IPVM Site Goes All HTTPS, Largest 3 Manufacturers Do Not

Author: John Honovich, Published on Jul 12, 2016

IPVM.com now serves all pages over HTTPS to improve security and privacy. However, a number of video surveillance manufacturers do not, including the largest 3. We review both of these items, including notable manufacturers lack of support in this report.

Moving to All HTTPS

HTTPS encrypts connections between a visitor and a server / site like IPVM. This reduces risk against attacks, tampering and eavesdropping when visiting a site.

HTTPS everywhere is a rising trend. Historically, HTTPS was used only for specific pages on a site, such as login / authentication and sending of specific sensitive information. Over the last few years, technology leaders have increasingly shifted to using HTTPS for all connections. In particular, Google is campaigning for "HTTPS Everywhere".

Adding EV Certificate

In addition to serving all IPVM.com pages over HTTPS, we have obtained an Extended Validation (EV) Certificate. This goes beyond simply using an HTTPS connection, adding an identity validation process (where a certificate authority manually verifies an organization) to provide further assurances to our visitors.

Now, IPVM pages show an additional Green bar on Chrome, signifying our EV certificate, before the URL entry like so:

This is similar to the security / assurances large corporations provide, e.g., here is Bank of America:

Get Video Surveillance News In Your Inbox
Get Video Surveillance News In Your Inbox

Benefits

While there are always cyber security risks and HTTPS is not a cure all, we expect implementing HTTPS site wide and adding an EV certificate to improve security and privacy when viewing IPVM.

For those wanting more direct benefits, Google indicates potential SEO / search traffic improvements for sites using HTTPS.

Moreover, the process of doing this was not particularly hard. Even a site with as many sections / elements as IPVM took less than 40 hours total to do the migration, solve any bugs in the transition and get the EV certificate added.

Industry Support

However, quite a number of large industry players do not.

No Default HTTPS

Of the manufacturers IPVM most frequently covers, here are those who do NOT default to HTTPS:

This includes the 3 biggest manufacturers in the world, companies one would expect to be on the forefront of things like that (Hikvision and their 5,000 engineers, Axis and their cybersecurity marketing, etc.)

UPDATE and Axis Warning

Not only does Axis not use HTTPS by default, they do not use HTTPS on their login page. This presents a risk of one's password being stolen before it is submitted via HTTPS. This is demonstrated at StealMyLogin. [Hat tip U1, who called this out in the comments]

Unfortunately and ironically, Axis requires this insecure login to access firmware to solve their critical security vulnerability (which we strongly recommend you do before it is publicly disclosed next Monday the 18th).

Yes Default HTTPS

By contrast, here are some manufacturers that DO default to HTTPS:

Distributors

Both ADI and Anixter default to HTTPS. Surprisingly, PSA Security, who is heavily marketing cybersecurity, has not. Additionally, Tri-Ed has not either.

Associations

ASIS defaults to HTTPS and has an EV certificate but SIA, who is also heavily marketing cybersecurity, has not.

Trade Magazines

None of the 7 trade magazines we checked had defaulted to HTTPS though, in fairness, they are still focused on print.

Outlook

Larger organizations that have lots of customers should default to HTTPS. We definitely expect many more manufacturers to do so.

If you have more information or you company has moved to site-wide HTTPS, leave a comment so it is noted.

Comments (29): PRO Members only. Login. or Join.

Related Reports on Marketing

How To Become an 'Expert' In An Hour on Sep 02, 2016
If you want to be perceived as an expert in your market, speak at every event possible... the math is simple: when someone stands in front of an...
Axis Takes Over Canon Surveillance Sales and Marketing on Sep 01, 2016
The wasteful Axis / Canon conflict is ending. After more than a year of Canon's video surveillance group competing with Axis, Canon...
How Much Axis and Avigilon Pay For Sales And Marketing Per Camera on Sep 01, 2016
When you buy an Axis or Avigilon camera, how much of that goes to pay sales and marketing expenses? Is it trivial like $2 or $3? Or is it far...
Get End User Leads for Just $997 A Month on Aug 31, 2016
Scam or opportunity? As trade mags continue to suffer from the decline of print media, they are scrounging for new ways to make money. Rather than...
Integrators Vs Manufacturers Direct To End Users on Aug 31, 2016
Many manufacturers have increasingly large and hungry sales forces that call on more and more end users. One recent example is Axis ~$20 Billion...
Milestone Declares End-To-End Is A Dead-End on Aug 24, 2016
While Axis celebrates their end to end system win at top 50 global retailer H&M, their Canon sister company Milestone is proclaiming that...
Hikvision 20% Price Cut Twice In A Month on Aug 23, 2016
Days after celebrating the Chinese government's commitment of up to $3 billion USD more in funding, Hikvision USA is now launching up to 20% across...
Axis Lists Itself First Among VMSes on Aug 19, 2016
When you think of VMSes, who do you think of first? Well, Axis, the camera manufacturer, thinks of itself. Axis declared: There are a variety...
Dahua Fakes Being American on Aug 10, 2016
Robbed from the Hikvision playbook, now Dahua takes it turn. Dahua, China's second largest manufacturer, is ramping up its...

Most Recent Industry Reports

Nest Cam Outdoor Tested on Sep 23, 2016
After years of claiming an outdoor model was "coming", addressing their biggest user demand, Nest has finally released their Outdoor Camera, an...
ACTi Refuses Race To The Bottom, Shifts To Solutions on Sep 23, 2016
The original low cost IP camera disruptor was ACTi. Back in the 2008 - 2010 time frame, Taiwanese manufacturer ACTi challenged the Western and...
You Get Robbed, Canary Will Pay You Up To $1,000 on Sep 22, 2016
Canary is trying to break the status quo in DIY security, first by raising over $40 million, and now a revamp of their monthly services package...
Milestone Ends Development of "Enterprise" VMS on Sep 22, 2016
Milestone 'Enterprise' was one of the first enterprise video management software offerings, selected by many early adopters of IP video. However,...
History of Video Surveillance on Sep 22, 2016
This is a concise history of video surveillance covering the past decade.  The goal is to help professionals newer to the industry understand...
Access Control Course Fall 2016 on Sep 22, 2016
IPVM offers the most comprehensive access control course in the industry. Unlike manufacturer training that focuses only on a small part of the...
Totally Wireless IP Camera (IPVideo Corp NomadHD) on Sep 21, 2016
Wireless battery powered cameras have been a surveillance pipe dream for years, limited by camera power consumption, battery technology, and...
Axis Launches IP Speakers on Sep 21, 2016
First, Axis introduced an IP horn, then it was video intercoms, and now it is Networked Speakers? While IP-based Public Address systems are not...
Tagged RFID Object Search Recorded Video on Sep 20, 2016
Video analytics has gotten fairly good at tagging people in video, but it does not solve the problem of finding items like specific merchandise or...
FLIR and Geovision Join the Hikvision Price Cut Race on Sep 20, 2016
Hikvision's price cuts are clearly a trend setter. After numerous and increasingly large cuts, the destructive cycle is accelerating. Last month,...

The world's leading video surveillance information source, IPVM provides the best reporting, testing and training for 10,000+ members globally. Dedicated to independent and objective information, we uniquely refuse any and all advertisements, sponsorship and consulting from manufacturers.

About | FAQ | Contact