How Verkada Locks You Out Of The Devices You Own

Published Mar 02, 2023 13:00 PM

While the risk of Verkada's "Hostage as a Service" business model has become well-known due to IPVM, the details of how Verkada locks device owners out are not.

IPVM Image

IPVM recently allowed our Verkada device's subscription to lapse to verify how they lock out cameras and what happens when users own Verkada devices but cannot use them. We also tested this with Verkada sensors (SV11 & SV25), access control, and alarm monitoring.

In this report, IPVM details and documents how this process works, including a video and multiple screenshots, and what problems a Verkada device owner faces without paying the subscription license.

Executive *******

****'* ******* ******** **** ******* ************** blocks ****** ** ******* *** **** video ******* ******* ******** ** **** they **** "*******." ******* *********** ***** upon ******* **** *** *** *********, revealing **** **** *** ***** ********** but ****** ** ******** ***** ******** have **** ****.

***********, ******* ********* ****** ****** ******* and ********* *********. ***** *********/************* ******* cannot ** ****, *** ******** ***** will ******** ***** ********** ********** ********. Users *** ***** ****/****** *** ***/****** sites. *******, ***** *** ** ******* added *** *******, * ********** ******** risk ** **** ** ****** ********* or ******** *** ******** ***** **** might *** ** ******* ** *********.

********, ******* ******* (**** *** ****) are **** ***** ******* ***. ****** are ** ****** **** ** ********** being ***/********. *******, *** ****** **** of *** ******* ******* ****** *********/***** operational, ****** ** **** ** ********* in *** ******* *** *********.

*** ******* ****** **** ****** ** functionality. *** ******* **** *** ***** works ** * **********/****** ********* *** existing ****** ******. *** ******* ****** app ***** ****** ***** ** ***/****** sites. *******, *******'* **** ******* ****** app *** ***-********** *** *** *** allow ***** ** *** **.

Full ******** ** ******* ********* **********

*** ***** ***** ******* *** ******* Command *** ********* ********* ******* ********. No ****** **** ** *********, *** all ***** ******* ***** ********, ****** the ***** ****, ***** *****:

Verkada ******* *************** ********

**** ********** ** ****** *******, *** Verkada ******* *** *** ******* ** load/populate ******* *** ~*-* ******* ****** showing ** ***** **** *******, "*****, there's ******* ****!":

IPVM Image

******* ********** ******* *******, ****** *******, intrusion, ** ************* *******, **** ** the ******* *** ******** ** *** Verkada ******* *** *** ******* ****** the ******* *******.

Locked *** *******

******* *** ******* ******* ********** *** normal **** ****** *** ********** **** the ****** ** ********* *** *********, they *** ****** ***:

IPVM Image

** *** ******* *********, ***** ****** view/access **** *******, *****, ********, ******, or ****** ********, **** *** ***** displayed ** ***** ***:

IPVM Image

********, *** ********** **** ****** *** expiration ** **** *** **********. *** example, ** ** ***** ********* ********* footage/events ******, ** **** *** ** an ******.

*******, ******* ****** ******* *** ***** streaming/recording ****** ***** ********* ******, *** all **** **** ** ******** **** licenses *** *********.

** **** ** **** ******* ******* are ***** ********* **** **** ******** to ****** ****. **** **** **** be ********* **** *** ****** ****** to *******, ** **** ** ***'** still ****** *** ********* ****** *** the ***** ******.

**** ******** **** ** ********, ** we **** **** ** ****** ********** recorded **** ***** *** ******* *** restored.

Limited ****** *******

***** *** ******* ******* *** ***** locked ***, *** ******* ****** ******* system ** ***. *** ***** ****** secure, *** *** *********** *** ******* function, *******/********* ******** *** *********/******* *********** (card *** ******) **** ******** ************** and *********** ******.

******* ********* ** ***** ********, *******:

****** *** ******* **** **** ***** work ** ******, *** ***’** ** unable ** ****** **** ******** *** Command. *** ****, ************* **** *******.

*******, ***** ********* *** *** **********, and ****** ************** *** *** *********. For *******, *********** ****** ** ***** or *******, *** ***** *** ****** Settings *** *********, ** ******** ****.

IPVM Image

Intrusion ***** *******

*** ******* ********* ***** *********, ******** users ** ***/******, ***** **** ************* continuing ** **** ** *** ********** admins *** *****. *******, ************** ********* are *******.

IPVM Image

*** *******, *** *****/****** ***** ****** be ********, *** ******** ***** ****** be *******.

*******, *** ***** ************ ****** ***** renders **** ** ***** ** *******, and *** **** ** *****.

IPVM Image

********/*** **** *******'* ********** ******** **** not ****/********, *** ***** *** ***** any ********** *** ***** *** ***** reviewed ** *** ********** *******, *********** dangerous ** *****/***** **** **** ** that *******.

*****, ******* ********** **** *** ******* can ** ****** *** *** ****-***** intrusion ***** **** **** ******* *********.

IPVM Image

******* ******** ** ******* ** *** access ** ***** ** *** ********* panel. **** ***** ** ** ********* on *******'* ****, ** **** ************** blocked **** **** ***** ** *** Command *********.

Environmental *******

**** *** *******, *** ************* ******* are ***** ****** ***, ****** **** display **** ****** *** ****** ********** the ******* *** *******, *********, *** recording ****.

***** ****** ****** ** **** **** from ***** *******, *** ****** ** previously ********** ********** ** *** *****. For *******, ************* *** *** **** due ** ****** ** *** **** or **** *******. *** ********* *** air ******* **** *** **** ***** in *** ******* *********.

IPVM Image

Verkada ****** **** ********

** *** ******* ****** ****: ******, Command, *** ****, *** ********* ********* varied *************.

** *** ******* ****** ***, **** could *** ****** *** ***, **** working/current *********** ******** ** *** *** version ** *******'* ******* ********.

IPVM Image

** *** ******* **** ***, **** could *** **, *** *** ****** app *********** ********/**** ********, ******** ** to ******/**** *** ***** *****.

IPVM Image

** *** ******* ******* ******* ****** Mobile ***, **** ***** ***/****** *** raise * ***** ***** ****** ** associated ***** ********* *** *********.

IPVM Image

Verkada's ********** *************

****** *** ******** **********/********** ** ****** to ******* *******, *** *******'* ******* team **** ****** ** *** **** Admin **** ***** ****** *** ***** email ********* *** **** ****** ***** lost.

***** *** * ******* ***** ******* the ******* ******* *** ***** ** expire ** ** ****:

IPVM Image

**** **** ***** *** ****, ***** was * ****** ********* ** *** Command ********* ******* *** ******* *** expired:

IPVM Image

********, ** ***** ******* *** ******* license *** *******:

IPVM Image

*******, *** ***** ******* *** ****** has **** ****, *** ** ******* licenses ** *** ** ** **:

IPVM Image

********* *** **** *****, * *** renewal ******* ****** *** *********, ******* access *** ****, *** * ******* contact *** ****** ** ******* *** renewal.

IPVM Image

Comments (30)
Avatar
Larry Adair
Mar 02, 2023

*** *** ******* ****** *** ** well? ** * ******** ******** ** cameras *** ******* ** ** **** a ********* *** (***** **** ******* Center) ***** ***** ******* ******* *** the ******* ***** ***** *********? ***** they **** ***** ******* *** **** on *** ***** ***?

(2)
MM
Michael Miller
Mar 02, 2023

** *** *** *** *** ******* hardware ** ***** *********. ** *** don't *** *** ******** *** ******** does *** ****.

(5)
(1)
JW
Jermaine Wilson
Mar 02, 2023
IPVMU Certified

** *****,

***, *** ******* *** ****** ***. In *****, *** ******* *** "****** in" ** *** ******* ********. ** you ***'* *** *** *** ********, the ******* **** *** ********.

** ******, ******* ******* *** ** added*** **** ****** (*** ****),****** **** *** ******** *** *******, you ****** ****** *** *******, *** they ****** ** ***** ** *** VMS *** **** *******, ***. **** are ***** ****** ***.

** ********* ** *** ****, ** saw **** ******* ** *** ********* panel, *** ** ******* **** *** an *********.

(3)
UI
Undisclosed Integrator #6
Mar 07, 2023

** **** ** *******, ** *** set *** ******* ***** ** *** RTSP ***** ** *** **********, **** they ******** ** ****** ** *** 3rd ***** *** ***** *** **********?

GH
George Hopkins
Mar 03, 2023

**** *** *** **** * **** expensive ***** ******* ***

(1)
DL
Daniel Lewkovitz
Mar 07, 2023

*** * **** ***.

(1)
(1)
UI
Undisclosed Integrator #7
Mar 07, 2023

*** *********** ********** *** ***** *** days.

U
Undisclosed #1
Mar 02, 2023

** * ****** ****** ** *******, I *** ******* **** *** ******* to ****** *** ******* ** ************ are **** ** *******. **** *** be ********* ** ***** **** *** end **** ** ** *** ****** sector *** ** *** **** **** to *** ******** ****** *** ****** cut ** * ******* ********.

(3)
JH
John Honovich
Mar 02, 2023
IPVM

**** *** ******* ** ****** *** licence ** ************ *** **** ** advance

* ********* ******* ****. *** ********* is *** *** ** *******'* *****. With ***** ***** ***-******* ********, *** manufacturer ****** **** *** *** ** the ******** *** ******* ***.

(2)
(1)
MM
Michael Miller
Mar 02, 2023

*** ****** * ***** **** **** in ****** ***:

IPVM Image

JH
John Honovich
Mar 02, 2023
IPVM

****, ******. *** ******, **** ** that ********** -**** ******* ***** ** *** ***** Customers?

*** *******, **** ******, *** ** not * ********* ********, **** *** access ** * ********* ******** ******. It ***** ** ********** ********* ** Milestone ** * ********* ******** *** that. ********* ****** *** **** *** do ****. **** *********'* ******* *******, if *** ***'* ***, *** ***'* get ****** ** ******* *****, *** your ******* *** ***** **** *** can ** **** *********.

********, *************, ***, ** ** **********, could ******* ****** ** **** ********'* systems *** **** ***** ** ********* from *** ************ ***** **.

(2)
MM
Michael Miller
Mar 02, 2023

* ***** ****** **** **** ******** to ************.

*** ******** ****** **** *** *** of *** ******** *** ******* ***.

JH
John Honovich
Mar 02, 2023
IPVM

*** **** ******.

UM
Undisclosed Manufacturer #3
Mar 02, 2023

**** ********, *** * ***** ***** in **** **** **** ********** **** a ****** ***** ***** ** *** Milestone ******** ****** ** ****** *** access ** (***/** ******* *** ******** so *** ******** ****'* **** **), then **** ** ** **** *** permissions *** *** ** ***** *****.

*'** ***** ** **** ********* ******, but ** **** ***** ********** ******* to ** **** ********* ** ***** software. ***** * ********** **** *** integrator ****, ********** * ***** *** action ** ******* ***** ***** ******* is *** ****.

(1)
(1)
(1)
JH
John Honovich
Mar 02, 2023
IPVM

#*, ***, ****'* **** **** ****** explained ***** ** *** ******:

*** *** ******* **** ****** ****** Milestone ********. *** * ******* ***** admin ******** ****** ******** *** ****** the ******* ****** **. **** *** zero *** ** *** **** *** camera ******, **** ** **** **** how ** ********** ********.

(1)
UM
Undisclosed Manufacturer #3
Mar 02, 2023

**** * *** * *********** ** a ************ **** * ***, **** or ***** * *** ** ******** ask *** **** ******* **** ***** system **** ** ********** *** ****** them *** ** **** ****. ** one **** * ****** ** *** definitely *** ********** ** *** *****, another **** ** * **-**** ***-****. But **'* * ******* *****, *****'* nothing ** ***** **, **** **** it ********* **** **** ** ********* their ****** **** ** *******'*, **** the ******* *******.

(2)
UM
Undisclosed Manufacturer #2
Mar 02, 2023

******* ****** *** ** ****** ******** in * ****** ** ******* ** you **** ******** ****** *** *** right ******** *****.

(3)
UM
Undisclosed Manufacturer #3
Mar 08, 2023

**** *** *** ********* * ************ should *** ******** **** ** ** view. ****'* * *******-**** ***** ***** IT ****** ****** **.

UM
Undisclosed Manufacturer #2
Mar 02, 2023

******* **** *** ******* ** *****. They ******** **** **** ***** *******, and ***** ******* *** **** ** used ** ***** ******. ** *** want ** **** ** * **** VMS, *** **** ***** *** *******, purchase ***, *** *********. ******** ***** / ******** *******.

(1)
(1)
JM
James Mifsud
Mar 02, 2023

***** ** ******* ** **** ***** get ** ** ******** ******* ** firmware ******** ** *** ** **** can **** ***** ******** **** *** Camera.

**** *** ** *** *** ** the ***, * ******* ******.

*** *** *** * ****, **** might **** ******** ***** ********** ** stop ****; ****** ******* **** **** sloppy ******.

(2)
JH
John Honovich
Mar 02, 2023
IPVM

*****, ****** ******** *** * ************* analysis ** *******'* ************** ** ****** ************* ******

***** ** *** *** *** ** load ***** ******** ** *** ******, he ************ ** ************ ** **** it *****, ** *******, ** ****** hard ** ** ********* **** ****.

(2)
UM
Undisclosed Manufacturer #3
Mar 02, 2023

**** ** **** * *** ******** a ***** ****. **** ****** ******* cameras ******** *** * **** ** five-year ******* ********* ******** ** ****** this ****, ** ***** **** ** opportunity.

*** ** *********** *** ********* *** possibly ******* **** ***** ****** ********** right-to-repair **** ***********. ****** **** *** much **** *** ****.

(1)
JH
John Honovich
Mar 02, 2023
IPVM

***** ** ****** ********* ** ******* here. **** *******, ** ** *** just ** ***** ** ******, ** is ** ***** ** *** **** cameras ******* ****** ****.

(1)
UD
Undisclosed Distributor #4
Mar 02, 2023

** * ********, **** ** ********* we ******* *********** **** ********* ******** times. **** ********* *** *** * fit *** ******* *** ***** *** those *** ***** **** **** *** pretty *****. ** **** **** ***** products **** *** **** ****** *** have ***** *** ** ***** **** Verkada ******* *******. **** *** *** subscription? ***** ****** ******.

(2)
UI
Undisclosed Integrator #5
Mar 02, 2023

** * ******* **** - * don't ***** ****** *** ** ***** with **** ******** *** ****** ** you *****'* ****.

*** ***** **** **** * ******* is **** *** ******* *** ******* unless ******* **** ********* ** **** all ***** ********* ****** ****'** ****** forced ** ******** ** ******* ****** the ******* ********* ***** ** ** a ********* ******* ** *** ******** again.

**** ***** ****** ** *** ***** sites ** ******* **** ***** **?

JH
John Honovich
Mar 02, 2023
IPVM

*** ******* *** ******* ****** ******* says *********

** ********, ** *** ***** ****** if ******* ******* ******* ****** ** the ****** ****'* *** *** ** would ** * ********** ********* ********* if ******* ******** **** **** **** access ** **** **.

(4)
JH
Jay Hobdy
Mar 03, 2023
IPVMU Certified

*** ******* ******* (*'** ***** **** may **** ***** ********** ******* ****)

********

*****

*****.*** ******

****** **** *** **** ****** ** those ******* ** *** **** ***. I'm *** * ******* *** ** any ***** *** ****'* *** **********?

(3)
(1)
MM
Michael Miller
Mar 03, 2023

* **** *** *** **** ** try *** ******* **** *** *** cameras *** **** ** ** ***** cameras *** ** ** ***.

IPVM Image

(3)
MS
Mark Schweitzer
Mar 07, 2023

*** *** **** *** *** ***** access *** ******* **** **** **** if *** ** ****** *** *** the ***** ********. *** ****** *** access ******* ******* **** *********** ********.

****** *** *** ******* **** **** this *** **** ** *** ***'* pay *** *** ***** ************ *** lose ******.

SD
Shannon Davis
Mar 08, 2023
IPVMU Certified

IPVM Image