Dahua's Terrible Cybersecurity, Buys Credibility From PSA And SIA

By: John Honovich, Published on Jun 04, 2018

Dahua has a terrible cybersecurity track record.

But American organizations, like the Security Industry Association (SIA) and the PSA Security Network, are happy to sell them credibility, declaring Dahua a 'cyber responsible partner', thanking Dahua for paying to be their 'gold sponsor':

Dahua deserves embarrassment and criticism for their actions, not thanks. These American organization's desire for money tops their claimed mission of improving cybersecurity.

Let's review Dahua's terrible record.

(1) Dahua Massive Hacks

Dahua's customers and integrators were hit with the industry's worst hack attacks in September 2017 due to Dahua's backdoor(s).

(2) Dahua Hide The Hacks

Dahua refused to give notice warning nor inform their dealers until after IPVM reported on it. Even after they did acknowledge it publicly, they buried it under the Orwellian spin "Dahua USA launches latest cybersecurity initiatives."

(3) Dahua Backdoor

Get Notified of Video Surveillance Breaking News
Get Notified of Video Surveillance Breaking News

In 2017, Dahua had a backdoor across virtually all of their products, which led to (1) and (2) above.

(4) Dahua Refused To Disclose Devices Impacted

Dahua hurt their customers by only ever releasing a short, incomplete list of devices vulnerable to the backdoor, refusing to make clear all the firmware versions and models impacted. As a point of comparison, much maligned Hikvision was able to do this, while Dahua refused.

(5) Dahua Mirai Botnet

Dahua's cybersecurity vulnerabilities also made Dahua devices a key weapon in the 2016 Mirai botnet attacks.

(6) Dahua Claimed To Be A "Victim"

Much like the 2017 hacks, Dahua refused responsibility for Mirai, arguing that they were a 'victim', rather than taking responsibility for their basic cybersecurity errors being the enabler of these attacks.

(7) Dahua Falsely Claims GDPR Certification

Not even 2 weeks ago, Dahua falsely claimed that their products were 'certified to comply with GDPR'. This is clearly impossible as no products can be certified for GDPR. Much like they are paying PSA and SIA for credibility, Dahua found another Western organization to validate them erroneously.

(8) US House Bill Bans Dahua

Not even 2 weeks ago, the US House passed a bill banning US government usage of Dahua among other Chinese companies found to be 'risky technology'.

SIA / PSA - Dahua 'Cyber Responsible Partner'

Not only does Dahua get SIA and PSA to thank them, these organizations are endorsing Dahua as a 'cyber responsible partner' featuring a Dahua salesperson at their cybersecurity forum [link no longer available]:

'Industry Leader'

Indeed, PSA President Bill Bozeman referred to Dahua as an 'industry leader' who, despite Dahua's terrible track record, was allowing Dahua to speak about 'what it means to be a responsible cyber partner' in their sponsor announcement:

Ethics aside, Dahua has made a smart move, paying to get labeled as a 'Cyber Responsible Partner' by the Security Industry Association.

Hold Dahua Responsible

A critical problem in cybersecurity are manufacturers who are indifferent, incompetent and unwilling to do the right thing. Dahua has demonstrated all of the above. If we truly want better cybersecurity, we need to hold these companies responsible. We cannot be like the PSA and SIA who happily endorse and thank them for money.

4 reports cite this report:

Dahua Ban Response: NOT Chinese Government Owned on Aug 08, 2018
Dahua has responded to the US Congress passing a US government ban on Dahua and Hikvision's products. While Dahua offered the now standard...
Drops Dahua, Fenner Becomes ISS CMO on Jul 09, 2018
Hired to improve Dahua's miserable marketing just last year, Janet Fenner has quit Dahua, joining VMS manufacturer ISS as Chief Marketing Officer....
2018 Mid-Year Surveillance Industry Guide on Jun 28, 2018
2018 has been an explosive year for the video surveillance industry, with the industry becoming a global political issue, with the expansion of...
The Dumb Ones: PSA's Bozeman On Cybersecurity on Jun 15, 2018
The smart ones are the hundred people who flew to Denver and spent $500+ on a 1.5-day conference featuring (now US government banned) Dahua as a...
Comments (9) : Members only. Login. or Join.

Related Reports

The Dumb Ones: PSA's Bozeman On Cybersecurity on Jun 15, 2018
The smart ones are the hundred people who flew to Denver and spent $500+ on a 1.5-day conference featuring (now US government banned) Dahua as a...
Bubble: Dahua Doubles Market Capitalization on Nov 07, 2017
Dahua's stock is in a bubble. Those of you in the industry know how bad of a year Dahua has had - the zero-day backdoor, the massive hacking...
Bad: Dahua Villa Video Doorbell Tested on Jan 11, 2019
Doorbells are one of the hottest segments in the residential market but Dahua's Villa Video Doorbell is the worst we have tested. We bought and...
Dahua Faked Coronavirus Camera Marketing on Apr 01, 2020
Dahua has conducted a coronavirus camera global marketing campaign centered around a faked detection. Now, Dahua has expanded this to the USA,...
Dahua Hard-Coded Credentials Vulnerability on Nov 20, 2017
A newly discovered Dahua backdoor is described by the researcher discovering it as: not the result of an accidental logic error or poor...
Dahua Favorability Results 2017 on Jan 19, 2017
Dahua, the mega-Chinese surveillance manufacturer not primarily owned by the Chinese government has been trying to break out of the shadow of...
Dahua Manager: Lots of Backdoors Beyond Dahua or Hikvision on Mar 29, 2017
A Dahua technical manager has fired back at criticisms of Dahua's backdoor, posting publicly what many at Dahua have privately been saying for the...
ASIS Show 2017 Final Report on Sep 27, 2017
ASIS is in Dallas for 2017 and this is our final show report (compare to our 2016 ASIS show report). When walking in, one is greeted with Dahua's...
Dahua Co-Founder Says Human Rights Sanctions Shows Strong Dahua Technology on Oct 29, 2019
Despite Dahua doing nearly a billion dollars of projects in Xinjiang, including building and operating police stations, Dahua not only denies 'any...
Dahua ‘Duplicitous’ Says Botnet Victim on Oct 11, 2016
The victim of the record-breaking botnet, Brian Krebs, is calling Dahua duplicitous in its statements about the Mirai botnet. He says Dahua should...

Most Recent Industry Reports

Startup Duranc Presents AI VSaaS on Jul 06, 2020
Duranc presented its system at the May 2020 IPVM Startups show. A 30-minute video from Duranc including IPVM Q&A Background on the...
Low Voltage Nation Wants to "Help You Carve Out A Fulfilling Career" Interviewed on Jul 06, 2020
It is difficult to make your way in this industry as there is little formal schooling. However, one person, Blake Urmos, the Founder of Low Voltage...
The Next Hot Fever Detection Trend - $100 Wall-Mounted Units on Jul 06, 2020
The first wave of the booming fever detecting market was $10,000+ cameras, now interest for ~$2,000 tablets is high and the next big thing may be...
Cisco Meraki Unlocks IP Cameras With RTSP Tested on Jul 06, 2020
Meraki opened up its cameras to 3rd party NVRs/VMSes by offering RTSP streaming because of "the need to solve a business problem". We tested...
Verkada: "IPVM Should Never Be Your Source of News" on Jul 02, 2020
Verkada was unhappy with IPVM's recent coverage declaring that reading IPVM is 'not a good look' and that 'IPVM should never be your source of...
Vintra Presents FulcrumAI Face Recognition on Jul 02, 2020
Vintra presented its FulcrumAI face recognition and mask detection offering at the May 2020 IPVM Startups show. Inside this report: A...
Uniview Wrist Temperature Reader Tested on Jul 02, 2020
Uniview is promoting measuring wrist temperatures whereas most others are just offering forehead or inner canthus measurements. But how well does...
Dahua USA Admits Thermal Solutions "Qualify As Medical Devices" on Jul 02, 2020
Dahua USA has issued a press release admitting a controversial point in the industry but an obvious one to the US FDA, that the thermal temperature...
Access Control Online Show - July 2020 - With 40+ Manufacturers - Register Now on Jul 01, 2020
IPVM is excited to announce our July 2020 Access Control Show. With 40+ companies presenting across 4 days, this is a unique opportunity to hear...