VMSes Adding 2 Factor Authentication

Author: Brian Karas, Published on Feb 01, 2017

2 Factor Authentication (2FA) support is growing across the Internet to improve the security of critical web services. For example, banks frequently use 2FA to mitigate against a user's password being stolen / hacked.

Now, VMS manufacturers are starting to add two factor authentication (2FA) support to their products.

In this report we outline how 2FA works, what problems it solves, who is using it (including BCD, Eagle Eye, Genetec, Milestone, OpenEye) and what vulnerabilities it still leaves open.

* ****** ************** (***) ******* ** ******* ****** *** ******** to ******* *** ******** ** ******** *** ********. *** *******, banks ********** *** *** ** ******** ******* * ****'* ******** being ****** / ******.

***, *** ************* *** ******** ** *** *** ****** ************** (2FA) ******* ** ***** ********.

** **** ****** ** ******* *** *** *****, **** ******** it ******, *** ** ***** ** (********* ***, ***** ***, Genetec, *********, *******) *** **** *************** ** ***** ****** ****.

[***************]

Two ****** ************** ********

*** ****** ************** (********* **** ****** *** **** ************) **** two ********** ** ****** * ***** ********. *** ***** ********* is ********* * *********** ********, *** *** ****** ********* ** a **** ** *** **** ** **** ****** * ****, or *** * ***** ******** ** ****.

*** **** *** *** ****** ****** ** ***** ********* *** SMS ** ***** ** *** ******** ********** ** *** **** when **** *** ****** ** *****. * ******** ******** ** for *** **** ** ***** ***** ********/********, *** **** ** presented **** * *** ** ******* *** ***** **** ***** like *** *-**** **** ** ** *********. ** **** ***** the ******* **** ** ********* ** ** *** *********.

** ****** *** *** **** ** ******** ** *** ****, the *** ********** *** **** *** **** ** **** ***** for * ***** ******** ** ****, *** ********* **** *** a ****** *****. **** ******* *** ****** **** ****** ********* can ** **** ** ***** ** **** ********.

*** ******* ******** ** ********* *** ** ********** ****** ** the **** **** ******* **, ****** **** ** ********* ******* unless *** **** ** ******** ******* ****** ** ***** *****, email *******, ** ****** **** ** ******* *** *-**** ****.

VMSes ********** ***

*********, *** ********* ********* ******* **** **** ** *** *****, generally ** ***** ****** ******** ****:

  • ********- ***** ***** ** ******* ** ********* ****** ******** ***, code ********* *** ***** ** ***.
  • ******* ********** - **** ******, ********* ** ***** ******, ***** can ** ************* *** *** ***.
  • ********* ********* / ****** - ***** ***** ******** *** **** enabled, **** ********* *** ***** ** ***, ******** **** ********* SMS *******.
  • ******* - ***** ***** ******** *** **** *******, **** ********* via ***.

************, ****** *************** *** ***** *** ********** ** ***** *** ** ***** *******, **** **** *** add *** ** ****** *****, *** ******** ****** ***** ** the ****** ******* ***** ******* *** ***-**** *******.

Problems ****** ** *** *** *****

*** ********* ******** ***** **** ******* *********, ** ***** ****** passwords ** ***** ** ******* ******* *******. ** **** ******** hackers **** ******** * **** ** ********/******** ************ **** * database **** ** ******* **** ***** ***** *********** ** ********** as * ***** **** *** ***** ** *** ******. ** can ** ************ ****** *** ******** **** **** *****-*****, ** other ******** **********, ** ******* ************ *** ** ***** ********.

What *** **** *** *****

*** ****** ************** **** *** ******* *** ***** ** ******** that **** **** ****** ** ******** ******* ******** - ******* leveraging ********** ** *** ******** ****** ** **** ****** ** backdoors, ********, ******* *******, ***. * ****** **** *** ***** requirements, **** *** ** *********** ****** ** **** ** * web/mobile ******* ***** ***** ** ********** ** **** ********.

More ********** ** ***** **** *******

***** ***** ** ******* *********** ********** * *** ************** ** a ****** ** ******* ******, ** ** ********* **** *********** on ******* ** ******* **** ****** ********* ***** ** ********. Implementing *** ** * ****** ***** **** **** **** *** VMS ***** **** **** *** ** ******* ** *** ******* for *** ****** ****** **************, ***** ***** **** ***** *** administration **********.

Good **** *** ********

****** *** **** *** **** * *** ****** **** *** forms ** ****** *******, ** *** ******* ******* ****** *** prevent ********* ***** **** ********** ** ****** ***** ******** ** change ********, ****** *********, ** ******* ***** ************ *********. *****, and **** ***** ********* **** ****** *** ***** ********* ***** the ****** ** *** *** ************, *** ***** *** *********** of **** *** ****, ** ** * **** **** *** manufacturers ** ***** ***** *** ******* ** ******** ******** ****** user ************.

Interest ** ***?

Comments (6)

******* **** *** ** ***** ******** **** *** *** ******** security ********. ** ****** *** *****, * ***** **** ****** be **** ********* ***** ***, ***** *** ** ***** ** concerned ***** ***.

* **** ******* **** *** ******* ** ******** ****** *** think *** *** *** ******** ****** ***** ********** *** ** world ****- * ***'* **** ** *** ** ****** ***********. But **** ****** *** ** ****** ** ***** *** ****** ideas. *** ****** *** ***** ** ** ***** **** *** stay ***** ** *** *** *** ************ ***** ***** ** learn *** ** ** * ******* **** *** ** *****.

*** ** **** *******. *** **** **** ** ****** ********** guy ***** **** ***** ***/***** *** ****** ****** ** * good **** ** **** ??
*** *** ***** * **** **** *********** ****** **** ****/*****/***/*********** ?

**'* *** * ***** ******* (**, ****** **********). *** ********* ********.
*** ??

**** ****** *** ***** ** *********** ****** ***** **** ******* information ** ************ *** * "*** **** ***". **'* **** to **** *** *** ***** **** **** **** ******* ***'* be **** ** **** ****** ***** *** **** **********, *** that ***'* * **** ********** ***** ****** ****** *********** *** concerned.

* ***** **** **** **** ** *** ** ******** ***** is ******* ** **** ** * ******** ******* ** ******** security *******, **** ** ***** ** ** ******* ** ******** the **** **.

******* ******** ******** * ******* ** **** ********** *** ** which ******** *** ****** ** ***** *** ** ***********. *** example * ****** ******** ***'* ********** **** *** ***** **** to ****** ***** *** **** ****'** ******* *** ** ******** them ** ****** *****. *** ********** ***** **** *** *** to ****** ** *** ********** ** *** ****.

** ******** *** *** ** **** ******* *** ** ** on *** *******.

********* **** **** *******. * *** ***** ********** **** ** general ******** ******** ******** **** *** **** ***** ** ********.

**** ** ********** ****** ************ *** *********, *** *** *********** were ***** ***** **.

***** **'* *** ** ***** ***** ***** **** *** ******* the *******?

********* **** **** *******. * *** ***** ********** **** ** general ******** ******** ******** **** *** **** ***** ** ********.

* ***** ***** **** ******* *** ****** ***** **** ******* the **** ** ****** *** **** ** ******* ***** ***. Surely, **** ***** *********** *** *** ***** *** **** "***'* care" ** "*** ********** ** **** *****".

** ** **** ******* ***** ******** ****** ***** ** ****.*** *** **** ************* *****.

Login to read this IPVM report.
Why do I need to log in?
IPVM conducts unique testing and research funded by member's payments enabling us to offer the most independent, accurate and in-depth information.

Related Reports on VMS

Stolen Video NVR / DVR Statistics on Aug 15, 2017
"But what happens if someone steals my recorder?" Anyone who has done more than a handful of jobs has probably heard this question several times....
IP Camera Specification / RFP Guide 2017 on Aug 14, 2017
RFPs are hard. Do them 'right' and it takes a lot of knowledge and time. Do them 'wrong' and you can be (a) unwittingly locked into a specific...
Briefcam New Outsider CEO Promises Exponential Growth on Jul 31, 2017
Briefcam is now nearly a decade old, having raised over $20 million, to improve investigations and review of video. The company has remained a...
Canon Sues Avigilon on Jul 27, 2017
Canon, owner of Axis and Milestone, has sued Avigilon for patent infringement in US court. This is a highly atypical move for Canon, pitting 3 of...
Sports Stadium Security Design Recommendations on Jul 24, 2017
Sports stadiums pose many challenges for designing security systems. The facilities vary from being mostly vacant, to packed with tens of thousands...
Genetec Mission Control Tested on Jul 13, 2017
Genetec continues to move up market with their Mission Control, "Decision Support System", bringing PSIM-like procedures and incident management to...
OnSSI Gets $16 Million Funding on Jul 11, 2017
OnSSI has had a rollercoaster past few years. Between acquiring VMS company Seetec, breaking up with former OEM partner Milestone and a rocky...
ONVIF Widely Used Toolkit gSOAP Vulnerability Discovered on Jul 10, 2017
A vulnerability has been discovered in a toolkit that video surveillance manufacturers widely use for implementing ONVIF. In this report, we...
H.265 / HEVC Codec Tutorial 2017 on Jun 30, 2017
For years, video surveillance professionals have talked about the potential for H.265. Now, in 2017, H.265 is starting to gain mainstream...
Hikvision H.265+ Tested on Jun 27, 2017
Hikvision, which in the past few years released H.264+ (see test results) has now released H.265+, that claims even greater bandwidth savings. We...

Most Recent Industry Reports

Final Day Save $50 - IP Networking Course September 2017 on Aug 17, 2017
Today, Thursday, August 17th is the last day to save $50 on the September IP Networking Course. This is the only networking course designed...
Directory Of Consumer Security Cameras on Aug 16, 2017
The consumer camera segment continues to grow, with new startups and models from existing players released seemingly every month. In this report we...
Cat 5e vs Cat 6 vs Cat 6a Network Cable Usage Statistics on Aug 16, 2017
Cat 5e? Cat 6? Cat 6a? What do integrators use in practice, today? 140+ integrators told IPVM. Here are the results: For those who want to...
Hikvision Responds To Cracked Security Codes on Aug 15, 2017
Hikvision has responded to IPVM's report on Hikvision's security code being cracked, both with a 2 page update to dealers and communication...
Stolen Video NVR / DVR Statistics on Aug 15, 2017
"But what happens if someone steals my recorder?" Anyone who has done more than a handful of jobs has probably heard this question several times....
Hikvision Europe Cutting Out Unauthorized End User Sales on Aug 15, 2017
The days of anyone buying Hikvision from anywhere off the Internet are numbered, at least in Europe, if Hikvision's plan comes to fruition. In...
Axis Laser Focus PTZ Tested on Aug 14, 2017
Axis has been touting its new Q6155-E laser focus PTZ as 'always in focus' and 'always in color'. Does it really deliver? We bought and tested...
Vulnerability Directory For Access Control Cards on Aug 14, 2017
Knowing which access credentials are insecure can be unclear, especially because most look and feel the same. Even the most insecure 125 kHz types...
IP Camera Specification / RFP Guide 2017 on Aug 14, 2017
RFPs are hard. Do them 'right' and it takes a lot of knowledge and time. Do them 'wrong' and you can be (a) unwittingly locked into a specific...
Cellphone Usage Issues For Integrators (Statistics) on Aug 11, 2017
Cellphones clearly offer significant advantages in communication and problem solving. But they can also be a major pain point if employees...

The world's leading video surveillance information source, IPVM provides the best reporting, testing and training for 10,000+ members globally. Dedicated to independent and objective information, we uniquely refuse any and all advertisements, sponsorship and consulting from manufacturers.

About | FAQ | Contact