

n3wb
Joined
Jun 23, 2024
Messages
6
Reaction score
9
Location
Canada
What is worse, is that the installer, that is Pissed Off at you, has access to your system. That would be my first thing to correct.
Yeah I'm hoping to have him removed next week. We're going to review his contracts but given that reusing passwords to the degree he has it wont he hard to claim negligence.
 

wittaj

IPCT Contributor
Joined
Apr 28, 2019
Messages
25,749
Reaction score
50,282
Location
USA
Blast company name here and on BBB and FB.

That sounds like the trunk slammer and has exposed many companies to vulnerability.
 
Top