element14 Community
element14 Community
    Register Log In
  • Site
  • Search
  • Log In Register
  • About Us
  • Community Hub
    Community Hub
    • What's New on element14
    • Feedback and Support
    • Benefits of Membership
    • Personal Blogs
    • Members Area
    • Achievement Levels
  • Learn
    Learn
    • Ask an Expert
    • eBooks
    • element14 presents
    • Learning Center
    • Tech Spotlight
    • STEM Academy
    • Webinars, Training and Events
    • Learning Groups
  • Technologies
    Technologies
    • 3D Printing
    • FPGA
    • Industrial Automation
    • Internet of Things
    • Power & Energy
    • Sensors
    • Technology Groups
  • Challenges & Projects
    Challenges & Projects
    • Design Challenges
    • element14 presents Projects
    • Project14
    • Arduino Projects
    • Raspberry Pi Projects
    • Project Groups
  • Products
    Products
    • Arduino
    • Avnet Boards Community
    • Dev Tools
    • Manufacturers
    • Multicomp Pro
    • Product Groups
    • Raspberry Pi
    • RoadTests & Reviews
  • Store
    Store
    • Visit Your Store
    • Choose another store...
      • Europe
      •  Austria (German)
      •  Belgium (Dutch, French)
      •  Bulgaria (Bulgarian)
      •  Czech Republic (Czech)
      •  Denmark (Danish)
      •  Estonia (Estonian)
      •  Finland (Finnish)
      •  France (French)
      •  Germany (German)
      •  Hungary (Hungarian)
      •  Ireland
      •  Israel
      •  Italy (Italian)
      •  Latvia (Latvian)
      •  
      •  Lithuania (Lithuanian)
      •  Netherlands (Dutch)
      •  Norway (Norwegian)
      •  Poland (Polish)
      •  Portugal (Portuguese)
      •  Romania (Romanian)
      •  Russia (Russian)
      •  Slovakia (Slovak)
      •  Slovenia (Slovenian)
      •  Spain (Spanish)
      •  Sweden (Swedish)
      •  Switzerland(German, French)
      •  Turkey (Turkish)
      •  United Kingdom
      • Asia Pacific
      •  Australia
      •  China
      •  Hong Kong
      •  India
      •  Korea (Korean)
      •  Malaysia
      •  New Zealand
      •  Philippines
      •  Singapore
      •  Taiwan
      •  Thailand (Thai)
      • Americas
      •  Brazil (Portuguese)
      •  Canada
      •  Mexico (Spanish)
      •  United States
      Can't find the country/region you're looking for? Visit our export site or find a local distributor.
  • Translate
  • Profile
  • Settings
Business of Engineering
  • Technologies
  • More
Business of Engineering
Blog Swann cameras may be worth avoiding for a while..
  • Blog
  • Forum
  • Documents
  • Quiz
  • Events
  • Polls
  • Files
  • Members
  • Mentions
  • Sub-Groups
  • Tags
  • More
  • Cancel
  • New
Join Business of Engineering to participate - click to join for free!
  • Share
  • More
  • Cancel
Group Actions
  • Group RSS
  • More
  • Cancel
Engagement
  • Author Author: shabaz
  • Date Created: 27 Jun 2018 2:20 PM Date Created
  • Views 1461 views
  • Likes 9 likes
  • Comments 10 comments
Related
Recommended

Swann cameras may be worth avoiding for a while..

shabaz
shabaz
27 Jun 2018

Rather shocking security issue, reported here:

https://www.bbc.com/news/technology-44628399

 

Long story short, users are seeing video captured from cameras they don't own.

Quite pathetic how come the system would allow such a situation to occur so easily - both the hardware and the software ought to have been designed to eliminate this possibility, from using guaranteed unique hardware keys (permanently burned in) to software developed and tested at a significant level commensurate to the high value of the data (i.e. the video) that was at risk if they got it wrong..

It's not as if security technologies do not exist. They exist, but in the reported system, on the face of it, maybe they were badly implemented or were not used at all.

  • Sign in to reply

Top Comments

  • ntewinkel
    ntewinkel over 7 years ago +3
    Yikes! I think the worst part may be the way the company handled it. 1) customer support said there's nothing they could do til after the weekend 2) they blamed the users for having the same username and…
  • DAB
    DAB over 7 years ago +3
    There are many reasons why I do not use these types of products. Security issues are high on the list. The people developing these things just have not done a sufficient risk analysis. The sad thing is…
  • ntewinkel
    ntewinkel over 7 years ago in reply to shabaz +3
    Oh wow, when a 'global leader' has this kind of bugs, it makes you wonder whether we are heading for a tech collapse!
Parents
  • ntewinkel
    ntewinkel over 7 years ago

    This article about TappLock (was that mentioned here on e14 earlier?) seems to hit the nail on the head pretty good:

    https://blog.hackster.io/the-tapplock-a-typical-iot-problem-child-60dff98a0407

     

    In a nutshell:

    "There’s a great deal of pressure on startups to ship product..."

    "Prototypes, intended as nothing more than proof-of-concept, have an alarming tendency to ship as product."

    "Not thought about during the prototyping phase... security is often times bolted on top as an after thought, after the prototype has already become the product."

     

    It seems a lot of startups are designed for the short term.

    I've also noticed a lot of such places are using very junior talent who often don't think far enough ahead.

     

    -Nico

    • Cancel
    • Vote Up +2 Vote Down
    • Sign in to reply
    • More
    • Cancel
  • ntewinkel
    ntewinkel over 7 years ago in reply to ntewinkel

    Although... Swann isn't a startup anymore, is it?

    • Cancel
    • Vote Up +1 Vote Down
    • Sign in to reply
    • More
    • Cancel
  • shabaz
    shabaz over 7 years ago in reply to ntewinkel

    Hi Nico!

     

    Interesting product your startup makes.

     

    Regarding Swann, their website states they are a 'global leader' and have presence in 40+ countries. It's awful customer-handling too you say. Definitely a case-study of what not to do!

    I am considering upgrading our ancient (8-year old model) Panasonic IP security cam this year.. it's been reliable except the fan started to whine in winter time. It is only standard-definition so due an upgrade. Swann wasn't on the list to be honest.

    • Cancel
    • Vote Up +2 Vote Down
    • Sign in to reply
    • More
    • Cancel
  • ntewinkel
    ntewinkel over 7 years ago in reply to shabaz

    Oh wow, when a  'global leader' has this kind of bugs, it makes you wonder whether we are heading for a tech collapse!

    • Cancel
    • Vote Up +3 Vote Down
    • Sign in to reply
    • More
    • Cancel
  • shabaz
    shabaz over 7 years ago in reply to ntewinkel

    I think it's just a lack of respect for their customers with some of their most valuable data.

    Engineers have gone to the effort of developing suitable security chips and software technologies, and organisations like banks manage to prevent users having the same username, and securing bank records, using known well established methods, many of which are open source. Sure things can go wrong and there could be zero-day vulnerabilities, but what happened here was through ordinary use of the product and is just embarrassing. They possibly didn't invest in the hardware and software to ensure security, because they possibly didn't respect nor place a decent value on their customer's data.

    • Cancel
    • Vote Up +3 Vote Down
    • Sign in to reply
    • More
    • Cancel
Comment
  • shabaz
    shabaz over 7 years ago in reply to ntewinkel

    I think it's just a lack of respect for their customers with some of their most valuable data.

    Engineers have gone to the effort of developing suitable security chips and software technologies, and organisations like banks manage to prevent users having the same username, and securing bank records, using known well established methods, many of which are open source. Sure things can go wrong and there could be zero-day vulnerabilities, but what happened here was through ordinary use of the product and is just embarrassing. They possibly didn't invest in the hardware and software to ensure security, because they possibly didn't respect nor place a decent value on their customer's data.

    • Cancel
    • Vote Up +3 Vote Down
    • Sign in to reply
    • More
    • Cancel
Children
No Data
element14 Community

element14 is the first online community specifically for engineers. Connect with your peers and get expert answers to your questions.

  • Members
  • Learn
  • Technologies
  • Challenges & Projects
  • Products
  • Store
  • About Us
  • Feedback & Support
  • FAQs
  • Terms of Use
  • Privacy Policy
  • Legal and Copyright Notices
  • Sitemap
  • Cookies

An Avnet Company © 2025 Premier Farnell Limited. All Rights Reserved.

Premier Farnell Ltd, registered in England and Wales (no 00876412), registered office: Farnell House, Forge Lane, Leeds LS12 2NE.

ICP 备案号 10220084.

Follow element14

  • X
  • Facebook
  • linkedin
  • YouTube