Verkada Global Admin Vs Hikvision Backdoor

Published Mar 29, 2021 14:52 PM

Which one was worse? And what does this say about video surveillance cybersecurity?

IPVM Image

In 2017, Hikvision's backdoor shook the industry. Now, in 2021, Verkada's "global admin access" lead to a breach that made global news.

Untrustworthy

Both companies proved to be untrustworthy as these were the consequences of dangerous and unethical design decisions. Many 'hacks' are the result of exploiting obscure or unseen coding patterns that the provider did not foresee. These were not.

With Hikvision and Verkada, both of these companies put these in on purpose, hiding them from the public until outsiders publicized, forcing the companies to make changes after years of secretly including them.

Hikvision ********

********* ****-***** * ***** ****** ******** across ******** ** ** ****** ****** that **** ******** ** ******** ** the ****** ******* ***** ****** ******* logging ** ** **** ******* **** the ******** ***.

**** ************ **** ** *** ***** video ******** *****:

******* ****** *****

******* *** * **** **** ********* 'backdoor', ** **** ******* *** ********* as "****** ***** ******', ***** *** only ******* ****** ** *******, ** allowed ****** ** **********, *********, **** root ** *** ********** ** ** the *******.

** *** ***** *****, ******* ****** and ********* ******** '****** ***** ******', at ***** ******:

Cloud ******* ** ***

*** *********** ********** ******* ***** *** vulnerabilities ** **** ********* *** ******** in ******** **** *** *** *****-*******, requiring **** *** **** ** ****** the ******** ** ****** *** ************* while *******, ***** ***** *******, *** able ** ****** *** ******'* ******** all ** ****.

Dangers ** ***** / ******* ***** *****

**** *****-******* *******, *** ******** *** spy ** ***** ********* ******** **** want. *** **** **** ** *** very *** ****** **** *** ******** can ********** ***** **** *** ******** is ****** ** ****. **** ** not ******* ******* **** ********** *** even ** *** ****, * ******** would ***** **** ** ***** *** traffic *** ********* *** *** ****** a ****** **** ** ******** *** system (***** ** ************* ******** ***** certainly *****).

*** ****** ** * ***** ****** is **** **** ********, *** ******** can *********** ** ******* ** ***** the ******** / ***** ******, ********* the ******** ** *** ***** ** customers ***** **** (***** ***** ***** be **** ** ******).

Dangers ** *** ***** / ********* ********

**** ******* **** *** *** ***** managed, * ******* ***** ***** **** the ******** ** ******* ** ***'* organization **** * ******** *****-**. ***** and ****** *** ******** ** ******* to ****** *** ********, *** ******** will ******, *** ****** ** *****. Secondly, ******** *** ******** *** ********, the **** ****** ** * *** backdoor ***** ********* **** ******** *** remain ******* *** ***** ** ** until *** ******** ** ***** *** a ******** ****** ******** ** ** applied.

Verkada ********

*** **** ****** ******* ** ******* being ******* ** ****, *** *****, they **** ******** ***** ********* ** the ******* **** **** *** *********** and ***** ******* *********** *** ***** and *********,*** *******:

IPVM Image

***:

IPVM Image

*** ******* ******** '*********' *** '*****? Maybe. *** ******** ******* ****** ******** 'DANGEROUS' *** '*****'? ** '******-****' *****, yes, **** ***.

Which ** *****?

*** **** ****** *** **** **** companies.

** *** *** ****, ** ***** with *********, *** *** *** ** barricade / ***** /********** ****** **** *** ******** ***, if *** ** ** ********* *** never ************* ***** ****** ************ *** can ** **** *** **** *** be ******** ** ******** ***********, *** might ** **. ** ******, **** is ** *** ******* ** ****** it ********* ** ********** *** ****** and *****-***** ****** (*.*., ****** ** an *********).

***********, ********* *** **** ****** *****-******* video ************ (*.*., ***-*******) *** ** you *** ***** **** *** **** risk ** ******* - *** *** trust **** ********* **** *** ****** or ***** ****** ** ****** **** video?

Trust *********

***** ** *********, ** *** *** ever ** ******* **** * ******** is *** ******* * ********* ** a *******. ***** ******, ******* ***, "Show ** *** ***** **** ******* X *** * ********?" ** ******, when ***** ** ***** **** ******, the ******* ***** ** (** ****** because **** **** ** ******** ******** is * ****** ** ********). *** proving **** *************** ** **** *** companies *** **** **** *** ***** (as ********* *** ******* **** *** here). *** *** ***** ** ******* that ********* ** ******* ** **** or ******** ** ***** ** ******, etc. **** *** ***** *** *********. You **** ** ** **** ** trust **** **** **** ***, **** organization's ******, ***, ** **** *********, even ******'* *****.

Vote / ****

Comments (28)
UM
Undisclosed Manufacturer #1
Mar 29, 2021

* **** *** * ***** *******.

* ***** **** *** ******* ****** was ***** **** ********* ******* ********* could ** ********** ********* **** ******* and ***** ** *******. **** ********* customers********* ********** ******, **** ** **** didn't ********* ** **.

*** ** ******* **** ********* ********* didn't **** ***** ***** ******** ***** Verkada ***. ** ** **, **** makes ** ***** *** ******* ** well.

(25)
(1)
UI
Undisclosed Integrator #5
Mar 29, 2021

**** ** **** **** ***, *** since ********* ****-***** *** ******** * would ******** ** ***** * ****** worse? * ********** *** *** ******* that ********* *** ****, *** ****'* really ****** ******* ** **** **** huge ** * ****. ******* ***** to ** **** ** ******** ** negligence ** ******** ****** ********. * don't ***** ****** *** :)

(1)
UI
Undisclosed Integrator #7
Mar 29, 2021

** ***'* * ****...

(3)
(1)
U
Undisclosed #2
Mar 29, 2021
IPVMU Certified

(7)
(9)
UI
Undisclosed Integrator #3
Mar 29, 2021

** ***** *** ************* ***** ** most ******** *********** ***/***'*, *** *** servers **** ***** **** ******* *** be ********, ******** *** ***** ** the ******* ** ******. ***** ******* and ***** ********* *** *** **** access ** *** ******* ** ****** on, ***** *** ** **** ** serial ****** **** ******* **** *** units, ** **** * '*******' ** at * **** ***** ** *** firmware. *********'* ** ************* **** ***** the ********** ******** ******** ** ********* to ***** ***'*. ** *** **** verified ** ***** *******, **** **** OEM ******* **** **** ******* *** access.

******** ******* *** ***** ***** ******* providing ****** ****** ** *** ******* can *** ******* ****. *** ******* are ***** *** ******** ** **** from ********* ** *****.

***** ***** ******* *** ******* '*** door **' ******. ** * ****** obtained, ** ****** ******** ****** ** is **** (** ******** **** *******), access ** **** ** ******** *** client *******/*******/******** ** ******.

***** ********* *** ***** ******* *** serious *******, ** * ****** ** address ******** ****** ** **** *******. Once **, ***** ******* *** **** likely ** ******* **** ***** ****** to *** ******* ** ***** *** system *******.

**** *** *** ******** *****. ***** systems *** *** ******* ******* **** risks ** ******** ***** ****. *** industry ***** ** ******* **** *****, and ********* **** ********* *** **********.

** *** **** ****, **** ****** logins *** * **** *****, *** as **** ** *** ******** ****** in ****** ******** ** **, ***** is ****** * ****.

* ***-************ ** ******** ******* ******* would ** ** ********* *** ****** access *****. ** *** ** * pain ** ******, *** ***** ** worth ***********.

(1)
(2)
UI
Undisclosed Integrator #7
Mar 29, 2021

***** ** ****** ********* ********** **** the *******-*****... *** - " **'** incorporated * ***** *********** ******* ********** to **** ****. ** ***** ** fact, ***** ** ** **** ** document **." *** -" **, **, our **** **** ***** ** **** screened ** ** ****** *****? ** problem"

(1)
UI
Undisclosed Integrator #4
Mar 29, 2021

***** *** *** "**** **** *** utmost ******** ** *****" ******?

(8)
(1)
UI
Undisclosed Integrator #7
Mar 29, 2021

******* "********" ****. * ***** **** a "***** ** ******* ******" **** we ****** *** "******/**" *** ***** either/or *****'* ***, ** ******, * properly *********** ****.... *'** **-**** *** question *** ********-******* ***** **** ** be **** **** * ***** **** been ******* ****'* ***** ** ****.

UI
Undisclosed Integrator #3
Mar 29, 2021

****** ******** ** ***** -

***** ** *** ************* ** ***** that ** *** ******* ** ***** products. *** **** ********** ** ******** within ******* ********* ******* ****** *******, Security, *** ************* ******* ******** ** government, *************, **********, **********, *** ******* consumers.

******, ******, ****, *** **** ****** provide ‘*****’ ******** **** *** ** Code ***/** ************* ********** **** *** behind ********* *** ***** *** ***** network *******, ** ***** ** ******* ‘easy ******’ ** ***** *******. ** is *********** ****** ** ***, *** it **** ******** ********** ***** **** each ************ **** ***** **** ****** to **** ********* *** ******* ********.

** *** **** **** ******* ** truly ****. ********** ** **** ** big ********. ***** *** *** ******** added ** *** ***** ********, ** provided **** *** ******* ********** *** potential ***** ** *******.

*** ******** ******** *** ******** ** consumers ***** **** **** ****** **** ‘easy ******’ ** ***** ** ** able ** ******* *** ******* ******* that *** ** **** ******** **** commercial *** ******* ***********. *** ***** suspect **** *** ********* ********* ***** products **** **** *** **** **** vetting, *** ********** ******* ***** ********** with *** ***** *******.

** ***** ** **** *** **** to ** ** ******* **** ******** how **** ********** *****, *** *****, and ********. **** ** **** ******* provide *********** ** *** ***********, *** end ***** ***** ******** *** **** when ***** ******** **** ***** ***** technologies.

(2)
(3)
UI
Undisclosed Integrator #7
Mar 29, 2021

***, ** * ****'* ******* **** that * ****'* ***** ** #*, I ***** **** ******* **** ******** was ****. **** ********.

UM
Undisclosed Manufacturer #6
Mar 29, 2021

*** *** **** **** ***** *** Tricky-Verk **** ** ******* ***** ****** control *** **** ***********?

UE
Undisclosed End User #11
Mar 30, 2021

******* **** *** **** ******* ******* at ***** **. ****’* ********, ** Arizona, *** **** **** **** ** see * ******** ****** ** *** used ******* ****** ******* ***** ** open ******* *****, *** **** **** did **.

**** *** ******** *******.

UI
Undisclosed Integrator #7
Mar 30, 2021

"******* **** *** **** ******* ******* at ***** **. ****’* ********, ** Arizona, *** **** **** **** ** see * ******** ****** ** *** used ******* ****** ******* ***** ** open ******* *****, *** **** **** did **."

**** *******. ****'* *** ** ** the *******-**** ** * ********* *********....**** not ** *** ***** ******... * mean ********.

UI
Undisclosed Integrator #7
Mar 29, 2021

** *****'* ****** ***** *** ** worse; **** ** ** ** ****. Many **** (*** **** ***** ********/********* MFG's) *** ***** **, **** **** happened ** **** ****** ******. ****.

(2)
UE
Undisclosed End User #8
Mar 30, 2021

******* ** ********** ***** ******* ***** is ** *** ** ****** ******* it ***** *** ******* ****** ** secured **** *** ***** ******. *** TruHikVision ******* **** ******* **** *** world **** *** ***, ***** ** ACLs *** ***** ** ******* **** on ******* ***** **** ** ***** to/from *** *****. *** **** *** NVRs ******** ** ******* ***** ** view **** ***** ** *** ******* network *** *** ****** *********** *** is ****** ****** *********** **** ** only ******* *** ****** *** **** limited ****** ** ********* ** *** internal *** *** ***** *** **** or *** *** *******. ** **** if *** **** ********** **** * backdoor *** **** ** *** ****** would **** ** **** **** ******* employees **** ******, ****** *** ******* IT ********* ** ** ******** *** manages ** ********** ********** * ********** on *** ******* ***. *********, ******* we ***** *** ****** (*** ** Axis **...) ** ** ****** ******* since ** *** ********* **** * near **** ***** ***** ******.

* ****** ** ****** **** ***** when ************ *** *********** *** ***** both ********* *** ******* ** **** as ****** *******.

(1)
(2)
UE
Undisclosed End User #10
Mar 30, 2021

* ********** *** ***** ***** ***** be ***********, *** * ****** ** local ***** ***** **** **** *** illusion ** ********, ******* ****** ********* it. ** ***** ** * **** feeling ** ******** ** ***** ******* at ***** * ** ******* ***-*** external ******** *******. * ***'* **** the ***** ** ****, *** ** left ********* ** **** ** **** an ******** ** ********?

(1)
AM
Andrew Myers
Mar 30, 2021

******** *** ** ** ******** ** security ** ** ***'* ********** ********. With ******* *** **********, **'* ** to *** ** ********* ********. **** devices ******* **** ***********, **'* ** to **** ** ********* ** ********. Outsourcing ** * ***** ******** ** the **** ** ******* ********* ** too ****. *** ** **** ***'** outsourcing ** *** ***** ************.

** *** **** *** ********* (*********, money, *********), ***** ********** ****** *** to ******* **** *** ****** ******** cloud *** ******** *****. *** *** setup *********, *****, ****, ****** *******, monitor *** ******* ****, *** ** reasonably **** **** ** *** *** compromised **** ***** ******. **** ***** video, *** *** *** ** ** trust *** ********. *** *** ***** know *** ******* **** **** ******** doesn't **** ** ******** ***** ******** your *****.

(3)
(2)
UI
Undisclosed Integrator #9
Mar 30, 2021

* ***** ******** ** ***** ** it *** ***% ***********.

******* *** **** ****** **** ********** and *********. *** ******** *** *** intentional.

(1)
(4)
UI
Undisclosed Integrator #7
Mar 30, 2021

"******* *** **** ****** **** ********** and *********. *** ******** *** *** intentional. "

*** *** **** ***** ****? ** experience (** ***** ** ** ** many **********, **** ****** *** ******* sectors), ***, *** ******* ********, *** otherwise ** **.....

(1)
UE
Undisclosed End User #8
Mar 30, 2021

*** ** *******'* ****** *****, *************?

(3)
UI
Undisclosed Integrator #5
Mar 30, 2021

******** *** ***** ***** ******* *** a ******* ****** *** ****** *** intentional. ********* ** ********. **** **** have * **** **** **************** ** ***** ** ******* *** dinosaurs *** *****, *** **** **** **** *** them ******.

UE
Undisclosed End User #8
Mar 30, 2021

** * ***. *** ************* *** breach ** ***** *** ***********, ** was *** ******** ** *** ***** admin ******** **** *** *************. ******'* that ** **** ** *** ********* backdoor? ********* ****'* *** **********, *** they?

(1)
UI
Undisclosed Integrator #7
Mar 30, 2021

****** ** ***** *** **********. **** always ****** **** *****. ********* ** Vulnerability *** ********** *** *************. ******* to ******** *** ** ****** *** "tools" ***** *** ***** ** "*******" was ***********.

MM
Michael Miller
Mar 30, 2021

* ****** ***** *** ******** ******* comparison **** ****** ******* **. * have * *** ** ******** ******* but * **** ** ***** ********* wrong ******* * ***'* **** *** paying ** $**,*** * ***** *** maintenance *** ******* **** $**,*** * year ** ********.

IPVM Image

(1)
(4)
UI
Undisclosed Integrator #12
Mar 30, 2021

*** * ***** ****

******** ******

** *** ***** **** *******

(1)
(1)
UI
Undisclosed Integrator #7
Mar 30, 2021

*** ******** ******* *** *** **** been *********** (*** ****, *** *** cover-up). *** ***** ** ***, ** my *******, ***********. ******* *** ************* using ******* *** *********** ************ ******** to ***** **** ****** *** *********** nefarious *******. ********, **** **** ***** organizations *********** * ****** ** *****( if *** ******** *** ********** *** 3rd ***** *******). *** ********-*** *** the *****-**.

AM
Andrew Myers
Mar 30, 2021

* *********** *****. ******* **** ******* devices ***** ***** ******* ****** ****. In ******, *** ******* ***** *** give **** ****** ** *******, *** pwning * ****** ***** ****** * camera (********** ** *** ****** *** on * **** **** ** ****** have ****🤞).

*******, *** ******* **** **** ****** to **** **** ******* *******, **** Tesla *** **********. ********* ** *** camera *********, **** ***** ********* ********* espionage. *'* *** **** ** ******** has *** ********* **** *** **** prominent. *** *** ******** ****** ***** up *** ** ** *** ***** number ** ***** ** ****** **********.

(1)
Avatar
Hauke Kerl
Apr 07, 2021

Both *** ************.

*** ** *** ***** (******) ******** to ******* ******* **** ******* *** Hik ********. ** *** ***, ** companies *** ** ******* (***** **** at ********) **** *** ********* **** this ** *** ****. **** **** out *** *** ***** ************ *** everyone. (****** *******)

**** *******, * ***'* ****** **** what ** ***. ***** ***** ** be * *** ***** ***** ** the *******. *** ***** ****** ** a ******* *** ********* **** **** and *** ***** **** ** **** internal ******** ********. *** * ****** one! ** ***** *****, ***** ** a *** ***** **** *** ************.