News: 1615402872

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Hacktivists breach Verkada and view 150,000 CCTV cams in hospitals, prisons, a Tesla factory, even Cloudflare HQ

(2021/03/10)


A CCTV camera biz which left an admin account username and password exposed on the World Wide Web has, you guessed it, been targeted by hacktivists.

Verkada, makers of internet-connected surveillance devices, had around 150,000 cameras and archive footage accessible through its web infrastructure when unauthorised folk went poking about.

[1]

Those cameras belonged to a whole host of organisations, according to the Bloomberg financial newswire, including: Tesla; Cloudflare; hospitals; police stations; prisons and, allegedly, more.

The security breach has been reportedly shut off, with a Verkada spokesman [2]quoted as saying: "Our internal security team and external security firm are investigating the scale and scope of this issue, and we have notified law enforcement."

[3]

Cloudflare said in a statement the cameras in its premises that the hacktivists accessed "were located in a handful of offices that have been officially closed for several months" and also added something incomprehensible about "zero trust" being relevant to cameras deployed in its offices and aimed at its employees. The devices have now been disconnected.

CCTV hack takes casino for $33 MILLION in poker losses [4]READ MORE

Tesla [5]told the Reuters newswire that the hacktivists viewed one Chinese production plant and not its showrooms in Shanghai, though the distinction was not explained.

Bloomberg also said it had been shown video footage of facial-recognition technology being operated covertly inside a US prison in Alabama. Britain's Daily Telegraph reported that the NHS was a Verkada customer, though it did not say whether the hacktivists had been viewing UK surveillance footage.

The global infosec industry fell over itself this afternoon to speek itz branes about the breach.

"While the true motivation of the group remains hidden, it looks like cyber activism – a breach aiming to expose the poor security of CCTV cameras. However, keep in mind that these compromised devices could also be used to install malware and start DDoS attacks, as well as infiltrate connected networks – with profit to be gained," opined Candid Wüest, Acronis' cybersecurity research veep.

Kelvin Murray, a senior threat research analyst at Webroot, commented: "Online cameras have been a favourite hacker hobby for years but it is rare to hear of a security camera company being owned in this fashion, especially one with such high-profile clients. Thankfully for the victims, on this occasion the attackers seem to be more interested in vandalism and were fairly open about their activities."

The attackers seem to be more interested in vandalism and were fairly open about their activities

Murray is right: CCTV cameras have [6]long been a [7]target for the [8]digitally naughty .

While some might baulk at the scale of digital surveillance revealed here, arguments against the digital panopticon were fought hard (and lost comprehensively) in the 2000s; these breaches are now a fact of life in the 21st century.

[9]

Numerous reports listed well-known hacktivist Tillie Kottmann as being partly responsible for the pwning of Verkada. We have asked Kottmann for comment. ®

Get our [10]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YElPjRqSMam9nVY53lJ-ywAAAIg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://www.bloomberg.com/news/articles/2021-03-09/hackers-expose-tesla-jails-in-breach-of-150-000-security-cams

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YElPjRqSMam9nVY53lJ-ywAAAIg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://www.theregister.com/2013/03/15/cctv_hack_casino_poker/

[5] https://www.reuters.com/article/us-verkada-breach/verkada-surveillance-cameras-at-tesla-hundreds-more-businesses-breached-hackers-idUSKBN2B2048

[6] https://www.theregister.com/2016/11/30/iot_cameras_compromised_by_long_url/

[7] https://www.theregister.com/2018/09/17/nuuo_cameras_rce/

[8] https://www.theregister.com/2016/02/03/motorola_cctv_iot_insecure/

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YElPjRqSMam9nVY53lJ-ywAAAIg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://whitepapers.theregister.com/

They told us it would be great

b0llchit

This type of story is so typical of the current state of affairs in the "connected" world.

"Use the cloud" they told us. "It will be great and cheap" they sold us.

Being a technical type, I can only see with a great deal of cynicism on the current state of security. Constant breaches are the norm and still people think the cloud is so great. Good, Cheap, Secure ; pick two, you can't have all three. That has not changed in all these years and it never will. When does management learn? Probably only when they will be made personally responsible.

Re: They told us it would be great

Paul Crawford

Good, Cheap, Secure; pick two, you can't have all three.

You will be lucky to get one of the three.

Not again!

MasterofDisaster

The irony of course is that Verkada bills itself as the solution to all the other camera vendors being insecure. Maybe they need to reassess having half the company in sales, instead of engineering. Yet another wakeup call for operators of physical security systems (IoT) to get some religion around updating firmware, managing certificates, and more comprehensive password management (i.e. what IT security has been doing for years).

CrackedNoggin

From an interview with Filip Kaliszan, CEO of Verkada, on Verkada's own website: https://www.verkada.com/blog/verkada-enterprise-security-startup-1-point-6-billion-dollar-valuation/

Q: What are your retention metrics? What causes people to cease using the service?

A: For today’s businesses, security is not an option - it’s a necessity. Unless a customer has a compelling reason to switch to another platform, Verkada is exceptionally sticky. That’s due mainly to the nature of our system. With security infrastructure, there’s a significant upfront commitment from the customer: she has invested both in the hardware and the labor to physically install a system throughout her buildings.

Its all Sh--.

Anonymous Coward

These camera platforms are all nightmarishly bad.

Worse, if you try to compete with the crap china is dumping on the market, you'll go bankrupt. Unless you bin and blacklist every camera in the IP era it will never get better. All of these little horrors should only be allowed on an air-gapped network, and have no direct access to the internet.

But I'm not holding my breath on the current leadership setting any kind of standards for IP cams, so the standard shall remain substandard.

As some day it may happen that a victim must be found
I've got a little list -- I've got a little list
Of society offenders who might well be underground
And who never would be missed -- who never would be missed.
-- Koko, "The Mikado"