{"id":200377,"date":"2021-03-11T21:14:56","date_gmt":"2021-03-11T18:14:56","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/hacked-security-firm-verkada-let-staff-view-clients-cameras\/"},"modified":"2021-03-11T21:14:56","modified_gmt":"2021-03-11T18:14:56","slug":"hacked-security-firm-verkada-let-staff-view-clients-cameras","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/hacked-security-firm-verkada-let-staff-view-clients-cameras\/","title":{"rendered":"#Hacked security firm Verkada let staff view clients&#8217; cameras"},"content":{"rendered":"<p>&#8220;<strong>#Hacked security firm Verkada let staff view clients&#8217; cameras<\/strong>&#8221;<\/p>\n<div>\n<p>Surveillance startup Verkada reportedly enabled dozens of staffers to peep on its clients \u2014 just like the hackers who attacked the company this week.<\/p>\n<p>More than 100 Verkada staffers had access to the internal \u201cSuper Admin\u201d privileges that hackers used Monday to get feeds from more than 150,000 cameras, <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.bloomberg.com\/news\/articles\/2021-03-11\/verkada-workers-had-extensive-access-to-private-customer-cameras?sref=rEjryNCU\">according to Bloomberg News<\/a>.<\/p>\n<p>That meant a wide range of workers\u00a0could watch the inner workings of Verkada\u2019s clients, including jails, hospitals, schools and major companies like Tesla, the outlet reported Wednesday, citing three former employees.<\/p>\n<p>\u201cWe literally had 20-year-old interns that had access to over 100,000 cameras and could view all of their feeds globally,\u201d one source told Bloomberg.<\/p>\n<p>Tillie Kottmann, one of the hacktivists responsible for the Verkada breach, told <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/ipvm.com\/reports\/verkada-super?code=allow\">surveillance research firm IPVM<\/a> that they posed as an employee with \u201cSuper Admin\u201d privileges to break into the company\u2019s system.<\/p>\n<p>The Super Admin accounts are supposed to help Verkada workers fix products and help customers with problems, according to Bloomberg. But the company\u2019s lax security measures reportedly made it easy to misuse the system.<\/p>\n<p>Staffers were supposed to submit a reason for accessing a customer camera, but the documentation was seldom checked, meaning a worker could just enter a space to access a feed, Bloomberg reported.<\/p>\n<p>Super Admin users could also disable the \u201cprivacy mode\u201d that allowed Verkada clients to hide cameras from the company\u2019s view, according to the outlet. It\u2019s reportedly unclear how many customers knew Verkada employees could access their cameras.<\/p>\n<p>\u201cCustomers didn\u2019t know and it was known at the company not to tell customers that,\u201d one source with direct knowledge of the matter told IPVM. \u201cNo customer directly asked since any sane person would never expect a vendor to be able to do this so broadly across teams.\u201d<\/p>\n<p>Verkada told Bloomberg that it has clear policies for how employees should use the Super Admin feature, which was only available to staff who needed to address \u201ccustomers\u2019 questions and technical issues.\u201d<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" width=\"1024\" height=\"682\" alt=\"Super Admin users could also disable the &quot;privacy mode&quot; that allowed Verkada clients to hide cameras from the company's view.\" class=\"wp-image-17532384 lazyload\" srcset=\"https:\/\/nypost.com\/wp-content\/uploads\/sites\/2\/2021\/03\/hack-allowed-peeping-toms2.jpg?quality=90&amp;strip=all&amp;w=300 300w, https:\/\/nypost.com\/wp-content\/uploads\/sites\/2\/2021\/03\/hack-allowed-peeping-toms2.jpg?quality=90&amp;strip=all&amp;w=640 640w, https:\/\/nypost.com\/wp-content\/uploads\/sites\/2\/2021\/03\/hack-allowed-peeping-toms2.jpg?quality=90&amp;strip=all&amp;w=1280 1280w, https:\/\/nypost.com\/wp-content\/uploads\/sites\/2\/2021\/03\/hack-allowed-peeping-toms2.jpg?quality=90&amp;strip=all&amp;w=1024 1024w, https:\/\/nypost.com\/wp-content\/uploads\/sites\/2\/2021\/03\/hack-allowed-peeping-toms2.jpg?quality=90&amp;strip=all&amp;w=2000 2000w\" data-sizes=\"(max-width: 640px) 100vw, 1024px\"\/><figcaption>Super Admin users could also disable the \u201cprivacy mode\u201d that allowed Verkada clients to hide cameras from the company\u2019s view.<\/figcaption><figcaption><span class=\"credit\">Ted S. Warren\/AP<\/span><\/figcaption><\/figure>\n<\/div>\n<p>\u201cVerkada\u2019s training program and policies for employees are both clear that support staff members were and are required to secure a customer\u2019s explicit permission before accessing that customer\u2019s video feed,\u201d a company spokesperson told Bloomberg.\n            <\/p><\/div>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/news\/\" data-internallinksmanager029f6b8e52c=\"2\" title=\"News\" target=\"_blank\" rel=\"noopener\">News<\/a> articles, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/news\/\" target=\"_blank\" rel=\"noopener\">News category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/nypost.com\/2021\/03\/11\/hacked-security-firm-verkada-let-staff-view-clients-cameras\/\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;#Hacked security firm Verkada let staff view clients&#8217; cameras&#8221; Surveillance startup Verkada reportedly enabled dozens of staffers to peep on its clients \u2014 just like the hackers who attacked the company this week. More than 100 Verkada staffers had access to the internal \u201cSuper Admin\u201d privileges that hackers used Monday to get feeds from more&#8230;<\/p>\n","protected":false},"author":1,"featured_media":200378,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/nypost.com\/wp-content\/uploads\/sites\/2\/2021\/03\/hack-allowed-peeping-toms.jpg?quality=90&strip=all&w=1200","fifu_image_alt":"","footnotes":""},"categories":[70897],"tags":[97194,70375,70944,81180,4965],"class_list":["post-200377","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-3-11-21","tag-cybersecurity","tag-hackers","tag-surveillance","tag-technology"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/200377","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=200377"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/200377\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/200378"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=200377"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=200377"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=200377"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}