

Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- Next up, chinese solar inverter firmware.by irishcoffee
- Do they even need that since, when most of the converters are attached to the Chinese cloud?by hansoolo
- To do what? Turn off the power in random individual houses?
- The problem I see is that Putin fully committed to the war. It is not only clear that he has no interest in ending the war, despite the lip service, but will continue to create problems and cause issues. This backdoor here is not an isolated problem - it is a systemic, concerted problem. All retaliatory moves are handicapped by orange Agent Krasnov being an asset for Russia. The EU needs to stop outsourcing its security. That includes having a nuclear arsenal available for all member states.by shevy-java
- I think i read Japan does this to CCTVs sold in China
Public Security Intelligence Agency (公安調査庁) apparently is sitting on a massive amount of data from China which imported their tech
by zuzululu - What's the purpose of this? Opening a way to make the cameras going rogue and starting to fine everybody in a particular period of time to create massive discontent, administration chaos, and unrest? maybe just before an election? Aren't this cameras connected with some government computers?by pvaldes
- Perhaps. What actually happened is that we have a demented interior minister in a unbelievably corrupt but also pro-russian government. So it's really anybodys guess if it's just pure corruption (the interior ministry wanting to buy some traffic cameras and someone bribing to get the contract while buying the cheapest they could find which were these russian ones) or indeed some covert russian operation (the responsible minister wouldn't know about it, he's too dumb for that, but there might be other government people who did know). In any case in a functioning state this would end up with the minister leaving his post at least. Not in Slovakia.by tpm
- Imagine somebody being able to track almost anyone using road side cameras. Good thing such things happen only in eastern Europe wink winkby tomas789
- For the goal of recording a cat scratching their car or catching an imaginary thief neighbour (a magpie or fox stole that thing that one time, you dullard) people will plug into Chinese, Russian, and American video surveillance networks in no time and pay for it.
- Most cameras are insecure by default. Check out: http://www.insecam.org/en/ or https://www.shodan.io/ The first isn't even using default access creds, which I suspect is what was 'discovered' in this case, but cameras that immediately hook up to the internet with 0 restrictions to access.
- It seems like a silly mess. But its easier than it sounds to end up in such a situation. We're are a lot of HN Kagi users that just have to trust that the Yandex collaboration is fully watertight.by tokai
- "Кордон.Про" product page on the simicon siteby sorokod
- > the cameras expose live streams to anyone without a password and who knows their broadcasting IP.
Are these cameras in use in Russia? Can people outside of Russia look in at Russian traffic in this way?
by Animats - There is a small number of cameras which broadcast the video publicly. For example, Moscow: [1] (Taganskaya square), [2] and Saint-Petersburg: [3] (Nevsky prospect and Gostiniy Dvor). Sadly the quality is not great and in reality those places look much better. For example, many of the small 2-floor buildings on Taganskaya square are over 100 years and have a nie classical architecture but one cannot see any fine details in the camera view.
[1] https://gidcam.ru/camera/moskva-panorama-centra-stolicy-s-ma...
[2] https://gidcam.ru/camera/moskva-volgogradskij-prospekt-i-plo...
[3] https://camguide.net/ru/europe/russia/saint-petersburg/nevsk...
by codedokode - Over 100 comments, zero mentions that government funds should be spent on devices with auditable open-source firmware. Anyone here? No? Then I'm the first one to say this.
SecureBoot is a funny one. It should be signed with the deployer's keys (Slovak), not the manufacturer's. Trusted boot probably wasn't a consideration here, really.
Ironically, a custom firmware can now be used thanks to the lack of a digital lock... if you still trust the hardware.
PS: Props to NBU for doing their job.
by PinkSheep - Would you be able to get those devices at all, especially at similar price as those with closed source firmware? Rby srdjanr
- Maybe you trust the hardware and software and firmware to not be malicious or negligent (currently such assurances are extremely rare [1], so it's hard to overstate what a step up in security just this bare minimum would be), but what if it simply gets hacked by a nation-state level opponent? And there are so many ways to hack it - hardware and software supply chains, interdiction and replacement with compromised parts, attacking the software systems connected to it (maybe the camera is secure, but what about the computers it sends its signals to?), or the human systems, blackmailing an employee to insert a backdoored USB key somewhere...
Are traffic cameras worth the risk of giving away the movement of your key personnel, military and political, in the age of drone warfare and targeted strikes?
- That was in fact the angle of the Fediverse post from which I first saw this story:
"Please use open source systems whenever possible so you can review the source code."
by dredmorbius - So they bought the cameras and some people pointed out they look exactly the same as Russian cameras. The government denied this but after they figured out the serial numbers matched the Russian cameras they started this investigation.
Good they investigated this before using them, but this sounds like a big fu...
by bdhdhduuyd - A big what?by NuclearPM
- With high probablity they are actually made in China. I don't think Russia makes their own chips for cameras.by codedokode
- This would be far more impressive if not for:
> multiple reports in Slovak media that linked the purchase to a Cyprus shell company with fake certifications.
We're talking about this as if it's some precursor to a James Bond plot, but it really fizzles after learning Nina in the sourcing department skipped the compliance paperwork. James Bond doesn't need to leave the bed!
Trojan exploits aside, I just assume that it'd be easier for someone in SVR/GRU to bribe an admin.
by caminante