Dear Members of the Board,
Two related pieces of work have come together this month, and I want to give you both in one letter: where things stand on the AI camera system, and what came out of the network security review that followed from it.
AI camera system. My recommendation is to stay on IntuVision, the platform already in place, and spend the year ahead hardening it and using more of what it already offers, rather than switching vendors. I looked seriously at two well-regarded alternatives, Coram.ai and Verkada, and neither is the right fit for a building this size right now: both are built for much larger portfolios, and a move to either would mean giving up detection IntuVision already does well (time-based rules, tailgating) and re-integrating against the roughly $80,000 the board has already invested in the current access-control system. I'll stay in touch with Coram as a potential partner, mainly so the board keeps pricing leverage and a fallback option, but the near-term move is working with IntuVision directly rather than through the current integrator. IntuVision's own team has told me plainly that the gap isn't their software; it's that the integrator on this account never fully learned it.
The most urgent item, separate from any vendor decision, is what IntuVision's founder called a “ticking time bomb”: the recording server's GPU has been disabled by a misconfiguration since setup, so it has been running on CPU alone. That is already being corrected.
Security review. While sorting out camera access for a small side project of my own, I found that the cameras themselves, not just the recorder, appear to have a path out to the public internet. That goes beyond what I had previously understood and reported, and it matters given the vulnerabilities described in the attached assessment. Confirming it for the cameras specifically requires access to the building's router, which is one of the open items below. It is the kind of gap that is easy to miss in a routine check, which is why I looked further and wrote it up formally.
In short: the recorders are reachable from the public internet, the administrator password is easy to guess, and several cameras are old enough that they can no longer be updated by the manufacturer. The most urgent item can be corrected at no hardware cost. The attached Executive Summary explains this in plain terms, and a detailed technical report is available on request.
I completed this work on my own time, at no charge, as a resident who wanted to help. It represented roughly nine hours in total: about three hours initially learning the system and the AI camera setup, and six hours of security assessment and hardening analysis across the two days that followed. This has reached the limit of what I can reasonably contribute pro bono. A few items remain open and would benefit from further work: confirming whether the cameras have internet access, checking one older recorder, and overseeing the corrections and re-testing to confirm the exposure is actually closed.
I would be glad to continue on an engaged basis. As a resident I would offer a preferential rate, and I can propose a fixed scope and fee so the cost is predictable. In the meantime, I recommend the Board direct whoever maintains the system to act on the priority items in the summary right away, independent of any further engagement, since they protect residents and cost little to implement.
I am happy to walk the Board through the findings at your convenience.