Forgotten Password Problem Importance (Statistics)

Author: Michael Budalich, Published on Sep 15, 2017

Forgotten passwords has become a major industry topic.

For example, Hikvision has been emailing admin passwords in plain text until IPVM's reporting prompted them to stop it.

And XiongMai, famous for its role in 2016's massive Mirai botnet attacks, allows mass emailing master password lists, like so:

Dahua and Hikvision still send out passwords, even after Hikvision's previous tool was cracked.

How Big A Problem Is This?

The great lengths that these companies go clearly implies that some people are having significant problems with forgotten passwords.

But how big of a problem is it overall?

150 integrators responded to IPVM's survey question:

How significant of a problem is your customers forgetting their recorder's password? What do you typically do when it happens?

In this report we examine the problem of lost admin passwords, how integrators manage this problem, and why manufacturer support for recoverable admin passwords is poor design.

********* ********* *** ****** * ***** ******** *****.

*** *******,********* *** **** ******** ***** ********* ** ***** ********* ****'* ********* ******** **** ** **** **.

***********, ****** *** *** **** ** ****'* ******* ***** *************, ********** ******** ****** ******** *****, **** **:

***** *** ********* ***** **** *** *********, **** **************'* ******** **** *** *******.

How *** * ******* ** ****?

*** ***** ******* **** ***** ********* ** ******* ******* **** some ****** *** ****** *********** ******** **** ********* *********.

*** *** *** ** * ******* ** ** *******?

*** *********** ********* ** ****'* ****** ********:

*** *********** ** * ******* ** **** ********* ********** ***** recorder's ********? **** ** *** ********* ** **** ** *******?

** **** ****** ** ******* *** ******* ** **** ***** passwords, *** *********** ****** **** *******, *** *** ************ ******* for *********** ***** ********* ** **** ******.

[***************]

Lost ********* ****** ****** ***********

*********** ******* ***** ********* ********* ** ** *************:

**** **** **** **** *** **** **** ********* ***** ****** passwords, *** **** *********** ********** ****, *** ****** *** ******* in *******, ** ********* ***** ****. *** *** **** ****** approaches **** ***** ****** ********, ** *********** **** ***********.

Solved **** ****** *******

*** **** ****** ******** (~**% ** *********** ****** ******* **** significant) ** ******** **** ********* *** ** ******** * ****** account, ** ******** *** ** *** ***** *******. ******* ** giving ***** ***** ******, **** ******* ***** **** ***** *** accounts. **** ******* *** *********** ** ***** **** ***** ******** and ***** *** ********** ***** ********.

  • "*** * **** ******* ** ** ******* **** *** ************* password ***** ** ** *** ****** *** **** *** ***** their ********. ** ****** *******, *** **** ** **** ** is *** **** ********* **** *** ****."
  • "** ** *** * *********** ******* *** ** **** ** do ****** ******* ******* * ***** *** ** ****** **** in ******* ******* (** *********** ** ***** ** ** **** little). **** * *** ********** *** ***** ********** ******* ***** managed **********, ** ******* **** *** *** ***** *******."
  • "**** **** *** ****** **** *****, *** **** ** **** it ** *** *** ******* *************. * ***** ** ** because **** ***'* *** ** ***** **** **** **. ***** are *** **** ***** ** ***'* **** ****** ****** **, so ** **** ****** ** *** ***** *** ********. **** places *** **** **** ** **** ****** ****** ***** **** our *** ******** *** ******** **** ***** ******."
  • "****** ********. ** ******** *** ********* ** **** ** ******* so ** **** ****** ***-** *** ******/****** ***** ******** ** work **** *** ************ **** ******* ** ***** *** **** as * ***** **** ********."
  • "** ****** ****** ** ***** **** **** ***** ****** *** solving ***** ******** ******** *****."
  • "** ** *** **** *** ***** ******** ****. ** ****** remotely ****** *** ******** ** ******."
  • "** ****** **** * ****** ** ************** ******** ********* ******** recovery ** *** ******* ** ******. ** ******** * ****** internal ******** ****** ** ****** *** ******* ** * ******* system ********* ****** *********, ********** ********* *** ************** *********."
  • "** ****** **** * ******** ***** ******** ** ** *** change ****** ** ******. **** ** *** ******** ** ** Admin ** **** **** ********."
  • "*** *****, *** **'* * *** ******* **** ** ****. We ********* **** *** *** ***** ********, ********* ************ ****** or **** **** (** *** :*)"
  • "** ********* ***'* **** **** ***** ** ** ****** * login *** **** *** *** *** ** **** *** ** can ****** *** **** *** ******. ********* ****** **** ** have *** ****** **** ** ** **** ** ******* *** system."
  • "** **** * ****** ** *** ********* ** ***** ***** password ** ******** ****** ************ *********. ** **** ******** ** admin ***** ***** ******* ** *** *****. ** ******** ******* most ***** *** ** **** **** **** **** *** ****** it ******* * *********** **** ** **** *** ********** *** recovery."
  • "*** ********* ****** ******. ** **** ** ** **** * password *** *** ***** ***** ******** **** *********."
  • "********* ***** ** ********** ******** ***** ***** *** ******** ** the ********. **** ****** ** ** ****** ***** ********."
  • "*** ******* ** ***** **** ** ** ********* **** ** install ******* ** *** ** * ******** ***** ******* *** our *******"

Solved **** *************

*** ***** ****** ********, ~**% ** ***** *** **** **** passwords **** *** * *********** *****, *** ** **** ************* of *********, ** **** ********* ***** ** ******** **** ***** password ***.

  • "** **** *** *** ******** ** *** ** *** *** customer ******* *** ****** ******."
  • "******* ** **** ** *** *******. **** **** *** ******** we ******** ** *** **** ** *********."
  • "*********... ** **** ** *** **** **** ******* ** *** installations ** * ******* ******** **** ** **** ***...*** **** can **** **** ********"
  • "**** ************ ****** *** **** **. ** *** ** **** a ******** ****** ** *** *****."
  • "*** * ****** *******. ** ** ******* **** * ****** of ******* ******** ** **** ** **** ** ****** **** they ****."
  • "** **** * ****** ** *** *********, ** *****'* ****** often ******."
  • "* ***'* ******** * ****** ********. ** ****** ******** *** credentials"
  • "*** *******. * ****** *** ************, **** **** *** ********** works *** ***** *** * ***** **** *** *** ******* of *** ******. * **** **** **** **** *********** *** login *********** *** ********* *** ** **** ** * **** place. ****** * **** ****** ******** ******* ***** ***** *********** and ***** *** ***** **** *** *** **** ** *** system. ***********, * ******** ********** *** *** **** **** **** this *******."

Rarely *******

*** **** ***********, ********* ********* *** * **** **********. **** may ** *** ** ******* **** *** ****** *********, ** other ************** ******* **** ****** ********* ************, ***** ********* ********* would ****** ** ******* ** *** ********* ** **********, ******* of *** **********.

  • "*** ***** ** ***. *** **** **** **, **'* * service ****. ** *** *** ******** ** ******* ********** *********** subscriptions ***** *** ******* ** ****** **** **** ********** ** the ***** ******."
  • "*% ****, ** **** *** *** ****** ******** ****** *** high ******* ******* ***** **** ** *** ***** ****."
  • "*** *********** ** *** ******* ****** **** *** ****** **** on ***** *******. ***** ******* *** ******* ******** *********, ** we ******* *** ****** ** ** **** ** **** *** in."
  • "** *** *** **** * *********** *****."
  • "*** ********* ****** ******. ** **** ** ** **** * password *** *** ***** ***** ******** **** *********."
  • "*** ***********; ** *** * ********* ******** ** **** *******, and **** ********* ** *** ****** **."
  • "*************. ****** *** ************* *** ********** **** ******* ****** *********."
  • "*** ***** *** **** ** **** ** ****** ** ********* it *** ****."

Significant ******* *********

*********** *** **** **** ********* ** * *********** ******* ***** relied ** ************ ******* ** ***** ** ***** **** ******** problems:

  • "**** ******. ** **** ** ************* ** **** **** **** of ******** *******. * **** ***** ********** * ******* ********** where ** *** ********** **** *** *** ***** ******** ** we *** ****** ****** *** *********, *** **** ********* ** not **** **** ****."
  • "*****. ** **** ***** * *** ** ****** **** ** their ****** ***** **** ******** ************* *** ****** ** *** be ******** **** **** ** ****."
  • "*** *** ************ *******"
  • "**** ***********, ** **** *********** ** **** *** ** ** automatically ****** *** ******** *** ***** *** **** **** *** password."
  • "***********, ** **** ****** *** *** *****. *** **** ***** and ********* *** ******** ** **** ** ************. ******* ******** with ************* *** **** ** ****. ** *** ******* ** customer *****, ********* **** ** *** *********. ****** ****** ****** typically ******* **** *********."
  • "**** **** ****** ** ***** *** ******* **** ***** ** document *** ********. **** ** ***** ****** *** ******** *** decided ** ****** ** ** ***** ***. ** **** **** we ******* *** *** ************ *** ********** ** * ******** reset."
  • "****** ******** **.* ** *** **** ******* *** *** ***** day. ** *** * **** *********. *** **** ******** ** just **** **** ** *** ****** ******** *** **** *** setup * *** ******** *** ***** ***** *******. "

Backup ***** ******* **** ****** ********

*********** ******** *****/*****-***** ******** *** ******** ******** ** * ********* accepted ****-********. ******* **** *********** (** ***** ********* ****) ** backup ************* ***** *** **** ** ********** ********** ** **** information, *** ** ********* *** * *********** ********. ** * minimum, *********** ****** **** *** ****** ** ********* **** * strong ***, *** *** **** ** ********-********** *******.

Manufacturer ******** ******** ******* ***********

******** ******** '********', **** ** ***********'* ****-**** ******** ********, ******** ******** *****, ****** ***** ** ******** **** ** ******. * ***** percentage ** *********** ********** ****-********* ** ******** ********* ***** ******** to ****** **** **** **** *********, *** ********** ************ ********* on **** ***** **** ****** *** ******* *******. ************* **** provide *****/******** ** ******* **** ***** ********* ** ** ** the ******* ** *** ******* ******** ** ***** *******, *** by *********, ***** *****. ***********, ** *****, **** *** ********* about *** ***** ******** ** ***** ******* ****** ******** ************* on *** ********* ** ******** ******** *********/*******, *** **** ******* consideration ** ***** ******** **** ***** ****.

Comments (10)

***** *** ** *** ********* ***** ** ******** ******, *********, and *** ********* *** ** *** ********** *** ******** ******* that **** *** ******* ** **** *** ** *** ******* in *** *****. **** ****** **** *** *********** **** **** implemented **** *******?

*'* * *** *** ** ******** *** ******** ***, *** I ***** ****** *** ***** ** *** ******* ************* ** customer ********* ********* ** ** **********. **'* ***** ***** *** supports * ****** **************, *** *** *** ***** ********* ******* accounts ** ******.

******* ** * ***** ******* *********** ***, **** **** **** to **** * ******!

* ******* ***** ******** ***** **'* ********* *** ***** ** KeePass ***** *** ***** **** *** **** **** ***** **** since.

******** *** **** ****** ******** ***** ** ******** ******** ******** already =(

**

**** ** *** ******* *** * ******** *** **** ****** database **** **, ***** *** ******** **** *******...*** ********* **** we *** ***** ******, **** **********, *** *** **** ********* security ***** ****** *** ********

* *** * ******** ********* "*******" *********, ****** ** *******.

*** ******* *****'* *** **** **** ***** *** ****** *** database ******** **** ***** *******, ***** *.*. "***************". * ***** there *** **** *** *** ***. *** ******* ** *** supported ****.

** ***** *** ** ☺️

****** ********* ******** *** ***** * ********* ******, *** ***** forget ******** ****** **** **** /**** **** ********,****** * **** (example: **-******-********************************-************.*** ) *** **** **** ** ***** ********* ******* team, **** **** ****** *** **** ***** **** (*******:**********.***). ****** this *** ***** *** *******. ** ******** *****.

* ***** ********* *** ** ***** *** **** **********/********** ******** Management *********, **** *** *** **** *** ** ****** *******, etc...

********:

  • ****
  • *******
  • ********
  • ******

*** ***** ** *** ****** ** *** ********, *****?

********. *** *** ******* ***** **** ****** ** *** **** physical ****** ** *** *******.

********. *** *** ******* ******** ******** ** *** **** "*************" type ****** ** *** **. *******: ****://*************.*****.***/*****-*******-********-********-******-*****.****

**, *** ** *** ******** *********** ****** "****** ********" ( I ****** ***** *** **** ******** *** ***** ********) ** save ********* ** ****** **** *****?

*** *** ****, **** ******** **** *** ***** ** ******* admin ******** ****** ** ***** ********?

*'* *** ** *** ************:-) ** ***** ** ******* ***** password **(*** **** **) *** **** ***** ****** ** *** machine **. ***, ** *** **** **, *** *********** *** do ******** ******... *** ** ***** ** *****?

* ***** **** ***. ** *** **** **** ****** ** the *******, *** *** ** **********.

*** ** **** ***** (*.*. ******** ***** ***** ***/***), *** have ** ****** ** *** ****** ***** (***** **** *** manufacturer ******* ***** **-********), ** **** **** *** **** ****** accounts ** * **** ******** ******* ** ******* **** ********* on *** *****.

* ***** ********** ** ***** ******* *** ****** *** ***/***.

Login to read this IPVM report.
Why do I need to log in?
IPVM conducts unique testing and research funded by member's payments enabling us to offer the most independent, accurate and in-depth information.

Related Reports

Geutebruck Company Profile on Oct 22, 2018
Geutebrück has been in business for nearly 50 years, but they are not well known within the US surveillance market. In this report, we profile...
Best Alternatives to Banned Dahua and Hikvision on Oct 17, 2018
With the US government ban and a growing number of users banning Dahua and Hikvision, one key question is what to use for low cost? While Dahua and...
Integrator Laptop Guide on Oct 16, 2018
This 18-page guide provides guidance and statistics about integrator laptop use. 150 integrators explained to IPVM in detail about their laptops,...
Security System Health Monitoring Usage Statistics 2018 on Oct 09, 2018
How well and quickly do integrators know if devices are offline or broken? New IPVM statistics show that typically no health monitoring is...
IP Camera Installability Shootout - Avigilon, Axis, Bosch, Dahua, Hanwha, Hikvision, Uniview, Vivotek on Oct 08, 2018
What are the best and worst cameras from an installation standpoint? Which manufacturers make it harder or easier to install their cameras? We...
ASIS GSX 2018 Mixed Manufacturer Reviews With Declining Overall Attendance on Oct 02, 2018
ASIS GSX 2018 show drew 9% fewer total registrants, however, it gained 15% more paid registrations, according to ASIS. In this note, we look...
Network Cable Testing Guide on Oct 02, 2018
Proper cable installation is key to trouble-free surveillance systems. However, testing is often an afterthought, with problems only discovered...
Favorite Power Supply Manufacturer 2018 on Sep 28, 2018
While power supplies are becoming less important as PoE matures, they remain vital to access control systems, where increased power for locks,...
Favorite Access Control Reader Manufacturer 2018 on Sep 25, 2018
Favorite reader votes are in, and it is not close. A global access giant ran away with the votes in a one-sided contest. But for many, the...
Favorite Request-to-Exit (RTE) Manufacturers 2018 on Sep 19, 2018
Request To Exit devices like motion sensors and lock releasing push-buttons are a part of almost every access install, but who makes the equipment...

Most Recent Industry Reports

IP Camera Installation Tool Shootout - Avigilon, Axis, Ideal, Hanwha, Triplett, Veracity on Oct 23, 2018
Setting up IP cameras has historically been challenging, with techs often precariously using a laptop on a ladder or lift. Some options for install...
ADT and Brinks Home Security Struggles Impact On Industry Examined on Oct 23, 2018
ADT and Brinks Home Security have both been struggling over the last year. ADT valuation is 50%+ less than their IPO target. Brinks Home Security,...
Hikvision Growth Declines Q3 2018 on Oct 22, 2018
Hikvision's growth continues to decline in 2018 going from: Q1 - 33% Q2 - 22% Q3 - 14.6% In this note, we examine Hikvision's newest Q3...
Geutebruck Company Profile on Oct 22, 2018
Geutebrück has been in business for nearly 50 years, but they are not well known within the US surveillance market. In this report, we profile...
Chinese Government Blocks IPVM on Oct 22, 2018
IPVM has been blocked by the Chinese government without any notice or explanation. This means IPVM.com is no longer officially accessible anywhere...
Startup SafePass Profile on Oct 19, 2018
A major problem with visitor management is that the systems mostly require adhesive printed paper labels and paper logs, creating waste and an...
China Is Not A Security Megatrend, Says SIA on Oct 19, 2018
The US Security Industry Association has released its 10 "Security Megatrends" for 2019. SIA declares that these megatrends, such as "Advanced...
Hanwha Dual Imager Dome Camera Tested (PNM-7000VD) on Oct 18, 2018
Hanwha has introduced their first dual-imager model, the PNM-7000VD, a twin 1080p model featuring independently positionable sensors and a snap-in...
Camera Height / Blind Spot Added to IPVM Camera Calculator on Oct 18, 2018
IPVM has added camera height and blind spot estimation to the Camera Calculator. This is especially helpful for those who need to mount cameras up...

The world's leading video surveillance information source, IPVM provides the best reporting, testing and training for 10,000+ members globally. Dedicated to independent and objective information, we uniquely refuse any and all advertisements, sponsorship and consulting from manufacturers.

About | FAQ | Contact