Security camera installer reuses passwords

techguy505

n3wb
Jun 23, 2024
6
9
Canada
So I recently discovered the outside contractor who installs and manages our security cameras and alarm systems has been reusing the same username "admin" and the same password on all of his NVR/DVR systems across all of his clients for years now. We have 7 NVR systems with him. Typically Dahua units and cams. Is this as bad as I think it is?
 
  • Like
Reactions: mat200 and TonyR
So I recently discovered the outside contractor who installs and manages our security cameras and alarm systems has been reusing the same username "admin" and the same password on all of his NVR/DVR systems across all of his clients for years now. We have 7 NVR systems with him. Typically Dahua units and cams. Is this as bad as I think it is?
Definitely not good.....although it could be worse if you find out even more similar no-no's......:wtf:
 
  • Like
Reactions: mat200
He did that because he is lazy. He does not need to keep track of different credentials for each installation. This goes against the first rule of cyber security that has been told to everyone for decades.

This is almost like installing a back door. He or anyone working for him can access your system without your consent. This also means that any of his other clients can know your password to your system, and anyone that those clients share the password with can know your password also.
 
  • Like
Reactions: mat200
I would expect the user to change the passwords after the installation. One of the first things I did moving into the current house was re-key the locks because I knew at least the builder could get in.
 
IMHO, these are not "security systems", they are more accurately called "surveillance camera systems". :cool:
 
  • Like
Reactions: bp2008 and mat200
What is worse, is that the installer, that is Pissed Off at you, has access to your system. That would be my first thing to correct.
Yeah I'm hoping to have him removed next week. We're going to review his contracts but given that reusing passwords to the degree he has it wont he hard to claim negligence.
 
  • Like
Reactions: mat200
If you can't remove him, then change the passwords and when he needs to "manage" the system, have someone enter the password without him seeing it. But if the management is remote, that will not work.
 
Blast company name here and on BBB and FB.

That sounds like the trunk slammer and has exposed many companies to vulnerability.
 
  • Like
Reactions: mat200