UK government ban for Chinese Hikvision CCTV cameras
techmonitor.ai
techmonitor.ai
https://www.fortinet.com/blog/threat-research/mirai-based-bo...
However, going after just a brand solves nothing; the problem is that nobody can properly audit these devices due to their closed nature. A huge number of IP cameras and DVR/NVR devices have been either compromised for botnet installation or caught phoning home (usually somewhere in China) in the past. Unless one can purchase a fully Open Source one (including hardware and firmware), there are no guarantees that a device won't be doing nasty things, or silently waiting for remote triggers to do so, which is something that only source code inspection could guarantee against. In the meantime the solution has always been to put them behind a firewall that doesn't let them initiate connections to the outside and also filters out incoming connections from untrusted parties; this should apply to all closed connected device, not just Hikvision cameras.
https://www.wsj.com/articles/hackers-infect-army-of-cameras-...
Even in this dual-homed setup, there is still the potential for the cameras to infect, or otherwise compromise the recording server, which itself generally has access to a much larger part of the organizations networks, if not the internet directly.
At this point, Hikvision has a well documented record of severe cyber security flaws, and countless public statements attempting to deny or downplay them. They are funded by the Chinese government as well. We have seen plenty of other examples of various governments utilizing vulnerable devices, like IP cameras, to gain access to networks, exfiltrate data, or perform other malicious acts.
There are many other good, cost-effective, alternatives to Hikvision that do not come with the legacy of vulnerabilities, and the risks of being closed tied to the Chinese government. Hikvision has brought this upon themselves.
As for how they were alerted, there have been publications documenting Hikvision's risks for years now. I started some of these back in 2017, including this from 2018: https://ipvm.com/reports/hik-hack-map
I agree that this is a potential risk.
But if the cameras themselves can't route to the internet in this scenario then how are they infecting the recording server? Is the suggestion that they come shipped from the factory with code to compromise common recording servers? It seems like that would be very significant and something that we'd be able to see in action.
My biggest concern with CCTV networks that I manage is some sort of backdoor access to the cameras themselves. So the dual-homed server design is exactly what I'd choose in order to control things.
Yes. While I have not seen it happen yet, there is plenty of precedent in cyber warfare tactics in general to have trojaned devices act in this way. The likelihood may be low, but it also very possible, and Hikivsion has already shown they cannot be trusted, so why risk it?
[1] <https://www.cctv.co.uk/how-many-cctv-cameras-are-there-in-th...>
I guess you've never been burgled or mugged?
https://www.cnet.com/news/privacy/u-k-turns-cctv-terrorism-l...
CCTV doesn't prevent crime. It might sometimes help find and punish the offenders later.
Offenders don't do punishment calculus. They assume they won't be caught.
2) from your own link "But are we really a Big Brother state? You may think that the government is behind this high level of surveillance, but the BSIA found that only around 1 in 70 cameras are owned by local authorities"
Does every product on sale get periodic testing to check for this kind of thing? It seems like they could manufacture clean devices to send to a test centre and then back door ones they release in the wild. In the case of non-brand goods such as cables it wouldn’t even really matter if they got caught because they could just spin up another drop ship company under a different name and keep selling.
Glenn Greenwald already went over how the US did this, which is to intercept the devices in transit. That way the backdoors wouldn't be there for general IT personnel or reviewers or state security agents, but they would be there for the targets.
https://www.theguardian.com/books/2014/may/12/glenn-greenwal...
The UK has a specific intelligence service review process for Huawei: https://www.ncsc.gov.uk/collection/ncsc-annual-review-2021/t...
> Does every product on sale get periodic testing to check for this kind of thing?
Other than in a very few intelligence-specific cases, nobody really cares very much about cybersecurity until they get ransomwared. Software everywhere is full of holes.
So is this less about the actual cameras, and more that they have been installed insecurely and not kept up to date with firmware? Or the hardware used to record the data is acutally in the cloud somewhere and that is the issue?
However, a lot of cameras these days come with a good sized amount of processing power onboard. This can be used for object detection amongst other things. Even without network access the devices could communicate and act on the command of others in many ways. A couple of ideas. You could communicate with the IR LEDs. You could blank the video feed if a certain QR code or flashing light pattern is detected. I'm sure there are more, but you get the idea.
I would NEVER buy hikvision again because as far as im concerned their products are absolute junk. Im amazed they would even be looked at for gov/edu. I guess cheapest really does win those tenders.
For home use they suit me perfectly, but I see what you are saying, I too thought that there was a more “pro” brand that govs would use.
I'll take an RTSP feed from AXIS over those any day.
When those responsible for “security” actually depend on countless things being insecure crap, we will never see any real change in how things are done, only the talks about never-ending work done ad infinitum. Cheaply and insecurely made device benefits not only its maker that saves money on development, it also benefits most of those who are supposed to check them, and set better rules for them. Instead, we have various “IoT security teams”. It's like starting the fire at an oil refinery, and then announcing that you need something more than a couple of fire trucks.
That's far more than enough to stream 4k HRD content on my laptop tethering to the phone.
5g range is limited compared to 4g. 5g is more spotty and needs more direct line of sight. A 5g base station consumes 3x more power than a 4g base station. So 5g is more of a gimick than anything else. The reality is, is there isn't any material benefit over 4g.
It works the exact same way with every American company, as evidenced by numerous backdoors revealed by Snowden and other folks.
Supporting American protectionism, even when the US effectively has a trade war with Europe with the Inflation Reduction Act.
That no one has seen. Huawei must be the most examined manufacturer in history by this point and no one has found any actual security flaw yet...
Are Hikvision significantly worse than the alternative?
"We wont ban TikTok because the CCP has given a commitment not to look at the massive trove of data they are continually harvesting..."
I'm sure anyone the UK Gov replaces it with will be from the same factory unless they want to start manufacturing their own.
Another option is VIVOTEK which is based out of Taiwan, and make NDAA-compliant cameras. Admittedly the software is not as polished as AXIS’ and the control panel is a bit of an eyesore, but they do support all the basic and intermediate features you may want.
There are many good choices for non-Hikvision or non-Dahua cameras. The Hanwha A-Series is very cost competitive with the Hikvision stuff, and from a far more reputable source.
"Hikvision cannot transmit data from end-users to third parties, we do not manage end-user databases, nor do we sell cloud storage in the UK."
Not saying it wouldn't be better - but I don't think that's what people would usually do.
Here’s some details:
https://www.securitycameraking.com/securityinfo/setting-up-y...
I'm pretty sure almost every Chinese made CCTV camera is riddled with backdoors and vulnerabilities. And almost all upload their video streams to some server in China.
is this an actual "professor" speaking sense? what do you mean untrusted companies? either hikvision exfiltrates data from the UK to china servers and there are logs to verify that or hikvision could remotely access any device even if it was not online or was online with security but they have a bypass, both could be verified but other than these two cases, what is this pre-emptive ban that could cost the public exchequer millions or billions for what? a hunch that, as they put it, >"We are no longer asking whether certain security companies can be trusted, we now accept they can't, but we need to work out how to verify those we can trust."
so they will first ban hikvision, remove all their cameras from UK, replace that with a competitor, THEN authenticate the trustworthiness of hikvision and THEN maybe let them back in the market.
WTF thinks like that unless you have malicious intent?
As per the article, even though some have opted to remove them they aren't removing them all. Just banning future installations.
> The new decision by the UK government includes a ban on the future installation of any security cameras...
Where are the in depth analysis reports? I want to see the reverse engineered code, ROM dumps, network dumps, hardware teardowns etc. I want to see what is getting collected, what is getting stored, what is getting sent and where.
I think it's perfectly fine to boycott a company for unethical practices. I'm actually for boycotting them for ethical reasons. I dislike how security gets muddied with ethical things. People dislike a company and then throw whatever they can at them to see what sticks.
I read the report, it states:
> There is no direct evidence in the public domain that Hikvison or Dahua provide data to the Chinese state or that their security vulnerabilities are exploited by Beijing.
They are insecure anyway, with many exploits discovered, but a quick search tells me that is the case for many CCTV cameras. The takeaway should be that all CCTV cameras are insecure and should be setup in private networks with no access to the internet. The security should be happening at a different architectural level regardless of who the supplier is.
The choice to boycott a supplier for ethical reasons should be separate. Just my opinion of course.
>There have been growing calls for a ban on their use, particularly in sensitive and high-security areas, in part due to Hikvision’s alleged role in aiding Chinese oppression in the Xinjiang province and Tibet. Big Brother Watch’s report alleged that Hikvision and Dahua have participated in China’s oppression of the Uyghur community in Xinjiang.