12 ms·
My security camera shipped a GitHub admin token in its login page
- RyJones 2mo agoWhen I cared, I found out that a lot of OBD-II dongles shipped with the same MAC, which gave you access to everything on a bunch of websites. You can curse the storm, but the wind will come.
- netsharc 2mo agohow did "same MAC" lead to "access to everything"? Was the website's security based on MAC, which presumably is supplied by the client? If so, I guess.. typical IoT.
- RyJones 2mo agobuy any dongle that sells for under $100 on amazon. they all have the same mac, and come with 'bespoke' apps to let you do things to your car. those apps are all thin wrappers on code widely shared; they use the MAC of the dongle as the keystone for ID. Short story: buy one cheap dongle on Amazon, dump the MAC (00:11:22:AA:BB:CC IIRC; it's been 15 years since I cared) and you have auth to all of the apps everywhere. Reminder: the Bluetooth logo comes, mostly, from self-certification.
- andreareina 2mo agoAmazing! I have the same MAC address on my luggage!
- walrus01 2mo agoI made things easier by setting the permission action link on all my nuclear weapons to zero https://www.google.com/search?client=firefox-b-d&q=permission+action+link+set+to+zero https://www.google.com/search?client=firefox-b-d&q=permissio...
- tclancy 2mo agoRemind me to rotate my GitHub tokens.
- pak9rabid 2mo ago00:11:22:33:44:55
- londons_explore 2mo agoI bought 3 from 3 different vendors and they all have totally different Mac addresses. Internally they're all Bluetooth to serial chips, and another pic16xxxx chip which does serial to canbus. I guess the Bluetooth serial chips probably have programmable Mac addresses, but equally they normally ship with a globally default one unless you flash a different one onto it.
- inigyou 2mo agoWhy do the apps need auth?
- 1718627440 2mo agoHow does this even work? A website doesn't know your MAC, that is only known in your local network.
- deleted 2mo ago[deleted]
- deleted 2mo ago[deleted]
- grommz 2mo agoThe US Department of War IP adresses baked into the firmware is the bigger story here. Note to self: never buy a Korean security product.
- hhh 2mo agoI do know of at least one company who has black-holed the entire DoD ip space and are using it for internal space, which is why I gave a speculation warning... it's really strange regardless.
- kotaKat 2mo agothere's a couple subnets I (ab)use in the DOD IP space for my home network knowing they'd never put them on the open internet. it's also fun to throw logging for a loop if someone digs. 22.0.0.0/8 - it's basically free real estate!
- cryptonym 2mo agoI have seen ISP doing CGNAT on DOD IP space.
- walrus01 2mo agothe entirety of 10/8 and 172.16/12 and 192.168/16 wasn't large enough for your house?
- kotaKat 2mo agoi deal with a lot of nerds that are all interconnected with one another and nobody can agree on a common subnet for their houses when we all decide to exchange routes internally. ;)
- myself248 2mo agoI deal with a lot of nerds, but starting in about 2008 we all segmented up the 10.x space and each of us has a /16, with each site we manage having typically a /24 or /22, so nobody overlaps. We can light up tunnels between each other and never have a collision. We have a little internal registry on a private wiki, and it's been serving us well for... oh dear, almost two decades now. Crucially, we set aside the common 10.1 and 10.10 ranges as nonroutable, so any devices that default into those have to be dealt with before they can live on the wider network. Newcomers get handed a block and have to renumber, or NAT into it, or whatever, but they cannot emit bogons. At a small scale (first-name basis), this works.
- whalesalad 2mo agoI bought some ambient room lighting recently. You cannot control them without a proprietary app. This bugged me ... so I grabbed an APK from the Google store, unpacked it, and found essentially keys to the kingdom: api keys for the backend, api keys for shopify, etc. Haven't done anything with this knowledge yet.
- Ecsta 2mo agoThere's a lot of public keys that don't give you any special access, unless the dev is really bad. Anyone who cares about security will be using App Attest or the Google store equivalent.
- JTbane 2mo ago>Anyone who cares about security I have something hilarious to tell you about IoT apps
- tclancy 2mo agoA Venn diagram like a 6th grade boy's graffiti of boobs.
- dhosek 2mo agoJust as a pedantic aside, people often use Venn diagram when they mean Euler diagram. A Venn diagram always has the overlapping circles and use shading or labeling describe the set relation. Euler diagrams let the circles describe the relation so two non intersecting sets in a Venn diagram might share the left circle green, the right blue and leave the intersection blank or grey. An Euler diagram will have two disjoint circles.
- tclancy 2mo agoA. I love a pedantic aside B. I love that Euler is pronounced “oiler” which is North American slang for a drunk. I’ve been trying to find that constant my whole adult life.
- that_guy_iain 2mo agoI bet someone returned that security camera.
- mikey_p 2mo agoNo, if you read the article the author was downloading firmware from their website and still found the token.
- IshKebab 2mo agoLLMs have truly killed obfuscation. It only worked previously by making things extremely tedious but AI doesn't care about that.
- llm_nerd 2mo agoAnd it's worth considering that obfuscation only ever worked against casuals for whom tedious was a bridge too far. Nation state actors and criminal hacker groups, on the other hand, consider the tedious entirely worth it.
- walrus01 2mo ago> consider the tedious entirely worth it. Entirely without LLMs, I'm imagining an office of North Korean compsci graduates doing astonishingly tedious tasks, for whom an office job on a basic Linux computer and slightly better diet and nice apartment put them in the top 1-2% of living standard in the country.
- inigyou 2mo agoPirates checked Denuvo, once considered the king of DRM.
- inigyou 2mo agocracked*
- phh 2mo agoYes, obfuscation was always a matter of cost: how much money do you need to break the protection? LLM just decreased that amount by a lot. (Yes ok, RSA4096 is technically a matter of cost, you just need an infinite amount of money)
- jaggederest 2mo agoThe cool thing about cryptographic security is that it's an asymmetric amount of cost for both parties - to encode is cheap, to break is many orders of magnitude harder, unlike obfuscation where the difficulty is approximately symmetrical.
- dev_l1x_be 2mo agoNot surprised, many of these vendors are doing crazy things, insane defaults, broken security, hardcoded values. Security is not a priority, I get that, but at the very least some baseline check would be nice (no hardcoded credentials for starting)
- snoman 2mo agoAs they say: in IoT the S stands for security.
- js4ever 2mo agoID-IoT-S
- deleted 2mo ago[deleted]
- folkrav 2mo agoThere’s some irony to security not being a priority for security cameras. Different kind of security I know, but still.
- daneel_w 2mo agoThere's also some irony in people happily ignoring that so many of these products live-stream the inside view of their homes and offices to some foreign corporate cloud - and in the case of suspiciously many Chinese security cameras, a state-backed corporation's cloud. Because, wow, it really is convenient.
- glitchcrab 2mo agoWhich is exactly why alll my cameras live in their own VLAN with no internet access, regardless of how trustworthy the company may be. Better safe than sorry and all that.
- awakeasleep 2mo ago
- deleted 2mo ago[deleted]
- aizk 2mo agoDepartment of War IP address? I feel this should be making headlines!
- CodesInChaos 2mo agoAbusing IP ranges which were assigned to an organization but aren't actually used on the public Internet as private addresses is pretty common. Sure, it's bad practice, but not a big deal.
- TeMPOraL 2mo agoOf course this looks entirely different when your corporate superstructure has a long and active history of developing military equipment.
- sodapopcan 2mo agoThis blog's misuse of the external link icon irks me.
- kyle-rb 2mo agoThe CSS selector they used (`a[href*="://"]::after`) is meant to only target only external links, but assumes any internal links will be using relative paths like `href="/about"`. The problem is that this site uses absolute URLs (`href="https://hhh.hn/about https://hhh.hn/about"`) for its nav links, so every link ends up with an icon. You could fix this by adding an exception to the CSS rule so it skips links starting with your site's name: a[href*="://"]:not([href^="https://hhh.hn"])::after
- AlienRobot 2mo agorel="external" solves this.
- hhh 2mo agowill fix it tomorrow
- joka88xj 2mo ago[flagged]
- tehlike 2mo agoA rule of thumb, put your cameras on a separate VLAN and never give that vlan internet access. Least you can do.
- caruasdo 2mo agoI know you're a mastermind when it comes to security, but you should provide more context about the tools and methods you're using in your article so we can better understand what it's all about and not have to Google every single step you're taking.
- sophacles 2mo agoSeemed perfectly reasonable to me. Not everything has to be written for a target audience that includes you, besides you were able to look up what you needed it seems. Another tactic is to feed the article to your favorite LLM and interrogate it about what you don't understand.
- dust-jacket 2mo agoOh I thought exactly the opposite! I feel like every security blog (or even just tech blog) I've read recently has had paragraphs and paragraphs of largely LLM generated explainer waffle. This felt refreshingly focused and to the point.
- hhh 2mo agoi’m not a mastermind, and I agree it could be more accessible. I treat this blog as somewhere to just dump my thoughts as unfiltered as I can while still being useful or entertaining, maybe for some other posts I will go more into depth
- hexxt-git 2mo agotrue open source!
- deleted 2mo ago[deleted]
- jwithington 2mo agoI've seen these systems at US defense industry tradeshows so I'm guessing they are in use somewhere.
- badatnames 2mo agoWorthy thread to ask: is there such a thing as a white label IP camera (or similar) with a supported open firmware? Not asking for open source, but something close to plug and play that nonetheless has a way of stripping the rootfs as desired for bespoke use in a manufacturer-supported way. I have looked around before but I only found genuinely dev-oriented kits that weren't even in a shell, and crazy priced. edit: seems there are some options now (or I missed them before), e.g. https://www.goodcam.io/#for-independent-developers https://www.goodcam.io/#for-independent-developers
- xiconfjs 2mo agoThank you. Ordered one to play around and see if this is a viable alternative.
- em3rgent0rdr 2mo agoESP32-CAM
- LastTrain 2mo agoI so want these to be a viable solution but man my experience so far is that it can barely be made to work and only in the most favorable environments. Compare that to the blink cameras I used to run outside where it occasionally went below -20F and they still went over a year on a couple batteries.
- nozzlegear 2mo agoSeems like the shop is broken? > Stránka nenalezena > There's been a glitch... > We're not quite sure what went wrong. You can go back, or try looking on our homepage.
- cenamus 2mo agoCzech for 'page not found'
- badatnames 2mo agoHuh, it was working an hour ago. The outdoor 8MP variant was around the 85 euro mark.
- kiddico 2mo agoI have yet to find a pattern for when the author chooses to capitalize things.
- asveikau 2mo agoMy cameras are analog rather than PoE or IP based, but that's just because I set up the initial iteration of the system a long time ago. The standard now is to give your camera an IP address. With many IoT type things I block access to the public internet. I think with cameras specifically a lot of people even set it up physically on a different network that can only talk to the NVR. But tldr, basing the cameras on IP invites some of the things in this article. Anyone deploying these devices needs to think about securing them.
- limsungkee 2mo agoThis kind of open source expands the world.
- qweqwe14 2mo agoWhy would you write like that? Not capitalizing the first word of a sentence makes the whole thing less readable. So that you can feel special? Really?
- explorigin 2mo agoWho hurt you? It's his own blog. Let him write the way he wants.
- pak9rabid 2mo agoPerhaps they should just drop the 'security' from the name and simply call it a camera.
- hnscum 2mo ago[dead]
- dare944 2mo ago> Why would Hanwha Vision need anything remotely related to the DoD? Is it possible that their CI is provided by some centralized team at their parent company Hanwha, where the needs of their sister company Hanwha Aerospace cause the shared platform to have these entries in the CI environment variables? Or maybe because of their other sister company, Hanwha Defense USA, where they make other large scary steel machines Or... the Department of Warmongers (nee DoD) addresses on the device are evidence of a supply-side attack targeting the DoW and carried out using the aforementioned github admin token. ... I mean, while we're in here speculating about truffles and all.
- bryanrasmussen 2mo agoit's not a bug, it's a freebie!
- David_runai 2mo ago[flagged]
- ButlerianJihad 2mo agoBack in the mid-1990s, I was working at an ISP and also at a consulting firm. The consulting firm's #1 business at the time was to get businesses connected to the Internet, where these businesses already had significant LAN buildouts. Now these were the days before IANA had officially assigned those "Private IP Network" numbers. Nobody had any private IPv4 space to work with! So the choices consisted of: make up some numbers and hope they don't conflict, or go ahead and register your IPv4 space and get public netblocks assigned, even if you're just using them privately. So, needless to say, we encountered some bonkers configurations, and a lot of our job was undoing some really awful configurations in order to make them compliant with actual Internet connectivity, and so that different office LANs would interoperate properly. We were also big advocates of security, firewalls, and the venerable "DMZ/Bastion" setups from back in the day, so those Private IP Network assignments would've been really useful, along with NAT, but we simply didn't have those tools at our disposal, and our clients were basically registering huge IPv4 blocks that they really didn't need to ever use.
- Kim_Bruning 2mo agoI generally run security cameras on a separate VLAN and use something like frigate or other floss dvr tool for them to talk to. Never let a cheap networked security camera touch the actual internet. %-/
- salvador-odil 2mo agowhat a good blog to read. Have you found answer on why they use the same token across these bunch of files? Maybe they are tying to adopt the agentic code writing? One interesting questions, what does that gh token give access to? It is only read from private repo, is not it? You said "admin" privileges earlier.
- OrangeMusic 2mo agoSorry to be that guy but if you can't even bother to capitalize your sentences then I won't bother to read your blog.
- Ovah 2mo agoAt least it's written by a human and not AI slop.
- tonyx1998 2mo ago[flagged]
- hassanfree 2mo ago[flagged]
- luciana1u 2mo ago[flagged]
- hluska 2mo agoIt’s kind of interesting - I imported security cameras for a business roughly twenty hours ago. The security problems at the time were unbelievable to a point that any kind of wireless, IP or any type of service offering remote view was really scary. It was always stupid stuff - little oversights, things that were hard coded and shouldn’t have been or extremely old versions of insecure software running critical functions. Apparently, nothing has changed in two decades.
- deleted 2mo ago[deleted]
- gatekeephqpro 2mo ago[flagged]
- julian-vix 2mo ago[dead]
- deleted 2mo ago[deleted]
- feiz45607 2mo ago[dead]
- hhh 2mo agoFYI, I have issued a correction to clarify that they were using the IP space for internal addressing.