Chinese Spam Access Control Is Here

Published Aug 04, 2016 15:34 PM

Notorious spammers like Longse, Cantonk, and Wodsee have flooded the video market with nuisance emails touting ultra low cost cameras for years, but is electronic access control the next target? 

Access has been a relative safe-haven for manufacturers and installers alike who have not needed to fight the substantial pricing pressures from product coming from overseas. However, signs are here that access is the next target.  

In this note, we examine:

  • Access control spam offerings being sent
  • Software functional issues
  • Hardware functional limits / omissions
  • Business barriers
  • 'Upscale' offerings expanding from Hikvision, Dahua and ADI W-Box

Spam ******* *******

**** ****** *** *****-***** ******** ********* are ******* ***, ********* ******** *** ******* * *** targeted ** *** ******* *** ****** PACS ******. **** **** **** *******, ******* IP *****, ****** **** *** ****** controllers *** $** ** ****-**** ****** for $**:

 

****** ********** ***** ****** ******* **** primarily **** * ****** *** ** both ******** *** ********, *** ***** focus ** ***** ***** ***** ********* is ********. ****** ** ** ******* of ********** ******** ** ********* ************ are ****; ****** **** ***** ** just *** *********** ****** ****** ***** are ******.

Big ********** ******

*******, * ****** ********** ****** *** gaps. **** ** *** ******* *** found ** ********* ********** ********, ** lack ** **. *********** **** **** commercial ****** ****** ******* * ****** vendor *** ******** *** ******** **** hardware *** ******** ***** * ****** brand, *** **** ***** ******** ******* ignore ** **** **** **** ******* of ******* ************* *** **** ** the ******.

******** ******** ********* ***** ******** *** managing **** *********** ** * ****** at ****, *** ****** ******* ***** individually **** *** **** *********. **** approach ** ******* ** *** ******** found *****'* **** **** ******, *** **** ***** **** ********** platforms ******** ***** ************* ***** ** ***** *** ****** multiple ***** ** * ******.  

****, ***** **** ******** **** '********' of *** ***** ** * ****** or ****** *** ***** *** ********* not *********. ******, ********* ********** ** each **** ** ******, *** **** a ***** **** ** ******* *** typically *****. *** ******** ** *********** controls *** ********** **** ****** ********** deployment ********* ****** ***********, ** ****** how *********** *** *****.

**** ********* ********

***********, *** ******* ** ******** ** often ********** ** ****** *********** ******, misspellings, *** ******* *********** ************.

*******, ****** ***** **** "****** ********* No." *** *** ***** ** * showstopper, *** ************ ******* **** ********* or ********* **** ****** *** ******* dismissal *** ****** ******* *********. *** example, ** *** ******** ******* *****, "**(*****) Name", "********", "*********", *** "********" **** may **** ** **************** ** ********** being *********/ **** ** ***** ****** in ****, *** *** ******* ******* these ***** ***** ** ********** ********* to ***** *** **** * ***** liability ** **** ********* ** *******.

******, *** ******** ****** ** *** * trivial *******, ** *** ****** ***** in ******* **********:

"[*********] *** ******** **** ** ******, ****** software ******** *** *** ***** ****** will ******* *********** ************* *** *** [North ********] ******. **** *** **** been ******** ******* * ******** ******* and ******** **** ****** * ****** that *** **** **** * *** Chinese ******* ** ** ***** *** were ********* ** *** * **** field ******* '***** ****'?  *** *********** is ** ****** **** *** ********** management ******** ***** **** *** ****** up ***** *** ************'* *** **** kit, [***** ***** ***********] $$$$ *** time."

Hardware ****** ************

*** ******** *** *** **** ********.  Comparing ******** ****** **** ******* *** gaps. ******** *** *** ******** ****** below, **** ****** ** *** *** same *********** ** *********** * ****** door *** ********** * '****-********' *********** of ****-** *** ****-*** **** *******:

******* ** **********, ****** ** $**

******* ** **********, ****** **** *** more ** ~$***

***** ***** ** *** *** **********. Consider ***** ******** ******** ******* ** *** spam *****:

  • ******* ****, ** **** *******
  • ** *** ****** *******
  • ** *** *******
  • ** **** ******** ****** *****
  • *** ****** **** (**** ****)
  • ** ***** ***** *******

***** ******* ******** *** *** ****** 'bells & ********', *** ********* ***** options ** ******** ********** ********.

Business ********

*** ************ *** *** **** ** software *** ******** ******. ******** ********** are *** ******** ** ****.

******* ****** ******* ** *****-************: ********** ****** ** ****-****** ** an *******. ** ***** *** ****** ** the ***** ****, ** ***** **** to ****** ** *****. *** **** users *** ******* ** **** * few ******* ** ****** ** '********' brand. ******, ****'** *** **** *** a '******* *** ********' ********** **** if ** ***** ******** **** ** function, *******, ** ******. **** ****** who **** **** *******/********/********** ******* *** a ****** *** ********** '***' ** a ****** ***** **** ********* ** back *** ***** ** ****.

** ************:******* ******* ******** ** **** ****** ****** is ** ******* *** ***** ******** system ***********. ****** ******* ****** ********* that ****** *********** ********* ** ******** connections **** ***** ************, **** ************, and **** ** ********* ***** *******, those ******* ****** ** *** ***** for **** *********. 

Other ********

** * ****** ********** ****** ****** "**** **** ******** *** ****** ******* Market ****? " ******* ******* ** ***** ******* problems **** **** ****** ****:

******* **************

"* **** ******* ***** ** ******* Asian **-***** ****** *********** ** **** as ******** ********* ** ** ****** from ******* ******* *** ********* **** the ***** *** **** ***** **** products **** *** ****-******** ****** *** of *** *** *** *** ** market. ********* **** **** * ******** NA ******** **** ***** ******* **** and **** "************" ***** ******** *** the *********, *** **** **** *** to ** ******* *** ***** ** modifying ***** ******** *** ******** ** meet *** ***** ** *** ** market ... *** **** *** ** go ******* *** **/*** ******* ********. This **** ** *** ****, *** while *** ******** *** ******* *****, it ****** ** **** ***."

********* ******* *****

"******* **** ***** ** **** ***** wear '**********' ** **** '*** *****' labels, *** ******* ** ******* ********/**** safety ***** *** *** *********. ***** a ****** ******* ********** ** ******, the **** ***** ** ****** ************ over ******* **** ******** ***** ** occupational ****** ** ** ***** ** isn't ****** ** *******, **********, ** enforced ** ****** ** ***** *******. *************, in ***** *******, ** **** * legacy ** ****** *** ***** ** industrialized ******* (****'**** ******* **** ****, ** ****) **** ********** *** a ****** *** ** ************* *** life ****** ***** *** ******* *****.

*** ****** ****: ********* *** ************* these *****, *** ***** ******** **********, is *** ** ********* ** ******* markets. ***** **** ****** ********* *********** or ***** ******* *********** * ***** commitment ** ************* ******* **** ********* product, *** ******** **** ***** *** the **** ** ***** *********** ** 'not *******' ** '*** ********** *****'.

*******, *** *** *** *** ******** as **************, *** **** ** '******* pains' **** ***** ****** ** ******** current ****** *******:

"[****] ** ***** **** ********* ***** **** used ********* **** *** & ***** were ** *** ****. [********** ********* on] "Trusted ******", "************* *******" *** ** on.

* *** ***** *** **** ** door *********** ** ******* **** **** at *** ****.  **** ***** *** Hik **** ********* ** **** *** which *** ********** ******. * **** ****** doubt **** *** & ***** ***** engineers *** ********* **** ******** ** EAC ******** ***** **** ** *** probability ********* ***** ********** **** ***** 5200 ********. *** *'* ** ********* surprised ** **** ***'* **** * 2142 **** ** ******* **** ********** in *** ***** *********."

More "***-****" ****** ******

******, * ****** ****** ****** ***** **** low-cost ****** ******* ** *** **** the ****** ** ********. ** ****, many ** *** **** ******* ****** that **** ********* ******* ** *** video ****** **** ********* ** *** actively ********** ****** ******* ********:

*********

***** *** ******* ****** ** ********* USA ****** ******* [**** ** ****** available]s ** ******* ** * *** western ******, *** ******* **** ********** ********* ** ******* ******* ******** and ********** ***************** ***********, *******, *** *****-***** ***** [link ** ****** *********] ******* ***** **** elsewhere ** ****** *******.

*** ******* *** **** *** ** the ********** ******* *** ************ ** those ******** ** ***** ******** *******, but ***** *** *********** ****** ************ of *** *****, *** **** **** not **** ****** *******.

*****

******** *********'* ****** ***********, ***** **** *** a ***** ****** ** ****** ******** [link ** ****** *********] ** *** wings, ******* *** ********** *******. *****'* portfolio ** *** ** ***********, *** also ******** **** ****** ** ***********, readers, *** *****, *** **** ***** biometric *********** ******* [**** ** ****** available].

******* *** ******* ************ ***** ******** internally, ** ****** ******** ******* ********* themselves ** *******, *** *** ******** of * ****-******* *** ********* ****** control **** ** *******.

* ***

*** *****, **** ******* ************ *** creeping **** ***-**** ******. ***** *********** ADI's ***** ***** * *** ** ****** ****** ******* *****. ***** options *** ********* ******* ** ****** lock *****, ******* **** ** ***** include ********* *** *****'* ********* ** the ***** **** *** ** * regular *****.

***** **** * *** ********* ******** product **** ******* *********, ********* ******** may ******* ***** ********* *** ***** in *** ***** ******** ******.

Comments (13)
U
Undisclosed #1
Aug 04, 2016
IPVMU Certified

'Upscale' offerings expanding from Hikvision, Dahua and ADI W-Box.

Maybe the low cost junk is out there just to make the Hikua look good.

Avatar
Jonathan Lawry
Aug 04, 2016
Trecerdo, LLC

You mentioned that Hik has 30,000 engineers.

Although figures like these are often mentioned in a political context of those arguing educational policy, very seldom is it mentioned that what is counted as an "engineer" in a lot of Asia, is not the same thing as an "engineer" here.

When we think of an engineer, we think of someone who matriculated at an accredited 4-year university and finished with a Bachelors in, say, Electrical Engineering.

An "engineer" elsewhere can sometimes be someone who went to 8 months vocational school and learned Visual Basic.

Just something to keep in mind when one considers the seemingly massive "engineering" staffs of some companies.

(1)
U
Undisclosed #1
Aug 05, 2016
IPVMU Certified

Hik has 30,000 engineers...

To be fair it's Brian quoting a member's hyperbolic statement.

(1)
(1)
(1)
JH
John Honovich
Aug 05, 2016
IPVM

Hikvision this year is regularly reporting 5,000 to 6,000 engineers.

(1)
(1)
UE
Undisclosed End User #2
Mar 24, 2017

28,998 Reverse Engineers, 2 Design Engineers?

(1)
(4)
UE
Undisclosed End User #2
Mar 30, 2017

I noticed I got 1 thumbs down, must be for the math error, so here is correction:

 

29,998 Reverse Engineers, 2 Design Engineers?

(1)
(1)
U
Undisclosed
Aug 05, 2016

A tour of the facility suggested they could indeed have 3000 engineers (that's the number I recall.) They looked like engineers because they were faffing around with boards in obvious debug configurations, editing code in visual studio, and had cubicles with books about data compression and H.264.

(1)
Avatar
Jonathan Lawry
Aug 05, 2016
Trecerdo, LLC

They were faffing around with boards? Oh then they must be engineers! My mistake.

(1)
(3)
U
Undisclosed #1
Aug 05, 2016
IPVMU Certified

They looked like engineers because they were faffing around with boards...

Did you get a look at any of the reverse engineers? Supposedly, they're the backbone of the organization.

(1)
(2)
Avatar
Jonathan Lawry
Aug 05, 2016
Trecerdo, LLC

I wasn't beating up on Brian per se. It just reminded me of those claims in the political realm of "Country X is churning out 10 gazillion engineers a year" and hence we are falling behind. I was just calling attention to the matter that elsewhere in the world, what counts as an "engineer" is very broad.

(1)
(1)
U
Undisclosed
Aug 05, 2016

Every time IPVM posts one of these spam-bottom-feeding hardware reviews I check it out on my integrator supplier of choice, Amazon.com. I just learned that ZKAccess (which I would characterize as a mainstream brand in North America) has panels for $95. Amazon seems to have stuff as cheap as $70 as far as I could see. Not UL, not safe, not enough digital outputs, I get it. However at 10 times cheaper than US stuff one wonders what it would take for them to compete. Would UL approval and a second relay increase the cost that much, especially if Home Depot buys a squidjillion of them...

As of last ISC West HIKvision still doesn't sell access control here, I think. The demo center in Hangzhou had panels, mifare/prox readers, fingerprint scanners, etc. on display. Not sure what features they offered but they certainly have figured out how to build some sort of product.

(1)
Avatar
Brian Rhodes
Aug 05, 2016
IPVMU Certified

We have a profile post upcoming on ZKAccess, who is based in NJ. Until recently, however (Q1 2015), they were a division on ZKTeco headquartered in Shenzhen. The company still uses ZKTeco for product design and manufacturing.

I do not think they are 'mainstream' yet with recognition onpar to Mercury, HID, Assa, Allegion, etc, but their prices are attracting attention at the low end.

(1)
Avatar
Armando Perez
Aug 09, 2016
Hoosier Security and Security Owners Group • IPVMU Certified

We have a client that was using cheap direct import parts for Access. Not a small company. The head of IT was doing all the work himself. WE would come out and quote and quote and quote, never landed the access control work. Until very recently when he was let go for doing too much and managing too little.

We are in the process of installing a Paxton system now.

Cameras are susceptible (more so anyways) to commoditization. It tends to be a set it and forget it type of purchase for most of the industry. They go back to it in a reactive way when something happens. Access Control is different in that it is used daily by every employee, and it requires changes whenever there are changes to the payrolls. Add to that the fact that if a door fails to open someone could die, and you have a market that is more resistant to the DIY guy on staff. Its still subject to market loss in cases of "self-integration" pr those really large clients that basically have their own integration department and are buying from the same distributors we are all buying from, but we never had their business anyways...