Edit mode
ELBERTA·LABS
Engagement & Quote
Network segmentation + private VPN
To The Gallery HOA Board  ·  From Aref Kashani, Elberta Labs  ·  Date 18 August 2026

Our most recent audit (v3) reviewed the building's camera and recorder network. It found several ways the system is exposed, and testing confirmed the exposure can reach residents' own devices. These should be remediated promptly.

What the assessment found

  • The camera network is not isolated from the resident network. Testing confirmed that a compromised camera or recorder can reach residents' personal devices. This is lateral movement.
  • The recorders are reachable over the internet. This is the same access path used for off-site camera viewing, and it lets an attacker try to hijack the system through it. Interim mitigation has reduced this. The attack surface is smaller, but anyone on the building's shared connection can still attempt to log in.
  • Multiple cameras are dialing out to the internet. The camera network is not blocked from internet egress. This corrects a prior assumption. Even if outside devices cannot reach in, a camera can open the tunnel from the inside and hand off access.
  • Several cameras and recorders are end of life. They no longer receive firmware updates. They remain standing vulnerabilities and need to be fully quarantined.

This proposal rebuilds the surveillance network. We segment devices by risk, and we enable firewalls so no device on the surveillance network can reach the broader building network, residents included. This requires new hardware and labor.

How this is offered. I do this as a resident, at a favor rate well below my standard rate ($150/hr versus my usual $300/hr). None of it has to go through me, and I'd encourage the board to get other quotes. The remediation, though, shouldn't wait.

Parts and labor. The HOA buys the hardware directly at vendor pricing (board owned, no markup). Elberta bills labor only, at the resident rate.

Why new equipment. The current gateway gives little visibility into network traffic, is hard to configure, and doesn't support the firewall rules and segmentation this work needs. The UniFi gateway handles the segmentation and firewalling, and it logs traffic so activity can be monitored day to day and reviewed after an incident. The VPN device is for reliable off-premise access.

Scope

  • Replace the router with a UniFi gateway (reusing the building's existing network switch); rebuild VLANs and firewall rules to isolate the resident, camera, and management networks.
  • Quarantine the end-of-life and likely-compromised legacy recorders and cameras into an isolated zone with no internet and no lateral access, pending their replacement.
  • Stand up a dedicated VPN for private remote access, and remove the camera system's public-facing exposure.
  • Per-person access (no shared password); short handoff and training for the board and property manager.

Where things stand

Interim steps were already taken after the incident: the known outside destinations were blocked at the router, remote access to the recorders was narrowed, and the attacker's on-screen tampering was removed. These reduced the active attack paths. They did not close them. The most recent testing showed the camera network can still reach residents' devices. This rebuild is the structural fix at the networking layer.

How this proceeds

Phase 1
Elberta Labs
Install the gateway, rebuild segmentation and firewall rules, stand up the VPN, quarantine the end-of-life devices, and remove public exposure.
About one day, HOA preferred hours
Phase 2
Blue Sky Systems
Reset the camera passwords, replace or repair the end-of-life cameras and recorders, and handle the camera-side hardening.
Scheduled with the vendor
Phase 3
Elberta Labs
Run the post-reset verification scan, confirm no unauthorized access paths remain, and finish the handoff.
After Phase 2

We anticipate this will take about two weeks, contingent on Blue Sky Systems being able to schedule their camera work on time.

Longer-term recommendation

This rebuild secures the network around the existing cameras and buys us a few years with the recommended long-term solution being a full replacement, retiring obsolete and non-compliant Dahua devices.

Responsibilities & liability

Division of responsibility. The cameras themselves (their passwords, firmware, and device-level vulnerabilities) are handled by Blue Sky Systems, the building's camera vendor, who resets the camera passwords, disables P2P, and remains responsible for camera-side security. Elberta Labs provides and hardens the network infrastructure (segmentation, firewalling, and private VPN access) to reduce exposure as far as the network layer allows.

This work reduces and manages risk at the network layer. It does not guarantee absolute security, and network changes cannot remove device-level vulnerabilities in the existing hardware. Scope is limited to the items listed above and does not include the cameras, residents' personal devices, or residents' own networks. Elberta Labs' total liability under this engagement is limited to the labor fees paid, and Elberta Labs carries cyber liability insurance. In this engagement Aref acts solely as an outside vendor, not in any board or governance capacity for the association. The board approves this engagement as it would any outside vendor, and Aref, as a resident, takes no part in that decision.

Terms

  • Cutover and disruption. The new gateway goes in front of the existing equipment first, then traffic is migrated block-by-block and verified at each step (internet up, VLAN isolation confirmed, cameras reachable only over the VPN). Camera feed and recording disruption is expected but should be minimal and scheduled. If something goes wrong, plan for up to one day of disruption.
  • Leave-behind. A written summary (network diagram, VLAN/firewall overview, and VPN access list) is provided to the board.
  • Workmanship. Configuration faults from this work are corrected at no labor charge for 30 days.
  • Ownership. The VPN (Tailscale) account and configuration belong to the HOA; access transfers to the board.
  • Payment. Labor invoiced on completion, net 30. Parts are paid by the HOA directly to the suppliers.

Quote

ItemQty / HrsAmount
Parts: bought directly by the HOA at vendor pricing (board owned, no markup)
UniFi Cloud Gateway Ultra (UCG-Ultra)
Replaces the router; enables the VLAN and firewall rebuild.
1~$139
UI Care for the UCG-Ultra
5-year coverage with advance replacement and priority support from UniFi.
1$25
GL.iNet Brume 2 (GL-MT2500)
Dedicated VPN gateway, native Tailscale.
1~$80
Parts subtotal (paid to vendor, not billed by Elberta)~$244
Labor: Elberta Labs, $150/hr resident rate
Network rebuild + VPN setup
Swap the gateway; rebuild VLANs/firewall to separate resident, camera, and management traffic; stand up the Tailscale VPN; remove public exposure.
up to 4.5up to $675
Handoff + training
Per-person access; walk the board and property manager through daily use.
0.5$75
Labor total (not-to-exceed)up to 5 hrsmax $750
Included, no charge (part of the original commitment)
Post-reset network verification scan
After Blue Sky Systems resets the camera passwords, confirm from the network side that no unauthorized access paths remain.
2 hrs$0

The 5 hours is a not-to-exceed ceiling. You're billed only for time actually used, and if the work would run past it I will cover the rest as our first engagement. Parts (~$244) are a one-time purchase the HOA makes and owns.

Aref Kashani
Founder, Elberta Labs · Resident, The Gallery
(425) 598-5288 · hello@elbertalabs.com · elbertalabs.com