Forgotten Password Problem Importance (Statistics)

Published Sep 15, 2017 12:03 PM

Forgotten passwords has become a major industry topic.

For example, Hikvision has been emailing admin passwords in plain text until IPVM's reporting prompted them to stop it.

And XiongMai, famous for its role in 2016's massive Mirai botnet attacks, allows mass emailing master password lists, like so:

Dahua and Hikvision still send out passwords, even after Hikvision's previous tool was cracked.

How Big A Problem Is This?

The great lengths that these companies go clearly implies that some people are having significant problems with forgotten passwords.

But how big of a problem is it overall?

150 integrators responded to IPVM's survey question:

How significant of a problem is your customers forgetting their recorder's password? What do you typically do when it happens?

In this report we examine the problem of lost admin passwords, how integrators manage this problem, and why manufacturer support for recoverable admin passwords is poor design.

Lost ********* ****** ****** ***********

*********** ******* ***** ********* ********* ** be *************:

**** **** **** **** *** **** that ********* ***** ****** *********, *** **** integrators ********** ****, *** ****** *** problem ** *******, ** ********* ***** show. *** *** **** ****** ********** were ***** ****** ********, ** *********** user ***********.

Solved **** ****** *******

*** **** ****** ******** (~**% ** integrators ****** ******* **** ***********) ** managing **** ********* *** ** ******** a ****** *******, ** ******** *** of *** ***** *******. ******* ** giving ***** ***** ******, **** ******* users **** ***** *** ********. **** allowed *** *********** ** ***** **** these ******** *** ***** *** ********** users ********.

  • "*** * **** ******* ** ** usually **** *** ************* ******** ***** so ** *** ****** *** **** and ***** ***** ********. ** ****** happens, *** **** ** **** ** is *** **** ********* **** *** over."
  • "** ** *** * *********** ******* but ** **** ** ** ****** systems ******* * ***** *** ** happen **** ** ******* ******* (** residential ** ***** ** ** **** little). **** * *** ********** *** large ********** ******* ***** ******* **********, we ******* **** *** *** ***** account."
  • "**** **** *** ****** **** *****, and **** ** **** ** ** for *** ******* *************. * ***** it ** ******* **** ***'* *** it ***** **** **** **. ***** are *** **** ***** ** ***'* have ****** ****** **, ** ** just ****** ** *** ***** *** password. **** ****** *** **** **** we **** ****** ****** ***** **** our *** ******** *** ******** **** their ******."
  • "****** ********. ** ******** *** ********* up **** ** ******* ** ** will ****** ***-** *** ******/****** ***** password ** **** **** *** ************ tech ******* ** ***** *** **** as * ***** **** ********."
  • "** ****** ****** ** ***** **** with ***** ****** *** ******* ***** forgeten ******** *****."
  • "** ** *** **** *** ***** password ****. ** ****** ******** ****** mgr ******** ** ******."
  • "** ****** **** * ****** ** administration ******** ********* ******** ******** ** all ******* ** ******. ** ******** a ****** ******** ******** ****** ** retain *** ******* ** * ******* system ********* ****** *********, ********** ********* and ************** *********."
  • "** ****** **** * ******** ***** password ** ** *** ****** ****** if ******. **** ** *** ******** is ** ***** ** **** **** separate."
  • "*** *****, *** **'* * *** problem **** ** ****. ** ********* have *** *** ***** ********, ********* manufacturer ****** ** **** **** (** Hik :*)"
  • "** ********* ***'* **** **** ***** as ** ****** * ***** *** them *** *** *** ** **** way ** *** ****** *** **** the ******. ********* ****** **** ** have *** ****** **** ** ** have ** ******* *** ******."
  • "** **** * ****** ** *** providing ** ***** ***** ******** ** customer ****** ************ *********. ** **** maintain ** ***** ***** ***** ******* by *** *****. ** ******** ******* most ***** *** ** **** **** both **** *** ****** ** ******* a *********** **** ** **** *** attendance *** ********."
  • "*** ********* ****** ******. ** **** do ** **** * ******** *** can ***** ***** ******** **** *********."
  • "********* ***** ** ********** ******** ***** login *** ******** ** *** ********. This ****** ** ** ****** ***** password."
  • "*** ******* ** ***** **** ** is ********* **** ** ******* ******* we *** ** * ******** ***** account *** *** *******"

Solved **** *************

*** ***** ****** ********, ~**% ** those *** **** **** ********* **** not * *********** *****, *** ** keep ************* ** *********, ** **** customers ***** ** ******** **** ***** password ***.

  • "** **** *** *** ******** ** our ** *** *** ******** ******* can ****** ******."
  • "******* ** **** ** *** *******. Send **** *** ******** ** ******** on *** **** ** *********."
  • "*********... ** **** ** *** **** good ******* ** *** ************* ** a ******* ******** **** ** **** box...any **** *** **** **** ********"
  • "**** ************ ****** *** **** **. We *** ** **** * ******** record ** *** *****."
  • "*** * ****** *******. ** ** usually **** * ****** ** ******* password ** **** ** **** ** forget **** **** ****."
  • "** **** * ****** ** *** passwords, ** *****'* ****** ***** ******."
  • "* ***'* ******** * ****** ********. We ****** ******** *** ***********"
  • "*** *******. * ****** *** ************, show **** *** ********** ***** *** print *** * ***** **** *** the ******* ** *** ******. * tell **** **** **** *********** *** login *********** *** ********* *** ** keep ** * **** *****. ****** a **** ****** ******** ******* ***** login *********** *** ***** *** ***** with *** *** **** ** *** system. ***********, * ******** ********** *** can **** **** **** **** *******."

Rarely *******

*** **** ***********, ********* ********* *** a **** **********. **** *** ** due ** ******* **** *** ****** passwords, ** ***** ************** ******* **** Active ********* ************, ***** ********* ********* would ****** ** ******* ** *** customers ** **********, ******* ** *** integrator.

  • "*** ***** ** ***. *** **** they **, **'* * ******* ****. We *** *** ******** ** ******* preventive *********** ************* ***** *** ******* us ****** **** **** ********** ** the ***** ******."
  • "*% ****, ** **** *** *** common ******** ****** *** **** ******* premise ***** **** ** *** ***** such."
  • "*** *********** ** *** ******* ****** view *** ****** **** ** ***** devices. ***** ******* *** ******* ******** protected, ** ** ******* *** ****** to ** **** ** **** *** in."
  • "** *** *** **** * *********** issue."
  • "*** ********* ****** ******. ** **** do ** **** * ******** *** can ***** ***** ******** **** *********."
  • "*** ***********; ** *** * ********* password ** **** *******, *** **** customers ** *** ****** **."
  • "*************. ****** *** ************* *** ********** with ******* ****** *********."
  • "*** ***** *** **** ** **** we ****** ** ********* ** *** them."

Significant ******* *********

*********** *** **** **** ********* ** a *********** ******* ***** ****** ** manufacturer ******* ** ***** ** ***** lost ******** ********:

  • "**** ******. ** **** ** ************* to **** **** **** ** ******** program. * **** ***** ********** * program ********** ***** ** *** ********** hold *** *** ***** ******** ** we *** ****** ****** *** *********, but **** ********* ** *** **** this ****."
  • "*****. ** **** ***** * *** to ****** **** ** ***** ****** which **** ******** ************* *** ****** as *** ** ******** **** **** to ****."
  • "*** *** ************ *******"
  • "**** ***********, ** **** *********** ** will *** ** ** ************* ****** and ******** *** ***** *** **** name *** ********."
  • "***********, ** **** ****** *** *** sites. *** **** ***** *** ********* for ******** ** **** ** ************. Provide ******** **** ************* *** **** on ****. ** *** ******* ** customer *****, ********* **** ** *** cellphone. ****** ****** ****** ********* ******* over *********."
  • "**** **** ****** ** ***** *** install **** ***** ** ******** *** password. **** ** ***** ****** *** customer *** ******* ** ****** ** on ***** ***. ** **** **** we ******* *** *** ************ *** assistance ** * ******** *****."
  • "****** ******** **.* ** *** **** problem *** *** ***** ***. ** was * **** *********. *** **** Spectrum ** **** **** **** ** hit ****** ******** *** **** *** setup * *** ******** *** ***** cloud *******. "

Backup ***** ******* **** ****** ********

*********** ******** *****/*****-***** ******** *** ******** recovery ** * ********* ******** ****-********. Storing **** *********** (** ***** ********* data) ** ****** ************* ***** *** lead ** ********** ********** ** **** information, *** ** ********* *** * *********** approach. ** * *******, *********** ****** this *** ****** ** ********* **** a ****** ***, *** *** **** on ********-********** *******.

Manufacturer ******** ******** ******* *********** 

******** ******** '********', **** ** ***********'* ****-**** ******** ********, ******** ******** *****, ****** ***** ** ******** **** of ******. * ***** ********** ** integrators ********** ****-********* ** ******** ********* admin ******** ** ****** **** **** user *********, *** ********** ************ ********* on **** ***** **** ****** *** message *******. ************* **** ******* *****/******** to ******* **** ***** ********* ** so ** *** ******* ** *** overall ******** ** ***** *******, *** by *********, ***** *****. ***********, ** users, **** *** ********* ***** *** cyber ******** ** ***** ******* ****** question ************* ** *** ********* ** password ******** *********/*******, *** **** ******* consideration ** ***** ******** **** ***** this.

Comments (10)
BM
Bob McCarvill
Sep 15, 2017

Right now we use Microsoft Excel to document admins, passwords, and MAC addresses but we are discussing new software options that have the ability to have all of our clients in one place. Does anyone have any suggestions they have implemented with success? 

Avatar
Josh Hendricks
Sep 17, 2017
Milestone Systems

I'm a big fan of LastPass for personal use, and I could easily see using it for keeping documentation of customer equipment passwords as an integrator. It's cloud based and supports 2 factor authentication, and you can share passwords between accounts as needed.

Keepass is a great offline alternative too, just make sure to keep a backup!

(1)
Avatar
Ricardo Souza
Sep 18, 2017
Motorola Solutions • IPVMU Certified

I started using Lastpass since it's inception but moved to KeePass since the first hack and have been happy ever since.

Lastpass has been hacked multiple times or suffered multiple attempts already =(

(1)
UI
Undisclosed Integrator #1
Sep 15, 2017

Hi

also we are looking for a software for keep client database with IP, ports and password from devices...but somethink that we can acces remote, from smartphone, etc and with different security acces levels for security 

UM
Undisclosed Manufacturer #2
Sep 16, 2017

I use a strongly encrypted "Keepass" databases,  stored in Dropbox.

For Android there's are nice apps which can access the database directly from cloud sevices, check e.g.  "Keepass2Android". I guess there are apps for iOS too. All desktop OS are supported also. 

It works for me ☺️

 

(1)
DC
Deepak C Shankar
Sep 18, 2017
eSecProfession

Latest Hikvision products are using a different method, its using forget password option SADP tool /iVMS 4200 software,export a file (example: DS-760XNI-EX_8P0X2014112AAARR491942694WCVU-20170XXX1554.xml ) and send same to local Hikvision support team, they will revert you with reset file (example:Encryptkey.xml). Import this and reset you devices. NO Question asked.

(1)
(1)
Avatar
Ricardo Souza
Sep 18, 2017
Motorola Solutions • IPVMU Certified

I would recommend you to check for more commercial/enterprise Password Management solutions, that you can also use to secure servers, etc...

 

Examples:

  • Zoho
  • OnionID
  • Thycotic
  • Keeper

 

UM
Undisclosed Manufacturer #3
Sep 18, 2017

The issue is not unique to our industry, right?

Example1. You can restore linux root access if you have physical access to the machine.

Example2. You can restore software password if you have "administrator" type access to the OS. Example: http://smallbusiness.chron.com/reset-mailbox-password-exchange-server-57287.html 

So, why in the industry integrators create "backup accounts" ( I assume using the same password for every customer) or save passwords in shared text files?

Are you sure, your software does not allow to restore admin password having OS admin password? 

I'm one of VMS manufactures:-) We allow to restore admin password if(and only if) you have admin access to the machine OS. Btw, if you have it, you practically can do anything anyway... Are we doing it wrong?

UM
Undisclosed Manufacturer #2
Sep 18, 2017

I agree with you. If you have root access to the machine, you can do everything.

But in many cases (e.g. Embedded Linux based NVR/DVR), you have no access to the system shell (given that the manufacturer thought about IT-Security), in this case you need backup accounts or a good password storage to support your customers on the phone.

UM
Undisclosed Manufacturer #3
Sep 18, 2017

I would understand if those answers are mostly for NRV/DVR.