Rautakuorikilpikonna

joined 6 days ago
[–] Rautakuorikilpikonna@sopuli.xyz 22 points 5 days ago (1 children)

Have they also banned cars from the area?

 

TLDR: New speed cameras in Slovakia contained an undocumented module that allowed them to be controlled remotely and granted full access to them via mobile network. All it took to activate it was to send a text message from one of 12 Russian numbers.

Further context:

Cameras purchased by Slovakia's Interior Ministry for road surveillance have been traced to a Cypriot shell company [Sodasus Ltd] with no business history, with the only identifiable trail leading back to Russia, raising serious security concerns about the procurement.

Article translation:

The cameras installed by the Ministry of the Interior along Slovakia’s roads were, in fact, entirely Russian-made. They even contained 12 Russian telephone numbers that could be used to hack directly into the cameras and view the footage.

This was highlighted by the opposition movement Progressive Slovakia, which claims that Interior Minister Matúš Šutaj Eštok was misleading the public when he claimed at a press conference last week that only certain parts of the speed cameras were Russian. Progressive Slovakia cites an assessment by the National Security Authority, which the movement obtained via a freedom of information request.

A backdoor for foreign espionage

On Friday, the National Security Authority issued its own assessment of the radars. Based on this assessment, Peter Bátor, a security expert with the movement, described the mechanism by which, in his view, it was possible to access data from the radars under test. According to him, all it took was to send a message to one of the pre-set telephone numbers, enter a password, and the attacker gained full access to the camera. This is because the devices contained a module that is not documented anywhere; it was retrofitted into the device and is hard-coded in such a way that it cannot be removed or altered.

“This is a very specific example of how Russia uses the technology it sells for espionage,” said Bátor, adding that twelve Russian telephone numbers were linked to this undocumented module. Any one of them was sufficient for an unauthorised operator to gain full control of the camera. Furthermore, the device also had built-in administrator access with a precisely defined password. According to the findings, it was therefore possible to control the camera not only via a standard 3G or 4G port, but there were many more connection options available.