Fortune 500 Company Bars Dahua and Hikvision

By IPVM Team, Published on Aug 30, 2017

A Fortune 500 company has barred Dahua and Hikvision cameras from a large RFP due to cyber security concerns, IPVM has confirmed with the company.

In this note, we examine the reasons, Dahua and Hikvision's cyber security issues, and why this is a growing trend for large end users.

The RFP Specification

The RFP explicitly prohibits Dahua and Hikvision under their camera section:

OEMs (i.e. licensed by) are also barred (related, see: Dahua OEM Directory, Hikvision OEM Directory).

Customer - Republic Services

The RFP is from Republic Services, who is #299 on the 2017 Forbes 500 list with $9+ billion revenue, 30,000+ employees and "340 collection operations, 201 transfer stations, 193 active landfills, 67 recycling centers."

Confirmation Cybersecurity

Get Notified of Video Surveillance Breaking News
Get Notified of Video Surveillance Breaking News

A Republic Services representative cited ongoing cyber security concerns for those two companies as reasons for them being barred from the RFP, in response to IPVM's inquiry.

Dahua and Hikvision Poor Track Record

Both Dahua and Hikvision have a poor cybersecurity track record, with Dahua's backdoor gaining a 9.8 out of 10.0 score from DHS ICS-CERT and Hikvision's backdoor gaining a 10.0 out of 10.0 score from DHS ICS-CERT. Both DHS advisories were issued in May 2017 and are therefore quite recent. That is not all. Dahua's security vulnerabilities were a key factor in the large-scale Mira botnet attacks of Fall 2016. And Hikvision continues to have new vulnerabilities discovered regularly.

Moreover, both companies struggle to responsibly, pro-actively and appropriately communicate the risks involved. For example, Dahua claimed to be a 'victim' of Mirai, has never released a full list of products impacted by their backdoor and failed to properly address another vulnerability in July 2017. Likewise, Hikvision has repeatedly shown they will hide known vulnerabilities until and unless they face bad press.

Poll / Vote

Expanding To The Enterprise

In the West, Dahua and Hikvision started their expansion targeting the lower end of the market, where lower camera counts and less sophisticated software was acceptable so long as they could offer low enough prices and sufficient local sales support. And, at that part of the market, few buyers are very concerned about cyber security vulnerabilities.

However, both companies have ambitions to break into the lucrative, large-scale enterprise market. However, these buyers are much more concerned about cyber security across the board, due to increasing number of organizations breached or hacked (e.g., Sony, Target, US government entities like OPM). Given these buyers much greater resources and concerns about cyber security, they are far less likely to take chances on any products (video surveillance) or otherwise that have a poor cyber security track record.

Chinese Decision Making Limits Enterprise Success

Western enterprise customers prefer dealing directly with corporate decision makers from their suppliers to ensure that problems or questions are quickly and clearly addressed.

This is unfortunately not feasible with Dahua and Hikvision. Both companies product decisions are made in China by Chinese executives whose English is generally limited. We have seen that while Western leaders of Dahua and Hikvision often try to help, they are constrained by geographic, cultural and language barriers. Answers to direct questions about security, or other specifics not listed on data sheets, typically have to come from or be approved by their respective Chinese headquarters.

Dahua and Hikvision's lack of strong cyber security controls, and inability of Western teams to directly solve these problems adds to the risks that Western enterprise buyers face.

Increasing Problem for Dahua and Hikvision

Cyber security is clearly an increasing problem for Dahua and Hikvision. Both companies are fundamentally fast moving, mass market, hardware focused, low price models. This fits poorly with the more careful and thorough software development expertise and open communication processes needed to be strong at cyber security. And this is a concern even without the role of the Chinese government and their control of Hikvision. Combining those elements, we expect large corporations and Western government institutions to become even more concerned about Dahua and Hikvision especially as understanding of these company's risks increases.

1 report cite this report:

Hikvision Removed From US Army Base, Congressional Hearing Called on Jan 12, 2018
Hikvision has been removed from a US Army Base and a US congressional...
Comments (140) : Members only. Login. or Join.

Related Reports

NDAA Compliant Video Surveillance Whitelist on Aug 10, 2020
This report aggregates video surveillance products that manufacturers have...
Salesforce Drops Dahua and Hikvision on Aug 12, 2020
Salesforce has dropped Dahua and Hikvision as customers, forcing the two mega...
SIA: "Refrain From Working With Companies And/or Products That Are Implicated In Human Rights Abuses" Like Dahua and Hikvision on Aug 17, 2020
The US (Security Industry Association) SIA has taken a stand, declaring that...
Huawei HiSilicon Shortage Impacts Surveillance Manufacturers on Aug 14, 2020
Huawei acknowledged problems and challenges for its HiSilicon chip business,...
Hanwha and Hikvision Selling H.265 Without HEVC Licensing on Aug 19, 2020
IPVM has confirmed that Hanwha and Hikvision do not have H.265 licenses from...
JCI / Tyco Drops Dahua on Sep 03, 2020
Johnson Controls (JCI) / Tyco Security has completely dropped Dahua OEMs from...
UK Firm Markets False Fever Screening, Hikvision Disavows on Jun 30, 2020
A UK security firm falsely claimed its Hikvision-based thermal solution could...
17 Alarm Company Lawsuits Against Competitors Faking Them on Oct 06, 2020
Alarm companies suing rivals for faking them are commonplace, an IPVM...
Huawei HiSilicon Production Shut Down on Sep 17, 2020
Huawei HiSilicon chips are no longer being manufactured or supplied to...
Panasonic i-PRO Hid Huawei, Does Damage Control on Aug 21, 2020
Panasonic i-PRO hid their usage of Huawei from the public, continues to...
2020 Mid Year Video Surveillance Industry Guide on Jul 27, 2020
The first half of 2020 has been shocking, for the world generally, and for...
Faulty Hikvision Fever Cam Setup at Mexico City Basilica and Cathedral on Oct 14, 2020
Donated Hikvision fever cameras (claiming screening of 1,800 people/min. with...
Fever Cameras Are Medical Devices, Per The FDA, Dahua, Feevr, Hikvision, InVid Contrary Claims Are False on May 28, 2020
Fever cameras are medical devices, despite what euphemisms various sellers...
Hikvision Hides Xinjiang R&D Activities on Apr 22, 2020
Hikvision has systematically deleted evidence showing their R&D base and...
Hikvision Illicitly Uses Back To The Future In Marketing on Jul 03, 2020
NBCUniversal told IPVM that Hikvision UK's ongoing coronavirus marketing...

Recent Reports

ISC Brasil Digital Experience 2020 Report on Oct 23, 2020
ISC Brasil 2020 rebranded itself to ISC Digital Experience and, like its...
Top Video Surveillance Service Call Problems 2020 on Oct 23, 2020
3 primary and 4 secondary issues stood out as causing the most problems when...
GDPR Impact On Temperature / Fever Screening Explained on Oct 22, 2020
What impact does GDPR have on temperature screening? Do you risk a GDPR fine...
Security And Safety Things (S&ST) Tested on Oct 22, 2020
S&ST, a Bosch spinout, is spending tens of millions of dollars aiming to...
Nokia Fever Screening Claims To "Advance Fight Against COVID-19" on Oct 22, 2020
First IBM, then briefly Clorox, and now Nokia becomes the latest Fortune 500...
Deceptive Meridian Temperature Tablets Endanger Public Safety on Oct 21, 2020
IPVM's testing of and investigation into Meridian Kiosk's temperature...
Honeywell 30 Series and Vivotek NVRs Tested on Oct 21, 2020
The NDAA ban has driven many users to look for low-cost NVRs not made by...
Ubiquiti Access Control Tested on Oct 21, 2020
Ubiquiti has become one of the most widely used wireless and switch providers...
Avigilon Aggressive Trade-In Program Takes Aim At Competitors on Oct 20, 2020
Avigilon has launched one of the most aggressive trade-in programs the video...
Mexico Video Surveillance Market Overview 2020 on Oct 20, 2020
Despite being neighbors, there are key differences between the U.S. and...
Dahua Revenue Grows But Profits Down, Cause Unclear on Oct 20, 2020
While Dahua's overall revenue was up more than 12% in Q3 2020, a significant...
Illegal Hikvision Fever Screening Touted In Australia, Government Investigating, Temperature References Deleted on Oct 20, 2020
The Australian government told IPVM that they are investigating a Hikvision...
Panasonic Presents i-PRO Cameras and Video Analytics on Oct 19, 2020
Panasonic i-PRO presented its X-Series cameras and AI video analytics at the...
Augmented Reality (AR) Cameras From Hikvision and Dahua Examined on Oct 19, 2020
Hikvision, Dahua, and other China companies are marketing augmented reality...
18 TB Video Surveillance Drives (WD and Seagate) on Oct 19, 2020
Both Seagate and Western Digital recently announced 18TB hard drives...