Suffering Criticism, Hikvision Keeps Insecure Online Service Up [Now Down]

Author: John Honovich, Published on Jan 03, 2017

Hikvision suffered severe criticisms for its abrupt plan to discontinue its Hikvision Online service, with 3 core functions to be removed on Dec 30th.

However, all of those functionalities continue to run in 2017, including the security vulnerabilities, and Hikvision has no explanation of what will happen next.

Update January 5th, Hik-online.com is now shut down. The site is up and one can login but when doing so, it just displays the discontinuation notice with no other options - e.g., no ability to manage devices or check status. In addition, new devices cannot be added, despite the notice saying that this could be done through February 16th.

********* ******** ****** ********** *** ********* **** ** ************** ********* ****** *******, **** * **** ********* ** ** removed ** *** ****.

*******, *** ** ***** *************** ******** ** *** ** ****, including *** ******** ***************, *** ********* *** ** *********** ** what **** ****** ****.

****** ******* ***, ***-******.*** ** *** **** ****. *** **** is ** *** *** *** ***** *** **** ***** **, it **** ******** *** *************** ****** **** ** ***** ******* - *.*., ** ******* ** ****** ******* ** ***** ******. In ********, *** ******* ****** ** *****,******* *** ****** ****** **** **** ***** ** **** ******* ******** 16th.

[***************]

Dec **** ***

*** **** *** ******** ** ** *** *** *** *** user ************, *** ****** ****** *** ********** ************. **** ** the *********** **** ********* *****:

*** ******* *** **** ********* ***:

******, **** ** ***** ******* ******** ** ** *********, ** is, ** *********'* *****.

******* *****

*** *** ************ ********* ** **** *** **** ****** **, device ****** *** ********** ******* ****** ** ***** *****:

No ***********

********* *** *** ******** *** ****** *********** *** ******** ** IPVM's *******. ******, **** ******* ** ** *** *******, *** interstitial ********* ** *** *** **** ** *** **** ** end ***** * *********, *** **** *********** ******* *** **** to ***** ****** *********.

Fix *** ******** ***************

** ********* ******* ** ******* ***** ******** **** *** **** Hik ****** ***** **********, **** ** ************** ***** *** *********** and ********** ********** **** **** *****.

*******, ** ********* ** ******* ***** ***** ***** ******** ********* claims *** **** ** ****** ********** ******* **** ***** **** track ******, *** ******** *************** ** ********* ****** **** ** fixed.

*** *******, *** ****** **** *** ******* ***** ** ***. Ironically, ***** *** *** ******** **** *** **** ***** **** their **** ******* *** **** ***** ** ******* ***** **** called ** ***. *********, ******* ***** ****-********** *,*** '*********' *** not **** **** **** ***'* *********.

********, *** ****** ***** ******* **** ** *********** **** (***** ******** ****) ***** *** ****** ** ******* ** ***** ****** ********* to *** ******* *** ****** ** ********** ** ********* ****** the *********** *** ********* **** ******, ********** *** *********** ***** devices **** ** ****** ** ******.

Communication ******** ********

**** ** *** ***** ** * ****** ** ************* ******.

  • *****, ********* ***** ***** * ****** ** *************** **** ******* **. It *** * **** ***** **** ********* *** ********* **, and **** ********* ******* *** ********* *** ***********.
  • ******, ********* *** ******* **** **** *** ****-**** *** ***** discontinued *** ** *** *** ***** * **** ***** **** Hikvision ********** ******** **** **** ***** ***
  • ***, ********* ****** ******* ** **, ******** ** *********'* ***** notice, **** ********* ***** **** ***** ****.

***** ********* ***** **** ***** *************** ********, ** ** * **** after *** ******* ***********. ***** **** **** ** ************ *** leave *** ******** *************** *******. ** ** ** *********** ********* for ********* ******* ** ********* ********* ** ****** ****** *** **** users **********.

Comments (15)

** *** ***** ********, ********* *** ***** *** ******* ** their ******-***************. *** ******** **************** ********. *** ******** *** ****** *** ****, ***:

  • *** *** ******* ** ***** *****, ****** ** ***** ******** 30th.
  • *** *** ******* ******* ***** **** **** *** ******** ***** their ****** **** *** ******** *******, *** ********* ** *** global *******.
  • *** *** ******* ***** ** **********-** ********* ******** ********, ****** *******, ***., ** ****-**** *** ****-****.

**** ******** ***** **** *** *** ***-******* *** ** ****** in *-* ****, ******** *** ***** *** **** ***** ********:

*** *** ***-******* *** ********* ***** **** * ******** **** EZVIZ ****** ********** ****:

*** ***** ** ** ****** ***** ******, ****** ** ******** or ****/********. *******, ******** ** *** **/**** **. ***** *** device's ** *******. **** ********** ** ***** ********.

*** *** **** ****/**** ******** ** *** ****** *** ********, but **** ** *** **** ************* *********.

**'** **** * **** ** ****** ***** **** *** ****** app ** ********.

**** *** ** *** *******,

*** **** ***** ** **** **** ** **** "*" ** the *** ** ****?

*-*?

** **** *** ***** ******* *** ***** / ******* / payment *** **** **** *****, ***** ******* ****.

** ***** ***** *** *** **** ** *** ****, *.*., reading ********, ** ****.

********* ***** **** *** **** ***** *** ******** ** *** Online, ********* ******* ** *** ******** ****** *********** *** ******* / *********.

**** ***'* **** ****** ***** **** *** ** :)

**** **** * ****** ******** ** ******** ** ********* ** millions ** ******* **** *** ****** ** ******* / ********** because ** ** ******* *********** *************. ** *** ** *** mind, **** ** ********* **** *********** *** ****** **** ******* do *** **** **** *******.

*** **** ****** ****** ** ***** "*" :)

**** *** *** ******. ***** *** * **** ** ****. We ******* *** ** ******* *********** ***** **** *** ***** has *** **** * **********.

** **** ** * ****** ***** ** ******* *** ******* we *** (***** **) ** **** ** **-**, ******** ** deletion **** *** ********* *******. **** *** ******** ** **** new **** ******* *** ************ ** *** *********.

**** ***** ** * ****** ******** **** ***** *** *** also *** *** **-** ****** ** ***** ******* ***/** *******/*********. Cost ** ***** * **** * **** *** **** **** a ******* **** **** ******** ** ****** ********* **** *******. Kind ** * ** *******.

* ****** **-** *** ****** *** ***** **-** ******* * could ****** ********* ** ****** ** ***** (***** ****** ******** generator). **** ******, *** ***** ****** * **** ****-*** *** Hikvision ***** *** ****** **** **** ********** ** *** ******** field.

** **, **** ** ****** ***** ** **** **** ******. Just **** **** *** **** * ***** ********** *** ****** naming ****** ****** *** ** ****. * **** * ******** generator **** *** ********** * ** ******. (******** ** "*****":"************").

* **** ** **** ** ******* **** ***** ** **** commotion **** * ******* ******* *** *********** (***** ** ***** vendors *******), *** ****** **** **** "*** ** **** *** risk". *** **** * **** **** ** **, ** *** pure ******** ** *** **** *** ** *** * ********* ddns ******, ********** **** *** *** ***** ******* *** ********* we **** ******** (*** ****** ** ***** ** ** *** router/firewall, ******).

**

***'* **** **** * *********** ****** **? ****** ** *** customers *** ***** ** ****? **** **** * ******** ***** on *** **** *********. **** ****** ** ** *****. ******* course. **** ** *** ** **** ******* ***** **** ***** that **** ** * ******* ** **** **** **** *********. Not **** *** **** *********, **** **** *** *********** ** act ******* **** *** ******* *** ******* *****. **** ****** be *********.

*** *******, ** **** ****** **** **** ** ********* **** "feature" *** ***** ** ***** *********** ** ********* ********. *** the **** **** ** ***** ********** ****** ****'* ********* *** video *********, ****** ********** *** ***** ********** ****.

**** ** ******** ******* ** *** **** ***** ** ********* which *** *** ******* **** *****'* *********... **** *** *** making ***** ******** ***** ** ******** ******** (**** *********).. **** Apple ** ****** ** * ********* *********...**** ******* *** **-***** earphone **** **** *** ****** *** ******* *** **** ***** Macbook ****** ** *** * ********** ***** *** . ********* Micro$oft ****** **** ** **** *** ****** *** *** ******** Laptop:The ******* ***** ** *** * ****** *** * ****** .... ** ** ** * ****** :) ***** ** ** OT

** ******** **** **** *** ** ********* ******-**** *** *****.

*** **** *** **** *********, **** **** *** *********** ** act ******* **** *** ******* *** ******* *****. **** ****** be *********.

********* **** ****** ** **** ** **** ****. *** ***** is ***** ** *******.

* **** ********** ***** **** *** ** **** **** ******** *** ******** ************************** ** ********. *********, ** ** **** *** ***** **** they *** *****.

** ******** **** **** *** ** ********* ******-**** *** *****.

************** ******* **** ********** **** ****** **** *****. *******, *** whole *******, ******** **** *** **** ** *** */***, ** definitely * ******** ** ******-**** *** *****.

* ** ***** **** ** **** *** ******* ** **** over *** **** ***** ** ***, ** **** ****** ****** over **** *** * ** *** ******* **** **** **** ever ** * *** ******* ** ********* (** *** ******* that **** ******* ** ******* **** ****).

****

***** **** ** **** ******* **** ********. ********* ** *** most ****** ** ******* ** ** *** ************ ******.. *** is ********** *** **** ******* ***** ***** **** ****'** *** leader ** *** ******** ** * **** ***** ******. *** vulnerabilities *** **** *** ** *** ***** **** **** ** their *********** **** ********** ******* ****** ***** ***** **** ******** at **** *****.

*** ****** ***** ** **-***** ************ *** ******** ******* ***** to **** * **** ****** *** ******** ************* ** **** of **** ** **. *** * ******** ***** ** ** handled-off ******** ** ******* *****. ** *** ******* ** ***** it ** *** *********** *** *** **** ***** *** ******* behavior ** *** ******* ** *** ** *****. ***** **** creates * *** ***** ** ************** *** ********** ** **** will ***** **** ********. *** ******** ** ****** ** **** us. **** *** **** **** ***** *** *******. *** ** Integrator ** ** ************ ** ** **** ** *********** *** a ******. * ********** **** ** *** ** ** * much ****** *********** **** ****** ** ******** ** ******* ** precipitously. *** ** *** ***** ****** ** ****: *** **** culprit ** *****'* ***. ******* *** **** ******* ******* *** better ** *** **********... ** ****'* * ***** *** **** a ***** *** *** *** *** * ** *** with ***....

**** ********** ******* ****** ***** ***** **** ******** ** **** point.

* **** *** *** ***** ** **** *** * **** to ********* **** ** **** *** **** **** ** ***** the **** ******** ******** ************* *** ** ******* ** **********, including *****, *.*.:**** ******** ******** *************,**** ****** **** ******,**** ******* ****** ******** ****** **** ******** *********, ***.

****** **** * ******* ****** ****:

  • ******, ** ******** ** *** ********* ** ******, **** **** people **** ** ********
  • *** ********** ** *** ************* - ** *** **** **** to **** *** **** **** ***** / ****** ** *******
  • **** ****** ********** **********

*** ***** ****** ** *********'* ********** *********. ********* ** ****** a ***** **** ** ************ **** *** ** *** ********* with *** **** *************. **** ****** ***** ** *** **** do ***, ********* ** **** ********** ******* ******** *** *********** are.

****** ******* ***, ***-******.*** ** *** **** ****. *** **** is ** *** *** *** ***** *** **** ***** **, it **** ******** *** *************** ****** **** ** ***** ******* - *.*., ** ******* ** ****** ******* ** ***** ******. In ********, *** ******* ****** ** *****,********** ****** ****** **** **** ***** ** **** ******* ******** 16th.

** ********* **** ********* ********* ******* **** **** **** **** with ********** ****** ***** ** *** ******* **** **** **** credentials: *** / ******** / ********.

**** **** *********** ***** *** ************* ****** ** *** *** ***: ****, **********, ** ******.

* ***** *** *** ***** ** *** ********* - ** they ** *** **** * **** **** ******* ********...

Login to read this IPVM report.
Why do I need to log in?
IPVM conducts unique testing and research funded by member's payments enabling us to offer the most independent, accurate and in-depth information.

Related Reports

Avigilon CEO Attacks Asian Companies Cyber Insecurity on Aug 18, 2017
Avigilon CEO is taking aim at their Asian competitors. And he is going directly after these company's cyber security issues. In this note, we...
IP Networking Course September 2017 on Aug 17, 2017
This is the only networking course designed specifically for video surveillance professionals plus it includes live training, personal help and...
Hikvision Responds To Cracked Security Codes on Aug 15, 2017
Hikvision has responded to IPVM's report on Hikvision's security code being cracked, both with a 2 page update to dealers and communication...
Vulnerability Directory For Access Control Cards on Aug 14, 2017
Knowing which access credentials are insecure can be unclear, especially because most look and feel the same. Even the most insecure 125 kHz types...
Hikvision Security Code Cracked on Aug 08, 2017
Hikvision's 'security code' feature has been cracked and a program generating security codes is being distributed online. IPVM has obtained and...
US Army Bans Chinese DJI Drones on Aug 08, 2017
The US Army has issued a ban on Chinese-made DJI drones. A US Army memo obtained by sUAS News references a classified document from the Army...
Healthy Skepticism for Deep Learning Is Prudent on Jul 26, 2017
The hype for deep learning in video surveillance is accelerating. Between the race to the bottom and dearth of a 'next big thing', certainly pent...
Dahua Suffers Second Major Vulnerability, Silent [Finally Acknowledges] on Jul 25, 2017
Less than 3 months ago, Dahua received DHS ICS-CERT's worst score of 10.0 for their backdoor. Now, Dahua has received another 10.0 score for a new...
Wireless Burglar Alarm Sensors Guide on Jul 21, 2017
Wireless sensors for burglar alarm sensors are an increasingly common option for the historical labor intensive wired alarm systems. However,...
PR Campaign Exploiting Manufacturer Cybersecurity on Jul 20, 2017
Manufacturers increasingly have a bulls-eye on their back. As cyber security solutions providers grow, they realize a great way to get publicity...

Most Recent Industry Reports

FLIR Restructures Security Division on Aug 22, 2017
FLIR's goal was once to have a single end-to-end security solution. However, FLIR's Security business unit has been struggling, with several areas...
Honeywell Total Connect 2.0 Tested on Aug 22, 2017
Honeywell is one of the biggest brands in security, with Total Connect 2.0 being the company's remote security and smarthome platform. We bought...
IP Camera Cabling Testing Statistics on Aug 22, 2017
Test and certify, or crimp and pray? Some integrators certify every cable they run, while others only inspect cables that have video issues. 130...
Dahua 4K IR PTZ Tested on Aug 21, 2017
4K has made its way to IR PTZs. In this report, we examine the Dahua 6AE830VNI, a 4K PTZ with 30x optical zoom, 200m (~650') integrated IR, and...
Top Used License Plate Capture Cameras on Aug 21, 2017
Capturing license plates is a common video surveillance application. But what cameras do integrators mostly commonly used? Special purpose LPC...
VLAN For Video Surveillance Usage Statistics on Aug 21, 2017
VLANs (see our tutorial) are an option for networks using video surveillance, but how often are they actually used? 125+ integrators told us how...
Avigilon CEO Attacks Asian Companies Cyber Insecurity on Aug 18, 2017
Avigilon CEO is taking aim at their Asian competitors. And he is going directly after these company's cyber security issues. In this note, we...
Sony Next Gen HD Dome Camera Tested (SNC-EM642R) on Aug 18, 2017
Sony has released their latest generation, claiming improved WDR and low light, increased IR range, and more. We tested the SNC-EM642R outdoor IR...
IP Networking Course September 2017 on Aug 17, 2017
This is the only networking course designed specifically for video surveillance professionals plus it includes live training, personal help and...
Knightscope Raises $10 Million With $3,320 Average Per Investor on Aug 17, 2017
Congrats to Knightscope. And condolences to their legion of little investors. Knightscope has disclosed they have raised $10+ million from their...

The world's leading video surveillance information source, IPVM provides the best reporting, testing and training for 10,000+ members globally. Dedicated to independent and objective information, we uniquely refuse any and all advertisements, sponsorship and consulting from manufacturers.

About | FAQ | Contact