Over 100 comments, zero mentions that government funds should be spent on devices with auditable open-source firmware. Anyone here? No? Then I'm the first one to say this.
SecureBoot is a funny one. It should be signed with the deployer's keys (Slovak), not the manufacturer's. Trusted boot probably wasn't a consideration here, really.
Ironically, a custom firmware can now be used thanks to the lack of a digital lock... if you still trust the hardware.
PS: Props to NBU for doing their job.
show comments
gumby
Slovakia has had a longstanding pro-Russia political stance and supports Russia’s invasion of Ukraine (and opposes the EU sanctions).
So they bought the cameras and some people pointed out they look exactly the same as Russian cameras. The government denied this but after they figured out the serial numbers matched the Russian cameras they started this investigation.
Good they investigated this before using them, but this sounds like a big fu...
show comments
Animats
> the cameras expose live streams to anyone without a password and who knows their broadcasting IP.
Are these cameras in use in Russia? Can people outside of Russia look in at Russian traffic in this way?
show comments
thisisnotauser
The comments here seem to presuppose that somehow Slovakia is the only ones who would need to worry about this, and not, say, any town with Flock in it
Imagine somebody being able to track almost anyone using road side cameras. Good thing such things happen only in eastern Europe wink wink
show comments
physhster
It's almost as if electing a pro-Russia politician has consequences...
pvaldes
What's the purpose of this? Opening a way to make the cameras going rogue and starting to fine everybody in a particular period of time to create massive discontent, administration chaos, and unrest? maybe just before an election? Aren't this cameras connected with some government computers?
show comments
tokai
It seems like a silly mess. But its easier than it sounds to end up in such a situation. We're are a lot of HN Kagi users that just have to trust that the Yandex collaboration is fully watertight.
shevy-java
The problem I see is that Putin fully committed to the war. It is not only clear that he has no interest in ending the war, despite the lip service, but will continue to create problems and cause issues. This backdoor here is not an isolated problem - it is a systemic, concerted problem. All retaliatory moves are handicapped by orange Agent Krasnov being an asset for Russia. The EU needs to stop outsourcing its security. That includes having a nuclear arsenal available for all member states.
irishcoffee
Next up, chinese solar inverter firmware.
show comments
koonsolo
It wouldn't surprise me if the Russian misinformation inside Slovakia is able to spin this into an anti-EU, anti-Ukraine story.
lifestyleguru
Slovakian prime minister is doing proud photos with Putin despite the ongoing war so the backdoor looks like a desired feature not a bug or fuck up.
LogTrim
The detail that gets me is the Ministry saying the cameras were safe because they'd be on a closed network, while the backdoor can apparently be triggered via SMS from hardcoded phone numbers.
That's a pretty good demonstration of why "it's not exposed to the internet" isn't a security boundary if the device itself has an out-of-band communications path.
Add Secure Boot being disabled and unauthenticated live streams and this seems less like one unfortunate backdoor and more like nobody established what the trust boundary was supposed to be in the first place.
show comments
yodon
Zero chance of vulns in flock, so we're good in the US /s
ojciecczas
Fits perfectly in the russian thinking scheme, always infiltrating their neighbours and trying to get more. Fucking parasites.
juliusceasar
Russia to Slovakia is Israel to USA.
Puppet state.
Over 100 comments, zero mentions that government funds should be spent on devices with auditable open-source firmware. Anyone here? No? Then I'm the first one to say this.
SecureBoot is a funny one. It should be signed with the deployer's keys (Slovak), not the manufacturer's. Trusted boot probably wasn't a consideration here, really.
Ironically, a custom firmware can now be used thanks to the lack of a digital lock... if you still trust the hardware.
PS: Props to NBU for doing their job.
Slovakia has had a longstanding pro-Russia political stance and supports Russia’s invasion of Ukraine (and opposes the EU sanctions).
You reap what you sow, MFs!
https://en.wikipedia.org/wiki/Slovak_opposition_to_sanctions...
So they bought the cameras and some people pointed out they look exactly the same as Russian cameras. The government denied this but after they figured out the serial numbers matched the Russian cameras they started this investigation.
Good they investigated this before using them, but this sounds like a big fu...
> the cameras expose live streams to anyone without a password and who knows their broadcasting IP.
Are these cameras in use in Russia? Can people outside of Russia look in at Russian traffic in this way?
The comments here seem to presuppose that somehow Slovakia is the only ones who would need to worry about this, and not, say, any town with Flock in it
"Кордон.Про" product page on the simicon site
https://simicon.ru/rus/product/gun/cordon_pro.html
Imagine somebody being able to track almost anyone using road side cameras. Good thing such things happen only in eastern Europe wink wink
It's almost as if electing a pro-Russia politician has consequences...
What's the purpose of this? Opening a way to make the cameras going rogue and starting to fine everybody in a particular period of time to create massive discontent, administration chaos, and unrest? maybe just before an election? Aren't this cameras connected with some government computers?
It seems like a silly mess. But its easier than it sounds to end up in such a situation. We're are a lot of HN Kagi users that just have to trust that the Yandex collaboration is fully watertight.
The problem I see is that Putin fully committed to the war. It is not only clear that he has no interest in ending the war, despite the lip service, but will continue to create problems and cause issues. This backdoor here is not an isolated problem - it is a systemic, concerted problem. All retaliatory moves are handicapped by orange Agent Krasnov being an asset for Russia. The EU needs to stop outsourcing its security. That includes having a nuclear arsenal available for all member states.
Next up, chinese solar inverter firmware.
It wouldn't surprise me if the Russian misinformation inside Slovakia is able to spin this into an anti-EU, anti-Ukraine story.
Slovakian prime minister is doing proud photos with Putin despite the ongoing war so the backdoor looks like a desired feature not a bug or fuck up.
The detail that gets me is the Ministry saying the cameras were safe because they'd be on a closed network, while the backdoor can apparently be triggered via SMS from hardcoded phone numbers.
That's a pretty good demonstration of why "it's not exposed to the internet" isn't a security boundary if the device itself has an out-of-band communications path.
Add Secure Boot being disabled and unauthenticated live streams and this seems less like one unfortunate backdoor and more like nobody established what the trust boundary was supposed to be in the first place.
Zero chance of vulns in flock, so we're good in the US /s
Fits perfectly in the russian thinking scheme, always infiltrating their neighbours and trying to get more. Fucking parasites.
Russia to Slovakia is Israel to USA. Puppet state.