Live data from Hacker News

New security camera compromised by worm within minutes of installation

twitter.com

91–94 of 94 posts

Re: New security camera compromised by worm within minutes of installation

#91
post #36

Earlier quoted context omitted.

Take a look at Axis Secure Remote Access solution for a way to avoid port forwarding (with its issues) and still get remote access, basically no configuration at all except from actually initially adding the camera to your site. Only works on Axis cameras though with Axis client software I should mention.

That's essentially using their servers as a middle-man. Which raises the question: why would one trust Axis to build servers that withstand attacks but not to build cameras that do the same?

It's still end-to-end encrypted though. Going through their servers it is in case peer-to-peer isn't possible to setup, otherwise it's a direct encrypted link between you and your camera (with client+server certificate validation) without any mediator servers.

Regarding servers vs cameras: To oversimplify; servers can have exponentially more capacity. Either how, in this case, the traffic is encrypted in each end so there's nothing to be done by "the middle man servers", they can't decrypt anything cause they don't possess the keys.

Re: New security camera compromised by worm within minutes of installation

#93
So I'm in the business of wheeling and dealing in these things.

It's common knowledge in the industry that all of these devices likely have government backdoors or (likely deliberate) critical security flaws at any moment.

Virtually all CCTV hardware comes from ruthless and unregulated Chinese markets where the goal is to obfuscate the price (and source) as much as possible, to prevent price discovery by the end user and allow 2-4x markups on the equipment by the integrator.

Usually these manufacturers will sell to separate companies for their name brand, off-brand, and offer custom branding to distributors.

Due to the obfuscstion of manufacturing source, and at the same time a desire to "stand out" amonst the rest, the industry is rife with knockoffs, third-shift products, stolen technology, unauthorized distribution, you name it.

As an example: Every single Hikvision camera on amazon.com is an illegal sale and void of any official support from Hikvision. Go ahead and try to call them with a serial number for a product you bought on amazon and see what happens. It doesn't matter that the company selling the product on amazon is also named Hikvision (its an imposter).

Point being, the surveillance camera market is so rife with corruption that you generally accept that everything is compromised.

But none of it matters, because as long as the features work and the equipment is reliable, you simply throw it all behind an isolated network and call it a day.

Re: New security camera compromised by worm within minutes of installation

#94
post #80

Earlier quoted context omitted.

Yes, in fact I have my own modem. When I bought this one, it seemed to be the only 4G modem with dual antennas, ethernet ports & wlan.

Then you knowingly bought a combo shitbox. There have always been quality consumer wireless access points, modems, and routers available, but you chose to buy the combo shitbox.

I knowingly bought the only device that will get me to the internet while having good antennas.
Post reply on HN