Fortune 500 Company Bars Dahua and Hikvision

Author: IPVM Team, Published on Aug 30, 2017

A Fortune 500 company has barred Dahua and Hikvision cameras from a large RFP due to cyber security concerns, IPVM has confirmed with the company.

In this note, we examine the reasons, Dahua and Hikvision's cyber security issues, and why this is a growing trend for large end users.

The RFP Specification

The RFP explicitly prohibits Dahua and Hikvision under their camera section:

OEMs (i.e. licensed by) are also barred (related, see: Dahua OEM Directory, Hikvision OEM Directory).

Customer - Republic Services

The RFP is from Republic Services, who is #299 on the 2017 Forbes 500 list with $9+ billion revenue, 30,000+ employees and "340 collection operations, 201 transfer stations, 193 active landfills, 67 recycling centers."

Confirmation Cybersecurity

Get Video Surveillance News In Your Inbox
Get Video Surveillance News In Your Inbox

A Republic Services representative cited ongoing cyber security concerns for those two companies as reasons for them being barred from the RFP, in response to IPVM's inquiry.

Dahua and Hikvision Poor Track Record

Both Dahua and Hikvision have a poor cybersecurity track record, with Dahua's backdoor gaining a 9.8 out of 10.0 score from DHS ICS-CERT and Hikvision's backdoor gaining a 10.0 out of 10.0 score from DHS ICS-CERT. Both DHS advisories were issued in May 2017 and are therefore quite recent. That is not all. Dahua's security vulnerabilities were a key factor in the large-scale Mira botnet attacks of Fall 2016. And Hikvision continues to have new vulnerabilities discovered regularly.

Moreover, both companies struggle to responsibly, pro-actively and appropriately communicate the risks involved. For example, Dahua claimed to be a 'victim' of Mirai, has never released a full list of products impacted by their backdoor and failed to properly address another vulnerability in July 2017. Likewise, Hikvision has repeatedly shown they will hide known vulnerabilities until and unless they face bad press.

Poll / Vote

Expanding To The Enterprise

In the West, Dahua and Hikvision started their expansion targeting the lower end of the market, where lower camera counts and less sophisticated software was acceptable so long as they could offer low enough prices and sufficient local sales support. And, at that part of the market, few buyers are very concerned about cyber security vulnerabilities.

However, both companies have ambitions to break into the lucrative, large-scale enterprise market. However, these buyers are much more concerned about cyber security across the board, due to increasing number of organizations breached or hacked (e.g., Sony, Target, US government entities like OPM). Given these buyers much greater resources and concerns about cyber security, they are far less likely to take chances on any products (video surveillance) or otherwise that have a poor cyber security track record.

Chinese Decision Making Limits Enterprise Success

Western enterprise customers prefer dealing directly with corporate decision makers from their suppliers to ensure that problems or questions are quickly and clearly addressed.

This is unfortunately not feasible with Dahua and Hikvision. Both companies product decisions are made in China by Chinese executives whose English is generally limited. We have seen that while Western leaders of Dahua and Hikvision often try to help, they are constrained by geographic, cultural and language barriers. Answers to direct questions about security, or other specifics not listed on data sheets, typically have to come from or be approved by their respective Chinese headquarters.

Dahua and Hikvision's lack of strong cyber security controls, and inability of Western teams to directly solve these problems adds to the risks that Western enterprise buyers face.

Increasing Problem for Dahua and Hikvision

Cyber security is clearly an increasing problem for Dahua and Hikvision. Both companies are fundamentally fast moving, mass market, hardware focused, low price models. This fits poorly with the more careful and thorough software development expertise and open communication processes needed to be strong at cyber security. And this is a concern even without the role of the Chinese government and their control of Hikvision. Combining those elements, we expect large corporations and Western government institutions to become even more concerned about Dahua and Hikvision especially as understanding of these company's risks increases.

1 report cite this report:

Hikvision Removed From US Army Base, Congressional Hearing Called on Jan 12, 2018
Hikvision has been removed from a US Army Base and a US congressional committee is planning a hearing on cybersecurity risks and specifically,...
Comments (140) : PRO Members only. Login. or Join.

Related Reports

Sony Gen 5 IP Cameras Critical Vulnerabilities on Jul 26, 2018
Cybersecurity vulnerabilities remain prevalent in video surveillance devices. Now Talos researchers have discovered multiple vulnerabilities in...
July 2018 IP Networking Course on Jul 12, 2018
Registration is closed. This is the only networking course designed specifically for video surveillance professionals.  Lots of network training...
Hikvision Corrects False Cybersecurity Announcement on Jun 18, 2018
Hikvision has corrected a false cybersecurity announcement that claimed a British government-sponsored program endorsed the cybersecurity of...
The Dumb Ones: PSA's Bozeman On Cybersecurity on Jun 15, 2018
The smart ones are the hundred people who flew to Denver and spent $500+ on a 1.5-day conference featuring Dahua as a 'cyber responsible partner',...
Debating Relevance of China Hacking US Navy Plans on Jun 11, 2018
"Chinese government hackers have compromised the computers of a Navy contractor, stealing massive amounts of highly sensitive data related to...
Remove Dahua and Hikvision Gov Installs Required By US House Bill Ban on Jun 06, 2018
The final released US House Bill HR 5515 verifies that it not only prohibits the purchasing of Dahua and Hikvision products, it requires removing...
Dahua's Terrible Cybersecurity, Buys Credibility From PSA And SIA on Jun 04, 2018
Dahua has a terrible cybersecurity track record. But American organizations, like the Security Industry Association (SIA) and the PSA Security...
Canon Responds To IP Camera Hacks on May 30, 2018
Canon cameras made international news earlier this month, with reports of them being hacked in Japan (e.g., Hackers disable scores of Canon-made...
Corruption Alleged Against Hikvision Procurement In India on May 28, 2018
Over the past month, allegations of corruption and national security risk have made the news in India over the planned purchase of 150,000...
Cybersecurity for IP Video Surveillance Guide on May 18, 2018
Keeping surveillance networks secure can be a daunting task, but there are several methods that can greatly reduce risk, especially when used in...

Most Recent Industry Reports

2Gig Gun Lock / Motion Detector Tested on Aug 17, 2018
Safer guns for families and an opportunity for security dealers to sell more services? That is the aim of Nortek's 2GIG 'Gun Motion Detector'...
Video Analytics Integration Guide on Aug 16, 2018
Video analytics is hot again (at least conceptually) but integrating video analytics with VMSes can be challenging. This is especially significant...
Hikvision IP Camera Critical Vulnerability 2018 Disclosed on Aug 16, 2018
The same day that the US government passed a prohibition on Hikvision cameras, Hikvision disclosed a critical vulnerability for its IP...
ISS VMS / Video Analytics Company Profile on Aug 16, 2018
Who is ISS? In the past few months, they had one of the craziest ISC West promo items in years. Then, they hired industry veteran and ex-Dahua...
Chinese OEM Avycon Gets ADI Push on Aug 15, 2018
Who is Avycon? An American company? A Korean company? A couple of guys relabelling Chinese products? The latter is the best explanation. While...
Backboxes for Video Surveillance Tutorial on Aug 15, 2018
Backboxes are a necessity in surveillance, whether for managing cable whips, recessing cameras, adding wireless radios. But it can be confusing to...
Genetec Stratocast / Comcast 'Motion Insights' Examined on Aug 15, 2018
Comcast recently announced "SmartOffice Motion Insights", an extension to their Genetec OEMed cloud video service (covered by IPVM here). This...
SimpliSafe Violating California, Florida, and Texas Licensing Laws on Aug 14, 2018
IPVM has verified that DIY security system provider SimpliSafe, founded in 2006 and acquired in June of 2018 at a billion dollar valuation, is...
Ban of Dahua and Hikvision Is Now US Gov Law on Aug 13, 2018
The US President has signed the 2019 NDAA into law, banning the use of Dahua and Hikvision (and their OEMs) for the US government, for US...
Cut Milestone Licensing Costs 80% By Using Hikvision and Dahua NVRs (Tested) on Aug 13, 2018
Enterprise VMS licensing can be quite expensive, with $200 or more per channel common, meaning a 100 camera system can cost $20,000 in VMS...

The world's leading video surveillance information source, IPVM provides the best reporting, testing and training for 10,000+ members globally. Dedicated to independent and objective information, we uniquely refuse any and all advertisements, sponsorship and consulting from manufacturers.

About | FAQ | Contact