Thursday, September 3, 2026

CCTV: The Camera is not the Country

Above: The right camera is not necessarily the one with the right flag on the box. Image: Unsplash.

There are considerations that procurement should subject any camera to – no matter its country of origin, writes Tara Pulawski.


Country of origin is a poor shortcut for judging a camera. Firmware quality, construction, support, network behaviour and real-world performance matter far more.

Ask a group of security installers about Chinese cameras and the discussion usually becomes political before it becomes technical. One side sees cheap hardware, opaque cloud services and firmware assembled with all the elegance of a banana on wheels.

The other sees enormous manufacturing capability, aggressive pricing and products that often do the basic job perfectly well.

Both sides can produce examples. Neither side, by itself, has a procurement method.

“Chinese manufacturers deserve criticism where the engineering is poor, the security model is weak, the translation is broken or the cloud behaviour cannot be explained. Western manufacturers deserve the same treatment.“

The market is not East versus West

The camera industry does not divide neatly into East and West. It divides into engineering tiers.

At the bottom are products built almost entirely to meet a price point. They often reuse common system-on-chip platforms, inherited software libraries, reference designs and outsourced development. Support can be thin, documentation can be worse, and the product may effectively stop evolving once the shipment leaves the factory.

At the top are products with controlled firmware, better environmental testing, documented security processes and support that continues after the invoice is paid. Between those extremes sits most of the market, regardless of where the company is based.

The useful question is not “East or West?” It is: what evidence shows that this exact product, firmware branch and deployment design are fit for this exact job?

Firmware from another era

Some camera interfaces still feel as though they were preserved in amber. Configuration pages depend on proprietary Windows tools, browser compatibility modes or plug-in technology descended from the ActiveX era. The interface may look like 1991, but the real problem is not the colour scheme.

Legacy plug-ins expand the trusted software running on an administrator’s computer, create compatibility problems and encourage people to weaken browser security just to configure a camera. A modern sensor wrapped in an old management stack can also contain outdated web libraries, weak session handling, unsafe input processing, hidden service accounts and update mechanisms never designed for hostile networks.

Public advisories and independent security research repeatedly show the same failures across network-camera products: hard-coded credentials, authentication bypass, command injection, exposed maintenance services, memory corruption and insecure firmware updates.

Some of these flaws are severe enough to allow remote compromise. Others turn cameras into convenient footholds for botnets or lateral movement into the wider network. This is not theory. It is a recurring industry pattern.

When the camera phones home

Put a packet capture beside many modern cameras and they will attempt outbound connections almost immediately. Installers often call this “ET calling home”.

Sometimes the reason is legitimate. Cameras use dynamic DNS, time synchronisation, licence checks, mobile push notifications, peer-to-peer remote viewing, firmware updates and cloud registration. High-numbered ports are also normal in peer-to-peer and NAT traversal systems.

Traffic to a Chinese server, or any foreign server, does not by itself prove a backdoor. It proves that the device is communicating with infrastructure outside the local network. That still deserves scrutiny.

The customer should know what data leaves, where it goes, who controls the service, what commands can be sent back, how authentication works, whether the feature can be disabled and what happens when the vendor stops operating the platform.

Peer-to-peer camera services are particularly awkward. They solve a real usability problem by connecting mobile applications to devices behind NAT without manual port forwarding. They also create a trust chain involving vendor servers, device identifiers, shared secrets and proprietary protocols. When that design is weak, server impersonation, traffic interception or full device compromise can follow.

The right response is not blind trust and it is not theatrical panic. It is network segmentation, egress control, DNS logging and verification. A camera should normally sit on a restricted network with only the destinations and protocols it genuinely needs.

A lack of security understanding at product level

One of the more worrying field observations is not a single vulnerability. It is the apparent lack of basic security understanding inside some product and research teams.

Representatives may be unable to explain whether encrypted communications use current Transport Layer Security (TLS), how certificates are validated, whether cloud traffic can be disabled or how credentials are protected.

Confusion between Secure Sockets Layer (SSL) and TLS is not harmless when it comes from people responsible for a connected security product.

SSL has been obsolete for years. In 2026, a manufacturer should be able to state exactly which TLS versions are supported, whether certificates are validated properly, how keys are protected and whether management, streaming, metadata and update traffic are encrypted.

The same problem appears in analytics. Manufacturers advertise artificial intelligence, deep learning, cognitive processing and intelligent recognition, while technical representatives sometimes cannot explain whether the product uses a trained machine-learning model, conventional computer vision, optical character recognition, rule-based processing or a mixture of these.

Customers do not need proprietary source code or model architecture. They do need a technically coherent explanation of the processing pipeline, validation method, known limitations, false-positive behaviour, update process and required image conditions.

When a manufacturer cannot say whether its analytics use machine learning or OCR, the problem is not secrecy. The problem is that the product may not be properly understood by the people selling it.

The same brain under different badges

Another repeated observation is the striking similarity between products sold by supposedly competing Chinese brands.

APIs can use almost identical command structures, configuration fields, error responses and undocumented behaviours. Web interfaces and firmware packages may contain matching terminology, folder structures, libraries and even the same implementation mistakes.

There are legitimate explanations. Manufacturers may use the same chip reference design, software development kit, original-design manufacturer, analytics engine or outside contractor.

Staff and intellectual property may move between companies. In a market built on intense price pressure, direct copying is also possible.

From the outside, this can look like internal industrial espionage or uncontrolled copying. Similarity alone does not prove how the technology was obtained, so accusations need evidence.

It is also reasonable to ask whether state-backed research, public procurement, industrial policy and technology-development programmes contributed to common technical foundations during the industry’s rapid growth. China has openly used these mechanisms to accelerate strategic industries.

Firmware similarities alone do not prove that the state supplied a common camera platform. The more defensible conclusion is that shared reference technology, public investment, common suppliers and aggressive imitation may all have played a part. The visible result is an industry where supposedly separate products can sometimes appear to share the same brain.

International products with local-market language

Broken English, inconsistent terminology, half-translated interfaces and leftover Chinese text remain common in products sold internationally. That may have been understandable when low-cost manufacturers first entered overseas markets. It is not acceptable in 2026.

Documentation and interface language are not cosmetic. They affect security configuration, alarm handling, firmware recovery, privacy settings and an operator’s ability to understand what the device is doing.

A badly translated option can reverse the apparent meaning of a control, hide a cloud dependency or cause an installer to leave an insecure service enabled. Manufacturers selling internationally should use professional technical translators and validate the wording with engineers and experienced operators.

The better Chinese manufacturers are improving rapidly. Some now provide credible documentation, international support teams and mature interfaces. Others still behave as though overseas customers should reverse-engineer the product after purchase.

Construction: the specification is not the enclosure

Firmware is only half the camera. Outdoor reliability depends on enclosure design, gasket compression, cable-entry geometry, membrane vents, fastener quality, corrosion protection, thermal cycling and installation practice.

A printed ingress-protection rating describes performance under a defined test condition. It does not guarantee that every production unit was assembled correctly, that seals will survive years of ultraviolet exposure, or that the installer will preserve the rating after terminating a cable.

At the lower end of the market, cost reduction can become painfully visible: thin castings, inconsistent gasket seating, poor cable glands, unprotected connectors and screws that corrode before the camera has earned back its installation labour.

Major manufacturers are not immune. We have seen condensation and water ingress in products carrying well-known names. A large logo does not stop water.

These claims should be backed by field evidence, service records, photographs and failure rates rather than treated as a universal feature of any country.

The economics are simple. A cheap camera may be perfectly sensible indoors, under shelter and within easy reach. The same camera can become a very expensive mistake on a coastal pole, above a fuel forecourt or at a remote site where the service visit costs more than the hardware.

The analytics gap

The newest sales language is no longer about megapixels. It is about intelligence: people detection, vehicle classification, face matching, intrusion zones, queue analysis and behaviour recognition. These functions can be useful, but the gap between a polished demonstration and a live site can be brutal.

Analytics depend on the pixels given to them. Low resolution, motion blur, bad lighting, arbitrary pose, poor camera angles, long distance, occlusion and dirty lenses all reduce performance. Rain droplets, infrared reflection, a slow shutter, heavy compression and excessive digital noise reduction can defeat an excellent algorithm.

This is why cognitive performance should be tested at the actual site, at night, in bad weather and with normal human behaviour. A daytime demonstration clip proves very little.

Poor analytics are not uniquely Chinese. Cheap edge processors may force simplified models, but expensive Western products also generate false alarms when the scene is badly designed or the settings were tuned for a brochure rather than operations.

The correct comparison is measured detection performance, missed events, false alarms and processing delay under the buyer’s actual conditions.

The Western mirror

The strongest argument against nationality-based procurement is the record of the wider technology industry.

Major Western network and security vendors have released products with critical authentication bypasses, hard-coded credentials, remote-code-execution flaws and vulnerabilities that were actively exploited before many customers patched them.

Premium camera brands can also ship fragile firmware, broken upgrades, browser incompatibilities, licence problems and cloud outages. They can produce terrible night images when the lens is dirty, the infrared reflects from the dome, the shutter is wrong or the camera angle is useless. A premium logo cannot recover detail that never reached the sensor.

What mature suppliers more often provide is not perfection. It is process: clearer support ownership, published advisories, signed updates, longer firmware maintenance, documented hardening and a credible organisation to call when something goes wrong.

Those things have real value. They should still be verified rather than assumed.

There is more than one Chinese camera industry

“Chinese camera” describes a country of manufacture, not one engineering culture.

The category includes anonymous white-label products, original-design manufacturers selling the same platform under dozens of names, enormous vertically integrated suppliers, specialist industrial manufacturers and newer companies deliberately moving toward international security and usability expectations.

Some products are genuinely a mess: recycled firmware, questionable cloud dependencies, poor documentation and mechanical shortcuts.

Others are moving closer to Western standards and, in some functions, may already outperform established competitors. The market is allowed to contain both facts at once.

Value is a system calculation

A camera costing one quarter as much is not automatically better value. A camera costing four times as much is not automatically four times better.

Value includes installation labour, configuration time, cyber controls, replacement visits, firmware maintenance, image usability, integration effort, storage efficiency, licence cost and the operational consequences of missed or false events.

For a low-risk indoor application, a basic camera on an isolated network may be completely rational.

For evidential identification, critical infrastructure, biometric processing or a remote coastal site, the requirements should be much higher.

Procurement becomes sensible when the risk class is defined before the brand shortlist.

The better procurement question

The East-versus-West argument is attractive because it replaces investigation with a label.

It does not tell us whether the camera supports secure updates, whether cloud access can be disabled, whether the enclosure survives the site, whether the night image is usable, whether the analytics work or whether anyone will still issue firmware in five years.

Country of origin may still matter for supply-chain policy, legal obligations, data jurisdiction or geopolitical risk. Those are valid considerations when they are stated honestly. They are not a substitute for technical testing.

The right camera is the one that fits the solution. Test the product, constrain the network, verify the image, understand the cloud path and price the entire lifecycle.

Final thought

Chinese manufacturers deserve criticism where the engineering is poor, the security model is weak, the translation is broken or the cloud behaviour cannot be explained. Western manufacturers deserve the same treatment.

The industry improves when buyers stop purchasing mythology and start demanding evidence.

In the end, country of origin does not dictate quality. Many Western-branded cameras are manufactured in China, often using the same factories, components and supply chains as local brands. What should determine the choice is the quality of the finished product, the clarity of its documentation, the strength of its support, the security of its design and the transparency of the manufacturer.

The right camera is not the one with the right flag on the box. It is the one that is fit for the application, properly supported and honest about how it works..

Logo

Join the discussion...

Discover more from Line of Defence

Subscribe now to keep reading and get access to the full archive.

Continue reading