Security deficiencies – Swiss authorities rely on Chinese security cameras – News


contents

Research by SRF Investigativ shows that Swiss authorities are using Chinese surveillance cameras. Vulnerabilities in the devices could compromise cyber security. SRF Investigativ tested a model.

Security cameras are often used to provide security. But they can become a security problem themselves. According to various analyzes and studies abroad, products from the Chinese camera manufacturers Dahua and Hikvision can have a particularly large number of weak points.

Products from these surveillance camera manufacturers led to discussions abroad about security gaps and data security. At the same time, suppliers from China are market leaders when it comes to surveillance technology.

Easy access through outdated software

In an experiment, SRF Investigativ tested how secure a commercially available model from the manufacturer Hikvision is. The result: no data flowed to China. But with the help of outdated camera software and a programming script found on the Internet, the camera was easily hacked.

David Gugelmann, IT security expert at the Swiss company Exeon Analytics, conducted the test. He describes the process: “We created a new user account with a password and we were able to use the user account to take over the image from the camera. We were able to redirect the camera data stream to our machine».

In order to find out which authorities used models from Hikvision or Dahua, SRF wrote to seven large cities in German-speaking Switzerland. The city of Zurich uses a large number of Hikvision cameras – the city police alone have 35 such cameras in use. The canton of Basel-Stadt and the Zug police also use cameras from Hikvision or Dahua.

The federal administration in Bern, on the other hand, says it does not use any of these models. The different use is due to the fact that there are no valid procurement guidelines in Switzerland. Analyzes of IP addresses by SRF Investigativ also show that thousands of such cameras are connected to the Internet in Switzerland.

Security risks for Swiss authorities?

At the request of SRF, the city of Zurich explained that the security cameras operated were not directly connected to the Internet. You would be in the city’s ZüriNetz network. In addition, the cameras are separated from external networks and access by technical measures. Other authorities argue similarly.

Security expert Gugelmann still sees a certain risk. For cameras in isolated networks, security updates are often not installed promptly. “And it’s a well-known fact that old software often has weaknesses that can be exploited.”

We must not make ourselves too dependent on countries like China.

Marionna Schlatter, National Councilor of the Greens and member of the Security Policy Commission, says to SRF: “Transparency is important: As long as we at the various levels of government do not know where what is procured from China, we are not able to act. We must not make ourselves too dependent on countries like China. In the case of sensitive, security-relevant technologies in particular, a strategy is needed to ensure that our sovereignty and independence can be preserved.»

Hikvision says about the test by SRF Investigativ that the affected security gap has already been fixed. Hikvision adheres to the strictest global standards. The devices and data of the end users are protected. Dahua says it protects users’ privacy and informs customers about vulnerabilities in a timely manner.

source site-72