Bosch Divar NVR Tested vs Dahua

By Ethan Ace, Published Oct 05, 2017, 11:19am EDT

Bosch has a partnership with Dahua.

But what type of partnership is it? How much is Bosch's own vs taken from embattled mega-OEM Dahua?

We bought and tested a 16 channel Bosch DIVAR network 2000 to see how it compares to Dahua's own models, examining:

  • Software similarities and differences
  • Physical construction
  • Internal components
  • Hard disk mounting
  • Firmware features
  • Web interface similarities
  • Bosch/Dahua software discovery and operation
  • Cyber security issues

See our full findings inside.

Still *****, *** **** **********

*** ***** ***** ******* series ** * ***** OEM *** ****** **** similarities ** ************, ********, and ************ **** *****, with *** **** **** software ********. ***** *** dislike *****'* ********/************ *** unlikely ** ** ****** by *****'* ******* *** additions. ************, ****** ***** performs ******** ***** ******** testing, **** ******** ** still *****, *** *** contain *************** *** *** discovered.

*******, ***** ** *** testing, *** ***** ***** network ****** ****** **** *** advantages ******** ** ***** models **** *** ***** on:

  • **** ****** ************:***** *** **** ******* physical ******* ** ******* thermal ********** *** *******, hard ***** *********, ****/****** resistance, *** ****. ***** improvements *** ****** ** increase *** *** **** drive **** ******** ** Dahua ******.
  • ******** ************:***** **** *** ****** authentication *** ******* ******** creation, *** ***** ** all ******* *** **** Dahua ******. ************, ***** ****** their ******** ** ************* penetration ****** ** * third *****.

******* ** ***** ************, though **** *** **** and **** **** ***** NVRs, ***** *** **** ***** advances ***** *** **** premium **** ******* ***** models.

*******, *** ***** ***** third ***** *******, ***** NVR ******* ****** ** verified, ** ***** ********** cameras *** ***** ******* S ****, ***** ***** includes **** ****** ******* for ****** ******.

Not ******* ** ****

***** *** **** *********** changes ** *** ***** network ****** ***** *** it ***** **** ******* Dahua *** *** ******, though **** ** *** often *** ****. **** manufacturers ***** ** **** "custom ********" *** ** more **** ****** * relabeled ***** ** ********* model, but *** ******* *** historically ***** *********:

*******

** * *** ****/** channel ***** ***** ******* 2000 (***-****-******) ***** *** about $*** *** ******, about $*** **** **** a ******* ********** ***** recorder (******), ~$*** ******.

***-*** ****** *** **** available, **** *** ** channel ***** ******* *** about $*** ****** (***-****-******). 

Front ***** **********

*** ***** ****** ** the ***** *** ***** recorders *** **** *********, with ***** ********* ***** panel ******** *** ***** and *********, ** **** as ***** *** ** optional *** ***** *** exports. *** ***** *** includes **** ****** ****** and * *** **** for ***** ** ***** drive.

Similarities ** *****

*** ***** *** ****** several ************ *** *** compatible **** ******** ***** software ************, *********:

  • *** ********* ************
  • ********* *** ***** **********
  • ********* *** ***** ********

Web ********** *******/****** ********* *******

*** ***** *** ***** recorder *** ********** *** very *******, ******* **** UI ******** (**** ** buttons, *****, ***.) *** layout, ***** *****.

**** **** ***** **** been ***** ** ******* in *** ***** ********. For *******, *** ***** connectivity ***** ** ***** models ** ******** ** Bosch **** ** *** ***** series, *** **** ***** have **** ***** ** a "*******" ****, **** typical ** ***** *******, etc.

Bosch ********* *** ***** **********

*** ***** ***** *** ********** via *****'* ********** ******** along **** ***** ***** product, ***** *****. 

********** *** **** ** used *** ***** ************* and ******** ********:

Bosch *** ********* *** ***** ***** ***

************, *** ******** *** viewable *** *****'* ****** software, ********. ****, ********, search, *** ***** ******* all ******** ******** ***** this ****** **** *** Bosch ***.

Bosch *** ****** *******

*** ***** *** ******** ONVIF ******* * *** camera ************ ****, ***** Dahua ***** **** ****** camera ******* *** ***** brands, **** ** ****, Samsung/Hanwha, *********, ***. ** our ***** ** *** no ****** **********/********* ***** cameras, *** ****** ********* was *** ********* ** all ******.

Firmware ***********

** ******** ** ****** rearranging *** ******** **** options ** *** *** interface, ***** *** ***** some ******** *** ***** in *****'* ******.

  • ********* ******** *******:*** ***** *** ******** a ******* ***** ************* detects *** ********** ******** from ***** ** *** recorder ******* *********. * second "*****" **** ** firmware ** ****** **** flash **** *** ******** is *******, *** ****** held ***** ********** ** detected. **** **** ** could *** **** **** feature, ** ** ** automatic *** ******** *** not ******* ****** *** time ** *** *******.
  • ***** *** ******* ******** updates **** ***: ***** *** ***** *** firmware ******* *** ******* them ***** * ********** in *** ******** *** interface, * ******* *** found ** ***** ****** (which ******* ***** ** separate ******** *** ****** the ****** ******** ****).

Cyber ******** ***********

***** ****** *** ******* key ******** *********** ** Bosch **** **. ***** models:

  • *********** ***** ******** *******: ***** **** ********* *** their ********* *** ************* tested ** * ***** party, ***** ** ***** released ** *****, ** addition ** *** ***** Dahua *** ******* **********.
  • ** ********* ********:***** ********* ** *** have ****** ** ****** hardcoded ******** ******* ** many ****/******* ***** *******. An ******* ***** "*******" is *******, *** ** not ** ****** ****, but ******* ******* ******** of **** ***** ********* actions *** ** ***** (PTZ *******, ****** *******, etc.) **** ** **** is ****** **** *** local *****/******* *********.
  • ******** *** *******:***** **** ****** **** not ********** ** *** backdoor ********* ***** *******, detailed ** ***** ******** ********* ************ **** *******, ********* ***** ***** OEMs**** ** ****.
  • ****** **************:***** **** *** *********** Digest ************** ** ********, which ** ***** ** new ***** ******** *********, but ***** ****** *** vulnerable ***** **************, ***** may ** ****** ******* using*********.

Bosch ******** ************

***** *** **** ******* notable ******** ************ ** the DIVAR ******:

  • ******** **** ***** ******** for ****** *********
  • ******** ******* **********
  • ******** ************

Improved **** ***** ********

**** ****** *** ******* in *** ***** *** via * ***** **** which ****** ** *** chassis ***** ****** **** for ********* *** ********** isolation. ** ********, ***** recorders ***** *** ***** directly ** *** ****** of *** ******* ***** keyhole ***** (******* **** the *********). **** ****** is ****** ** ********** to **** **** ****, as ******, *****, *** vibration *** **** ****** to ****** *** *****, as **** *** ******** by *** ****** ****.

Improved ******* **********

***** *** **** ******* changes ** ******* ******* management ** ***** ****:

****** ****/****** *******

******** ** ***** *********, similar ***** ****** *** larger, ****** ****** ****:

************, *** *** ****'* perforations *** ******** *** more ******** ******* **** high *********** **********, ***** Dahua ********* *** ***** perforated ** **** *****, which ***** ** **** directional ******* ****** *** areas.

****** **** *****

************, *** ***** *** uses * ********** ****** heat **** **** *** similar ***** *****, **** below:

Improved ************

***** **** *** * strengthened ******* ******, **** a ****** ***** ** metal ** *** ****** of *** ****, ******* isolating ******** ********** **** dust *** *********. ** contrast, ***** ******* *** numerous ******** ***** *** other ************ ** *** bottom, *** **** ******, standoffs, ****, *** ****, shown *****. **** ****, these ************ *** ****** to ********* **** **** and ****** **** *** side ***** ** *** recorder.

Bosch *** ******* ****

*******, **** **** *** NVR *** *** *** OUI**:**:**, ***** ** ********** to ***** ******** ******* (shown *****). **** ** fairly ******* ** ****** OEMs, ***** ***** **** their *** *** ******** to ******* *** ************ to ***** ********, ** *** done ****.

Comments (19)

So in summary, the Bosch Divar 2000 is to Dahua what the Cadillac Catera was to the Chevy Malibu... 

Wrap it however you want, it’s still the same under the hood.

Poor example. The catera was not a tarted up malibu. Perhaps youre thinking of the cimarron?

Cimarron was my first thought.

Another crap-tastic example, although the Cimarron was based on the Cavalier platform.

The Divar 2000 is a Cimarron.

I'm not sure what article you read, but I see may very specific non cosmetic differences referenced in this article including: Looks to me like Bosch looked at the Dahua and said well you can put the components together but you need to change a bunch of stuff before Bosch was willing to put their name on it.

More robust construction: Bosch has made several physical changes to improve thermal management and airflow, hard drive isolation, dust/debris resistance, and more. These improvements are likely to increase NVR and hard drive life compared to Dahua models. Several side by side photos showing those differences.

Security improvements: Bosch NVRs use Digest authentication and require password creation, not found on all current and past Dahua models. Additionally, Bosch claims their firmware is independently penetration tested by a third party.

Improved Construction Bosch NVRs use a strengthened chassis design, with a double layer of metal on the bottom of the unit, further isolating interior components from dust and vibration. By contrast, Dahua chassis has numerous mounting holes and other perforations in the bottom, for hard drives, standoffs, PCBs, and more, shown below. Over time, these penetrations are likely to introduce more dust and debris than the side vents of the recorder.

Bosch has made several notable physical improvements to the DIVAR models:

  • Improved hard drive mounting for better isolation
  • Improved thermal management
  • Sturdier construction

Cyber Security Differences

Bosch points out several key security differences in Bosch NVRs vs. Dahua models:

  • Independent Cyber Security Testing:  Bosch says firmwares for their recorders are independently tested by a third party, prior to being released to users, in addition to any tests Dahua may perform themselves.
  • No hardcoded accounts: Bosch recorders do not have 888888 or 666666 hardcoded accounts present in many past/current Dahua devices. An account named "default" is present, but is not an actual user, but instead defines behavior of what local interface actions may be taken (PTZ control, layout changes, etc.) when no user is logged into the local mouse/monitor interface.
  • Backdoor not present: Bosch NVRs tested were not vulnerable to the backdoor impacting Dahua devices, detailed in Dahua Backdoor Uncovered and impacting many devices, including other Dahua OEMs such as FLIR.
  • Digest authentication: Bosch also has implemented Digest authentication as standard, which is found in new Dahua recorder firmwares, but older models use vulnerable basic authentication, which may be easily decoded using Wireshark.

 

Thats pretty cool. Wonder how much it costs bosch to add all the additional hardware and software features. Its like they took everything I dont like about Dahua and fixed it.

Bosch has some experience here...

We have started using these appliances and they have worked great so far. For motion recording on Axis cameras you have to set them up in the camera for that to work on most models but not all. Also this works with their BVMS video client as well to have a better interface for the recorder. I believe it is free up to 5 recorders.

Maybe a cheap German product, but they couldn't keep their German mitts off it to make it at least a little better.

Are there any other OEMs besides Bosch that do more than just cosmetic changes?  Bosch appears to have taken the extra step of remedying defects in the product as well as other items under the hood that would go unappreciated if not for this article.

Are there any other OEMs besides Bosch that do more than just cosmetic changes?

We'd have to test to say so definitively. It wouldn't be fair to speculate on specific companies without formally testing.

As a general rule, Dahua OEMs are overwhelming relabelling. Lots claim to be doing more, most are probably exaggerating but which ones are legitimately better, we do not know until we specifically test.

Where the main boards the same on the Dahua and Bosch or was it just a general comparison? 

Typically Dahua say that Dahua branded units will always have the newest features first and that OEM's don't get them for months later, while true in certain cases if you really want something you can get whatever you need from a software prospective. 

 

Thanks.

Great article, keep it up.

 

What about noise levels? Bosch fan looks faster and might be noisier than Dahua’s.

Both units doesn’t seem rack-mountable, so fan noise might be disturbing when installed in a living/working area.

Fans used by Dahua for their dvr’s are very noisy and traditionally had quality issues over the years. They don’t seem to implement any acoustic engineering into their designs.

...Bosch NVR supports ONVIF Profile S for camera connectivity only, while Dahua lists some direct camera drivers for major brands, such as Axis, Samsung/Hanwha, Panasonic...

So no direct driver support for Bosch cameras?  

Since one would expect the direct drivers for Axis/Samsung etc, could have been enabled, had Bosch desired it, why do you suppose they didn't?

This Divar IP product line from Bosch has a great price/value ratio, but unfortunately they have nothing to offer for systems between 32-128 channels in this product line, from 32 cameras you have to go for their pricey iSCSI servers.

There should be a DIVAR NVR for 64 and 128 channels but at least a 64 channel NVR.

 

#8, good feedback. Bosch response:

It is correct that we do not have a 64 channel unit in the DIVAR 5000/3000 series. This decision to restrict up to 32 channels was made purely to ensure full performance i.e., simultaneous live viewing, playback, recording and network streaming. To allow 64 channels, we will have to go to different hardware platform which would drive the price up for this market segment. As an alternative customers can use multiple 32Ch. NVRs and then combine them in VMS like BVMS.

As an alternative customers can use multiple 32Ch. NVRs and then combine them in VMS like BVMS.

That's what I was thinking, and would have the benefit of minimizing your single points of failure. Eg. 1 out of 3 NVR's fails means only 1/3 of the cameras go down.

Hmm. I wouldn't really say Digest authentication is significantly more secure than Basic authentication.

If an attacker holds a privileged position on the network and are able to intercept and tamper wirh your traffic, and you are either using HTTP or HTTPS with self-signed certificates, you can just downgrade the authentication to Basic and see the password.

If they are using HTTP or HTTPS with self-signed certificates, and all they can do is sniff your traffic, then most passwords can be found by brute-force using Digest.

Read this IPVM report for free.

This article is part of IPVM's 6,653 reports, 896 tests and is only available to members. To get a one-time preview of our work, enter your work email to access the full article.

Already a member? Login here | Join now
Loading Related Reports