Educause Security Discussion mailing list archives

Re: Security Cameras


From: Frank Barton <bartonf () HUSSON EDU>
Date: Wed, 30 Oct 2019 14:19:35 -0400

I think part of the discussion needs to come down to network segmentation.
Your security cameras just need to be able to talk to the
management/monitoring system, and NOTHING else. set up a dedicated network,
and segment the heck out of it - no internet, no "production" network.

If you watch the CERT weekly vulnerability list, I'll paraphrase the 'mutt'
email client tagline: "All [cameras] suck. This one just sucks less." I'm
not sure I'd trust *any* camera vendor further then I could throw them, but
we have to have them on the network.

In our case, the servers that capture the data are dual-homed... One
interface on the camera network, and one so that we can talk to them.
Anything that we need to do to the cameras must be done using one of those
servers as a jump server.

Now... we still do firmware updates, change default passwords, all of the
usual hardening steps, but by keeping them isolated to that extreme, we're
not worried about them being used as a jump-point to get into our network,
or to be able to get data out of our network.

Frank

On Wed, Oct 30, 2019 at 1:47 PM Hoover-Cox, Reba <coxrh () uncw edu> wrote:

Hello,



We are currently evaluating Genetec.



https://www.genetec.com







Best Regards,

*Reba*

Reba L. Hoover-Cox

IT Project Manager  |  Information Technology Services

University of North Carolina – Wilmington  |  Box 5908

coxrh () uncw edu | O: 910-962-7618 | F: 910-962-2486





*NOTICE: Emails sent and received in the course of university business are
subject to the North Carolina Public Records Act (N.C.G.S. §132-1 et seq.)
and may be released to the public unless an exception applies.*





*From:* The EDUCAUSE Security Community Group Listserv <
SECURITY () LISTSERV EDUCAUSE EDU> *On Behalf Of *Klingaman, Ryan
*Sent:* Wednesday, October 30, 2019 12:53 PM
*To:* SECURITY () LISTSERV EDUCAUSE EDU
*Subject:* Re: [SECURITY] Security Cameras



⚠ *CAUTION:* This email originated from outside of UNCW. Do not click
links or open attachments unless you recognize the sender and know the
content is safe.

I was recently pointed in the direction of this solution which I have been
exploring a little:



https://www.verkada.com/
<https://nam05.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.verkada.com%2F&data=01%7C01%7Ccoxrh%40UNCW.EDU%7Cefe82b4cc21241e42d7408d75d5afe38%7C2213678197534c75af2868a078871ebf%7C1&sdata=%2BW3%2BQZ27u3C9Q9sT6JPXmtnNBUcNAHVbUnT9FALC4pY%3D&reserved=0>






Ryan Klingaman

Enterprise Systems Manager

(406) 447-4434

Carroll College

1601 N. Benton Ave
<https://nam05.safelinks.protection.outlook.com/?url=https%3A%2F%2Fmaps.google.com%2F%3Fq%3D1601%2BN.%2BBenton%2BAve%250D%2BHelena%2BMT%2B59625%26entry%3Dgmail%26source%3Dg&data=01%7C01%7Ccoxrh%40UNCW.EDU%7Cefe82b4cc21241e42d7408d75d5afe38%7C2213678197534c75af2868a078871ebf%7C1&sdata=iZx8kkoMU0Xb32WUy0sB0LlM%2F%2F3i9vCbOh%2FGPJnw%2FCc%3D&reserved=0>

Helena MT 59625
<https://nam05.safelinks.protection.outlook.com/?url=https%3A%2F%2Fmaps.google.com%2F%3Fq%3D1601%2BN.%2BBenton%2BAve%250D%2BHelena%2BMT%2B59625%26entry%3Dgmail%26source%3Dg&data=01%7C01%7Ccoxrh%40UNCW.EDU%7Cefe82b4cc21241e42d7408d75d5afe38%7C2213678197534c75af2868a078871ebf%7C1&sdata=iZx8kkoMU0Xb32WUy0sB0LlM%2F%2F3i9vCbOh%2FGPJnw%2FCc%3D&reserved=0>





On Wed, Oct 30, 2019 at 9:36 AM Ronald Loneker <rloneker () cse edu> wrote:

Good Morning -



I am working with our campus security department on upgrading our security
cameras on campus as part of a grant we received.



One of the vendors has proposed using cameras manufactured by Hikvision
and Dahua, two Chinese manufacturers.



Has anyone been involved with the deployment of cameras on campus that
have been manufactured in China from either of these vendors?  I'm
interested in your experiences with them and with the security of the
cameras themselves.



Thank you.


Ron Loneker, Jr.
Director, IT Special Projects
College of Saint Elizabeth
Mahoney Library
2 Convent Road
Morristown, NJ  07960

Phone:  973-290-4229

e-mail:  rloneker () cse edu











**********
Replies to EDUCAUSE Community Group emails are sent to the entire
community list. If you want to reply only to the person who sent the
message, copy and paste their email address and forward the email reply.
Additional participation and subscription information can be found at
https://www.educause.edu/community
<https://nam05.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&data=01%7C01%7Ccoxrh%40UNCW.EDU%7Cefe82b4cc21241e42d7408d75d5afe38%7C2213678197534c75af2868a078871ebf%7C1&sdata=eDgESby4MS8eJkT4ENtBXe2ik0tSnf5ujFo0Atwiwdk%3D&reserved=0>

**********
Replies to EDUCAUSE Community Group emails are sent to the entire
community list. If you want to reply only to the person who sent the
message, copy and paste their email address and forward the email reply.
Additional participation and subscription information can be found at
https://www.educause.edu/community
<https://nam05.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&data=01%7C01%7Ccoxrh%40UNCW.EDU%7Cefe82b4cc21241e42d7408d75d5afe38%7C2213678197534c75af2868a078871ebf%7C1&sdata=eDgESby4MS8eJkT4ENtBXe2ik0tSnf5ujFo0Atwiwdk%3D&reserved=0>

**********
Replies to EDUCAUSE Community Group emails are sent to the entire
community list. If you want to reply only to the person who sent the
message, copy and paste their email address and forward the email reply.
Additional participation and subscription information can be found at
https://www.educause.edu/community



-- 
Frank Barton, MBA
Security+, ACMT, MCP
IT Systems Administrator
Husson University

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community

Current thread: