Honeywell Speaks On NDAA Ban, New Non-Banned Cameras and Cybersecurity

By: John Honovich, Published on Aug 06, 2019

For years, Honeywell has depended on Dahua, a company with a poor cybersecurity track record and now banned by the US NDAA, for the development and manufacturing of 'Honeywell' branded IP cameras.

free image3

Now, after years of silence, Honeywell has spoken to IPVM, explaining what they are doing to address the NDAA ban, the release of their 30 series IP cameras, their cybersecurity process and whether any Dahua-OEMed Honeywell cameras have the Dahua wiretapping vulnerability.

*** *****, ********* *** depended ** *****, * company **** * **** cybersecurity ***** ****** *** now ****** ** *** US ****, *** *** development **************** ** '*********' ******* IP *******.

free image3

***, ***** ***** ** silence, ********* *** ****** to ****, ********** **** they *** ***** ** address *** **** ***, the ******* ** ***** 30 ****** ** *******, their ************* ******* *** whether *** *****-***** ********* cameras **** ******** *********** *************.

[***************]

Executive *******

********* **** ******** ** OEM *** '***********' *** '*****' ****** **** ***** while ****** ***'**' *********** **** ****** ************ Vivotek. ********, ********* **** the ***** ***** ***** series ******** * ****** chip **** ****** ***** cameras ** *** **** they **** ******** ** 2900-1 ************* *********** *** the ***** ****.

**** ********* ** ********** this ******** ** ********* a ***** **** ******* in ************ *** *******. On *** ***** ****, this ****** ** ******** from *** ********* *** the ********* ****** ** Dahua ******** ***** ****** buyers ** **** ** inadvertently ********** **** ****** products. ********, ***** ****** a ***-***** *** ********* the ****, ** ***** leaves ********* ********* ** other ************* ****** *** IP ****** *********, * notable ******** *** * company **** *** ***** heavily ** *** **** few ***** ** ***** security ***** (*.*.,********* *******************).

Wiretapping *************

********* **** ** ***** August *, ****:

** *** ******* ** determine *****, ** ***, cameras *** ******** ** this ************* *** *** working ******* **** ***** on ************ *** ********* firmware *****.

**** ** * *******. Dahua **** ***** ****, at ***** *** ****** and ********* ** ******** on ****** *** ***** IPVM ******** *** ********* still *** *** ********** if **** *** ********. While ***** *** **** made **** ***** ** delaying, ** ********** ** still *********'* ************** *** picking *****.

Background ***** ******

*** ***** ***** **** our********* ***** ******* ** Gov ****** ******* ***** Surveillance***** *** ******* *****:

Honeywell ************* ***********

********* **** * ***** case ** **** *** what **** *** ***** for *************.

*** ***** ****** ******* have * ****** ******* in ****** *** ** their ******* ****** **** Honeywell **********:

*** ********* ***** ****** cameras **** *****-** ****** chipsets ** ******* ******** tampering **********. ************, *** crypto ******** *** ********* store ********** ************, ****** key *** ******* **** in * ****** ****** environment. **** ******* ********-***** encryption *** ******* ****** is ********* *** *** entire ****** ** ******* against ***** ******* *** tampering. ********* ********* ******** leading ***** ********** *** protection ***** ** **; for *******, ********* **** and ***** ************* **** HTTPS, ****** ******** *** firmware ********** *** ********** against ******* ********* ** tampering ****** ******** *******, signed ***** ********* *** application ******** ******* ********* while ********* ** ************* VA ********* ******* *******.

** ********, ********* **** that *** ***** *** cameras ** *******:

******** **** ********** ***** on *** ****** *********** faced ** * ********** product ** ******** ** well ** *** ********* features *** ******** *****

******** ************ *** ******** controls ***** ** ******** standards *** ********** **** as *****, ***/*** **/*****, ISO *****, *** ***, GDPR, *****, ********** ***** laws *** ***********, *** others ********* ** *** product ** ******** *** the ******** **** **********

******* ****** ***********

****** ********

****** ******, ******* ** Design, *** ****** ****** standards *** *********

****** **** ******** (****** code ********) ** ******* secure ****** *** ****** practices

****** ******** ** ******** open ****** ***** *** potential ***************

*** ******** ** ******* a ****** *** ************* penetration ******* *******. ** some *****, ********** *********** security ******* ** ********* for ******** ********. *** criteria *** **** ********** testing – ** **** as ***** ******** ** offerings *** ******** *** this – ** *******-**** proprietary ***********.

* ****** **** ********** Policy **** ******** ******** mitigation ********* ***** ** severity

****** *** ******** ** cybersecurity ** ****** ********** prior ** ******* ********

********* ******* *** ******** notification *** ******** *******

** *** ***** ****, as *** *********** ************* delay *****, **** *** still ******* ********* ** Dahua ** ****** **** issues.

********, ********* ********** **** the ***** ****** *** a ** ****-* *************.

*******, **** ** **** for *** **** ********* equIP ******. ***** *****-**** Essentials ****** *** ** chip, ** ** *************, etc.

NDAA **** *** *********

********* ********* ****:

**** **** ** *********** a ******* ** ***** additional ****** ** *** market ***** **** ****** federal ******** *** *** other ********** ** ******** Honeywell *******, **** *** 30 ****** ****, **** are ******** *** *** as **** ** ***** systems ***** ****** **** NDAA ****, ******* ***. The ** ****** ** the ***** ******* ** this *******. ** **** expand ***** ****** **** the **** ** ****** to **** **** ***** customers *** ****** *** video ******** **** **** from *********. ** **** continue ** ******** * range ** ******* *** those ********* *** ***’* require ***** ***** ******* to ****** **** **** 2019, ******* ***. ** are ********** ********* *** products ** ****** **** they **** *** ******** needs ** *** ********* for ***** *** ********.

********* *********** ****** ***** excited, ** ***** ***** on *** ****** ** LinkedIn ***** ** *** past ***** **** **:

***:

OEMing **** *******

*** ** ****** ** OEMed **** ******* ** the **** ****** *** both ********* *****:

********* ******** ** ******* on **** *** ** is ****-*******.

**** *** *** **** they *** "*********** *** 30 ****** ** *** mid-scale *****: ***** *********** and ***** ***** *** able ** **** ** the **** ****** ** us."

***** ** *** ****-***** analysis ** *** *** 3 ********* ***** *******:

*******

*** ******* ** *********'* IP ****** ******* ** much ********. *******, ** is ******* **** ** incredibly *** **** ** hiding ******* ****** *** Honeywell ****** ** ********** to ******** ** ** more *********** *** ********* about *** ******** *** cybersecurity.

** * **** ***, from * ****** ******** perspective, ** *** ************** that ********* ***** **** easy ******* ** *********** other ************'* *******. **** time ** *** ****.

**** ********* ********* ***** still ** ******** **** buying **** ****** ******** is * ******* *** Honeywell *** *********** ******* this ** ******* *** Dahua **** ****, **** using ***** *** ***-** sold ********, ********* ** Vivotek ********* ** ****** a ****** ************, ***.

Comments (10)

********, *** ********** ********** of *** ****** ******* marketplace (******** **** ****, blaster *****, *** ****-***-**** wiegand ******), ***** ** with *********** ***** ********.  Who ****** ***** **.

********* ******* **** **** description ** *** **** fides ** **** ****** chip.  *** ***** *******  that *** ****** ******** is *********.  *** *** not *** **** *** an *** ********* ****** Element ** ***** ** that ****** (** **** it's ****-*** ** ******** else.)  **'** ******** ** believe * ******* **** is ********* ***** ********** was ** ** *** crypto ******** **** *** device ** *** ******* in *** ******* ******* in ******** *** ****'* ok?  ** *** **** me ** ***** **** you **** ** **** me **** ****** ******** paperwork.  (*** ****** ****** that ******* ***** ****** you ********* ******** ****** know **** *** **** the ******** ***** **** up.)

 

********, *** ********. ** is ***** * ***** camera *** ** ** still ** ********** ******, with ** ******* *** chip, **** ** ********* so ***** ** ****** justification ** *** ***** cameras. * ***** ** is **** ********* ****** a ********* *** ***’* see *** ***** ** buying ***** *** ******* when *** **** **** can ** ****** ****** for * ***** ***** and ****** ****** *******.

** ***** *** **** screwed ** ** *** talking ***** ****, * don't **** *** **** or **** *** *** the ******. 

***** ** ******** *******/********* of ********, * ********** your ********** ********** ***** 😜.  *'* ***** ** use *** ********** ********** riff ** ******* (*** know....like ** *** ** events **** ****).

“****** ******** ** ******* firmware ********* **********.”

*** **** *** **** impacts **** *** ******* of *** ********?

*** ******-******* **** **** will ****** **** ******* against ***-********* ****** ********... unless **** ****** ******** Hue’s ******* ** ************ bundling *** ******* ******* key **** *** ********...

****** ****** ******** ***** it * *** ****** to ******** ********* ** modified ****, * ****** see *** ** ***** possibly ****** * ******** file **** *** ***************?

****** ** **** **** knowledgeable **** ** **** to *** ** ****?

 

* ******* *** ***** digital ******* ********** ******* to ********** *** ** the ****** ** ** should **** ****-*******.  * agree **** ** *** introduce ** ******* ****** the ****** ****** ***** you *** *** ** with * ********* ****** exploitable ****** ***** ********* in *** *******.  **** would ** *** **'* apropos ** ** ********** vendor ********** ********* ** crazy ****** **** ****.***, right?

******* ******* **** *** HiSilicon?

** ** **** *************, they ** *** ********* chips, ***** *** ************ in *****.  ***** ** (consumers *** ****** ** video ********) *** ********* drive *** ****** *** other ************* ** *** cost **** **** ***** ago, ******* **** **** or * **** **** alternative **** ****.

* ** ******* **** sudden "******** *** ***** source ** ******" ******** can **** **** ******* innovation ** ***** *********.  I **** ** **** the ************ *** ******** to ****** ********* ** sources.  ** ****** *** quick ** ****** *** go **** ** *** "allure ** *** *****" that ***** ** ** skilled ** ********.

**** ***** ****** ****** fronts: 

*** *** *** ******** from ***** ****** *********

******* ***** *********.

******* ******** ****** *** self ******* **** ********

**** ******* *** ***:

********* ***** *** **** Costco ****, *** ***** out *** ** **********.

********* ****, ******* *** High *****, ***** ********.

*** **** ******** ****, killing ****** *** ******* America

** ************** ****

 

***** ** *** ***, they **** **** ***** world *********.  ** *** can **** **** ****, keep ****** "*** *****".

 

** ****** ** **** that *** *********** ** the ********* (**** *********) Series ** ******* *** not **** *****. *** purpose ** ** *********** a ********** ********* ******. Thus ** ********* *****. 

***** ****. * ******* Honeywell *** ******* *********** sources.

Login to read this IPVM report.
Why do I need to log in?
IPVM conducts unique testing and research funded by member's payments enabling us to offer the most independent, accurate and in-depth information.

Related Reports

Alarm Veteran "Demands A Criminal Investigation" Of UL on Oct 18, 2019
The Interceptor's Project pressure against UL continues to rise. Following Keith Jentoft's allegation that "UL Has Blood On Their Hands", Jentoft...
"UL Has Blood On Their Hands" Alleges The Interceptor / Keith Jentoft on Oct 14, 2019
"UL has blood on their hands" alleges Keith Jentoft of "The Interceptor Project". We examined The Interceptor in-depth last year, see: The...
RealNetworks SAFR Facial Recognition Profile on Sep 25, 2019
RealNetworks entered the surveillance market by giving away their analytics to schools for free, and is now targeting large commercial users with...
Hikvision Acusense Analytics Tested on Sep 23, 2019
Hikvision touts "The Magic Behind It All" in their new Acusense line are 'deep learning algorithms' inside these cameras and recorders. But how...
Open Access Controller Guide (Axis, HID, Isonas, Mercury) on Sep 19, 2019
In the access control market, there are many software platforms, but only a few companies that make non-proprietary door controllers. Recently,...
Directory of 70 Video Surveillance Startups on Sep 18, 2019
This directory provides a list of video surveillance startups to help you see and research what companies are new or not yet broadly known. 2019...
Vivotek "Neural Network-Powered Detection Engine" Analytics Tested on Sep 17, 2019
Vivotek has released "a neural network-powered detection engine", named Smart Motion Detection, claiming that "swaying vegetation, vehicles passing...
AI Video Surveillance (Finally) Goes Mainstream In 2020 on Sep 03, 2019
While video surveillance analytics has been promoted, hyped and lamented for nearly 20 years, next year, 2020, will be the year that it finally...
Scylla AI Video Analytics Company Profile on Aug 29, 2019
Scylla, an AI analytics startup, says they are targeting 1 Billion dollar valuation in 5 years and it "is not rocket science" to detect weapons and...
Anyvision Facial Recognition Tested on Aug 21, 2019
Anyvision is aiming for $1 billion in revenue by 2022, backed by $74 million in funding. But does their performance live up to the hype they have...

Most Recent Industry Reports

Government-Owned Hikvision Wants To Keep Politics Out Of Security on Oct 21, 2019
'Politics' made Hikvision the goliath it is today. It was PRC China 'politics' that created Hikvision, funded it, and blocked its foreign...
Integrated IR Camera Usage Statistics 2019 on Oct 21, 2019
Virtually every IP camera now comes with integrated IR but how many actually make use of IR or choose 'super' low light cameras without IR? In...
Alarm Veteran "Demands A Criminal Investigation" Of UL on Oct 18, 2019
The Interceptor's Project pressure against UL continues to rise. Following Keith Jentoft's allegation that "UL Has Blood On Their Hands", Jentoft...
Camect "Worlds Smartest Camera Hub" Tested on Oct 18, 2019
Camect is a Silicon Valley startup that claims the "Smartest AI Object Detection On The Market", detecting not only people and vehicles, but...
Hikvision Global News Reports Directory on Oct 17, 2019
Hikvision has received the most global news reporting of any video surveillance company, ever, ranging from the WSJ, the Financial Times, Reuters,...
Camera Calculator V3.1 Release Improves User Experience on Oct 17, 2019
IPVM has released a new version of our Camera Calculator, V3.1, with significant user experience improvements, a new development plan, and an...
Securing Access Control Installations Tutorial on Oct 17, 2019
The physical security of access control components is critical to ensuring that a facility is truly secure. Otherwise, the entire system can be...
Access Control Course Fall 2019 - Last Chance on Oct 17, 2019
Register Now - Fall 2019 Access Control Course. Thursday, October 17th is the last day to register. IPVM offers the most comprehensive access...
US DoD Comments on Huawei, Hikvision, Dahua Cyber Security Concerns on Oct 16, 2019
A senior DoD official said the US is "concerned" with the cybersecurity of Hikvision, Dahua, and Huawei due to "CCP" (China Communist Party)...
Pelco Sarix Pro3 Camera Tested on Oct 16, 2019
Pelco has released their Sarix Professional Series 3 cameras, claiming "more security detail in challenging scenes with excellent low light and...