Hanwha / Kaspersky Vulnerability Dispute Examined

JH
John Honovich
Mar 29, 2018
IPVM
IT media ran numerous reports in the past month featuring two prominent companies - Hanwha (previously part of mega manufacturer Samsung) Techwin who sells significant numbers of consumer security cam...

Read the full report here
JH
John Honovich
Mar 29, 2018
IPVM

Btw, a note on why we are 'late' reporting (not to the security trade press, which rarely covers such things but to mainstream IT). As noted in the report, we went back forth between both parties and that took time to get answers, check on things, etc.

(1)
(1)
JH
John Honovich
Mar 29, 2018
IPVM

Two other things that did not make the post but worth commenting on. Kaspersky included this infographic in their press release:

And report from Sputnik News: Kaspersky Lab Researchers Discover Sinister Flaw in Popular Smart Cameras

(1)
bm
bashis mcw
Mar 29, 2018

But the difficulty becomes what responsibility the researcher has in terms of accurately and fairly disclosing vulnerabilities as well as providing proof of those vulnerabilities. 

I believe it is important to prove the claims, so it can be reproduced and verified by other researchers.

When reading;

Kaspersky: Unfortunately we cannot disclose any technical details of the critical vulnerabilities because we are still not sure if all the smart cam owners have installed security updates.

It becomes in my eyes clear that will never happen, because how to verify that "all the smart cam owners have installed security updates."

 

(4)
(1)
New discussion

Ask questions and get answers to your physical security questions from IPVM team members and fellow subscribers.

Newest discussions