Hikvision CSO Denies Backdoor, Denies Government Control

Published Oct 20, 2021 11:58 AM

Hikvision's DPO/CSO Fred Streefland has fired back, issuing Hikvision's most blunt and public statement alleging that Hikvision's 2017 backdoor was not a backdoor and that Hikvision is not controlled by the PRC.

IPVM Image

Streefland also had words for an Axis Communications employee, telling the employee that Axis has more CVEs than Hikvision.

IPVM released a video covering Hikvision's most recent critical vulnerability and its history of issues, embedded below:

*********'*********** ****** * ******** ********** **** ***** ****** ** ********, copied ** **** *****:

IPVM Image

************, ********** ********* ** ** **** employee ** *** **** ******:

IPVM Image

Backdoor ** *********

********* *** ********** *******:

*** **** '********' *** * '*************' and *** * ******** (**********, **** doesn't ********** *** ********** ******* * backdoor *** * *************);

** ********, *** ********** **** ***** it******** ** *** * ********, ******:

* ******** **** ****** *************** ************* of *** ********** **** *******... *** vulnerability ** ******* ** *******

********* ******** * ***** ****** **** allowed ******* ****** ** *** ******, regardless ** **** *** ***** ******** was. *** **** ****** *** ********* this ****** ** ********* ****** ********:

?****=************

***** ******* ** *** ********* ****** themselves **** ****. ********* ******** **** magic ****** ** *** ****, ***** the ***** ***** ** *** *** it ******:

*** ********* ******** **** ***** ******, Hikvision *** ***** ******** *********. *** clear ************** ** *** **** ******** is ********* **** *** *** **** critical *************.*** **** ************* ***** ** ******* is *** ********* *** ** ********** here, *** **********.

*** *** ****,********* ******** ********:

**. ********* **** *** **** ********** backdoors ** *** ********

***** ***** ***, ** ***** *********, "Can ********* ****** **** ** *** "Hikvision **** *** **** *** ********* in *** ********"? **** ***, ********* would ** ** *** ****** ********* no ********* ** *** ****, *** simply ******* ** '**********' ****."

** ******** *** ******** *** ** changes ** **** *********** **** **** made.

* ********** ******* ********* **** "** not **** ********** *********" ** **** someone ******* *** * ***** *** assuring ***, "* *** *** ****** this **** *******."

Government ******* **** *********

********* *** ********** **** *******:

********* ** *** * '*** ******** & ********** *******'; **'* * ****** company **** **** **** **% ** the ***** ** ******;

** ********, *********'* *** ****** ********* report ***** ***** **** ************** ************* "******* *****-*****":

IPVM Image

*** *********'* **************** ********* ** ** * "*****-***** company"** **** **** ** ******* ******* Hikvision. ***** **** ***** *********'* ********* and ******* ****:

*********'********** ** ** ****** ******* ******* He********* ************** *** ** ******** **** Erik ********** *** ******* ** ****'* ******* for ********, ******* ***** ***** **** days ***** ** **********. ***********, ********* clearly ***** *** ***** *********** *********** is *** **** ** *** *** government.

** ********, ***********'* ****** *** **********, *********'* ********* ** *** **** that *** *** ********** ** ***** controlling ***********, **** ****** **** **** material *********** *** ***** **** **** is *** ******** ** *** ** day **********:

*** ******* *********** ** ***** *********** Technology ***** *********** (“****”), * ******* state-owned **********, **** ** *** ******** in *** ***-**-*** ********** ** *** company[.]

*******, ** *********'* *** ********* ******* show, *** *********** *********** ** ******, a ********** **** ******* ************ ** run *********. *** ******** ** ****** and ********* ** *** **** ***—**** ********.

*************, ** *** **** ******, ********* muses **** ** *** *** ******* influence **** ********* ** ***** *** matter ******* ** *** ******* *** firewalling:

******, **** ** *** ******* *****-***** enterprise *** ***** *********** ********* **** Hikvision, ***** ***** ** ** ****** to ******** ********** *** ********* **, again, *** ***** ** *** ****** States ****** *********’* ******* ** **** they *** ********** ** ********* ******** from ****************** ********, ** ** ** Internet-connected **********, *** ********* ***** ***** and *********.

** ******, ********* ***** **** ** a ******** ******** ** **** **** long ********** ********* *** ** ******* their ** ******* ** *** ******** (*.*., **** **** ********* ********).

*VE ********** ********* *** *********

********* *** ********** **** *******:

***** *** ********** ** ********* (****), ONLY ** *************** (****) **** **** detected ** *** ********* *******, ** if *** ******* **** ****** **** with ***** *******, **** *** **** admit **** ********* ***** ***** ******** very *********;

** ************ ********* ** **** ************** employee:

****** ******* *** ******* ** *************** (CVEs) ******* **** *** ********* *** you ***** **** ** ********* **********!

******* ******** ***** ** **** ** like ******* ************ ***** ** *** many ***** ****** ***** **** *** wrong. ** **** **** *** ****, Donald ***** ***** ** *** *****'* smartest ******.

***** **** ****** *********:

**.*** ******* *** *** * **** source ** **** ******** ** ***** "overall ********".

*** **** **** ****** *** *** system ** ** ****** ****** *********** for ******** ***************. **'* *** ******** to ** * ******** *** ******** database ** *** ***** *************** ** any *******. **** **, * ****** or ********** ***** ****** ****** ** not ******* * *** ****** *** a ***** ****. *******, ******* ********* combine ******* **** ***** * ****** ID ** ***'* ******** *** ***** impact, ****** * ****** "*** *****" a ****** *********** ******** *********. ****, for * ******* ***'* **** ** find ******** ******* ** ******* ********* severities. (*** **** *** **** ***** a ****** **** *********...?)

********** ***** **** **** ** *** track *** **** *************** "**** **** detected", ** ****** *** **** **** been ******** ********. ********* ***** **** argument ************ **** ** **** *** vulnerabilities, * ********** ******* ***** **** Hikvision **********, **** **********, ****** **** acknowledge ***** ********* ** *** *******'* own *******.

Comments (11)
Avatar
Brian Karas
Oct 20, 2021
Pelican Zero

** **** *** **** ******** *** actually * "*************", **** * ***** of **** ******* ****** **** ********* trying ** ******** ********* ** *** a ************* ****.

*** ***** ****** *** ******* ********** coding. ** ****'* *** ****** ** a ***, * ****** **** ***, etc. ** *** **** *** ***** explicitly ** ******* *****-***** ******** ******* requiring ***** ***********.

**, ********* ** ********* ** ************ putting *************** **** ***** ********, *** at *** **** **** ****** ** say **** **** ***** ******** *********?

(20)
(3)
(1)
(1)
(2)
U
Undisclosed #1
Oct 20, 2021

**** **** *****, *'* **** ** hear *** *** ***'* ****** ** the ***** ******.

(1)
(1)
(2)
UM
Undisclosed Manufacturer #3
Oct 20, 2021

*** ********** ** **** ** ******. It's *** ***** ** ** ** when *** ********. *** ********** ** in *** *** ******** ** ******* out. **** ** *** ***** ***** and ** *** ***** ******* **** truths **** **** ******* ******* **** proactively ************. *** ********** **** ***** the ************* **** ** *** ** simple ** ******* **** ** ******'* fathom **** **** ********* ******* **. Fred ****** ** ******* ** ******* and ***** ** ****** ***'* ****. Also, ***** *** *********** ***** ****** a **** ************ **** *** ***. This **** ******* *** ********* ****'* cred.

(4)
(1)
(1)
UM
Undisclosed Manufacturer #2
Oct 20, 2021

****** ****** ** ****** *** *** years *** ****** *** ****** ******** at *** "****", ****** ****** *** company ***** **** **** *** ** their **** *** *** ** *******, they ***** *** ** ***** ****** of ******* **** ** *****.

*** ********** ** *** **** *** engineers *** **** ********* ******** *** as **** ** ******* ** * playground ** ****** ** * ***** in ********** ******.

*** * *** ********* ***** *** same ***** **** **** **** *** years *** ** ** ******* ** politics *****, ****, ****, ****.... *** if *** *** ******, **** *** truth, ***** *****, *** ** ***** to ***** ** ** ***.

(2)
(2)
(1)
U
Undisclosed #1
Oct 20, 2021

*'* *** ********* *** ** ***, but *** *********/**********/*****-******** ** *** *******(*) should **** ** *********** *** ******** the ** ****** ******* **** ****/******** rules/etc.

**** **********/***-**** ***** ***** ****** **** how ** **** ***** ** * router *** ***** *** ** * proper *** **** ***** ****** ** view *** *******/***.

"** ** *** **** ** *** a *** *** **** **** * want ** **** ** *** *******, can't ** **** **** ******* *** use *****/**** ** *** ** ********* can ****** **** *** ******* **** anywhere?"

**** **** ***** ****, ***** ******/******** are ******** **** *** **** ******, but ****'* ******* ***** ** *******, there *** ****/**** *****, ** ****.

(3)
UE
Undisclosed End User #4
Oct 20, 2021

?****=************

$ **** -** '************' | ****** -d

*****:**

(2)
(6)
AM
Andrew Myers
Oct 20, 2021

**, ****'* *******. * ****'* ******* that. *********** ****** ** **** ************** **** (******** *****):

*** ****** ******** ******* ****** *** the ******** ** * ********* ***** "auth" ** *** ***** ****** ***if **** ********* ******** * ******-******* "********:********" ******, the HikCGI API call assumes the idntity of the specified user. The ******** ** *******.

********* *** ********* ******** **** **** a ********* ******* ***** "*****", ***** can ** ****** ************.

** ***********, ************ ** ************* *** *** ***. *** *** also *** ** **** ************ (*****:***), for *******. *** ** ** ******:****://*****************.******.***/*****-****/********?****=************

(3)
(1)
UD
Undisclosed Distributor #5
Oct 20, 2021

*** ****, **** * ***** ********.................

*** **** *** *** *** **** for *** ******** ******** ** **** article?

* **** **** ** **** *** much ** ***** ** *** *** an *********.

(2)
(2)
U
Undisclosed #6
Oct 20, 2021
IPVMU Certified

…** **** ******* ******* *** * drink *** ******** ***, "* *** not ****** **** **** *******."

******** ********* :)

(1)
(1)
(1)
UM
Undisclosed Manufacturer #7
Oct 21, 2021

***** **** *** *** ********** ** threatening ****'* **** ****.

(1)
JH
John Honovich
Oct 30, 2021
IPVM

*********'* *** *** *********** ** **'* ********* ******:

** **** *********, ********* *** ***** temporarily ** ******** ** ************* ** support ***********, *******, ** *********** ********* *** ***** ********* *** *** removed ** ********.

***** ** **** *** ********** ******* this ***********'* **** ********, **** ** *** ******* ** have **** *** ********* ******** ******* how *** ******* ******** *** *****.

** **** **** ** ** *** "misuses ** ********* **********" ******* *** users *** ***********:

*** ***-***** *** *** ***** ******* are *********** *** *** ****/***** ******* they ********...

** **** ******* **** ********* ***’* be **** ** *** ** *********, individuals, ** *******. *** ******** ******** built **** *******, ********, *** **** centres, ******** **** ***-***** ****-********** ****************, make ********* *** ***** ******* ** backdoors **********.

** **** ** / **** ********* puts ********* ** ***** ********, ** is *** ***** ** *****.

(4)