Verkada Internal Cameras Leaked

bm
bashis mcw
Published Oct 21, 2022 13:17 PM

Cameras inside Verkada's facilities were made publicly available by a leak of a Verkada API key, IPVM discovered, though Verkada told IPVM that this was a "demo" system that they shared with partners and customers.

IPVM Image

Nevertheless, the Verkada API key we found was quicky revoked and IPVM sees significant concerns for the privacy and security of Verkada employees and visitors who are exposed to anyone who Verkada shares these API keys with.

IPVM found the Verkada API keys, verified authenticity with Verkada's own API Web GUI, and was able to retrieve information and camera images as we show herein.

******

**** ***** * ****** ********** **** leaked ******* *** **** *** *******'* internal ****** **** ******.

IPVM Image

******* *********** *** **** ** *** Verkada*** ****************** ******** ************* ***** **** * fairly ****** *** ********* **** ****** interactive *********** ** ***** ***.********* ************** *********** ************ ** **** ** *********** ******* the ****** *********** *** *** ******.

Leaked *** ****

*** ****** *** **** **** *** primary ********* ** *** *** *******, authentication *** *************. ***** *** ************** key ** **** ** *********** *** request **** ***** ************* *** *** authorization *** ***** *** *** ******* the ******* ** ********** ** *** the *** *** ***** ** *** API's ******** ** *** ******.

**** *** **** ** ****** *** authenticity *** **** *********** ***** +** outdoor *** ****** *******, ***** ****, and ***** *********** *** ****** **** the *******, ** ***** ***** ** a *********.

******** ** *******, **** **** ****, UT:

IPVM Image

******** ** *******, ******, **

IPVM Image

***** *, ******** ******* ** ******* HQ, *** *****, **

IPVM Image

***** *, ********* ****** ** ** P1 ******** ** ******* **, *** Mateo, **

IPVM Image

*** ***** ** ******* **, *** Mateo, **

IPVM Image

Croatia **** ********* ******

*** ****** ***** ***** ** ** Zagreb, *******, ******** *****. *********, **** installation ***** ************ **** ********** **********(****) *** ****** **************** */**** ** ********** ** ******** data ******* ***** ********* *** ******** **** ********** *****.

IPVM Image

IPVM Image

**** ******** *** ************ **** *** help ** *** ********* ******* *** coordinates.

IPVM Image

IPVM Image

API *** *********

**** ******* *** ** *** ***** of *** ****** **********, *** ******* thereafter **** *** ********** *******, ***** should **** ******* **** **** ** the ***** *****.

Key *******

**** ****** *** ****** *** **** once * *** **** ***** *** response, ***** *** *** **** *******, so ** ***** *** *** **** were ********* *** ** ***** ******** after ***.

IPVM Image

Verkada **** **** ******

**** **** ******* *** ** *******, who *********:

*** *** *** *** ******* **** IPVM ******** *** **** ** *** public-facing ************* ******** ** *** ******* platform, ***** ** **** “***********.” ** ********* *** ****** **************** **** *** ******** *** ********* on * ***** ***** ** *********** our ******* ************. ** ************* ***** the*********** ******* (********* *******) ** ******** locations ******* **** *** *** *** public ***********. ** ****, ** **** our ********* ***** ***** ******* **** the *** **** ***** ******* ************ ** ******* **** *** **** cameras. ** *** *** ******* ****** you ***** *****, ** ** *** of *** **** ******* – * company ****** ** ** *** ** its ******** ************ ** ************** *********** *** ****** ************ *********’* **** ***.

*******’* *** ** *** ** *** many ******** ** ******** *************. ** ******** ************ ****** ** some ** *** **** *********** **** can ** **** ** ************** ******* **** *********. ***** *** public ****** *************, ** *** *** ********** ** the *** ****, ***** **** **** access ** ************** ********. ** ****, ** ***** our ********* ** ******** *** ****** these **** ****** ** **** *** more ****** ******** *** ********. ***********, we *** *** ***** ** *** evidence ** * ****** **** ***** trigger * ********* ********** ***** ****.

********

** **** ******* ** ****** *** keys, ***** **** *** *** **** important, ** ** ***** ********* ** protect **** *** ***** **** ** sensitive, ** **** *** ** **** for ************** *** ************* ** ******* important *** ********* ***********.

****** *** ****** **** *** ******

IPVM Image

Comments (8)
UE
Undisclosed End User #1
Oct 21, 2022

***** ** ** *** ** * limb **** *** *** **** *** of *** **** ****** ** *******'* mind ** **** ***/** ******** ** any ** *** ***********.

(8)
UE
Undisclosed End User #1
Oct 21, 2022

** ****, ******* *********** ** * can ******** ** **** ** ** Yeti's, "******-*******", ***********, ***** *** ****, and *****-***** **** ********!

(14)
UI
Undisclosed Integrator #2
Oct 27, 2022
IPVMU Certified

* **** *** **** **** * got ** ***!

(2)
Avatar
Dwayne Cooney
Oct 21, 2022

********, *** ** *** **** ****** on *** ***** ** ******* ***** have **** **** ******** ****** ******* at ****.

(2)
(7)
Avatar
Donald Maye
Oct 21, 2022

**** ** *** *** ***** **** IPVM *** ******** ** *******'* ******** cameras:******* ****** **********, **** *** *** False ****** ******* ** *********

****** ** ****** ********* ***** ****Verkada's *** ***** ************ system were passed around by Verkada sales managers captioned with graphic sexual comments, causing strife within the Silicon Valley unicorn. [emphasis added]

(2)
MS
Mark Simon
Oct 21, 2022
IPVM • IPVMU Certified

* ****** ** **** *** ******* in **** ** ********'* ******** *********** into *** *****

IPVM Image

** **********, *** ***** ***** *** that ** ***, ****** *** *** it ** ** ******* ** *** code **************, *** **** ** ***** exposed ******** ** *** ******** ** the ****** *** ********** *********.

(1)
Avatar
Cody McCormick
Oct 24, 2022

** ** **** ** ** *** some ** *** ****** ** ************ a ***??? **** **...** ****** ** your "**** ******"

(2)
(1)
Avatar
Dwayne Cooney
Oct 25, 2022

***.

*** **** ******* ** *** ******** shots *** *** ******** ***** ****** be **** *****.

************...