← 回到最新日報完整解析

#10 risky.biz

Slovakia finds Russian backdoor in traffic speed cameras

原文連結(在新分頁開啟)HN 討論(在新分頁開啟)

文章洞見

原文內容目前無法安全取得,因此未產生文章摘要。

討論洞見

討論聚焦於斯洛伐克政府採購的交通攝影機:部分留言稱設備外觀與俄羅斯產品相同,且序號相符,促成調查;另有留言指出採購可能牽涉塞浦路斯空殼公司與偽造認證。技術層面的疑慮包括硬編碼 SMS 控制通道、未啟用 Secure Boot、未驗證的直播串流,以及設備可能連接外部網路或行動網路。討論也延伸至供應鏈安全、開源 firmware、政府採購合規,以及其他國家和城市使用類似監控或中國製設備的風險。

共識:留言大致同意這些設備存在嚴重的供應鏈與基本資安風險;但對於設備是否由俄羅斯控制、是否屬於蓄意的情報行動,證據不足且看法分歧。

實務建議

  • 不要把「未連接網際網路」視為完整的安全控制;應盤點並監控 SIM、SMS、無線及其他 out-of-band 通道。
  • 在部署前進行硬體、firmware、序號、供應商、認證文件及實際製造地的獨立驗證,並要求可稽核的 supply-chain provenance。
  • 使用部署方控制的 Secure Boot 金鑰、簽署 firmware、最小權限網路規則及 carrier-level filtering;對直播介面與管理介面實施強式認證。
  • 政府採購應保留完整的 compliance、來源與驗收紀錄,並對空殼公司、偽造認證及異常低價進行 enhanced due diligence。
  • 不要只針對俄羅斯來源設備;相同的審查標準也應適用於中國、美國及其他供應商的 surveillance、solar inverter 與 cloud-connected infrastructure。

待釐清問題

  • 設備的實際製造商、firmware 來源,以及俄羅斯產品與涉事設備之間的法律或技術關係是什麼?
  • 序號相符、SMS 後門、Secure Boot 狀態及未驗證直播等細節,是否已由獨立技術鑑識確認?
  • 塞浦路斯空殼公司與偽造認證的說法是否有正式調查、採購文件或司法結果支持?
  • 設備是否曾實際部署、連線或被未授權人士存取?有沒有資料外洩或操作紀錄?
  • 事件究竟是貪腐與採購失誤,還是有國家級蓄意滲透;現有討論材料不足以判定。

代表性留言

  1. Do they even need that since, when most of the converters are attached to the Chinese cloud?

    hansoolo · HN #49410727

  2. It's almost as if electing a pro-Russia politician has consequences...

    physhster · HN #49412341

  3. So they bought the cameras and some people pointed out they look exactly the same as Russian cameras. The government denied this but after they figured out the serial numbers matched the Russian cameras they started this investigation.Good they investigated this before using them, but this sounds like a big fu...

    bdhdhduuyd · HN #49409559

  4. This would be far more impressive if not for:> multiple reports in Slovak media that linked the purchase to a Cyprus shell company with fake certifications.We're talking about this as if it's some precursor to a James Bond plot, but it really fizzles after learning Nina in the sourcing department skipped the compliance paperwork. James Bond doesn't need to leave the bed!Trojan exploits aside, I just assume that it'd be easier for someone in SVR/GRU to bribe an admin.

    caminante · HN #49410093

  5. With high probablity they are actually made in China. I don't think Russia makes their own chips for cameras.

    codedokode · HN #49411162

  6. Over 100 comments, zero mentions that government funds should be spent on devices with auditable open-source firmware. Anyone here? No? Then I'm the first one to say this.SecureBoot is a funny one. It should be signed with the deployer's keys (Slovak), not the manufacturer's. Trusted boot probably wasn't a consideration here, really.Ironically, a custom firmware can now be used thanks to the lack of a digital lock... if you still trust the hardware.PS: Props to NBU for doing their job.

    PinkSheep · HN #49411955

  7. That was in fact the angle of the Fediverse post from which I first saw this story:"Please use open source systems whenever possible so you can review the source code."<https://floss.social/@mikebabcock/117134334377276076>

    dredmorbius · HN #49415098

  8. Would you be able to get those devices at all, especially at similar price as those with closed source firmware? R

    srdjanr · HN #49412189

  9. > the cameras expose live streams to anyone without a password and who knows their broadcasting IP.Are these cameras in use in Russia? Can people outside of Russia look in at Russian traffic in this way?

    Animats · HN #49410513

  10. There is a small number of cameras which broadcast the video publicly. For example, Moscow: [1] (Taganskaya square), [2] and Saint-Petersburg: [3] (Nevsky prospect and Gostiniy Dvor). Sadly the quality is not great and in reality those places look much better. For example, many of the small 2-floor buildings on Taganskaya square are over 100 years and have a nie classical architecture but one cannot see any fine details in the camera view.[1] https://gidcam.ru/camera/moskva-panorama-centra-stolicy-s-ma...[2] https://gidcam.ru/camera/moskva-volgogradskij-prospekt-i-plo...[3] https://camguide.net/ru/europe/russia/saint-petersburg/nevsk...

    codedokode · HN #49411331

  11. "Кордон.Про" product page on the simicon sitehttps://simicon.ru/rus/product/gun/cordon_pro.html

    sorokod · HN #49411613

  12. Imagine somebody being able to track almost anyone using road side cameras. Good thing such things happen only in eastern Europe wink wink

    tomas789 · HN #49409694

  13. Most cameras are insecure by default. Check out: http://www.insecam.org/en/ or https://www.shodan.io/ The first isn't even using default access creds, which I suspect is what was 'discovered' in this case, but cameras that immediately hook up to the internet with 0 restrictions to access.

    somenameforme · HN #49409907

  14. For the goal of recording a cat scratching their car or catching an imaginary thief neighbour (a magpie or fox stole that thing that one time, you dullard) people will plug into Chinese, Russian, and American video surveillance networks in no time and pay for it.

    lifestyleguru · HN #49409758

  15. It seems like a silly mess. But its easier than it sounds to end up in such a situation. We're are a lot of HN Kagi users that just have to trust that the Yandex collaboration is fully watertight.

    tokai · HN #49409858

  16. I think i read Japan does this to CCTVs sold in ChinaPublic Security Intelligence Agency (公安調査庁) apparently is sitting on a massive amount of data from China which imported their tech

    zuzululu · HN #49414160

  17. The comments here seem to presuppose that somehow Slovakia is the only ones who would need to worry about this, and not, say, any town with Flock in it

    thisisnotauser · HN #49411018

  18. What's the purpose of this? Opening a way to make the cameras going rogue and starting to fine everybody in a particular period of time to create massive discontent, administration chaos, and unrest? maybe just before an election? Aren't this cameras connected with some government computers?

    pvaldes · HN #49411493

  19. Perhaps. What actually happened is that we have a demented interior minister in a unbelievably corrupt but also pro-russian government. So it's really anybodys guess if it's just pure corruption (the interior ministry wanting to buy some traffic cameras and someone bribing to get the contract while buying the cheapest they could find which were these russian ones) or indeed some covert russian operation (the responsible minister wouldn't know about it, he's too dumb for that, but there might be other government people who did know). In any case in a functioning state this would end up with the minister leaving his post at least. Not in Slovakia.

    tpm · HN #49412386

  20. Next up, chinese solar inverter firmware.

    irishcoffee · HN #49409431

  21. To do what? Turn off the power in random individual houses?

    victorbjorklund · HN #49409454

  22. The problem I see is that Putin fully committed to the war. It is not only clear that he has no interest in ending the war, despite the lip service, but will continue to create problems and cause issues. This backdoor here is not an isolated problem - it is a systemic, concerted problem. All retaliatory moves are handicapped by orange Agent Krasnov being an asset for Russia. The EU needs to stop outsourcing its security. That includes having a nuclear arsenal available for all member states.

    shevy-java · HN #49411777

  23. It wouldn't surprise me if the Russian misinformation inside Slovakia is able to spin this into an anti-EU, anti-Ukraine story.

    koonsolo · HN #49411006

  24. Slovakian prime minister is doing proud photos with Putin despite the ongoing war so the backdoor looks like a desired feature not a bug or fuck up.

    lifestyleguru · HN #49409824

  25. The detail that gets me is the Ministry saying the cameras were safe because they'd be on a closed network, while the backdoor can apparently be triggered via SMS from hardcoded phone numbers.That's a pretty good demonstration of why "it's not exposed to the internet" isn't a security boundary if the device itself has an out-of-band communications path.Add Secure Boot being disabled and unauthenticated live streams and this seems less like one unfortunate backdoor and more like nobody established what the trust boundary was supposed to be in the first place.

    LogTrim · HN #49409786

  26. "Not exposed to the internet" means exfiltration is hard in this case. If I were to dream about defense in depth, these SIM cards should be monitored for traffic anyway or have filtering rules at carrier level. Because at the end of the day, Russian numbers or not, mobile networks are insecure.

    PinkSheep · HN #49411883

  27. Zero chance of vulns in flock, so we're good in the US /s

    yodon · HN #49410021

  28. Russia to Slovakia is Israel to USA. Puppet state.

    juliusceasar · HN #49410405

  29. Most people talking about Slovakia wouldn't even be able to put it on a map or know what currency they use, but they become instant geo political expert.They don't even know how to pronounce Fico properly... Give me a break lmao

    toasty228 · HN #49410818

本頁摘要由 AI 生成,請回到原始來源核對脈絡。

ARTICLEgpt-5.6-luna · v1 · 2026/8/24

DISCUSSIONgpt-5.6-luna · v1 · 2026/8/24