Verkada Revokes Global Admin Access To Cameras, Says Requiring 2FA 'Excellent Suggestion'

Published Mar 25, 2021 16:36 PM

Verkada's CEO confirmed yesterday that they revoked 'global admin access' to cameras, which the company hid from their customers for years. Moreover, Verkada's CEO said that requiring 2FA on these accounts was "an excellent suggestion."

IPVM Image

Filip Kaliszan, Verkada CEO, held his second AMA for customers yesterday amid continued fallout from a massive hack two weeks ago.

Super *****/"****** *****" *******

*******'* *** ******* ********* **** **** concerned ********* ******* ************ **** ******* would *** ******** ** **** ******* without *******. *** **** ******** *******'*********** *** ** ***** ***** ***********, ******** >*** ********* ********* ******* to **** *********' *******.

*******'* **** ** ********* ****** *** question:

**** ***, *** ****, ***** ** a *** ***** ********, *** *** global ***** ****** ** *******, *** how ** *** **** ** ***** who *** *** **** ****** ******* with ***** ***********?

*******'* *** ********* ********** **** **** was *******:

So *****, *** ****** - *** ****** ***** ****** - ** ******* *** **** *******. And the only people in our organization that have access to the admin rights are the few folks that are the most senior, and the engineering team that are conducting the investigation and need to access logs on cameras and kind of carry out their investigative tasks. [emphasis added]

***** ********** ** ******* ***** ***** access ******** *******, ******* ********* **** again.

**'* ******* **** *******. ** * think **'** ******* ** **** ********, but **** *** **** *** **** revoked, ******* **** *** **** ****. Yeah, *** ****** **** *****'* *****.

Intern ****** *********

******* **** ********* **** ******* *** access, ** ***** **** **** ****, saying ****:

***** *** **** ****, *** ****, talk *****, *** ****, *****, *******, interns ****** ****** ** **. **** is ****. *** *********** ******* *** are **** **** *********, *** *** we *** **** **** *** ***** engineers *** ****** ** **** ****, and ***** *** ** ** **** on, *** ****, ** ******** ******

2-Factor **************, "** ********* **********"

* ******** *****, "**** *** ***** accounts **** ** ****** ******** ******* require ***?" **** *******'* **** ** marketing ****** "**'** ***** **** ***** a ***". *******'* *** *********:

****. ** *****, ****'* ** ********* suggestion, * *****, *** ****, ***, the ***** **** * **** **, again, ****** ******** ** **'** ******* at, *** ****, *** ***** ******** of ****** ** ******, *** ****, any ***** ******** *** *** ******* accounts.

** *******'* '****** ***** ******' ******** had ******** ***, **** ***** **** either ******* *** ****** ******** ** made ** *** **** ********* ** access *******'* ********.

***** ** ***** **** ** ** an '********* **********', ** **** ********* that, *****, ******* *** *** ******* require *** *** **** ******* *** able ** ****** ** ********* **.

** ******* *** ** ******* ** this ***** *** *** *** ******* a ********.

"How **** *** ****** *** ***** **** *** **** **** ** ******?"

** ******** **** ********'* ******* ****** District, * ******* ********, *****:

* ******* ***. *** ** **** customers ******* ***. *** **** *** repair *** ***** **** *** **** lost ** ******? ****'* ****, * have **** * **** ******** *** Verkada ******** ***I'm ********** *** ***** ****** *********** *** ******** ******** *** ****** ** *******. ** ********** ** *** ******* **** ***** *** * ********* *** ******* ** ***** ******* ** ****. *** *********** *** **** *** *** *** **** ********** *****, ****'** **** *** ****. How do you respond to that comment? [emphasis added]

*******'* *** *********:

****, * ****** ** ******. * mean, * *****, ****, ***** ** all, ***** *** *** ***** ** advocate ** *** ******, ** ****** appreciate ****, *** ****, **** ***'** been ** ******** ** *******, ***, you ****, *** *** ***** *** what ** ***** *** ***. * think, ** **** *** * **** a ********** ****** ** ************** ** you ** *** ********* ** ******* on *** ** *** ******** ** make **** ******* ** *** ********. I ***** *** **** * *** offer ***, *'** *******, *** ****, kind ** ****** ** **, ** my **** **** **** * ***** was ***** ** **** ***.

"They ******** **"

*******'* *** ********** ** *** ******* of *** **** * **** **** they **** * ******:

**** ***** ** ****** ********* * crime, **** ******** **, **'* ** international ********* ***** ** *********, **** attacked **.

Recorded ***** **** *

***** ** *******'* **** * '*** Filip ********' ************ ********:

**********

** ******* ****** **** *******, ** becomes ***** **** ***** *** ********** (allowing ********** ****** ***** ****** *** not ********* ***), *** ******** ** this ********. ** ******* *** **** as ********* *** ****** ** ************* as **** ********** ********, **** ***** have **** *******.

*******:

(**/**/**): ******* *** *** *********** ****** use ** ***** ***** ********. **** have ********** *** *** "******* ********** System" *******, ***** * ******** *** use ** ***** ******* ***** ****** to ***** ********. ** ******** *** customer ** ******* ******* ***** **** a ***-**** **** *** ****** ** be *******. ***** ******* **** ******* * ****** ******* **** ****.

(**/**/**): ** * ******** *******, *******’* CEO ****** ******* *********** ***** ***** response ** *** ****:

  • *** ****/**** **** ********* **** ** conducted **** ****. **** ********* ******* hiring *****-***** ******** ******* ** **** and ******* ***** ***************.
  • * *** ****** ******* **** ** launched ****** **** *** ******, ********* individuals **** ***** ************* *************** ** Verkada’s *********.
  • ********* **** **** *** ******* ** access/download **** ********** **** ***** ******* within *** “**** ****** *****.”
  • *** ** *** **** ** ******** for ******* ******* *****.
Comments (44)
JH
John Honovich
Mar 25, 2021
IPVM

******* * ******** ***** *** **** how ***** ** **. *** ******** guard ****** *** **** ********, ****** a ******* ** ******* **** **** on *** ****, *** **** **** to *****. **** ** **** ****** and ********* **** ** ** *** victim.

**** ** **********. **** ** *******.

(25)
(2)
UI
Undisclosed Integrator #17
Mar 30, 2021

***** *** **** **** ***** **; these ***** **** *** ******. **** up *** **** ************* **** *** you **** **** **** ** * much ****** *******. ********* *** ***'* strike *** ***** ***** ** *** wrong ****** ** ******, ***** *** way......

DS
Derek Schartung
Mar 25, 2021

"**** ********* *** '********* **********'"

**********.***

(9)
UI
Undisclosed Integrator #1
Mar 25, 2021

* **** * ******* ********** *** the ********. *** ***** ** ***** apply ** *******, * ***** ** can ** ******* **** **** *******:

* ***** ************ ********** *** ********** superadmin ****** ** ******** ******* *** says **** **** ****** *** *******. Instead, **** ******** ****** *** ******** and ******** *** **** ***** ****** employees ** **** ***** **.

*** **** *** **** **** ***?

(8)
UM
Undisclosed Manufacturer #3
Mar 25, 2021

**** * ****** **** ************ ****** like ********* ***. **** ** *** that ******** ***** ********** ** ***** open *** ****** *** ******** ****** to **** ***** ****** **** ****** to ****** *** ****** ******.... ;)

(3)
UM
Undisclosed Manufacturer #5
Mar 25, 2021

**** ** *******, *** *** ****** that ********* (****** ***** *****) ***** have ****** ** ***** ********'* *******? I ******** ***** *** ********** *** answers **** *****.

(7)
UI
Undisclosed Integrator #1
Mar 25, 2021

**. ** ***** **, **** ** they *** **** **** ******* *** account, ***** ** ** *** ** tell ** **** *** ******* *** truth (****** *****'* * ************* ** another ****). *** **** *******, ***** is ** *** ** **** **** for******** **** **** ************.

(3)
UM
Undisclosed Manufacturer #5
Mar 25, 2021

**. **** *****.

UI
Undisclosed Integrator #17
Mar 30, 2021

******** ** ** ********** ** ********.

(1)
U
Undisclosed #2
Mar 25, 2021

**’* ***** ** ** *********** **** the **** *** ***** ** *** where *** “**** **** *** ***** things” ******* ****** *********** ***** *** where ** *****’*.

**** ******** ******** **** ** *** at *** ** ** *************. **** deal **** **** **** ****** *****’* show ***** **** ******** **** **** too. *** **** ********* *****’* ***** you ** ***** *** ***** *** wanted ** *** ** **** ******** camera ******* ‘************’ ****** *** ******* access **** **** **** ********** *** services **** *** ** ****** ********/********?

(3)
(2)
Avatar
John Bredehoft
Mar 31, 2021
Bredemarket / Incode Technologies

"**** **** *** ***** ******" *** (at ***** ** ******) **** ** the "*****" ** *********** ********* ** rigorous *** - ** *** ********, then ** ***** ** **** ******* fashion. *'* *** **** *** ** address ****** ** *********** - *** example, **** ********** "*****" ************* *** required *** * ***** ******* *** or * ******** ******?

(*********** *** ****** ** ********** - if *'* ****** ** ******, * food ******** *** ******* *** ** perceived ** ****** *** ******* ********.)

*** *******, "**** **** *** ******* things" ** ** ********* ** **********. There **** ****** ** ******** *** software ******** **** ** *** **** when "*****" ****'* ***** ** * process.

UI
Undisclosed Integrator #4
Mar 25, 2021

IPVM Image

(4)
(29)
UM
Undisclosed Manufacturer #6
Mar 25, 2021

** *****'* **** ** ** ******** to ****-*** ******* *****.

*. *** ** ******** **** ********. Has ******* ** ** **** ****** of ****-*** ****** ***** ****** ** all ******** ******** *** *********** ****** access.

*. ** **** ******* **** ****** to ** ******* **** * ***** (cloud-initiated ******), ***** ** ***** ** centralized ********** ** *******. ***** ** going ** ** **** ********** ** and ********* ** ****** *******. ** such **** ***** ** ****** **** user *** *** ******** ****** *** root *** *******.

*. ** ******, ***** ***** **** ground ** ** **** ******* ***** and *********** ******** **********, ** ***’* be **** ** ****** **** *****. You ***** **** ** **** ***** backed **********.

(8)
(2)
U
Undisclosed #10
Mar 25, 2021

*. ** ******, ***** ***** **** ground ** ** **** ******* ***** and *********** ******** **********, ** ***’* be **** ** ****** **** *****. You ***** **** ** **** ***** backed **********.

IPVM Image

**** ** ******* *****:*** ****** ********* ** ***** **- *** ***** *** **** ** himself **** ** ***** **** *** thing *** ****directly ******* *** *** ******** ** *** **** **** ********:

"So *****, *** ****** - *** ****** ***** ****** - ** ******* *** **** *******. And the only people in our organization that have access to the admin rights are the few folks that are the most senior, and the engineering team that are conducting the investigation and need to access logs on cameras and kind of carry out their investigative tasks. [emphasis added]"

(5)
(4)
UE
Undisclosed End User #14
Mar 27, 2021

*****, ** ************ ******* ** *** same ********.

(1)
MB
Matt Bartenhagen
Mar 29, 2021

****** **** **** ***** ****** *******. Unless ** ****** **** ******, ****** want **.

(3)
(4)
U
Undisclosed #7
Mar 25, 2021

** ** ****'* *******. ****** *** limited. *** ** ***'** ***** ********, the ********* ************* **** **** ****** eventually. *** ***** ****** ****** ***'*. So **** ** *** ******* **** will *** ** ***** ** **** those ****** ****** **** ****** *** admin ****** ** **** ****** *****? What ** *** ******* ** **** that ******* **** ****** ** **** coded ** ************** *****?

*'* ******** *******.

(8)
UE
Undisclosed End User #8
Mar 25, 2021

** *** *** *** ***** **** drank **** *** *********, **** *** have *** **** ******** ** **** CDSD ******** *** *** *** * tarnished ********** **** ******* ****** ****** no ****** **** **** **** ** Verkada ****. **** * **** ************ with * ******** ****** ****** ****** ones **********.

*** *** **** *** **** ** the ***** "********'* " **** ***** have *********** *** ***, ** *** the ******* ** *** **** *** only ***** **** *** **** ****** solution *** *** ***** ********* ** their **********. *** *** ***** ** said ** *******, ****** **** ****** his *** *** *** ****** ****** engineering **** * **** ***.

** ******** **** ********'* ******* ****** District, * ******* ********, *****:

* ******* ***. *** ** **** customers ******* ***. *** **** *** repair *** ***** **** *** **** lost ** ******? ****'* ****, * have **** * **** ******** *** Verkada ******** ***I'm ********** *** ***** ****** *********** *** ******** ******** *** ****** ** *******. ** ********** ** *** ******* **** ***** *** * ********* *** ******* ** ***** ******* ** ****. *** *********** *** **** *** *** *** **** ********** *****, ****'** **** *** ****. How do you respond to that comment? [emphasis added]

(4)
UM
Undisclosed Manufacturer #9
Mar 25, 2021

****'* ** ******** ...

** **** *** * **** **** was **** ** ******* ***** *********, and **** **** ****** ** *** - *** ** **** ******* ***** customers ***?

(1)
(2)
JH
John Honovich
Mar 25, 2021
IPVM

**** *** ***** ****, *******'* *** explained *** ******:

*** ****** **** *** **** ** our ******* **** ** ******* **** of ***** *****, ************, **** *** you ****, *** ** ****** ***** operation. ** *******, *** ****, ******* might ** ******* *** ****** *** to ****** ***, *** ********* *** transition **** *** ** ***** ****, I **** ** **** ** ******* to **** ************ ****** ** ***** mode. ****'* * ***** ********* **** our ******* **** *****, *** ****, might **** ** ******* *** *** customer.

***** ******:

** **'**, *** ****, **'** **** of ********** **** * ***** **** and * **** **** **** ** how ** *********** **** ** *** functionality *** ******, *** ****, ****** the ***** *** ******* ** ** able ** **** *** ****, *** know, **** *** ****** **** *** might ****.

UM
Undisclosed Manufacturer #5
Mar 26, 2021

***** *** * *** ** "*** know" ** *** **********. ** ****** speaking ********* ***** ** ** ***** with **** **** ** ******. ***** a *** ***** *** ** ** a ****** **** ************.

(2)
(1)
UI
Undisclosed Integrator #1
Mar 26, 2021

**** **** ***, ***. **** **** are *** ***** ** *** **** you **** * **** ******* *** you **** ** *** ******** **** knows ** *** **** **** ****** about **? *** ***** "*** ****"* sound **** * ******* ***. * don't **** *** ******** ** ***.

UM
Undisclosed Manufacturer #12
Mar 26, 2021

* ****** ******* ***** ** * long ***...*** ****

(6)
(5)
UI
Undisclosed Integrator #17
Mar 30, 2021

** ****'* * *******; ** *** intentional. **** *** "*** *****"...

UM
Undisclosed Manufacturer #3
Mar 26, 2021

***** * *** ***** *** ** be * ****** **** ************.

*** ****, *** ***** ***** **...

(5)
JH
John Honovich
Mar 26, 2021
IPVM

** ********,****, *** ********, ** *** **** person ******* *******, ********* ** ******** sources. **** ****** ** *** *** answering ***** *********.

(1)
(1)
UM
Undisclosed Manufacturer #13
Mar 26, 2021

*** *** ****** *** ******* ****** ensures ** *** * ****-*** ** place.

**** ** *** ***.

(2)
(5)
UI
Undisclosed Integrator #17
Mar 30, 2021

****...."*** ****"....

UI
Undisclosed Integrator #17
Mar 30, 2021

*** ****, *******, *** **** ******** in ******* ** *** ****, **, you ****, ********** ** *, *** know, ************ *********. **** ***'** *** good ****** ** *** ****, ***** dishonest, **** *** ****, **** **** let's ******** *** ****, ****. *** know?

(1)
(1)
U
Undisclosed #10
Mar 25, 2021

** *****, *** ****** - *** global ***** ****** - ** ******* has **** *******. *** *** **** people ** *** ************ **** **** access ** *** ***** ****** *** the *** ***** **** *** *** most ******, *** *** *********** **** that *** ********** *** ************* *** need ** ****** **** ** ******* and **** ** ***** *** ***** investigative *****. [******** *****]

**'* *** ****** *** - ******* they ***'* **** ** ***... ******* it ** ********* *** ******* ** senior ********** *** *********

(5)
(3)
UI
Undisclosed Integrator #17
Mar 30, 2021

** ***'* ********. ****'* ***.

(1)
UI
Undisclosed Integrator #11
Mar 25, 2021

*** ******, *** ****!

IPVM Image

(10)
UM
Undisclosed Manufacturer #9
Mar 26, 2021

$** ****** *** ****!!!

(1)
UI
Undisclosed Integrator #1
Mar 26, 2021

**** *** ** ****** *** *** Charlie ***** *** ** ****** ****, too

(4)
(1)
SC
Sean Chang
Mar 26, 2021
Rasilient Systems

* ** ****** *** **** ***** Verkada's ********* **** *** ****. **** allow *******, ** *** "***** *******" 3rd *******, ** **** ** **** outside ** *** ********** ********. ** is * **** **** ********** ** 2FA ** *** ******** *****.

******** *** *** **** ***** "******-***** cybersecurity" ******* ** ** **********-**** **** and **** **********. ***** **** ******* when *** ******** **** ******. ***, something *** ******** ** *** *********** to ** ******. **** ** ******* no-no.

* ** **** ** **** **** more ***** **** *** "***** *******" deployments.

(5)
UI
Undisclosed Integrator #17
Mar 30, 2021

***** ** ***** ***-******. **** ** is, ** "***** *********"

UE
Undisclosed End User #15
Mar 29, 2021

*** ** **** ******** **** ******* when **** **** ** *** *** result ** ******? ** ** *** user, ****** ** ** ***** **** when ******* ***** ******* ** *********. not * **** ****

(3)
(1)
UE
Undisclosed End User #14
Mar 29, 2021

*** ** ********** **** *** **** timed. * **** **** ******* ******* pushing ******** ******** ******* ** *** cloud *** * ****** ** *******, one ** ***** ** *** **** of ******* **** *** *******, ******** and *******. * **** **** ******* of ********* ****** *** ********** * level ******* ** **** *** ******** services **** *** *****.

* *** ****** ** *** ********. Now ***** * **** ** **** as *** ********* **** * ***** am.🤪

(6)
(1)
UI
Undisclosed Integrator #17
Mar 30, 2021

"* *** ****** ** *** ********. Now ***** * **** ** **** as *** ********* **** * ***** am.🤪"

-******.

* ***** **** *** "**********, ******** thinker"

UM
Undisclosed Manufacturer #16
Mar 29, 2021

** ** ***** *** **** ******** entity **** ** ********** **** ** prior ******** ******** ********** ******* **** to ******. **** **** **** **** thinking *** **** *** ** **** was *** *** **** ******* **** were **** ******** ****. *************, **** also ********* *** ***** ********* *** are ***** ** *** ***** *** with *** *********** ******** ** *****. 2FA ** *** ** ******* ******** that ****** ** ***********. *** ******* one ** ** *** *** *** User ********* *** *** **** ****** to ***** ******. ******** **** ******* is ** *** *** ** ********** service ** ******** * *** ** is ******* ************ ** **** ******. *** ***** would ** ** ** **** *** into **** ****** *** **** **** guy ******* ** **** *** ******* your *********. ********** ** *** **** turns *** *** ******* * ***** this ** * ***** ****** ***** for *** ****** ********. *** ********* this **** *********** *** **** ******* from *** ******.

(2)
UI
Undisclosed Integrator #17
Mar 30, 2021

** ****'* ** ********...

CH
Conor Healy
Apr 07, 2021
IPVMU Certified

**** ****** *** **** ******* ***********'* **************** ***** ***** ******** **** ** longer ** ****, *** ***** ************ of * *** ******* *** ********* to ***** ******* ****** *** ******* staff.

CH
Conor Healy
Apr 15, 2021
IPVMU Certified

(**/**/**): ** * ******** *******, *******’* CEO ****** ******* *********** ***** ***** response ** *** ****:

  • *** ****/**** **** ********* **** ** conducted **** ****. **** ********* ******* hiring *****-***** ******** ******* ** **** and ******* ***** ***************.
  • * *** ****** ******* **** ** launched ****** **** *** ******, ********* individuals **** ***** ************* *************** ** Verkada’s *********.
  • ********* **** **** *** ******* ** access/download **** ********** **** ***** ******* within *** “**** ****** *****.”
  • *** ** *** **** ** ******** for ******* ******* *****.
CH
Conor Healy
Apr 22, 2021
IPVMU Certified

***** **** *********'* ******* ******* *****. Verkada's *** **** * ***** ** what *** **** **** ** ******** to *** ****, *** **** **** Verkada ** ***** ** *** ******.

Recap ** ******* ******** ** ****

  • ******** ********** - **** ****** ***** to ***** ** ********* *****, **** locking **** ****** **** *** *********, and ***** ** ******** ************* ** what ********.
  • ******** ************** - "**'** **** * ton ** ******** *************," **** ********* all ********* **** *** **** ********.
  • ******** ********* ***** - *** * firmware ********* ***** *** *** ******* on *** ******* ******* ******* ********* were ****** ** ***** ******* *** been ***********, ** ** *** **** had ****** ** ***** ********.
  • *** ******* ********** ****** ******** - Revamped *** ******* ***** ***** *** path ** ********* *** ******* *** support ****. ******* *** **** **** that ******* ****. ***, ** ******* you **** * ******** ***** *** can *** ** ****** ******* ******. When *******, ******* ****** *** *****, they *** **** **** ******** *******. [In * ******** *******, ******* **** support *** *** ***** *** *** customer **** ***** * ****** ** give **********]
  • "******** ******" **** - ******** ********* visibility **** ***** ****.
  • ********** **** *** *** - ******, customers *** ** ******* ******* ** set **** **. ***, ********* **** "full *******" **** *** ** *** changes, ***** *** ** ******** ** Command.

Coming ** *** ******

  • ******* ***-**** **** ****** - **** better **, ** *** *** ******** logs, ***** ****, ********, ***.
  • *** ********** ****
  • ******** ******** *********** - ********* **** be **** ** ******* ******** ******** for *** ***** *****. *** *******, forcing *** ** *** *****.
  • ********* ******* ****** ************* - ***** will ** ** ****** ** ****** customers ******** ******* ** ********* **** account, ***** ***** ********** ******** ***** permission **** *** ********.
  • *** ************* - ** ******** ** support ******, ********* **** ** **** to **** ** *** ************* ** various ****** ** ***** ****
  • ******* ******* - ******* **** ***** customer ******** *** **** *********** *** best *********

***** ********* **** **** *****. ***** are *********, *** *** ****** ******.

********: *** * *** ********* ** writing ****** *** ****** *** *** compromised?

******: ***, ***** *** *********@*******.***.

********: ** *** ****/*** *** **** diverting ********* **** **********? ** ** going ** **** ************** ****** ******* of ****** ** ******** *********?

******: ***, ******* *** ******* ********* to ******** ** *** ****, *** "innovation ********* ** ********."

********: *** ******* ** *** ******** for *** **********?

******: ******* ** ******** ******* ** it, *** **** *** **** *** updates ** *** ********. *******, **** expect ** *** * *** * type *********** *** ****** **** ********* can **** "***** **** ****."

********: **** **** *** ******** ****** come ***? [******** ** *** *****-***** firm ***** ** ******* ** ******* an ************* ** *** ****]

******: ** ******* ** **** **** will **** ***.

(1)