james.wilson Posted November 8, 2015 Share Posted November 8, 2015 surely in our industry we should be top of our game securitywarehouse Security Supplies from Security Warehouse Trade Members please contact us for your TSI vetted trade discount. Link to comment https://www.thesecurityinstaller.co.uk/community/topic/39326-csls-m2m-sim-registration-portal-database-leak/page/4/#findComment-434193 Share on other sites More sharing options...
cybergibbons Posted November 8, 2015 Author Share Posted November 8, 2015 That would be our CEO Well, his own email rather than a generic one is on the list. I have a blog, some of which is about alarm security and reverse engineering:http://cybergibbons.com/ Link to comment https://www.thesecurityinstaller.co.uk/community/topic/39326-csls-m2m-sim-registration-portal-database-leak/page/4/#findComment-434194 Share on other sites More sharing options...
james.wilson Posted November 8, 2015 Share Posted November 8, 2015 id assume its not just csl that are lax, its long been roumored, where next? securitywarehouse Security Supplies from Security Warehouse Trade Members please contact us for your TSI vetted trade discount. Link to comment https://www.thesecurityinstaller.co.uk/community/topic/39326-csls-m2m-sim-registration-portal-database-leak/page/4/#findComment-434195 Share on other sites More sharing options...
cybergibbons Posted November 8, 2015 Author Share Posted November 8, 2015 Well, I personally wouldn't touch Videofied gear with a bargepole. That's being released 30/11 - they need to get a fix out. I have a blog, some of which is about alarm security and reverse engineering:http://cybergibbons.com/ Link to comment https://www.thesecurityinstaller.co.uk/community/topic/39326-csls-m2m-sim-registration-portal-database-leak/page/4/#findComment-434202 Share on other sites More sharing options...
jimcarter Posted November 10, 2015 Share Posted November 10, 2015 .....and WebWayOne, should definitely be pentested. To clarify, our ATS has been independently pen-tested twice, by a UK Banking company and publicly owned shipping organisation. The pen testing covered very low level scrutinisation of our encryption techniques and policies. Correct that 3rd party testing to EN only requires a self declaration on encryption and substitution protection. We deploy AES128 encryption with substitution protection and key changes. Jim Carter WebWayOne Ltd www.webwayone.co.uk Link to comment https://www.thesecurityinstaller.co.uk/community/topic/39326-csls-m2m-sim-registration-portal-database-leak/page/4/#findComment-434443 Share on other sites More sharing options...
james.wilson Posted November 10, 2015 Share Posted November 10, 2015 Jim has cyber played with your spt's securitywarehouse Security Supplies from Security Warehouse Trade Members please contact us for your TSI vetted trade discount. Link to comment https://www.thesecurityinstaller.co.uk/community/topic/39326-csls-m2m-sim-registration-portal-database-leak/page/4/#findComment-434445 Share on other sites More sharing options...
jimcarter Posted November 10, 2015 Share Posted November 10, 2015 No. Jim Carter WebWayOne Ltd www.webwayone.co.uk Link to comment https://www.thesecurityinstaller.co.uk/community/topic/39326-csls-m2m-sim-registration-portal-database-leak/page/4/#findComment-434447 Share on other sites More sharing options...
jimcarter Posted November 12, 2015 Share Posted November 12, 2015 Jim has cyber played with your spt's Just for continuity (as I have confirmed this on a separate thread). Andrew does indeed have a couple of our units (I was not aware until today) and he has carried out some basic testing and evaluation. As far as I'm aware, all ok but I'm sure I will hear otherwise if this is not the case! Jim Carter WebWayOne Ltd www.webwayone.co.uk Link to comment https://www.thesecurityinstaller.co.uk/community/topic/39326-csls-m2m-sim-registration-portal-database-leak/page/4/#findComment-434532 Share on other sites More sharing options...
cybergibbons Posted November 12, 2015 Author Share Posted November 12, 2015 Yes - I have two of the recent SPTs. The testing was basic, but nothing raised red-flags. I couldn't just download the firmware and tear it apart, and none of the common failings were made. I have a blog, some of which is about alarm security and reverse engineering:http://cybergibbons.com/ Link to comment https://www.thesecurityinstaller.co.uk/community/topic/39326-csls-m2m-sim-registration-portal-database-leak/page/4/#findComment-434537 Share on other sites More sharing options...
secureiam Posted November 12, 2015 Share Posted November 12, 2015 interesting. Link to comment https://www.thesecurityinstaller.co.uk/community/topic/39326-csls-m2m-sim-registration-portal-database-leak/page/4/#findComment-434542 Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now