Live data from Hacker News

Romanian Hackers Infiltrated 65% of DC Outdoor Surveillance Cameras

lite.cnn.io

41–50 of 88 posts

Re: Romanian Hackers Infiltrated 65% of DC Outdoor Surveillance Cameras

#41

It is 65% of outdoor cameras operated by the DC city police, not 65% of all outdoor cameras in DC. That would have been impressive, Person of Interest style.

Yes 65% is a soundbite.

Cameras are notoriously easy to break into. I would venture to say those 123 cameras has the same manufacturer and share the same reset instruction.

Re: Romanian Hackers Infiltrated 65% of DC Outdoor Surveillance Cameras

#42
post #39

Too many cameras exploits in the wild these days indeed. Need a OSS system for the cameras, just like OSS firmware such as Openwrt to replace vendor firmwares. Camera itself does not have enough resource to deal with DDOS or brutal-force attach or updating-with-CVE-quickly if they'are exposed to the public internet _directly_, they should sit behind some firewall. I hope those important cameras, or privacy-concerned…

Doesn't open wrt have a pretty shoddy security track record

Re: Romanian Hackers Infiltrated 65% of DC Outdoor Surveillance Cameras

#43
post #26

Earlier quoted context omitted.

How do you imagine a camera honeypot at the CIA parking lot? They'd still be leaking a lot of information if the image was true.

Not if the DVR is actually in their lab and video inputs are fed with streams coming from a place where trained personnel will show only what they want to show.

I can't even imagine what the purpose of this sort of honeypot would be. What a waste of money that would be. It's so absurd an idea that I would laugh at it if I didn't know how much money was spent and wasted by the federal government. Really the only way to explain it is this sort of thing.

"Let's set up a whole fake parking lot, hire people to come and go in it, get a bunch of fake license plates, buy a bunch of cars, setup a camera surveillance system and feed it out onto the internet and see if anybody finds it!"

"APPROVED! I don't care how much it costs!"

Re: Romanian Hackers Infiltrated 65% of DC Outdoor Surveillance Cameras

#44
post #43

Earlier quoted context omitted.

Not if the DVR is actually in their lab and video inputs are fed with streams coming from a place where trained personnel will show only what they want to show.

I can't even imagine what the purpose of this sort of honeypot would be. What a waste of money that would be. It's so absurd an idea that I would laugh at it if I didn't know how much money was spent and wasted by the federal government. Really the only way to explain it is this sort of thing. "Let's set up a whole fake parking lot, hire people to come and go in it, get a bunch of fake license plates, buy a bunch of…

You could probably save on reusing the video footage of another parking lot, instead of using actors.

Re: Romanian Hackers Infiltrated 65% of DC Outdoor Surveillance Cameras

#45
post #39

Too many cameras exploits in the wild these days indeed. Need a OSS system for the cameras, just like OSS firmware such as Openwrt to replace vendor firmwares. Camera itself does not have enough resource to deal with DDOS or brutal-force attach or updating-with-CVE-quickly if they'are exposed to the public internet _directly_, they should sit behind some firewall. I hope those important cameras, or privacy-concerned…

Doesn't open wrt have a pretty shoddy security track record

any source? openwrt can't fix kernel security bugs, or OpenSSL issues, but it can provide a fast fix after those exploits are announced at least.

i have not hearded wide spread problem with openwrt yet.

Re: Romanian Hackers Infiltrated 65% of DC Outdoor Surveillance Cameras

#46
post #40

Are there any actually secure ip cameras? Somehow I don't think this is a badge of honor for the "romanian hackers". They probably just scanned for default passwords and known vulnerabilities.

How is that not hacking? Many hackers use known exploits to break into systems.

Re: Romanian Hackers Infiltrated 65% of DC Outdoor Surveillance Cameras

#47
post #37

Earlier quoted context omitted.

I agree with the rest of your points, but that "shitty" high school hacker managed to hide his identity from CIA. You're underestimating him. Majority of wannabe hackers would screw up some detail and get discovered.

Or, since he's taken steps to protect his identity, CIA might have offered a fake job offer for the purpose of him revealing his identity.

I think this what happened.. the government has very formal hiring procedures, a government employee can’t just send spurious offer letters to foreign nationals.

Re: Romanian Hackers Infiltrated 65% of DC Outdoor Surveillance Cameras

#48
post #45

Earlier quoted context omitted.

Doesn't open wrt have a pretty shoddy security track record

any source? openwrt can't fix kernel security bugs, or OpenSSL issues, but it can provide a fast fix after those exploits are announced at least. i have not hearded wide spread problem with openwrt yet.

That may be based on vendor implementations - I think there are a bunch of consumer routers or there that are based on reskinned old versions of OpenWRT.

Re: Romanian Hackers Infiltrated 65% of DC Outdoor Surveillance Cameras

#49

When I was an irresponsible high school grey hat (2001) I was part of a small group of people that shared exploits. We weren't that talented, but one of the guys in our group was still able to get into the cameras in the parking lot of the CIA. This is the problem with cyber security: Even if you're the most knowledgeable organization on earth you still fuck it up. Any one person can fuck up any one thing and if it i…

> This is the problem with cyber security: Even if you're the most knowledgeable organization on earth you still fuck it up. Any one person can fuck up any one thing and if it isn't part of your predetermined threat vector analysis then it gets through and you lose everything. It isn't just cyber security but surveillance infrastructure in general. If you cultivate a large group of surveillance assets (even people) w…

> It is safer to not build the surveillance apparatus in the first place because you _always_ lose control of it sooner or later.

I'd rather be able to watch and data mine citizens for 6 months to a year, before control is lost. And companies do.

Post reply on HN