DEV Community

Serguey Shinder
Serguey Shinder

Posted on

Our Depot Cameras Were Installed by a Security Company and Secured by Nobody

In May our external scan reported a login page on the public address of one of our depots. It belonged to the video recorder for the site's cameras. The username was admin and the password was the one printed in the installation manual, which is available to anybody on the manufacturer's website.

We looked further. Across thirty one sites there are about four hundred cameras and thirty four recorders, installed over a decade by the security company that facilities contract for guarding and alarms. Their engineers maintain the equipment remotely, and to make that possible they had asked each site, years ago, to open a port on the router for them. Nine sites still had one open. The recorders ran firmware from 2019. Two had been added to a botnet at some point, which we only established after taking them apart.

None of this was hidden from us in any deliberate way. The cameras sat in the facilities budget, on the facilities contract, and appeared nowhere in our inventory. The security company assumed we looked after the network. We assumed the security company looked after its own equipment. Each of us was right about the other's responsibilities and wrong about our own. In the middle sat a set of devices that record the loading bays, the yard gate and the cash office, on the same network as the depot's warehouse terminals.

So the cameras are now ours, in the sense that matters. Every recorder is in our inventory with an owner in facilities and a technical contact in my team. They sit on their own network at each site, with no route to anything but a recording server and the internet addresses the supplier needs. The open ports are closed, and the supplier's engineers connect through our remote access service with named accounts that expire each evening. Firmware updates are a quarterly obligation in the renewed contract, with a report we check, and the default passwords were changed on the day we found them.

The awkward conversation was with facilities, who were entitled to ask why nobody had told them. Nobody had told us either.

Anything plugged into our network is part of our security whoever paid for it. I had not been treating a security contractor's equipment as a security risk, which in hindsight was the obvious place to look.

– Serguey Shinder

Top comments (0)