18 ms·
Hackers break into thousands of security cameras, exposing Tesla, jail, hospital
- judge2020 6y agoDupe of https://news.ycombinator.com/item?id=26404799 https://news.ycombinator.com/item?id=26404799
- deleted 6y ago[deleted]
- ocdtrekkie 6y agoPutting surveillance video on the cloud is... kinda dumb. It's rarely viewed outside your network, and local drives cost drastically less than the bandwidth needs. Also it's incredibly sensitive data that shouldn't leave your network without really good reason anyways. The solution to this hack is simple: Shut this company down, because it's a bad idea.
- _-david-_ 6y agoI think the biggest selling point to cloud security cameras is to have a copy of the video not at the location. If your house / business is robbed or burns down you will possibly lose the video. This video could be used to find the theif or arsonist. Ideally it would store video locally, then encrypt it and upload the last minute to the cloud.
- ocdtrekkie 6y agoPlausibly, yes, though again, large enterprises should be able to handle this internally, especially some of the listed customers here.
- zerkten 6y agoThere are plenty of use cases, such as the various forms of analysis with ML, which are often only implemented outside the "company firewall" (this idea is antiquated.) Of course, this could and should be handled inside a trusted boundary (I can't think of a better term for today's networks), but in practice security here is fairly immature and people try things when there isn't good governance in place.
- TeMPOraL 6y agoThis sounds like general problem of enterprise security. There are no consequences. I can entirely get why a company would outsource IP cameras to a third party cloud, even with storing data on-site. Business runs on contracts. It's entirely normal to contract out everything except your core competencies, if it's cheaper this way. It's how you turn CAPEX, complex OPEX and high risk into simple OPEX and low risk. A contract is in big part a risk shifting tool. This works well in practice... outside IT. The problem is, with IT and data, there's a mismatch between expectations and reality. An enterprise should feel safe buying their video surveillance from Verkada, because between the contract and the legal framework, Verkada should be bankrupt now, and their management possibly facing jail time. That's the part where contracts work as Cover-Your-Ass tool: if you shift risk and liability to outside party, the liability is not on you. However, this only works as long as the other party actually internalizes the risk and liability. Since there are no consequences for mishandling data, operating IT services you're not structurally competent to operate, and eventually having your crown jewels stolen - the contractor doesn't really internalize risk, has no incentive to mitigate it. All this to say: Verkada should go down after this, and their customers should be named and shamed widely - the latter is so that future customers of IT services put more care into vetting companies they contract IT out to. You shouldn't get to CYA with a contract where assumptions around contracting are broken.
- AmericanChopper 6y agoI work in a large enterprise. If my employer were to decide to exclusively store security footage on our own infrastructure, then I would have access to every piece of hardware it’s stored on. The risks associated with that is why every piece of mission critical data where I work is, at a minimum, backed up in a 3rd party facility.
- nielsbot 6y agoAlso, convenience: Buy this camera, get access to recordings anywhere over the internet with nearly zero setup time. If you have an on-site system (like I do) it's way more effort for the average consumer.
- andrewprock 6y agoThat's not security, that's voyeurism
- vincnetas 6y agoWas also thinking the same. Security cameras should be used where there is an incident and additional information is needed to clarify what happened. Then you check the security camera footage to figure out what happened. If there were no incidents there is not reasonable need for anyone to look at that footage. edit: not talking here about active monitoring security cameras used by guards.
- ma2rten 6y agoAnother one is that you can run machine learning on it. For example to automatically detect unusual activity.
- ocdtrekkie 6y agoYou can absolutely run machine learning on-premise hardware.
- brk 6y agoThe biggest selling point is really the OPEX sales model, and outsourcing of the general care-and-feeding of the recorders/servers. The tradeoff is that you tend to get lesser quality video and/or less scalability of the size of the system from bandwidth limitations. Theft of recorders/loss of recorded video is much much less of an issue than it is generally made out to be, and most systems have various means for auto backups, dual recording, etc. Many also have the ability to send select segments of video, based on motion or analytics, to cloud/FTP/email for free, which adds some extra resiliency if you are really worried about random arsonists :) (I work in the industry)
- pdimitar 6y ago> (I work in the industry) Ohhhh, you are so in trouble now! :P I am pondering moving to a rather remote estate with my wife but we're both city kids and have zero clue how to defend ourselves in such conditions (I am even thinking we should take shooting lessons and bring guns to the estate as well). Part of our plan is a surveillance system -- I planned to have an on-site ZFS storage cluster with several cameras that periodically encrypts the last 5 minutes and sends them off-site. Not sure how complex such a setup might turn out to be though... Maybe there's a way to make the storage cluster itself auto-replicate remotely often enough? I'm not that educated yet. Do you have any recommendations? I don't want to spend $5000 due to paranoia but I don't want to be defenseless in case of a robbery either. What's the middle ground?
- brk 6y agoThis isn't a short conversation, but you can contact me offline and I can give you some pointers.
- pdimitar 6y agoPinged you on twitter several hours ago, as I can't find any other accounts in your HN profile and don't want to stalk by looking you up online.
- bigbillheck 6y ago
- bsder 6y ago> Putting surveillance video on the cloud is... kinda dumb. I tend to agree, but ... If you're a small business or manufacturer, IT is a pain in the ass. The "cloud" is a benefit because you don't need to maintain any servers yourself and can just get on with your business. The problem is that these companies don't face any consequence for claiming that they're secure and then not actually being ... you know ... secure. If this stuff was simply encrypted at rest, that would have mitigated most of this breach.
- ocdtrekkie 6y agoSure, but many of Verkada's customers are large enterprises with large IT teams just making a bad decision. Small businesses have either a box they bought at Costco or use something like Comcast's service which they just add on to their cable modem.
- leesalminen 6y agoThose boxes from Costco come with WiFi built in and a mobile app paired to it. The small business owner invariably sets up port forwarding so they can watch from home and leaves the default password because it doesn’t force you to change it. Not much better there either.
- ocdtrekkie 6y agoMy point was less that those were good solutions, but that a company I contend "shouldn't exist" likely has a different customer segment, like Tesla and Cloudflare.
- intrasight 6y agoOh, the places I've boldly gone - using default passcodes
- brundolf 6y agoI don't think it would, because they leaked admin credentials (unless it was encrypted with a customer key and inaccessible to admin/support) Anyway, I think we're at the point with software/digital systems where food manufacturing was in 1900: there's been a gold-rush due to new technology, and we're reaching peak negligence in the pursuit of profit, and I think we'll soon get to a threshold where regulators will finally step in and lock down the wild-west and impose some real standards. Between SolarWinds, Exchange, and now this, it's to a point where it's dragging down our whole society. Something has to give.
- Hnaomyiph 6y agoIt's amazing how much security people and companies are willing to give up for a smidge of convenience. Properly deployed CCTV has little worry of hackers since, hence it's name, it is closed-circuit.
- lancesells 6y agoThis made me wonder if there's a place for a company to disrupt the video cloud industry by selling CCTV cameras and devices that would require physical updates sent on a usb drive.
- ocdtrekkie 6y agoIt's not actually hard to do that today with existing equipment: Put it all on a network switch and then just... don't plug it into the Internet. Plenty of on-premise solutions exist and work with or without remote connectivity.
- vel0city 6y agoGet this: closed circuit television systems actually existed before updates could be delivered by the internet. Another crazy fact: there are still products sold which don't connect to the internet. You don't see nearly as many ads on these products though and don't seem to be as popular these days.
- pugworthy 6y agoTrust me, it's not always about convenience for some of us remote camera users. In my case, I've got a camera in my elderly parent's back yard as there have been a few falls in the back yard, and one break-in some years back.
- stjohnswarts 6y agoThat seems like more trouble than it's worth though. Do you like just check every hour to see if someone has fallen or something? That seems like something that could become either an obsession or something you'd forget to do.
- passivate 6y agoOuch! That's a bit harsh! Well, I suppose cloud archives could be encrypted? We use a cloud based system (but no cloud backup) and with multiple facilities, its nice to be able to launch the app and stream the camera's live feed using the cloud as a bounce. Also with the cloud being used as the de-facto off-site backup location, most data these days will end-up (hopefully encrypted) in some kind of cloud service or another.
- ocdtrekkie 6y agoRemote access is fine, it can be reasonably managed: Generally the client sets it, and the manufacturer doesn't retain access. Usually you can geoblock and such as well. You have control of the hardware and can implement encrypted storage and better access controls, rather than trusting a third party to decide what is "secure".
- bredren 6y agoThis would be a much bigger hack if it were Wyze. Wyze cams are generally placed in residential interiors and contain a mic that can not be disconnected without physical removal. It wouldn’t be as newsy, though because people put these in their own homes. The only way this group raises awareness instead of angering people is by targeting companies and institutions, rather than forcing people to confront their own compromises with technology, time and effort.
- tkinom 6y agoAny known security issue with Wyze? I am very impress with their features. I am planning to buy couple of them, but I would never point them inside the house. Probably will put them in their own wifi network. I built a home grow solution with RPi + Webcam + Google Drive with some python script. But the performance to upload Pics to G Drive was slow and the way viewing the pics uploaded to G Drive was not very convenient.
- GloriousKoji 6y agoIf you're serious about security I recommend against wyze. You're locked into their platform and it isn't fully reliable. If you want something like a video of that opossum sneaking in the attic, coyote peeing in your rose bushes, that kid across in the street with the razer scooter and german shepard not cleaning up the poop off your lawn or what your iguana is up to when you're not home then it's great for that. The UI is probably worse than your gdrive setup. You have to use the wyze app to access it, which has a terribly slow scrubbing interface. The more convenient part is to check the motion/sound triggered 15 second clips which are upload to their cloud servers. Other than that I find myself frustrated and just take out the microSD card and browse it on my computer. Also don't buy the sense kit. It just doesn't work. I've even tried experiments with it right next to the camera and it's not consistent enough. If you want to use the wyze cams are generic IP cameras they offer unsupported firmware for that but then you'll need to roll your own DVR and I'm not sure if that supports all the new features the V3 offers or follows the genric protocol for remote pan control.
- 6y ago
- tomc1985 6y agoBut then how will techbro wantrepreneurs build their unicorn business?!?!
- Spooky23 6y agoFor anything small, the local drives are obvious theft targets. For anything large or distributed, you’re probably going to spend less for better security with a cloud system. It’s sensitive data, but probably in a second tier of sensitivity. The integrity of the on-prem system depends in your remote access security and operational practices. Solutions like this often really suck.
- pugworthy 6y ago> Putting surveillance video on the cloud is... kinda dumb It's a necessity for some cases. I commented on this elsewhere, but for me it's having an eye on my elderly parents back yard in case of falls. Past history of not knowing is precisely why we got the camera.
- ronnier 6y agoYou can still keep them local and use a VPN. That's what I do.
- contravariant 6y agoPeople really should. It's pretty easy these days with wireguard or tailscale. Just plug a raspberry pi somewhere with network and power and you're set.
- pugworthy 6y agoI spend my day doing the "tech shit" for work. I don't want to mess with stuff, I just want it to work. I'm willing to risk a bit of security for it to "just work", which it has now for multiple years. Without any security issues (so far).
- contravariant 6y agoI completely agree, even though I do tinker around with stuff for fun. However in my experience so far wireguard and tailscale (which is based on wireguard) are the kind of solutions that just work with little to no oversight.
- SilverRed 6y agoIts still on the internet though. Its just the VPN becomes the security barrier. Although if you keep it up to date, its going to be safer than iot crap
- mike_d 6y ago> It's rarely viewed outside your network The majority of real camera systems (100+ cameras, 10+ locations) I have interacted with are monitored by outside vendors.
- quasirandom 6y agoThere's more information here as well. Cloudflare was apparently operating network connected facial recognition cameras in their offices. I'm not someone who's crazy about privacy, but this is a pretty dark indicator for a company housing DNS query records. Maybe its time for someone to build a proxy for tunneling Cloudflare DoH/DoT over tor or some other free mixing network.
- bradlys 6y agoHow is that something to be worried about? There are companies out there that try to monitor if employees are in rooms/areas that they're not supposed to be. You can do that with badges/RFID but then people can take a card or slide by in various ways. (Happens all the time at big companies - people just tailgate) If anything, they might be taking privacy more seriously by not letting people without authorized access into secure areas. I think you give up any sense of privacy as to where you're located in an office or where you've been in an office when you decide to work in an office owned by some employer. I don't know why there'd be any expectation there.
- batty_alex 6y agoI find it fascinating how okay you are with your employer tracking you. We aren’t to the life contract part of the dystopia yet, quit trying to skip ahead and give away your freedom so easily
- Shank 6y agoCloudflare sells security to people. If you don’t want to work at a company that has security requirements like that, don’t work there. Lots of people choose to donate their fingerprints, facial data, life history, and polygraphs to work for the government. That’s their choice to make.
- tartoran 6y agoIf that info is well taken care of is one think. If it ends up floating on the internet is another. Rfid badge data floating on the net creates is useless however other personal data could be very toxic in the wrong hands. And usually this info leaks thats why its not a great idea to let it outside the network let alone record it in the first place
- Black101 6y agoPretty much all consumer security cameras do this by default nowadays... I had to disable it on mines and send it to my own server instead, as a backup.
- spoonjim 6y agoPutting the surveillance video on-site is... kinda dumb. If someone breaches your facility and wants to take the evidence of them doing so, they just have to steal the video storage. Cloud security footage makes sure that you have at least the footage up until they disable your network.
- httpz 6y agoWhen Microsoft Exchange servers were hacked a few days ago, people on hacker news were talking about how most companies are not capable of securing their own on-premise systems and they should have used Office 365. There really isn't a perfect solution. There are trade-offs.
- ocdtrekkie 6y agoIt's a lot easier to secure on-premise Exchange than Office 365. For one, having OWA exposed to the Internet is entirely optional for Exchange on-prem... but impossible for avoid for a cloud service. Most possible ways to secure access to Exchange on-prem are built into your firewall, and you can configure at leisure... most possible ways to secure access to Office 365 are billable add-ons to your subscription. Any side channels to that... you just have to trust Microsoft... I agree there are trade-offs, but especially for large enterprises with security teams, on-prem is definitely more secure.
- rapsey 6y agoUnfortunately local storage is a problem. It is very vulnerable to arson or theft.
- balfirevic 6y ago> Shut this company down Who should shut it down?
- Ensorceled 6y agoThere are actually plenty of reasons for remote storage of surveillance footage; not the least of which is that offsite storage of such video can be a regulatory or insurance requirement.
- philjohn 6y agoAnother take on this - I have google nest outdoor cameras. Recently, a car park company tried to claim I was in a car park for 7 hours. In reality, I had gone earlier in the day, come back home, and then gone back hours later - but their ANPR system must have had a glitch. I was able to send them links to the video clips on the Nest site, with embedded timestamps. If this was a local system there would be no way to prove I hadn't just faked the timestamps.
- mattacular 6y agoYou not having to pay an unfair fee for parking one time hardly seems like a good tradeoff for massive surveillance overreach by truly incompetent companies but maybe that was one really expensive lot or something
- listenallyall 6y ago>> no way to prove I hadn't just faked the timestamps. Showing a ticket? Parking lots have been using them pretty successfully for 50+ years
- philjohn 6y agoNot in the UK - most free parking for shopping centres use ANPR cameras so that people who are going there for a few hours can do so, but people trying to be cheeky and park there all day to go elsewhere can't.
- antihero 6y agoVerkada has prioritized sales expansion over growing the engineering team, with 150% more salespeople than engineers and almost half the entire company in sales, per LinkedIn” Exactly the sort of people you want to trust with highly sensitive surveillance.
- stjohnswarts 6y agoAssuming one size fits all is dumb as well. This could be handled much better but it won't be cheap and that's what everyone is trying to do, "cheap". Other things are "on the web" and much less easily hacked.
- DoofusOfDeath 6y agoIn the U.S. legal system, is video footage exposed in this manner admissible in court? E.g., if a prison inmate was physically abused by staff, and his only corroborating evidence would be this video footage, can it be used to justify a civil or criminal complaint?
- ocdtrekkie 6y agoI think so? Law enforcement can't break into something without a warrant, but if someone brings them evidence of wrongdoing (especially a third party who didn't conduct the hack themselves), I believe they can act on it.
- skybrian 6y agoIt seems like someone would have to testify that it's authentic? Who is going to do that?
- dylan604 6y agoThe guy receiving the beating?
- ocdtrekkie 6y agoUnder oath, presumably you compel the people in the footage. But I would imagine that the footage of questionable sourcing might count as the probable cause to go in and get the footage directly via warrant? I am not a lawyer.
- throwanem 6y agoWhoever at Verkada gets subpoenaed by the inmate's counsel to do so, I'd assume. That said, I'm no more a lawyer than anyone else who's commented here so far.
- dylan604 6y agoIANAL, but from all of the cop shows on TV, if the lawyer was provided the evidence and did not break laws themself OR as long as the lawyer did not entice someone else to commit the offense or provide instructions on what to do, then typically the judge allows the evidence.
- swiley 6y agoTo the surprise of absolutely no one closed IP cameras that rely on a manufacturer run internet service are not secure. Consumer electronics really suck, I wish there was an alternative to the DIY approach of Linux SBCs with rsync over ssh.
- jtchang 6y agoI'm making it -- https://github.com/openmiko/openmiko https://github.com/openmiko/openmiko if you want to help!
- dylan604 6y agoEach of these security camera system/IoT companies are only offering you a bit of hardware to interact with their true purpose of making you a user of their SaaS product.
- bombcar 6y agoGet cheap-ass wired camera (even PoE). Isolate the network they are on behind a Linux box that cannot route. Record on the box, display from another hardware port. Wrap all the above behind another firewall. Make it all IPv6 only.
- totony 6y agowhy ipv6?
- mensetmanusman 6y agoThis is amazing. If they would have added software to the cameras to mine bitcoin, it would’ve been absolute peak cyber punk. People that sell video cameras attached to the Internet should always have a disclaimer that the user should assume that the system will probably be accessible by anyone at some point in the future. I believe Samsung started doing this with their TVs in regards to audio. We are certainly building ourselves an interesting future.
- dylan604 6y agoMining on a SoC that fits in a security camera must be the definition of futile. How in the world does one of these ever "win" to earn?
- jffry 6y agoThey could mine for a mining pool
- rtrdea 6y agoCould maybe mine Monero
- TeMPOraL 6y agoDistributed computing. Customer's electricity is free for you, so whatever you manage to mine, is pure profit (and invisible to IRS if you're clever). Making this work would also be an interesting Big Data Hyper Edge Cloud Computing project to keep the engineers occupied and further justify the need for the money they got from investors.
- belval 6y agoExcept there are no coins that could be mined with a camera CPU. Even with Monero (which is CPU based) you will not meet the RAM requirements or clock-in a "share" of work in any useful timespan. You statement is true in the wider sense, you can have mining botnets of computers and maybe some high-end phones, but IP cameras are really-really weak as far as compute power go.
- cwkoss 6y agoI wonder how much footage has been captured. Hackers could have produced a prison reality TV show with all that access.
- edoceo 6y agoNever be as good as Oz, that show was amazing
- philip1209 6y agoIsn't Cloudflare notorious for otherwise wanting only on-premise software?
- lima 6y agoYeah... I bet today was the security team's "told you so" day.
- ocdtrekkie 6y agoEspecially if https://twitter.com/nyancrimew/status/1369437256193343496?s=21 https://twitter.com/nyancrimew/status/1369437256193343496?s=... is true.
- mcv 6y agoTweet account has been suspended. Could you tell us what was in it?
- ocdtrekkie 6y agoThe person behind this claimed to have root shells on the networks of both Cloudflare and Okta. (FWIW, if the network is well segmented, this may have limited impact.)
- TameAntelope 6y agoThese folks (the hacker group) are a hoot to follow on Twitter, I do recommend searching for and finding them there. Hacker demons, the lot of them. :)
- bredren 6y agoSequoia is mentioned prominently here. What is the role of venture funds in ensuring their startups operate or endure some basic regular external security audits?
- naebother 6y agoIf they've got nothing to hide, they've got nothing to fear.
- rozab 6y agoCloudflare? Wonder if any were pointed at their lava lamps ;)
- ocdtrekkie 6y agoYeah, I wonder if the hackers had the same feed used to generate Cloudflare's randomness... that could be a vastly bigger security breach on top of this one.
- karlding 6y agoIf their blog posts are to be believed [0], lava lamps are not the only source of entropy available. > Hopefully, the primary sources of randomness used by our production servers will remain secure, and LavaRand will serve little purpose beyond adding some flair to our office. But if it turns out that we’re wrong, and that our randomness sources in production are actually flawed, then LavaRand will be our hedge, making it just a little bit harder to hack Cloudflare. [0] https://blog.cloudflare.com/randomness-101-lavarand-in-production/ https://blog.cloudflare.com/randomness-101-lavarand-in-produ...
- jgrahamc 6y agoNo.
- modzu 6y agoanyone else doing this in 1995??
- A4ET8a8uTh0 6y agoSo a real question.. was HIPAA violated or since they used a 'good' vendor, the check mark is on the compliance list and auditors will be happy?
- SilverRed 6y agoI think anyone who has had to comply with those compliance lists knows how useless they are. Easy to make the minimum change that makes you compliant without being any more secure.
- bronson 6y agoAlso Verkada, 4 months ago: Surveillance company harassed female employees using its own facial recognition https://news.ycombinator.com/item?id=24906940 https://news.ycombinator.com/item?id=24906940
- f430 6y ago> Last year, the sales director accessed these cameras to take photos of female workers, then posted them in a Slack channel called #RawVerkadawgz alongside sexually explicit jokes. The incident was first reported by IPVM and independently verified by Vice. damn that is despicable but this sort of brogrammer behavior appears rampant. How would you address this as a manager? This is absolutely not okay.
- 46Bit 6y agofire for cause, file a police report depending on what the photos are, and support the victims
- mcv 6y agoNot what they did, mind you. The culprits merely got their stock options reduced. And the fact that the sales manager could access the camera feed may have been a big hint that security was not their biggest priority.
- ALittleLight 6y agoYou think their sales director is also a programmer? What's the point of combining "programmer" and "bro" like this?
- vineyardmike 6y ago> What's the point of combining "programmer" and "bro" like this This is a known (to some) phrase, with a known (to some) meaning... its about bro-y silicon valley culture more than actual programmers
- ak217 6y agoEarlier feature about the culture at the security camera company in question: https://www.vice.com/en/article/pkdyqm/surveillance-startup-used-own-cameras-to-harass-coworkers https://www.vice.com/en/article/pkdyqm/surveillance-startup-...
- gibolt 6y agoQuite comical that the image in the article is subtitled 'Madison County Jail', but is actually seemingly a Tesla service center. Other options are the reporting site got hacked or it is quite the experience at that jail.
- xiphias2 6y agoI thought that jail workers are used to fix Tesla cars. I have read that people in jail are used for work in the US.
- marshmallow_12 6y agoThey do actually get pay from what i hear. It's not like its forced labour (labor).
- danaliv 6y agoA whopping $0.14-$1.41 per hour. https://www.prisonpolicy.org/blog/2017/04/10/wages/ https://www.prisonpolicy.org/blog/2017/04/10/wages/
- marshmallow_12 6y agoI still think it's better then sitting and staring at the walls, yet that option is open to them .
- to11mtm 6y agoIt's a worse option for everyone: - Pushes down wages for other workers doing similar labor, by taking demand out from the normal market - Because the prison itself (or, more likely, the prison-industrial-complex corporation running it) is seeing a huge profit from these ventures, it provides a perverse incentive to keep their labor pool 'strong', be it through lobbying for harsher sentences, or encouraging shot quotas amongst their guards/COs. - Conditions prisoners towards working less for equal work (we shouldn't encourage the idea that -any- class, race, or creed of human being is worth less for the same amount of work)
- rossdavidh 6y agoWell, that looks bad. Thank goodness, though, that after a security lapse this awful, corporate and government bureaucracies will come to their senses and stop outsourcing critical functions to cloud companies they don't know all that much about. Oh, wait...
- vanillax 6y agoThis is why I self host all my cameras. https://mitchross09.medium.com/how-i-self-host-my-own-sites-and-applications-with-unraid-docker-authelia-and-cloudflare-1f0d8e6f8912 https://mitchross09.medium.com/how-i-self-host-my-own-sites-...
- SilverRed 6y agoThe sad part is the majority doesn't know how and why they should do this. They just get their personal lives broadcast to the web for all to see. There was or at least used to be a subreddit showing the more interesting exposed cams.
- antihero 6y agoHow likely is it that for someone who isn't technically as adept as a team at a (good) cloud NVR provider, the security is actually worse? Bit like rolling your own crypto.
- waz0wski 6y agoVerkada set the bar awfully low: > The hackers gained access to Verkada through a “Super Admin” account, allowing them to peer into the cameras of all of its customers. They found the user name and password of the account publicly exposed on the internet Don't put your personal stuff directly on the internet, use separate admin accounts with 2FA, gg, you're doing better than Verkada - comically valued at $1.6B
- jtsiskin 6y agoWhy would the footage not be E2E encrypted? Hospitals and police stations are installing cameras which store unencrypted footage remotely?? What is this madness
- ocdtrekkie 6y agoEnd-to-end between the cloud provider and the cameras at the site, sure. But it's stored unencrypted, mostly because cloud providers provide the web interfaces and such to stream the video, provide services to analyze and classify the video, etc. Nobody encrypts their surveillance video storage, AFAIK.
- d110af5ccf 6y ago> End-to-end between the cloud provider and the cameras at the site, sure That's TLS, not E2EE. E2EE means the provider never sees the unencrypted data. (Ex SMS is unencrypted, most internet services use TLS these days, Matrix and Signal use E2EE.) > Nobody encrypts their surveillance video storage, AFAIK. This is a serious problem.
- ocdtrekkie 6y agoIt's never going to change because of the performance implications. Most video surveillance systems have poor CPU to begin with.
- d110af5ccf 6y agoWhat performance implication?! AES-NI has been standard for mainstream x86 hardware since ~2013 and ARMv8 introduced optional crypto instructions in 2011! The issue is that manufacturers choose the cheapest possible SoC that lacks these abilities. Given the small cost savings and importance of basic security measures, that really needs to change. (A quick look at Amazon shows many of the top sellers advertising various "AI" features and streaming video at 4K or better. Given their apparent capabilities, I strongly suspect that such SoCs do in fact have hardware support for crypto.)
- robbyking 6y agoA while ago there was a post on Reddit about something similar, and there wasn't even any "hacking" going on; the video feeds were just unsecured. Using Google, someone search for a proprietary video protocol (IIRC) and found tons of video streams that weren't even password protected. Some in schools, some in warehouses, and some just on the street as part of neighborhood surveillance. I think I have the link saved, I'll look for it.
- Mixtape 6y agoFinding unprotected streams via Google Dorking like this is easy. Here's an article that doesn't cover this particular use case, but rather the broader practice: https://exposingtheinvisible.org/guides/google-dorking/ https://exposingtheinvisible.org/guides/google-dorking/ I've personally dabbled with it a bit in the past, and while I didn't find anything particularly interesting, it did make me a bit more cautious about enabling anyone with a link to access a Google Doc. With a good enough scraper or even just a lot of patience, there are a lot (potentially sensitive) data out there for people to harvest. That's not to say there aren't a number of benefits to having access to advanced search tools though, just that individual mindfulness when making something completely open for anyone to access is all the more important.
- judge2020 6y agohttps://www.shodan.io/explore/tag/webcam https://www.shodan.io/explore/tag/webcam
- SilverRed 6y agoIts horrible how common this is. I used to do work on local business sites and the security was horrific. Pages that contain sensitive data or even CRM management pages exposed to the public internet with no password at all. On some of the less sensitive ones I had a look I found details of family members in these exposed sites. Not only that, but it was all horribly outdated. Seen some things running on rails 1 pre release on a debian server about 6 years passed end of life. Its a wonder the world works at all.
- Teknoman117 6y agoWasn't there a website along the lines of "camroulette" that showed you random unsecured IP camera feeds?
- dhdhhdd 6y agoI own reolink and amcrest cameras. I put them in a vlan with no outside connectivity (and frankly no inside either!). They try to call home constantly :-(
- walrus01 6y agoThis is the same company that was in the news back in October related to harassing its own female employees with fratboy douchebag behavior: https://www.theverge.com/2020/10/26/21535089/surveillance-company-verkada-harassed-female-employees https://www.theverge.com/2020/10/26/21535089/surveillance-co...
- tartoran 6y agoGood catch. I wonder if it’s just kharma or they were targeted specifically in response to those behaviours
- walrus01 6y agoOr maybe companies run by sleazy people have less than stellar infosec/netsec practices, or are prone to sweeping gaping security holes under the rug rather than fixing them, which will inevitably result in something like this.
- Balgair 6y agoIt's talked a bit more downthread, but I mean if the sales director is making public slack channels featuring female employees alongside explicit jokes, then long-term thinking may not be a strongly selected for attribute at the company. https://news.ycombinator.com/item?id=24906940 https://news.ycombinator.com/item?id=24906940
- adolph 6y agoTo be fair, it was a specific person with a set of other employees who were all punished for the incident. It wasn’t the company which includes the people were harassed.
- jhanschoo 6y agoThe headline oversells it but your comment undersells it. The specific person and set of other employees were "a group of men in leadership positions on the sales team", including the "sales director". When found out, > Verkada CEO Filip Kaliszan gave employees in the Slack channel [i.e. those involved] a choice: leave the company or have their stock options reduced. All of them chose to stay and take the stock option cut, according to Vice. “I was shocked. To me that’s not just a fireable offense, that’s a career-ending offense,” one employee told IPVM.
- DudeInBasement 6y agoSo, do they know what happened to Jeffery?
- cosmodisk 6y agoYou hardly need to be a hacker for this. I did some Google dorks out of boredom. In 15 min, I saw live feed from some CCTVs exposed to public internet. The most disturbing one was someone's living room...
- atum47 6y agoBack in college I was studying security and eventually I found out about shodan. I mean, when people don't even care to put passwords on their connected to the internet device, can you even call it hacking?
- atum47 6y agoMeaning no disrespect to the people who find the user and pass, but criticizing people who don't set passwords or leave the default ones
- Teknoman117 6y agoAre there any companies actually pushing a security-first IoT model?
- gostsamo 6y agoIn my experience - no. I've seen devices sold for thousands of dollars whose login screen could be bypassed with a magic cookie. Here and there you will find a device that will force you to change the default password upon activation, but this is as far as it goes and the cheaper models from the same vendor will be as shitty as anybody else's. The best that you can hope in consumer devices is something like Apple, Google or Amazon, because they can afford the support costs, but it comes at the price of privacy and funneling your money in many other ways. Enterprise stuff could be found, but you can never trust just the brand for every model. Edit: grammar.
- rickspencer3 6y agoForget where I read it, but it always makes me laugh: The "S" in IoT stands for "Security"
- jrochkind1 6y agoThis is the important part. NOT that their network was not secured, but that anyone with a super-user account can simply view archived and live video feeds of any of their customers???? > The hackers’ methods were unsophisticated: they gained access to Verkada through a “Super Admin” account, allowing them to peer into the cameras of all of its customers. Kottmann says they found a user name and password for an administrator account publicly exposed on the internet.
- heracles 6y agoThis really struck me also. I work in the relevant industry (we make cameras etc.) and there is always a bit of pain to get user footage. This is how it should be! To have everything from source code to customer material accessible to an admin is bottom-tier thinking. Why not just rename your "admin" to "GOD" and then ask yourself if you have any single point of failure?! I do NOT want to sound smug, but there is a little bit of amateur hour going on here both from buyer and seller. High value and large targets (like airports) and more established sellers usually don't work like this, and that's for a reason.
- jrochkind1 6y agoIt's not just that it's a single point of failure, it's that as a customer I do not want any admin who is feeling curious to be able to snoop on my footage with a click. I don't know how "established" this company is, but their customers appear to include city governments, hospitals, and Tesla motors, which I would consider "high value and large targets". Makes me suspicious of the whole industry. If others in the industry dont' want that, time for some industry codes and audits and self-regulation.
- heracles 6y agoI've added a link to IPVM to the parent to my comment that might interest you! Regarding established: I might be wrong! I willingly admit that I knew nothing about verkada some days ago. Seems to be relatively new (5 year-ish) and "classic" Silicon Valley in that they push hard for growth to get their valuation up and try to "disrupt" by running everything in the cloud. More sales people than R&D, which I think is uncommon. Verkada runs full lock-in, so if you buy a camera from them you have to buy their services. This is again relatively uncommon. Most of the industry supports the ONVIF standard, so you can run the hardware you bought with different software solutions. If you want encryption at rest, no problem. You just make an on-premise solution with full encryption. With verkada you can't do that (incidentally verkada have mocked ONVIF due to alleged security concerns, but obviously it undermines their business model with full lock-in). Since combining verkada and other hardware would require parallel systems I made an educated guess that most customers would be places without previous hardware and/or less concern for the long run. Most large and high value targets have previous hardware, but certainly there are exceptions. And as stated earlier, I might be wrong:) And lastly, you should be suspicious! Last time I bought a car I was very suspicious. I like the car I did buy very much, but next time I will be just as suspicious again. That's how things should be when it's about trust and high impact.
- ck2 6y agoIf only there was a way to keep an intranet inaccessible from the internet like not connecting the two. You think there are nuclear missiles somewhere on the internet? Someday some general will want to monitor them and order that.
- soheil 6y agoIs there an archive of the raw photos/videos someone can link to?
- tanseydavid 6y agoI cannot wait until the whole world is run by machines that do not work very well. </sarc>
- NiceWayToDoIT 6y agoFrom some reason, all I am wondering is how huge is potential for industrial espionage this way?
- figassis 6y ago“Our internal security team and external security firm are investigating the scale and scope of this potential issue.” Potential issue? Your house is on fire. When will these businesses just be straight rather than PR everything?
- heracles 6y agoNothing on blog or "What's new" either, just corporate newspeak.
- heracles 6y agoI'd like to add a bit of context to how security cameras most often are installed. In the industry in general you have producers of the equipment and you have buyers, but in between there you have integrators. The integrators plays a crucial role when installing big systems. They win the bid for an installation and carries out the work. This means that there is seldomly any direct path between camera producer and the customer. For the producer to get access to footage they must go through the integrator, so the friction is non-trivial. Direct contact producer <=> buyer might happen in the small case, like a store with a single camera or you placing one at home. My guess (!) is that verkada tries to pry away the integrators with a simpler model for installation. Most larger producers now have cloud offerings, which could have some similar vulnerabilities to those mentioned in the article. However, my impression is that security is taken VERY seriously. Not just lipservice, but in practice. This makes sense as it is a key selling point and the larger buyers are competent judges of this. This is in stark contrast to the "typical" hacked target, which seems to be autoshops and hospitals (I am generalising to get through a point, I am not sure what the most common victim is).
- pmlnr 6y agoAnd when you try to describe the problem with cloud connected "security" devices to your non techie neighbour, all you get is a "whaaa...?" expression.
- hummel 6y agoNote to HN. I know personally the attackers, and they send me proof of the attack before making it public. They are just two south america teens having fun cause they can't leave home. They were doing just for the lolz, there is no complex supply chain attack or state-actors involved. Just two kids pwning billions of VC money.
- 19h 6y agoNot sure who contacted you but one of them is definitely from Switzerland.
- moosebear847 6y agoIdk anything, except that one of these ninjas is lying.
- adtac 6y agounless Switzerland happens to be in South America!
- mavhc 6y agoWhy would anyone ever send their unencrypted cctv footage to a 3rd party?
- irthomasthomas 6y ago"Kottmann said their reasons for hacking are “lots of curiosity, fighting for freedom of information and against intellectual property, a huge dose of anti-capitalism, a hint of anarchism -- and it’s also just too much fun not to do it.”" .... "Kottmann says they found a user name and password for an administrator account publicly exposed on the internet" Excuse me but finding a password that some idiot included in their public git project is not fucking hacking.
- rapjr9 6y agoI'd like to see an overview of everything that has been hacked so far, arranged by both device/protocol and industry/gov/social structure. It would be interesting to see if there are any categories that have not yet been hacked and what their characteristics are and where in society they reside. Maybe secure internal networks at the DoD have not yet been hacked? (How would we know, aren't those networks the ones the state attackers really REALLY want to attack? Who would tell us if they'd been compromised? There have been some news reports on the use of insecure drone control wireless protocols.) Crypto protocols used for chemical plant SCADA? Have parts of Starlink been hacked yet? Which banking protocols and hardware security modules have been hacked and which have not (SWIFT? HSM's based on ASC X9 standards?) Might give us some clue as to what actually works, what needs to be abandoned, and what needs changes. At the moment this looks like a losing battle (possibly a loss of civilization?) with the number of big data thefts and compromises if something does not change. Does anyone know if such a comprehensive review exists in the literature?
- brk 6y agoI started this list when I was part of IPVM: https://ipvm.com/reports/security-exploits https://ipvm.com/reports/security-exploits It's probably missing some, and is specific to security cameras, but it is a start.
- klingon78 6y agoI wonder about Cloudflare. It seems like the Windows Vista of its genre. It’s big, pretty, and possibly doomed to be replaced. Tesla is fine. It may as well have been a publicity stunt for them. “For a limited time, you can tour the Tesla facility, but please don’t. (wink wink!)”
- TobySKT 6y ago"If you’ve ever searched for content and interacted with the results on a mobile device, you’ve probably encountered AMP, or Accelerated Mobile Pages. AMP is a good solution for websites that deal with huge volumes of data and need to retain fast performance. These can be informational websites, blogs, and news sites. For large projects, AMP can’t substitute for responsive or adaptive web design. If you’re interested in using AMP or If you want a free consultation from our team, feel free to contact us. We’d be happy to help." https://steelkiwi.com/blog/accelerated-mobile-pages-what-is-amp-and-what-does-it-mean-for-your-mobile-business/ https://steelkiwi.com/blog/accelerated-mobile-pages-what-is-...
- throwawaygulf 6y agoHilarious. Software development at Verkada is filled with "non-traditional backgrounds" leftist SJW types that spew neurotic delusional beliefs on Slack all day. I bet management wishes they would have hired some real devs with backgrounds in software development and security. You reap what you sow.
- deleted 6y ago[deleted]