Live data from Hacker News

Romanian Hackers Infiltrated 65% of DC Outdoor Surveillance Cameras

lite.cnn.io

31–40 of 88 posts

Re: Romanian Hackers Infiltrated 65% of DC Outdoor Surveillance Cameras

#32
post #26

Earlier quoted context omitted.

> . We weren't that talented, but one of the guys in our group was still able to get into the cameras in the parking lot of the CIA. Well, by now, 16 years later perhaps you will have learned about the concept of honeypots.

How do you imagine a camera honeypot at the CIA parking lot? They'd still be leaking a lot of information if the image was true.

Did they go there in person and verify it's an actual CIA parking lot?

Re: Romanian Hackers Infiltrated 65% of DC Outdoor Surveillance Cameras

#33
post #20

Earlier quoted context omitted.

A big factor might have been ISP-provided routers coming with random passwords printed on the underside of the router instead of uniform defaults. The same tactic would work with many IoT devices but the incentive isn't there.

What incentive pushed the manufacturers of those routers in that direction though?

Torrenting and child porn, I would guess. I remember the slow transition from people using open networks to securing the shit out of them, and there was this big fear that someone could use your network to download copyright-protected and/or illegal material, and it would be tied to your IP.

Re: Romanian Hackers Infiltrated 65% of DC Outdoor Surveillance Cameras

#34

When I was an irresponsible high school grey hat (2001) I was part of a small group of people that shared exploits. We weren't that talented, but one of the guys in our group was still able to get into the cameras in the parking lot of the CIA. This is the problem with cyber security: Even if you're the most knowledgeable organization on earth you still fuck it up. Any one person can fuck up any one thing and if it i…

I agree with the rest of your points, but that "shitty" high school hacker managed to hide his identity from CIA. You're underestimating him. Majority of wannabe hackers would screw up some detail and get discovered.

"Hiding your identity" is a relative premise, not an absolute one.

Re: Romanian Hackers Infiltrated 65% of DC Outdoor Surveillance Cameras

#35

When I was an irresponsible high school grey hat (2001) I was part of a small group of people that shared exploits. We weren't that talented, but one of the guys in our group was still able to get into the cameras in the parking lot of the CIA. This is the problem with cyber security: Even if you're the most knowledgeable organization on earth you still fuck it up. Any one person can fuck up any one thing and if it i…

> This is the problem with cyber security: Even if you're the most knowledgeable organization on earth you still fuck it up. Any one person can fuck up any one thing and if it isn't part of your predetermined threat vector analysis then it gets through and you lose everything.

It isn't just cyber security but surveillance infrastructure in general. If you cultivate a large group of surveillance assets (even people) with a method of collection that can be effectively attacked, you are creating something worth the effort to attack.

By creating a position that can be attacked, you will get attacked. And given enough attacks you will get attacked successfully sooner or later.

It is safer to not build the surveillance apparatus in the first place because you _always_ lose control of it sooner or later.

Re: Romanian Hackers Infiltrated 65% of DC Outdoor Surveillance Cameras

#36
Cyber security issues are only recently becoming a point of awareness in the surveillance industry.

Some manufacturers have hard-coded backdoors/authentication bypasses, any vulnerable devices spread across the US, and the rest of the world.

Here is an example of one vulnerability from one larger manufacturer (Hikvision): https://ipvm.com/reports/hik-hack-map

Re: Romanian Hackers Infiltrated 65% of DC Outdoor Surveillance Cameras

#37

When I was an irresponsible high school grey hat (2001) I was part of a small group of people that shared exploits. We weren't that talented, but one of the guys in our group was still able to get into the cameras in the parking lot of the CIA. This is the problem with cyber security: Even if you're the most knowledgeable organization on earth you still fuck it up. Any one person can fuck up any one thing and if it i…

I agree with the rest of your points, but that "shitty" high school hacker managed to hide his identity from CIA. You're underestimating him. Majority of wannabe hackers would screw up some detail and get discovered.

Or, since he's taken steps to protect his identity, CIA might have offered a fake job offer for the purpose of him revealing his identity.

Re: Romanian Hackers Infiltrated 65% of DC Outdoor Surveillance Cameras

#38
post #26

Earlier quoted context omitted.

> . We weren't that talented, but one of the guys in our group was still able to get into the cameras in the parking lot of the CIA. Well, by now, 16 years later perhaps you will have learned about the concept of honeypots.

How do you imagine a camera honeypot at the CIA parking lot? They'd still be leaking a lot of information if the image was true.

Not if the DVR is actually in their lab and video inputs are fed with streams coming from a place where trained personnel will show only what they want to show.

Re: Romanian Hackers Infiltrated 65% of DC Outdoor Surveillance Cameras

#39
Too many cameras exploits in the wild these days indeed.

Need a OSS system for the cameras, just like OSS firmware such as Openwrt to replace vendor firmwares.

Camera itself does not have enough resource to deal with DDOS or brutal-force attach or updating-with-CVE-quickly if they'are exposed to the public internet _directly_, they should sit behind some firewall. I hope those important cameras, or privacy-concerned cameras, are at least not installed with a public IP, not sure if that is true though, otherwise more exploits will keep coming.

Post reply on HN