Hikvision 'Phone Home' Raises Security Fears

Author: John Honovich, Published on Nov 10, 2016

The escalating attention towards Hikvision's China government ownership and Genetec's removal of Hikvision due to cyber security concerns has triggered increased scrutiny of Hikvision devices.

Hikvision's 'phone home' feature is raising particular fears as users evaluate Hikvision devices, attempting to understand what is happening and what risks this raise.

In this note, based on our testing, we examine how Hikvision 'phone home' works, its benefits and risks.

*** ********** ********* ****************'* ***** ********** *******************'* ******* ** ************ ** ***** ******** ******** *** ********* ********* ******** ** Hikvision *******.

*********'* '***** ****' ******* ** ******* ********** ***** ** ***** evaluate ********* *******, ********** ** ********** **** ** ********* *** what ***** **** *****.

** **** ****, ***** ** *** *******, ** ******* *** Hikvision '***** ****' *****, *** ******** *** *****.

[***************]

'Phone ****' - **********

**** ********* ******* *** ********* ** '***** ****' ** ********** service (*** *****, ****** ***** ** **** *** **** ** their ******** ********). *** **********, ************ ***** ******* (***** / **********) ******.

**** ********** ***** * ******* ***** *** * ****** ********* device ******** ** '***** ****' ** ***-*******.***:

******* *** **** ********* ** ******, ***** ********* ******* ** have ****** ***** *** / ******* ** ****** *** ********:

** **** ***** **** *** *** ****** (*****/***** ****) ******* ***** ********, ***** ****** *** *****/*** ****** (********************, **, ***.) ** ***.

Purpose - **** ***** / ****** ******

*** ******* ** **** ********, *** ** ***** ******* ** default, ** ** ******** ***** *** ******** ***** ** ***** video ********. **** ***, *** **** **** *** **** ** login ** *** ******'* *** *********, ** ******* / ****** configurations, ***. **** ****** ** ** *********'* ***** ********* ** connect ** ***** ******* **** ******* ***** **** ** *********. Indeed, ******* / ****** ***** ** *** ** *** **** common **** ****** *** *** ******* ***** *********.

******* ** *** ***** ** ****, **** ***** ******* **** services, *.*., ****** *******. *******, *** ************ / ********** ***** surveillance ***, **** ** ******. *** *******, **** *** ***** both **** ***** **** ******** ********* *** **** *** ********* off, ****** *********.

***** ********* *** ******* **** ** *** ** *** *** devices *** *** **** *** ****, **** ********** **** *** goal ** ****** ***** / ****** ****** *** ******* *****. However, **** ** *** ***** *** ***** **** *******, ******* of *** *** ***** *** ***** *******, *** ***** **** in ****** *** **********.

Risk - ********* / ***** ********** ******

*** **** ** ********* ******** ***** *********** ****** ** ******* networks. ********* ***** *********** **** ** ******** ***** ** *** that ****** ** ****** ***** ******* ****** * ***. ************* ******-*** ********** ***** ** **** ** ***** * ******* shell ** *****-***, ******* ********* ****** ** ** *** *******, using *** ****** ** ** **-*** ******.**** ** * **** ** *** ******** **** **** ******, though ********* *** **** *** ** *********'* ********** *********.

*** *** ****, ********* ********** **** *** ***** ******** **** for ***** ******** ********"********** ******* ***** ****** ******, ** *** **** *** *********** ****** *****." *** ********* is **** ** ********* ****** ** ****** ***** ******* **** anywhere **** ** *** *****, **** ***** ****** ** ** via *** ****** ********.

**** **** ********* *** **** ** **** ** *********** *** many ***** *** *** ******* ** ***** ******** ****** **** find *** '***** ****' ******* ** **** ******* ** ** a ****, ** ******, *** **** ** ***** *********'* ***** government *******.

Vote - **** ****** ** ****?

**** ** * *********** ****. *** **** ******* **** **, for ****, ************ * **** *********** ** **** ********** * security **** *** ****.

Comments (29)

********:

** ********* *** **** ************ (** ***** ********* *********) **** has **** ********** ******* ** ******* ******* *** ******* ** default ** *********?** **** ***** **** ****** ******* ***** ********* as ****.

* ** ********** **** ** ********** ***** ********* ** * company *** *** *** **** **** ********* **** ****** ***** this ******* *** *** ******** *** ******** ** ******** ***** that *** ***** ******* *** ** *** **** *** ********* know-how ** *** ** * **** ** * ******.

**********, * **** *** ****** *** ********** ******** ******** **** each ****** *** ******* ** **** ******* ** ********* ** those ************ *** ******* *** *********** ** *** ******** ******** them ** ***** ************ ** *** ******* "****** ****** ***-**".

** ***** ********* ** ******** ******* *** *** *** *** purchasers ** ***** "***-***" ***** **** ** ******* ** ***** homes ** ********** **** ******** ****.

****** ******** **** ******* ********* = ******** **** **** ****** does *** "**** * ****" **** **.

**** *** *** *** "****" ************, *** ***** *** ****, two ****** **** **'** *******/****** **** ***** ******** ******** ** default.

****'* * ******* ********* ***** ******, *** *******:

**** ******* ******* * ***** ****** *** ****************** ***** ******, ***** ** *** ********* ** *******.

****** ******** **** ******* ********* = ******** **** **** ****** does *** "**** * ****" **** **.

*** ** ******** **** ********:

****** ******** **** ******* ********** ******* ********* = ******** **** ones ** ********** ****** **** *** "**** * ****" **** me.

**** **** **** * **** *** ***?

***** *** *** ***** ** ***** **** ******** ************** ********** must ********.

********* *** **** ******* ***** ******** - ***** ******* *** the *********. **** *** ******** ** *******.

**********, * **** *** ****** *** ********** ******** ******** **** each ****** *** ******* ** **** ******* ** ********* ** those ************

* *** **** ** *** ******** * **** **** ******* at, *** ****'* *** *** *********** **** *** ************* **** it ***********. * **** **** ** ** ** *** ****** when ** ***** ** *** *** **** *** ** ****** a ****** **** ** ****.

* **** ** ***** ** *** ***** ***** **** ** information ******* ******.

***** ****** ********* ******* *** ** ******** *** ****** **** them ****** *** *** * ******* **** **** *** *****'* come ****** **.

*** ** *** ******* ******** *** **** *** ** ****** to **** **** *** ** *** **** ** *** *** habits ******** **** ** ********* **** ****** **** ******** ***** versions.

*** ** *** ******* ******** *** **** *** ** ****** to **** **** ***

***-*******/***** ** ******** ***** **** **** *** *** ** *** absolutely ** ****** ***, ** ***** ** ***** ******** ********, and *** ***** ****** ********* *'** ****. ******* *** "******" checkbox ** *** "******** ******" ***. ** ****** *** ********* cameras (** ****** ** *** **-*******), ***** ***'* **** ** option ** ****** **.

*'** *********** ******** ********* *******, *** **** ****'* ******** ** not *********, ***** ** ** ******** ******* ** *** ********.

* **** ***** ** *** ******* ***** *** **** ***** here

hik firmware

*** ***** *** ******** *** *** ***

** *** *** *** ******* ******* ** *** ********* ***** in **, *** ****** ***** *** ** **** ******** ***** are **** ***** **** **** *** ******** ******* **** ****** gray ******.

hik_disclaimer

* ** ******* ***** ******** *** ********.

**** **** ***** ****** ************* **** ** ****** **** ***** has **** ***** ** *** **** **** ** **** ****** firmware **** *** *****

******, ****'* **** * *** ********* ** *** **** ******* about. * ****** ** **** **** ******* **** ***** **** we've ******* ********* ***** ******** (*** **** ********) ********* *** the ******* **** ***** ** ********.

****, * **** * ******* ********* ***** *** *'* ****** sure * *** ***** ******* **. * ***** **** ** Wireshark ** ** ***** *** *** ** **** ******** *****, though.

...***** ****** ********* ******* *** ** ******** *** ****** **** them ****** *** *** * ******* **** **** *** *****'* come ****** **.

******** ** *** *** ***** ** ** ******** *** **** for *** ******* ** ****-********* *** ******* ** ***** *****.

** *** *** ***** ** ** ******** *** **** *** IOT ******* ** ****-********* *** ******* ** ***** *****.

******. *** ***** ** **** * *** ** *** ***** end ********* ******* *** ***** ******** ****** ** **** *********** internal ********. ** ***** *****, **** ***** **** ********* ****** no ******* ***** ********** ****.

*****, * ***** **'* * ***** **** ******* **** ********* users *** **** *** *** ** ***** ****.

***** *** *** ******** **** ** ** * ***** **** as ****, **** ********** *** *** **** **** ** ****** 'networking ******' *** ***** **** ******* *** ****** **** **** to ****, ******** * ** *** ****** **** ******.

*****, * ** ***** **** **** **** ** **** * better *** ** ******* ***** ******* **** ***** ****.

*** *******, *** ***** ******* ******* **** ******* ***** *** this ***** **** *** ******** ** ** **** ** *** users.

*******, *** ********* ******* **** *** **** ***********, ********** ** Hikvision ** ******* ***** ** *** **********. ** ***** ** safer ** ******* ** *** ****.

** ****** ***, ** *** ******* *** *** ***** ** the ******* **********, **** ***** ** * ***-*****. ** **** correct?

**, *** **** *************, ** ***** ** * **** *** any ****** ** '***** ****' ******* *** ************ ********** ******** it.

** **** *** ****, *** *******, ** ************ ***** **** would ***** **** ** ***** / ** ********* **** **** did *** ***** **** ** **** **** ** *********.

*** **** ******* *************, **** *** ******* ** ***** ** the ******* ********** ********* *** ****. ********, * ** **** many ******* ************* ***** *** ** *********** **** (******) ******** inside ***** ********.

*** ***** **** ***** * **** ***** ** *** ** three

***** *** ******* ********** ********** ******* ** **** **** ** you **** **** **** **** **YOUR government?

***** *** ******* ********** ********** ******* ** **** **** ** you **** **** **** **** ** *Foreign government?

** *** ***** **** ********** ****** ** ** *** ******** of ************* ******** *** *** ********?

**** ***** *** * **** **** *** **** **** ********* think ***** ** ** *****.

*****,

** ** **** ******* ******* ** ****:

********* ****** ******* *** ** ********** ***** ***** *********

**** *** ***** ****** ********* ******* ** ** ***** ******* attitudes.

**** * ****** *** ***** ***** ** *** * ****** ago ****** .

***** ** ****** ** **** ** ***** ******* *** ******* though, ** *** ***** *** ********** ****** *** **** **** about ****.

** ** * **** ******* *** **** ***** *** **********. That ****, ** ****** ** ********* ***. ** *** **** to **** * ***** ****** ** ****** **, ******* ** easy *** *** *** *****, * ***** **********.

**** ****, ** ****** ** ********* ***...

**, ***, **** **** ********...

** ** ******* ******* **** *** ****** *** ***** **** the *** **** * ****** ** *** ********.

**

*** ******* *** ******** ******* *** *** ******** ** ****** their's *** *****'* ********* ********. ** **! *** ******* ********** is ********** *** ******** ** ***** **** *** **** *** World's **** ********** ** *****... **** ***** ** ... **** .. ******** *** * ******* ** **** ** ******** **** restraint ****** *** **** **** ******* ********** **** ** ********** this ********* ***** ****.

****** **** ******* * ***. **'** ****** ** * *** world ***** *** ***** ** * **** ** **** ***'* watching *** ******** *** ***** ******** *** ********. ** **** learned **** *** *** (**?)**************** ******* ** **********. *** ********* **** **** ** *******. I ***** ********** **** **** ***** ****** ** ***** ******* upon * ******** ****** *** ***** ** ** ************* *** ...selling **? ....*********?????******??? ... ***!!??!!! ** **** *** ***** ***** ** *******'* be ***** *** ******* **** *** ***** ************ **** **** so **** ***** ** *** ************* **********. **** ****'* *** even **** ******* *********** *** ** **** **** * **** limited ** * ******** ********** ** ******* ** ****** ***** is ***** *** *** ****.

*** "***** ****" ******* ** ********** *******'* ** *** *******. that ** *** ****.. *** **** ** **** ****** ** the ***** ** **** **** **** ******** **** ********* ** the ****** ** ******** *** ****. ******* *** *** ********* to *** ***** *** ****** ************* ... *** **** ****** would *** *** ** ***** ****** ******** ** ******* *** communicating **** *** *****? ****! **** ****** **************** ** **** *********** **** *** *****

******* *** *** **** *** *****-*** ** **** ***** ****.

** **** **** * **** ******* ** * ******** ********** or ******* ** ****** *****

**** ** ** *** *****, ******(*.*., '*****') *** ******(*.*., '******') *** *** **** ****** *****. ****** ******* ** Taiwan *********, **** *** * ******** ****** ***** *****, *** a********** ***.

******* *** *** ********* ** *** ***** *** ****** ************* ... *** **** ****** ***** *** *** ** ***** ****** settings ** ******* *** ************* **** *** *****?

*****, *** ***** **** ** *** ***** ********* ******* ******* to **********, ** ** ***** ***** ** ************ *** *********** with **** '***** ****'.

****

** ** **** *** ********* ** **** ********* * ***** Ethnic ***** * *********. ***** ** ******* * ***** **** toward ********* ********** * ***** ****** **** ***** ************ ** similar ****** ******* *** ****** ******** ** ***** ************ *** in **** **** **** ** *** **** ***** *** **** intimate **** ** ***** ** **** *** ** **** ******** ATT **** *** **** ** **** ** * **********.

*** ***** ***** ****** ** **** **** **** ***** ** people **** *** ***** *** **** ** ************ *** *********** in **** ** ***'* ***** ***** ** **** ***** ***'* even **** **. *** **** *** ***** **** ************ ******* that *** **** ** *** ***** **** ******** **** *** average ******** *****'* ***** ***** ** **** ** ******** ** modify **** ** **/*** ***.

**** *****'* **** *** ***** ******. *** ****** ******* *** be ******* ***. *** ******* ** ****** *** ** * have **** ******* ***** ** ** ****** *******. *** ****** is ********** *** ****** ** ******. ** ****** *** ******* be ***** *** ****. *** **** ***, ****, *** ...

***** *** ********** ******** ** ******* ********** ********* *** ******** concerns. ****** *** ******* *** ****** **** **** **** ******** telecom ******** *** ** ***** ******* ********** ********* ** *********'* NBN.

******* ***** **** **** **** ** * ******* *****. ** may *** ** *** ****** ****** ** *****, * ******* bans ** *** ******** *** ** ***** *********. *'* ** with ****.

***, ****** *******'* ******** **** ***** ****** ** ** * don't *** ***** *******, *** ***** **'* **** ***** ******** to ********* *** ******* ******* *** ******** **** *** ***, I ***'* **** **'* *******'* ******** ** **** ** *** we ****** *** ****** *** ***. ** ** **********, ****'* my ******** ** *** ******* ***********.

** ***** **** * ********* ***** (***** ** ** ****** has ****** **** ** **** ** *** ****** ** ************ and ******* ** *** ********* ** *** ***** ******).

******** ***** ***** ** **** ******** ******

*** *** ****** ** **** ** *** **** ** * world ***** ******** ** ********* *****, ********-********* ***********, *********, *******, point-of-sale *********, *** *** ******* *** ******* * ******* ** data ***** ***** ****** ** *** ***** **** *** *****, where **’* ********** ** *** **********’* ******** *** ******** ******** forces ****** ******* ****’** ************ ** ** ******** ** ****’** commandeered ** **** ******** ******* ****** ** *** ******* **

****** ******* ****’** ************ ** ** ******** ** ****’** ************ it **** ******** ******* ****** ** *** ******* **

****, *** ******* *** ********** **** ***** ******* ******. ******* out *** *********.

*********** ****. ****** ***** * ******* ***** **** ******'* *** *******. *** *** ************* *** ******* ** *******, *** **** turning ** *** ** *** ******** ****'* ******* *** *** communications. * ****** ** ********** *** ******* ***** **** *****?

*** ******* *****'* **** **** * *** ** **** ** off, **** ****** *** ***** ***** *** *** ** ****** out ** **** *****:

**** ***+ *****, **% ** ******* ***** **** **** ****** not ** ******* ** *******. **** ** ********** ****** *********** and *************.

***** ** * ***** **** ******* ** **** ** * user ****** ** ******* ** ******** - **** **% ** integrators ********* ** ******* ** ******** ******* ****** **** (**%) of ************ *** **. ***/***, *********** ***** *** ********* *** this ******* *** ** *** **** ** ** ** *** default.

Login to read this IPVM report.
Why do I need to log in?
IPVM conducts unique testing and research funded by member's payments enabling us to offer the most independent, accurate and in-depth information.

Related Reports

Sony IP Camera Backdoor Uncovered on Dec 06, 2016
A backdoor has been uncovered in ~80 Sony IP camera models, attackers can remotely enable telnet on the camera, and then potentially login as root,...
XiongMai Master Password List Emailed By Chinese Spammer on Dec 05, 2016
XiongMai created an international uproar as their devices drove massive botnet attacks of major Internet sites. After pledging to recall cameras...
Hikvision Cloud Security Vulnerability Uncovered on Dec 05, 2016
A security researcher uncovered a critical vulnerability in Hikvision's global cloud servers. This vulnerability allowed an attacker to remotely...
Hikvision CEO Declares 'We Do Not Cut Rates" on Dec 02, 2016
Hikvision has led another press trip to China, and this time Hikvision's CEO is sharing insights into their competitive strategy, including...
Hikvision Removed From US Embassy on Nov 22, 2016
Hikvision cameras have been removed from the US Embassy Afghanistan and a procurement for more Hikvision cameras has been cancelled, after IPVM's...
Longse vs Dahua and Hikvision Tested on Nov 16, 2016
For many, even $100 cameras are too expensive. That is where spam king Longse comes in with their relentless offer of ~$20 cameras. In our past...
Avigilon Stock Surges 40% On Strong Growth (Q3 2016) on Nov 15, 2016
The roller coaster continues. After a brutal Q2 heading down, Avigilon's Q3 growth is strongly up. Inside this note, we examine what powered...
Genetec Expels Hikvision on Nov 08, 2016
Genetec has removed support for Hikvision devices, deeming them 'untrustworthy', citing customer concerns about Chinese government ownership /...
Now Knocking A Country Offline - The Video Surveillance Driven Botnet Wreaks Havok on Nov 03, 2016
The video surveillance driven botnet is now attacking an entire country. The Mirai malware that took advantage of poor security in Xiongmai, Dahua...

Most Recent Industry Reports

Knightscope - $122,509 Revenue, $2.5 Million Loss Seeks $20 Million Investment on Dec 09, 2016
The robot that ran over a child, Knightscope, wants money and they need it. Investors can invest as little as $1,000 to participate and...
'Solution' Manufacturers Threaten Integrators on Dec 09, 2016
The race to the bottom has driven manufacturers to become 'solution' providers, threatening integrators. Axis shift to 'solution' sales might be...
The Russian SMP Security Robot on Dec 08, 2016
A Russian manufacturer, SMP, has a commercially available outdoor security robot, at a lower price and with much less marketing than their main...
How Hikvision Beats Its OEMs on Dec 08, 2016
Hikvision GM declared that they are not aggressive with their competitors. But some of their own OEM partners disagree. Inside, we reveal a key...
Dahua Discontinuing H.264 Only Products on Dec 08, 2016
Dahua has taken a stand for H.265 and is discontinuing its H.264 only products. We examine the shakeup inside this...
IP Networking Course January 2017 on Dec 08, 2016
This is the only networking course designed specifically for video surveillance professionals plus it includes live training, personal help and...
Hikvision vs Dahua Mobile Apps Tested on Dec 07, 2016
With smartphone use and low-cost video recorders surging, many user's main interface to their surveillance system is their phone. With mobile video...
Paxton Drops US Reps, Plans Major Expansion on Dec 07, 2016
Paxton is gearing up to make a big run at  US access control success. The first step they have made is to cut all US Rep Firms, in anticipation of...
Axis Partner Elder Care Video Analytics (Smartervision) on Dec 07, 2016
Can video analytics be used to improve the care of the elderly? Axis and a video analytics startup, Smartervision, are working together to do so....
Sony IP Camera Backdoor Uncovered on Dec 06, 2016
A backdoor has been uncovered in ~80 Sony IP camera models, attackers can remotely enable telnet on the camera, and then potentially login as root,...

The world's leading video surveillance information source, IPVM provides the best reporting, testing and training for 10,000+ members globally. Dedicated to independent and objective information, we uniquely refuse any and all advertisements, sponsorship and consulting from manufacturers.

About | FAQ | Contact