Multiple Backdoors Found In Sony’s 'IPELA Engine' IP Cameras

SEC Consult, a European security company, uncovered a backdoor in 80 Sony IPELA Engine IP camera models. This latest discovery shows, once again, that it is universally a bad idea to have a backdoor in software and devices--no matter what the intentions are behind it. Sony has since fixed the backdoor with a firmware update, but it highlights the problems created by using a backdoor.

SNCVM602R - one of the affected Sony IP cameras
Latest Videos FromTom's Hardware
Contributor

Lucian Armasu is a Contributing Writer for Tom's Hardware US. He covers software news and the issues surrounding privacy and security.

  • DalaiLamar
    All your data will be channeled to the evil Abe government.
    Reply
  • LeeRains
    Why is Sony always at the center of hacks, leaks, breeches, backdoors, rootkits... They seem incapable of learning anything from their past experiences when it comes to privacy and security (their's and other's).
    Reply
  • Zaxx420
    So a multi-multi billion dollar corp. isn't capable of maintaining a team or teams of white hat hackers to screen (attempt to hack) sony products before selling millions worldwide? wow...just wow. smh
    Reply
  • rantoc
    IoT, a bazzilion soon to become cancer cells on the internet. Some only need a nudge, other need a kick but in the end the result will in most cases be the same - Unless someone wakes up and take it responsibly. IMO the company that have vulnerable devices should be fined HARD so its less profitable to cut corners...

    @ZAXX420: Its all about the final line on the excel sheet and cutting corners short term makes that division deliver better numbers. Sony is imo one of the least reliable companies, they had huge hacks all over the place and have a history of unprotected devices.
    Reply
  • Achoo22
    So a multi-multi billion dollar corp. isn't capable of maintaining a team or teams of white hat hackers to screen (attempt to hack) sony products before selling millions worldwide? wow...just wow. smh
    Why should they when the overwhelming majority of people are sheep that don't seem to care that they are being spied on? Sony is the company that got away scot-free with audio CDs that added rootkits to any PC that played them... The only entities that could punish their behavior are instead complicit accomplices. It's a nasty situation and it's getting worse.
    Reply
  • Remote access was disabled, it's not that big a deal.
    Reply
  • Pdiddy1134
    Multiple back doors have been found on your mom...
    Reply
  • therealduckofdeath
    Sony's motto: "Why are you still buying our stuff?"
    Reply
  • DarkSable
    Remote access was disabled, it's not that big a deal.
    Andy Chow, you missed a line:

    The debugging accounts were completely open for remote access and could be used to allow remote access to the root user. It's a huge deal.
    Reply