TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

UK government ban for Chinese Hikvision CCTV cameras

108 pointsby TT482over 2 years ago

14 comments

squarefootover 2 years ago
They probably were alerted by this.<p><a href="https:&#x2F;&#x2F;www.fortinet.com&#x2F;blog&#x2F;threat-research&#x2F;mirai-based-botnet-moobot-targets-hikvision-vulnerability" rel="nofollow">https:&#x2F;&#x2F;www.fortinet.com&#x2F;blog&#x2F;threat-research&#x2F;mirai-based-bo...</a><p>However, going after just a brand solves nothing; the problem is that nobody can properly audit these devices due to their closed nature. A huge number of IP cameras and DVR&#x2F;NVR devices have been either compromised for botnet installation or caught phoning home (usually somewhere in China) in the past. Unless one can purchase a fully Open Source one (including hardware and firmware), there are no guarantees that a device won&#x27;t be doing nasty things, or silently waiting for remote triggers to do so, which is something that only source code inspection could guarantee against. In the meantime the solution has always been to put them behind a firewall that doesn&#x27;t let them initiate connections to the outside and also filters out incoming connections from untrusted parties; this should apply to all closed connected device, not just Hikvision cameras.<p><a href="https:&#x2F;&#x2F;www.wsj.com&#x2F;articles&#x2F;hackers-infect-army-of-cameras-dvrs-for-massive-internet-attacks-1475179428" rel="nofollow">https:&#x2F;&#x2F;www.wsj.com&#x2F;articles&#x2F;hackers-infect-army-of-cameras-...</a><p><a href="https:&#x2F;&#x2F;hacked.camera&#x2F;" rel="nofollow">https:&#x2F;&#x2F;hacked.camera&#x2F;</a>
评论 #33743419 未加载
tingleover 2 years ago
The behavior of the United Kingdom looks incoherent: it wants to become a surveillance state [1], but without using cameras manufactured in China, on the grounds that China is a surveillance state.<p>[1] &lt;<a href="https:&#x2F;&#x2F;www.cctv.co.uk&#x2F;how-many-cctv-cameras-are-there-in-the-united-kingdom&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.cctv.co.uk&#x2F;how-many-cctv-cameras-are-there-in-th...</a>&gt;
评论 #33743321 未加载
评论 #33743266 未加载
rcarrover 2 years ago
Possibly stupid&#x2F;overly paranoid question: if most products are being made in China anyway, how do we know they’re not putting backdoors in everything including goods branded for non Chinese companies? Cables, power adapter etc all house chips nowadays. In theory couldn’t they have some kind of silent zero day virus on them, keylogger etc?<p>Does every product on sale get periodic testing to check for this kind of thing? It seems like they could manufacture clean devices to send to a test centre and then back door ones they release in the wild. In the case of non-brand goods such as cables it wouldn’t even really matter if they got caught because they could just spin up another drop ship company under a different name and keep selling.
评论 #33742126 未加载
评论 #33742289 未加载
评论 #33742176 未加载
bennyp101over 2 years ago
My cameras are on their own vlan, with outbound internet access disabled - so in theory they aren&#x27;t sending anything anywhere else.<p>So is this less about the actual cameras, and more that they have been installed insecurely and not kept up to date with firmware? Or the hardware used to record the data is acutally in the cloud somewhere and that is the issue?
评论 #33741548 未加载
评论 #33741867 未加载
评论 #33741643 未加载
评论 #33741969 未加载
评论 #33742773 未加载
评论 #33741511 未加载
hhhover 2 years ago
I had to hunt down all of the banned devices when the 2019 ban took place on Dahua, Hikvision, and Huawei. I&#x27;ve never seen worse quality feeling looking software. Random cameras requiring Chrome Apps to manage, or some obscure Windows software package.<p>I&#x27;ll take an RTSP feed from AXIS over those any day.
ilytover 2 years ago
At that scale it <i>gotta</i> be cheaper to pay someone to reverse-engineer them and flash with something open source ?
评论 #33741439 未加载
评论 #33741477 未加载
评论 #33741538 未加载
LatteLazyover 2 years ago
This reminds me of the whole Huawei thing: no actual evidence of any problem, no economic reason, no real political gain, but &quot;feelings&quot;. I wonder if a US CCTV provider is about to get a multi billion pound contract having recently &quot;donated&quot; to the groups making this &quot;necessary&quot; &quot;security&quot; decision...
评论 #33742587 未加载
评论 #33743348 未加载
评论 #33742624 未加载
评论 #33743282 未加载
lazyeyeover 2 years ago
Why is the response to this kind of major security risk always a barely there, bit of useless security theatre?<p>&quot;We wont ban TikTok because the CCP has given a commitment not to look at the massive trove of data they are continually harvesting...&quot;
drekipusover 2 years ago
Hikvision is leading cctv manufacturer. They make Swann CCTV systems as well.<p>I&#x27;m sure anyone the UK Gov replaces it with will be from the same factory unless they want to start manufacturing their own.
评论 #33741638 未加载
评论 #33743328 未加载
andrewstuartover 2 years ago
Love the utterly irrelevant denial from Hikvision:<p>&quot;Hikvision cannot transmit data from end-users to third parties, we do not manage end-user databases, nor do we sell cloud storage in the UK.&quot;
Havocover 2 years ago
Somewhat OT but perhaps someone knows. I noted the cameras in UK airports have dual eth cables going in. Anybody know what&#x27;s up with that?
评论 #33742619 未加载
评论 #33741413 未加载
评论 #33741407 未加载
UltraViolenceover 2 years ago
Why just HikVision? And why only certain models?<p>I&#x27;m pretty sure almost every Chinese made CCTV camera is riddled with backdoors and vulnerabilities. And almost all upload their video streams to some server in China.
评论 #33757591 未加载
jeffalyanakover 2 years ago
Time to watch the government auction sites for cheap cameras.
评论 #33742031 未加载
2Gkashmiriover 2 years ago
&gt;Professor Sampson asks: &quot;Do you want untrusted companies screening at airports, watching school playgrounds or on hospital wards?&quot; He gave the example of one such company that has won awards for work monitoring children on school buses in Scotland that is now on the new ban list.<p>is this an actual &quot;professor&quot; speaking sense? what do you mean untrusted companies? either hikvision exfiltrates data from the UK to china servers and there are logs to verify that or hikvision could remotely access any device even if it was not online or was online with security but they have a bypass, both could be verified but other than these two cases, what is this pre-emptive ban that could cost the public exchequer millions or billions for what? a hunch that, as they put it, &gt;&quot;We are no longer asking whether certain security companies can be trusted, we now accept they can&#x27;t, but we need to work out how to verify those we can trust.&quot;<p>so they will first ban hikvision, remove all their cameras from UK, replace that with a competitor, THEN authenticate the trustworthiness of hikvision and THEN maybe let them back in the market.<p>WTF thinks like that unless you have malicious intent?
评论 #33741361 未加载
评论 #33741360 未加载
评论 #33741441 未加载
评论 #33741455 未加载