Your IP camera is a computer

November 2015 News & Events

It’s a sad fact that in the security industry, cost more often than not clinches the deal. This is not always the case as there are some people out there buying security because they know what they want to get out of it, but in many cases it is still a grudge purchase and the cheapest offer wins – or the guy who knows the guy and/or sweetens the deal, wins.

A couple of decades ago this may have been acceptable, but not today. In a world where everything is connected, you can’t leave vulnerabilities open to exploitation because they will be exploited. Take the example of Hikvision a few months ago when its cameras were used to compromise a network. The issue was publicised and Hikvision’s name was associated with the breach, but in the end it was not the camera manufacturer’s fault.

In this particular instance, the installer hadn’t bothered to change the default password on the IP cameras, allowing hackers to easily access the cameras and then the network. Hikvision has since said it is updating its firmware to ensure that installers have to change the password when installing a camera. Unfortunately this won’t help unless the installer uses a decent password and not “password” for every camera. And that won’t happen unless the customer insists on strong passwords and actually manages the process to ensure it’s done.

Another more recent example comes from Israel where researchers found malware had been installed on a mall’s cameras – again the default passwords were left in place by an irresponsible installer – and the cameras were used to launch a denial of service attack. The attack was launching about 20 000 requests per second from around 900 IP cameras in this particular mall and other cameras around the world – a global CCTV attack. (You can see more at https://www.incapsula.com/blog/cctv-ddos-botnet-back-yard.html, short URL: https://goo.gl/NEh0Kp).

Identity and access

And on the subject of access and identity, our Access & Identity Management Handbook 2016 is being posted at the same time as the November issue, so make sure you get yours. It has 144 pages of information, trends and products to ensure you get a head start on access control in 2016. As always comments are welcome at [email protected]

Andrew Seldon

Editor



Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...
From the editor's desk: Showtime for Securex
Technews Publishing News & Events
We have once again reached the time of year when the security industry focuses on Securex. This issue includes a short preview, with more coming online and via our special Securex Preview news briefs. ...

Read more...
Chubbsafes celebrates 190 years
Gunnebo Safe Storage Africa News & Events Security Services & Risk Management
Chubbsafes marks its 190th anniversary in 2025 and as a highlight of the anniversary celebrations it is launching the Chubbsafes 1835, a limited edition 190th-anniversary collector’s safe.

Read more...
Suprema unveils BioStar Air
Suprema neaMetrics News & Events Access Control & Identity Management Infrastructure
Suprema launches BioStar Air, the first cloud-based access control platform designed to natively support biometric authentication and feature true zero-on-premise architecture. BioStar Air simplifies deployment and scales effortlessly to secure SMBs, multi-branch companies, and mixed-use buildings.

Read more...
New law enforcement request portal
News & Events Security Services & Risk Management
inDrive launches law enforcement request portal in South Africa to support safety investigations. New portal allows authorised South African law enforcement officials to securely request user data related to safety incidents.

Read more...
Igniting standards, powering protection
Securex South Africa News & Events Fire & Safety
Fire safety is more than compliance, it is a critical commitment to protecting lives, assets, and infrastructure. At Firexpo 2025, taking place from 3 to 5 June at Gallagher Convention Centre, that commitment takes centre stage.

Read more...
Digitising security solutions with AI and smart integration
Regal Security Distributors SA Technews Publishing Integrated Solutions
The Regal Projects Team’s decades of experience and commitment to integration have brought the digital security guard to life as a trusted force for safer, smarter living.

Read more...
The rise of AI-powered cybercrime and defence
Information Security News & Events AI & Data Analytics
Check Point Software Technologies launched its inaugural AI Security Report, offering an in-depth exploration of how cybercriminals are weaponising artificial intelligence (AI), alongside strategic insights defenders need to stay ahead.

Read more...
From the editor's desk: We’ve only just begun
Technews Publishing News & Events
The surveillance market has expanded far beyond the analogue days of just recording and/or monitoring screens. The capabilities of surveillance technology today extend to black screen monitoring with ...

Read more...
The future of the surveillance channel
Duxbury Networking Technews Publishing Elvey Security Technologies SMART Security Solutions Surveillance
The video surveillance market has evolved from camera-based specifications to integrated solutions that solve customers’ problems. Moreover, the growth of AI and cloud has changed the channel even more, with more to come.

Read more...