Hikvision Cybersecurity 'Not Professional'

JH
John Honovich
Oct 04, 2017
IPVM

Morten Tor Nielsen defended Hikvision a few months ago. Now, he is back, post the Hikvision backdoor details disclosure, contending:

if someone suggests using a non-standard port to “protect their installation”, then you know that the guy is not professional (doesn’t mean he’s not paid, just means he’s not competent). [emphasis added]

What is fascinating and ironic is that Hikvision's own hardening guide recommends port forwarding and just that technique:

We agree with Tor Nielsen, port forwarding generally and changing port numbers specifically are not prudent ways to protect an installation.

Port forwarding exposes devices to the entire public Internet, whereas security cameras are generally only intended for a few clients / people to view. Moreover, using a non-standard port is a shallow form of security by obscurity that can easily be overcome by various bots and attackers scanning the Internet.

Where we disagree with Tor Nielsen is the extent of blame on users:

And that’s at the core of this debacle: people that are incompetent, feel entitled to be called professionals, and when they make mistakes that pros would never make, it’s the fault of the equipment and it’s not suitable for professionals either.

Users are making mistakes but they are literally following the directions of Hikvision, who is telling them to do this in a hardening guide.

(6)
DR
Dennis Ruban
Oct 10, 2017

I wouldn't trust all those cheap cninese manufacturers. Here's the way I usually setup security system remote access: Ubiquiti router (the smallest one is ER-X, which costs just $50), VPN configured, your phone/PC connects to the router and you have secured connection without any exposed ports.

(1)
Avatar
Jon Dillabaugh
Oct 10, 2017
Pro Focus LLC

Not true at all. VPN routers still have an open port. If you are running OpenVPN on the Ubiquiti Edge Routers, the default open port is UDP 1194.

DR
Dennis Ruban
Oct 10, 2017

I meant hikvision device ports. I'd recommend to not use GW or use some random IP to prevent Hik NVR/camera from getting access online. Who knows what they have in the firmware. I wouldn't be surprised if someone finds trojan or backdoor there.

For sure, when you initiate a connection from outside, you need to have an open port

New discussion

Ask questions and get answers to your physical security questions from IPVM team members and fellow subscribers.

Newest discussions