Fortune 500 Company Bars Dahua and Hikvision

Author: IPVM Team, Published on Aug 30, 2017

A Fortune 500 company has barred Dahua and Hikvision cameras from a large RFP due to cyber security concerns, IPVM has confirmed with the company.

In this note, we examine the reasons, Dahua and Hikvision's cyber security issues, and why this is a growing trend for large end users.

The RFP Specification

The RFP explicitly prohibits Dahua and Hikvision under their camera section:

OEMs (i.e. licensed by) are also barred (related, see: Dahua OEM Directory, Hikvision OEM Directory).

Customer - Republic Services

The RFP is from Republic Services, who is #299 on the 2017 Forbes 500 list with $9+ billion revenue, 30,000+ employees and "340 collection operations, 201 transfer stations, 193 active landfills, 67 recycling centers."

Confirmation Cybersecurity

Get Video Surveillance News In Your Inbox
Get Video Surveillance News In Your Inbox

A Republic Services representative cited ongoing cyber security concerns for those two companies as reasons for them being barred from the RFP, in response to IPVM's inquiry.

Dahua and Hikvision Poor Track Record

Both Dahua and Hikvision have a poor cybersecurity track record, with Dahua's backdoor gaining a 9.8 out of 10.0 score from DHS ICS-CERT and Hikvision's backdoor gaining a 10.0 out of 10.0 score from DHS ICS-CERT. Both DHS advisories were issued in May 2017 and are therefore quite recent. That is not all. Dahua's security vulnerabilities were a key factor in the large-scale Mira botnet attacks of Fall 2016. And Hikvision continues to have new vulnerabilities discovered regularly.

Moreover, both companies struggle to responsibly, pro-actively and appropriately communicate the risks involved. For example, Dahua claimed to be a 'victim' of Mirai, has never released a full list of products impacted by their backdoor and failed to properly address another vulnerability in July 2017. Likewise, Hikvision has repeatedly shown they will hide known vulnerabilities until and unless they face bad press.

Poll / Vote

Expanding To The Enterprise

In the West, Dahua and Hikvision started their expansion targeting the lower end of the market, where lower camera counts and less sophisticated software was acceptable so long as they could offer low enough prices and sufficient local sales support. And, at that part of the market, few buyers are very concerned about cyber security vulnerabilities.

However, both companies have ambitions to break into the lucrative, large-scale enterprise market. However, these buyers are much more concerned about cyber security across the board, due to increasing number of organizations breached or hacked (e.g., Sony, Target, US government entities like OPM). Given these buyers much greater resources and concerns about cyber security, they are far less likely to take chances on any products (video surveillance) or otherwise that have a poor cyber security track record.

Chinese Decision Making Limits Enterprise Success

Western enterprise customers prefer dealing directly with corporate decision makers from their suppliers to ensure that problems or questions are quickly and clearly addressed.

This is unfortunately not feasible with Dahua and Hikvision. Both companies product decisions are made in China by Chinese executives whose English is generally limited. We have seen that while Western leaders of Dahua and Hikvision often try to help, they are constrained by geographic, cultural and language barriers. Answers to direct questions about security, or other specifics not listed on data sheets, typically have to come from or be approved by their respective Chinese headquarters.

Dahua and Hikvision's lack of strong cyber security controls, and inability of Western teams to directly solve these problems adds to the risks that Western enterprise buyers face.

Increasing Problem for Dahua and Hikvision

Cyber security is clearly an increasing problem for Dahua and Hikvision. Both companies are fundamentally fast moving, mass market, hardware focused, low price models. This fits poorly with the more careful and thorough software development expertise and open communication processes needed to be strong at cyber security. And this is a concern even without the role of the Chinese government and their control of Hikvision. Combining those elements, we expect large corporations and Western government institutions to become even more concerned about Dahua and Hikvision especially as understanding of these company's risks increases.

1 report cite this report:

Hikvision Removed From US Army Base, Congressional Hearing Called on Jan 12, 2018
Hikvision has been removed from a US Army Base and a US congressional committee is planning a hearing on cybersecurity risks and specifically,...
Comments (140) : PRO Members only. Login. or Join.

Related Reports

No GDPR Penalties For UK Swann 'Spying Hack' on Nov 20, 2018
The UK’s data protection agency has closed its investigation into Infinova-owned Swann Security UK, the ICO confirmed to IPVM, deciding to take “no...
Winter 2019 IP Networking Course on Nov 05, 2018
This is the only networking course designed specifically for video surveillance professionals.  Lots of network training exists but none of it...
HID: Stop Selling Cracked 125 kHz Credentials on Nov 05, 2018
HID should stop selling cracked 125 kHz access control credentials, that have been long cracked and can easily be copied by cheap cloners sold on...
"New Zealand Govt Uses Chinese Cameras Banned In US", Considers Security Audit on Oct 12, 2018
Newsroom NZ has issued a report: "NZ Govt uses Chinese cameras banned in US": This comes after the US federal government banned purchases of...
China Hacks Video Servers Causing Uproar on Oct 05, 2018
An incident causing an international uproar is hitting home in the video surveillance industry as a Bloomberg report, "The Big Hack: How China...
Genetec Takes Aim At 'Untrustworthy' 'Foreign Government-Owned Vendors' on Sep 24, 2018
Genetec is taking aim at 'untrustworthy' 'foreign government-owned vendors'. This is not a new theme for Genetec as nearly 2 years ago, Genetec...
Hikvision FIPS 140-2 Cybersecurity Certification Examined on Aug 27, 2018
A week after the US government passed a law banning Hikvision, Hikvision announced it had obtained a FIPS 140-2 certification from the US...
Sony Gen 5 IP Cameras Critical Vulnerabilities on Jul 26, 2018
Cybersecurity vulnerabilities remain prevalent in video surveillance devices. Now Talos researchers have discovered multiple vulnerabilities in...
Hikvision Corrects False Cybersecurity Announcement on Jun 18, 2018
Hikvision has corrected a false cybersecurity announcement that claimed a British government-sponsored program endorsed the cybersecurity of...
The Dumb Ones: PSA's Bozeman On Cybersecurity on Jun 15, 2018
The smart ones are the hundred people who flew to Denver and spent $500+ on a 1.5-day conference featuring (now US government banned) Dahua as a...

Most Recent Industry Reports

Imperial Capital Security Investor Conference 2018 Review - ADT, Resideo, Alarm.com, Arlo, Eagle Eye, ACRE, More on Dec 14, 2018
Imperial Capital Security Investor Conference is an event matching industry executives with financiers that frequently leads to future funding...
Cisco Meraki New Cameras and AI Analytics on Dec 14, 2018
Meraki has released their second generation of video surveillance with 3 new cameras, AI-based video analytics, and 2 cloud-based storage...
Foolish Strategy: OEMing Facial Recognition on Dec 13, 2018
Almost as 'hot' as face recognition marketing right now is OEMing facial recognition. Last year, they were a who's who of company's with...
DVR Examiner - Video Recovery from Recorder Hard Drives on Dec 13, 2018
Bypassing passwords and long download times on-site, DVR Examiner collects and organizes video evidence directly from a hard drive extracted from...
2019 Access Control Book Released on Dec 12, 2018
This is the best, most comprehensive access control book in the world, based on our unprecedented research and testing has been significantly...
Huawei Hisilicon Quietly Powering Tens of Millions of Western IoT Devices on Dec 12, 2018
Huawei Hisilicon chips are powering, at least, tens of millions of Western IoT devices, such as IP cameras and surveillance recorders, a fact that...
FLIR Launches Body Cameras Unified With VMS (TruWitness) on Dec 11, 2018
While FLIR is best known for their thermal cameras, now they have expanded into body cameras, launching TruWITNESS, a public safety focused body...
Startup Sunflower Labs' Autonomous Drone Security System on Dec 11, 2018
Startup Sunflower Labs is claiming a unique design on a home security system, combining autonomous drones and 'Sunflower' sensors. Imagine an...
The 2019 Video Surveillance Industry Guide on Dec 10, 2018
The 300 page, 2019 Video Surveillance Industry Guide, covers the key events and the future of the video surveillance market, is now available,...
Multi-Factor Access Control Authentication Guide on Dec 10, 2018
Can a stranger use your credentials? One of the oldest problems facing access control is making credentials as easy to use as keys, but restricting...

The world's leading video surveillance information source, IPVM provides the best reporting, testing and training for 10,000+ members globally. Dedicated to independent and objective information, we uniquely refuse any and all advertisements, sponsorship and consulting from manufacturers.

About | FAQ | Contact