Jump to content

Recommended Posts

Posted
We have around 85 HikVision Cameras and they are on their own physical network, our CCTV company just uses our Spare fiber pairs to link their switches so no worries for us.
Posted
So... recommended:

 

CCTV > separate VLAN + ACLs > VPN > a single client I.P. address...?

 

You shouldn't have to worry so much about the client IP if they are using VPN, whether you tie the access down to a specific user on VPN will depend on your own requirements/risk. Allowing a specific IP address from the Internet is not ideal unless the source user has a fixed public IP but even then I'd say a VPN with MFA is prob better.

  • Thanks 1
Posted
We have around 85 HikVision Cameras and they are on their own physical network, our CCTV company just uses our Spare fiber pairs to link their switches so no worries for us.

 

That's how we've set ours up too.

Posted
Our CCTV NVR is on a seperate isolated VLAN but do you guys do anything about users who use HikConnect to view cameras. Their devices will be on any network or maybe their 4G mobile connection.
Posted
If your using Hikconnect then that is the risk as that is beyond your control (and in Hik's control...)

 

 

Yes but what are the actual risks? Your connection from the NVR will obviously be talking to a server in China but as long as your NVR is on a seperate network then no one can access your other networks.

 

From a privacy point of view they could watch your cameras but apart from that couldnt get into anything else.

Posted
Yes but what are the actual risks? Your connection from the NVR will obviously be talking to a server in China but as long as your NVR is on a seperate network then no one can access your other networks.

 

From a privacy point of view they could watch your cameras but apart from that couldnt get into anything else.

 

Well the actual risk is far more than if they didn't have cloud access to anything, that's for sure!

  • Thanks 1
Posted

Most smart tech / home automation / Security etc that is controllable via your phone will go via the cloud.

 

To me it comes down to two things:

 

- How strong the users passwords are.

 

- How efficient the company that stores your credentials in the cloud is at securing that information and not letting it out via a data leak.

Posted (edited)
From a privacy point of view they could watch your cameras but apart from that couldnt get into anything else.

 

Barring everything else jus this is enough for me. You only have to look at the Ring issue.

Edited by Davit2005
Posted
Most smart tech / home automation / Security etc that is controllable via your phone will go via the cloud.

.

 

Exactly! That's why you shouldnt be enabling cloud access on devices that you may not posibly trust.

 

I don't get it - whats the point of vlanning things out or physically seperating networks if your just gonna tick the enable cloud box anyway and lose all semblance of security??

  • Thanks 1
Posted (edited)

For those who are separating the hikvision CCTV equipment in a seperate VLAN, how are you virulent the footage?

 

Using software on a PC in the main LAN that has the internet? Also shared with data, emails etc. That’s a risk in itself.

 

I work in a regulated environment. We have dedicated CCTV workstations for viewing footage and they don’t have internet or access to any other resources either.

Edited by FN-GM
Posted (edited)
Yes but what are the actual risks?

 

Classified. Need to know. No smoke without fire etc etc. However I've not seen it seriously suggested that remote access and viewing without local authorization is a substantial risk for these devices. If they had we'd all have them isolated by default.

 

 

From a privacy point of view they could watch your cameras but apart from that couldn't get into anything else.

 

Some random bloke outside of UK jurisdiction without a DBS somewhere on the internet can view students who believe themselves to be in a safe environment... that is enough to require the system to be isolated from the internet.

 

What is problematic: we have no way of evaluating how likely that scenario is. Except that even the most recent reporting on this topic does not present a case that such backdoors or behaviours exist:

 

https://www.theregister.com/2023/06/08/uk_government_china_cam_removal/

 

The threat, I suppose, for each organisation to evaluate is that it is trivial (for the most part) to embbed backdoors into these types of devices (computers), and they are everywhere and sometimes not where they are supposed to be (whomsoever among us has never found a device patched to the wrong port?) They are computers - do you want computers that are trivially backdoored by a potentially hostile entity hooked up to your network, or even in the same building as your network?

 

But how likely is it that they will turn hostile? And what will that impact be on your organisation, its infrastructure and the data you hold? We all are at risk from this kind of shenanigans:https://www.tenable.com/blog/rooting-a-printer-from-security-bulletin-to-remote-code-execution but what if it came as a state-level intervention?

 

Each organisation has its own risk profile, and some organisations may not appreciate their profile in the national security landscape. We saw this through lockdown, schools, hospitals and local government are pretty important pieces of national infrastructure even though they aren't handling 'security marked' communications of central government and agencies.

 

Personally I've never trusted them, so they are isolated with no internet. But again then, so was the previous system.

 

Hopefully (for us) it will be a year or three before anything need to be done with existing installations outside of those handling sensitive data.

Edited by psydii
Posted
Exactly! That's why you shouldnt be enabling cloud access on devices that you may not posibly trust.

 

I don't get it - whats the point of vlanning things out or physically seperating networks if your just gonna tick the enable cloud box anyway and lose all semblance of security??

 

 

The point is that if they can access your NVR it is an open door to then access other parts of your network so you are securing your important network by restricting CCTV to it's own VLAN.

 

As for them viewing my cameras, I'm not that bothered with that. We all get picked up by millions of cameras around us on a daily basis.

 

By using HikConnect our Premises officers can be off site and notified of any movement instantly to their devices.

As long as you do not give access to the Hikconnect software to anything else then I don't see how using it can compromise your mobile device.

 

A main feature of CCTV is instant notifications so how are you supposed to get these if you aren't connected to the internet?

Posted
The point is that if they can access your NVR it is an open door to then access other parts of your network so you are securing your important network by restricting CCTV to it's own VLAN.

 

As for them viewing my cameras, I'm not that bothered with that. We all get picked up by millions of cameras around us on a daily basis.

 

By using HikConnect our Premises officers can be off site and notified of any movement instantly to their devices.

As long as you do not give access to the Hikconnect software to anything else then I don't see how using it can compromise your mobile device.

 

A main feature of CCTV is instant notifications so how are you supposed to get these if you aren't connected to the internet?

CCTV notifications does NOT require NVRs to be accessible from the public internet. All our NVRs are on a private VLAN with no internet access. Notifications use SMTP server on the network to send email notifications to me, no open inbound ports required and we do not use Hik-connect.

Posted
Personally my issue is that some CCTV systems take away a lot of the control and put it in someone else's hands. I might go back to Unifi Protect as example here as I don't think there is anyway set your own email server for notifications in Unifi Protect it is simply enable cloud connectivity or it notifications do not work, is HikVision like that too?
Posted
CCTV notifications does NOT require NVRs to be accessible from the public internet. All our NVRs are on a private VLAN with no internet access. Notifications use SMTP server on the network to send email notifications to me, no open inbound ports required and we do not use Hik-connect.

 

 

So if you are sent an email notification when you are offsite are you then having to remote in to your PC to then access your cameras?

  • 2 weeks later...
Posted

There's an article on the BBC website today about Hikvision cameras:

 

https://www.bbc.co.uk/news/technology-65975446

 

If I'm reading the article correctly, they had someone try and hack in to a "demo" Hikvision camera, possibly with out-of-the-box firmware from 2017 rather than a more up-to-date version with a specific, known vulnerability patched. That's probably a reasonably fair test, as I imagine there's a fair few installations of various CCTV cameras where they've been installed and simply left with no further updates since, although I don't think the article explains that very well. They did point out that they had to put the camera on a separate network as the standard network at the BBC was properly VLAN-ed, firewalled, etc. I suspect the replace-specific-brands-of-cameras solution is simply going to create the same problem in a few years time - CCTV system gets replaced with new install-and-forget system, system has security flaw discovered in a few years time, people can use that flaw to exploit un-patched out-of-date cameras.

  • Thanks 4
Posted
It's all political. Not technical.

Yes to some degree it is definately political. However, securing any IOT device or device that communicates over the cloud should be mandatory.

 

There will always be people trying to get round the latest technology.

Posted
That BBC article is utter rubbish, Sun level Journalism.

 

So a vendor (Who no doubt has an ulterior motive), supplies the BBC with a hikvision camera with a known firmware bug from 2017, slaps it on a open network and then goes LOL LOOK WE CAN HACK IT.

No kidding?

 

How is this any different than other CCTV vendors that have had firmware bugs over the years? It's not - They are scaremongering.

 

What matters is that Hikvision patches the exploit, which they did.

Target HikVision for legit reasons, not random nonsense.

 

Yep. If we're going to panic and boycott everyone who has ever had a security exploit then we might as well give up on computers, issue everyone with an abacus instead and pray no-one with woodworking tools finds out.

  • Thanks 1
Posted
Yep. If we're going to panic and boycott everyone who has ever had a security exploit then we might as well give up on computers, issue everyone with an abacus instead and pray no-one with woodworking tools finds out.

 

It's the way they word this

The camera Panorama tested contains a vulnerability discovered in 2017. IPVM's director Conor Healy describes this as "a back door that Hikvision built into its own products."

 

The implication from this is that the vulnerability is deliberate, but there's no evidence of that & indeed it was patched quickly.

 

By his logic here, every other vendor is guilty of "deliberately" adding backdoors into their software.

Posted

I have to agree - if the security issue is still there on a 2023 firmware patched camera, then fine you have a point.

 

Otherwise lets load Windows 7 RTM and connect it to the internet and see what happens. I really see no difference.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...