Jump to content
Security Installer Community

Dick

Member
  • Posts

    90
  • Joined

  • Last visited

  • Days Won

    1

Posts posted by Dick

  1. 4 hours ago, Lwillis said:

    Surely nobody is still fitting these?  Didn’t think any of them would be on clients phones for remote viewing. 

    The live images are shocking never mind trying to view one remotely... 

     

    I doubt they are still being fitted but as for picture quality in remote viewing mine is superb, as is the still image emailed on zone trigger. With 4G and or WiFi as it is now, live monitoring with telemetry is equally superb with rarely any motion stuttering. 

  2. I've come to the conclusion Nest is probably a front runner for heating without getting too annoying, though I'm not interested in app control, nor geo fencing. That said, apart from being able to control DHW, which is always on a schedule anyway, there is no benefit to me compared to what I have now via its alarm output and use daily during the heating season.

     

    Lights indoors are switchable still and a select few are on outputs too but that is a security measure rather than an automated convenience/pointless addition. Doing away with switches is a step too far for me and would only cause mayhem when visitors stayed over.

     

     

  3. There's just too much choice and choosing the "best" route forward often leads to disappointment with drop-outs, failures, uncompatibility etc further down the line, if reading the automation forums is anything to go by. 

     

    I keep reading up on going the Evohome route for individual heating control but when you need to involve 3rd party apps with a distinct lack of security, change batteries in every TRV, put up with disconnects (still), unexplicable timer clock changes causing heating to not come on when scheduled, binding issues, etc etc, it just isn't worth the hassle.

     

    I always come back to simplicity, effectiveness and above all security, no matter how intrigued or interested in technology I may be, and right now there appears to be a lot of choice to potentially become an expensive ballache with incompatibility just down the road.

     

    Basic on off automation from my alarm outputs suit me perfectly for now and possibly forever, allowing voice activation via Siri on my Watch or phone for activation.

  4. There's plenty of input in the trade part of the forum.

    Ah, OK. That's a pity those with an interest aren't allowed in but I get why not for the most part.

    I think you are right and the focus should be back on the topic, unfortunately I have to remain rather cautious as the subject is a competitive service. 

     

    CGs work is very good and has been endorsed not only by me but Texecom in a separate thread.

     

    This is an extremely important topic and one that we (WebWayOne) take incredibly seriously, indeed we have argued at the standards committees that all communications should be at the highest level, no matter what the risk. It makes absolutely no sense to say "well its only low risk so we don't need to bother about security, its never happened before and probably never will".

     

    That is insane. Because as Dick says, it may not be a security product that is hacked, it may be something simple to disrupt companies or peoples lives. 

     

    We advocate (and deploy) AES encryption techniques at every level, it should be a standard requirement. Period.

     

    The implications of a security breach or published weakness cannot be underestimated and if you cannot update your software remotely then the impact on the end user, installer etc are immense. Just look at the security updates you get for your PC, MAC or firewalls as an example. Imagine if Microsoft could not remotely update their software, there would be queues for miles outside PC world etc for updates. Hence we have always deployed flash upgradeable equipment.

    Superb post, Jim, and one that should be replicated by other companies but sadly doesn't appear to be the case.

    No, it really is just yourself.

    Righto.

  5. Why not just tell em your a house basher who dabbles with diallers, but to be a pro house basher like me you got to realise customers will rarley use outputs on them

    So although I am a hard core house basher, monitoring is not my business model , house bashing is just wack a dialled in with the odd one paying for a gsm as well

    Off topic hkc needs a free basic app lol

    Just like every village has one, a forum does too and it is never that long before they appear.
    • Downvote 1
  6. None of us are pretending anything, there has been and all ways will be ways around security systems, so long as the kit is one step ahead of the type of burglar expected then whats to worry about?  I understand that there are vulnerabilities with some of the signalling options available, but I also understand the risk and anyone with any real intelligence are unlikely to want to risk their freedom for low value. On the other hand if something is worth protecting then its worth protecting properly that means understanding the risk. I have been in this industry for over 25 years now and I cant think of a burglary where any real technical intelligence has been used. Though I have seen many clever burglaries in my time

    Peter, the lack of any real input from installers on here has been noted and not just by myself. One point of CG's findings is that serious vulnerabilities can't be patched in some cases so keeping one step ahead of threats isn't going to happen. You may well have been in the industry since Noah but we are in 2015 now and facing a different kind of threat from, in some cases, kids younger than your favourite pair of socks who have more technical knowledge than most, if not all, any old school installer on how these things tick. You talk like a bigger cost option is definitely more secure than a cheaper device but maybe CG has more to come to dispel that belief.

    Grade 3 security aside who wants their automation equipment being messed with as is happening now with things like central heating being turned up at daft hours by a hacker? Expecting proper secure coding isn't much to ask is it?

    • Downvote 1
  7. Angry.

    I suppose if you can't manage a decent post on CG's findings something is better than nothing. His findings have no bearing on me whatsoever but I note them with interest, nothing more. When it comes to security I'm an end user so evaluating the information is important should I go a particular route. However, the results haven't come as a total surprise, the level of incompetence on the other hand has though.
    • Downvote 1
  8. I think that's too much of a sweeping statement.

    An opinion you're entitled to.

     

    If your line of expertise is not important then your view may be taken as much the same, without some form of clarification to the guys who post on this forum would you not think?

    Indeed it may, Jim, but It doesn't alter the findings or my opinions on the very same.

    Just curious, you seem quite angry and defensive probably work related I guess?

    Not angry or defensive in the slightest. Why on earth you'd come to that conclusion is beyond me. I'm merely saying it as I see it because I don't have to pretend all is well in the world of security like some of you guys obviously are.

    • Downvote 1
  9. Depends what kit you're using. Even in it's insecure state, it still beats anything relying soley on a telephone line.

    When you have to revert to saying "even in its insecure state" as a reference to G3 security just highlights the state of the industry in some areas and the thinking therein.

    Maybe the companies could use it as a tagline.

    • Downvote 1
  10. I didn't record the call, but during the call in May 2014 when Rob Evans called me to ask me to take down the blog posts, the following (paraphrased) conversation happened:

    RE: We have a case recently where a shop was robbed. The owner pressed the panic button and the signal didn't get to the ARC. The owner got hurt.

    AT: Ok.

    RE: If you release your research, this kind of thing could happen more often.

    AT: So it's my fault for finding these issues, and not CSL's for developing the system?

    RE: Well, we wouldn't want anything bad to happen if it is released.

     

    Clear?

    Oh dear! It makes an utter mockery of monitored security, it really does.
    • Downvote 1
  11. so what do u use?

    What I use is irrelevant. What I don't use is all that matters to me.

    Let's hope Andrew can expose more insecure, shoddy security software peddlers to encourage/force them to clean up their act. Furthermore, it'd be good if self certification was made a thing of the past. I will be following with interest.

    • Downvote 1
  12. Ask the question to Redcare, Emizon or WebWayOne - have you been pentested?

     

    We already know what one of them will say.

    What, and take your fun away, never!! I've stayed away from 'this' technology on purpose waiting for this day of reckoning. Whichever the way you look at it it'll only get worse, or more entertaining, before it gets better.
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.