My security camera shipped a GitHub admin token in its login page (hhh.hn)

411 points by hhh 8 hours ago

badatnames 4 hours ago

Worthy thread to ask: is there such a thing as a white label IP camera (or similar) with a supported open firmware? Not asking for open source, but something close to plug and play that nonetheless has a way of stripping the rootfs as desired for bespoke use in a manufacturer-supported way.

I have looked around before but I only found genuinely dev-oriented kits that weren't even in a shell, and crazy priced.

edit: seems there are some options now (or I missed them before), e.g. https://www.goodcam.io/#for-independent-developers

numpad0 26 minutes ago

Not exactly what you have asked for, but ESP32 based M5Stack and Seeed Xiao modules might fit the bill. They are not so expensive, are Linux-free, and there's no report so far of secret ping home features in the SDK.

tehlike 2 hours ago

You can get close.... I guess...

Some cameras do support thingino, so you can override their firmware. Then there's this: https://openipc.org/supported-hardware/featured

makefu an hour ago

There is also https://thingino.com/ which has a clear set of supported cameras. The installation is straight forward if you choose a cam with SD-Card flashing support. I upgraded two of the Sonoff Slim Gen2 without any issues.

nozzlegear 3 hours ago

Seems like the shop is broken?

> Stránka nenalezena

> There's been a glitch...

> We're not quite sure what went wrong. You can go back, or try looking on our homepage.

badatnames 2 hours ago

Huh, it was working an hour ago. The outdoor 8MP variant was around the 85 euro mark.

cenamus 3 hours ago

Czech for 'page not found'

em3rgent0rdr 3 hours ago

ESP32-CAM

LastTrain 2 hours ago

I so want these to be a viable solution but man my experience so far is that it can barely be made to work and only in the most favorable environments. Compare that to the blink cameras I used to run outside where it occasionally went below -20F and they still went over a year on a couple batteries.

TaLiTr 2 hours ago

I wish... The best I've found is https://openipc.org/ which is a very manufacturer unsupported way of reflashing certain chips with open-source firmware. It seems very fiddly as only certain SoCs are supported and good luck finding out if a specific Chinese camera has one.

xiconfjs 3 hours ago

Thank you. Ordered one to play around and see if this is a viable alternative.

grommz 7 hours ago

The US Department of War IP adresses baked into the firmware is the bigger story here. Note to self: never buy a Korean security product.

hhh 7 hours ago

I do know of at least one company who has black-holed the entire DoD ip space and are using it for internal space, which is why I gave a speculation warning... it's really strange regardless.

anonymars 5 hours ago

Interesting -- seems like the side effect would be to basically prevent use by the DoD but not really anyone else. Bonus points if they sell a "government" version for higher cost

accrual 5 hours ago

I also know of a company who does this. The reason in their case is they act as a network concentrator, bridging hundreds of client IP spaces, so this helps them avoid conflicts with their own space without having to NAT constantly. There is still a lot of NAT for the more common ranges.

inigyou an hour ago

ec109685 4 hours ago

Yeah I wanted to do that at previous company. Got talked out of it, but it's nice have all those ips available.

makr17 4 hours ago

I used to work somewhere that did that. Several of us in Eng pointed out that it was likely impossible to sell anything to DoD personnel since the reply would route internally. But I don't know if it was _fixed_, was still an issue when I left.

ErroneousBosh 6 hours ago

I recently troubleshot an installation for someone where at some point in the past they'd picked 1.1.1.0/24 as their address range because "all that 192 stuff was silly and too complicated".

You know, I'm not sure I can explain how I feel about this properly without waving the shotgun around.

mr_mitm 4 hours ago

tracker1 4 hours ago

jabart 5 hours ago

cyanydeez 6 hours ago

inigyou 6 hours ago

bflesch 6 hours ago

This will trip up most SOC workflows in funny ways, and I like it.

IPs having a global distinction between public/private is a convention, but local routing can widely differ.

Same with the "China Cyberattacks" - the guys sitting on top of my outgoing fiber can simulate any IP address they want to me.

freeone3000 6 hours ago

kotaKat 7 hours ago

there's a couple subnets I (ab)use in the DOD IP space for my home network knowing they'd never put them on the open internet. it's also fun to throw logging for a loop if someone digs.

22.0.0.0/8 - it's basically free real estate!

walrus01 6 hours ago

cryptonym 6 hours ago

webstrand 4 hours ago

walrus01 6 hours ago

> Note to self: never buy a Korean security product.

The Canadian Navy very recently made a major choice and agreed with you

https://www.google.com/search?client=firefox-b-d&q=hanwha+oc...

lardosaurusrex 5 hours ago

just buy stuff you can put your own firmware/os on because it's either just the worst security in the world (aka anything not from china) or, well... china.

and while i currently don't hate china as much as i do US rn (because canadian; sorry) i can also say -- due to being an aforementioned leaflandian -- that due to very personal experience i have zero faith in anything from china that has the ability to connect to any type of network :')

And so yeah at this point if I can't at the very least get a whatever-wrt firmware (preferably a proper linux distro nowadays; not to say the *-wrt firmwares aren't a real OS but, y'know) on the device i just avoid them entirely since, well... it's all i can do at this point because even if there were baked in hardware-based backdoors i as an individual can't do much more than that.

prox 5 hours ago

That sounds horrible. I got an old PI4, would it make for a decent router, if at all possible?

myself248 3 hours ago

edwinjm an hour ago

The DoWD owns such a large chunk of the IP space, it can very easily be a coincidence

dev_l1x_be 6 hours ago

Or Korean IoT products. The ones I was working on had insane approach to security.

RajT88 4 hours ago

As if domestic products aren't a hot mess of security issues and sloppy engineering. Lol

kingleopold 6 hours ago

Note to self: never buy any Korean hardware or software product.

/S

walrus01 5 hours ago

Note to self, never buy any hardware product, move to a yurt in the woods, start an alpaca ranch, write a manifesto

KPGv2 3 hours ago

> Department of War

n.b., it's the Department of Defense, just like the Kennedy Center doesn't have Trump's name attached, and the large body of water by Texas is the Gulf of Mexico.

dev_l1x_be 6 hours ago

Not surprised, many of these vendors are doing crazy things, insane defaults, broken security, hardcoded values. Security is not a priority, I get that, but at the very least some baseline check would be nice (no hardcoded credentials for starting)

snoman 5 hours ago

As they say: in IoT the S stands for security.

js4ever 4 hours ago

ID-IoT-S

folkrav 5 hours ago

There’s some irony to security not being a priority for security cameras. Different kind of security I know, but still.

daneel_w 5 hours ago

There's also some irony in people happily ignoring that so many of these products live-stream the inside view of their homes and offices to some foreign corporate cloud - and in the case of suspiciously many Chinese security cameras, a state-backed corporation's cloud. Because, wow, it really is convenient.

awakeasleep 4 hours ago

How can there be a baseline check when you operate by getting the most inexperienced cheapest person possible to do the work?

gxs 2 hours ago

Especially these days there’s really no excuse

Add a skill to your repo that does some basic checks at least, not that hard

tehlike 5 hours ago

A rule of thumb, put your cameras on a separate VLAN and never give that vlan internet access.

Least you can do.

RyJones 8 hours ago

When I cared, I found out that a lot of OBD-II dongles shipped with the same MAC, which gave you access to everything on a bunch of websites.

You can curse the storm, but the wind will come.

netsharc 7 hours ago

how did "same MAC" lead to "access to everything"?

Was the website's security based on MAC, which presumably is supplied by the client? If so, I guess.. typical IoT.

RyJones 7 hours ago

buy any dongle that sells for under $100 on amazon. they all have the same mac, and come with 'bespoke' apps to let you do things to your car. those apps are all thin wrappers on code widely shared; they use the MAC of the dongle as the keystone for ID.

Short story: buy one cheap dongle on Amazon, dump the MAC (00:11:22:AA:BB:CC IIRC; it's been 15 years since I cared) and you have auth to all of the apps everywhere.

Reminder: the Bluetooth logo comes, mostly, from self-certification.

andreareina 6 hours ago

londons_explore 6 hours ago

inigyou 6 hours ago

1718627440 3 hours ago

How does this even work? A website doesn't know your MAC, that is only known in your local network.

pak9rabid 3 hours ago

Perhaps they should just drop the 'security' from the name and simply call it a camera.

sodapopcan 5 hours ago

This blog's misuse of the external link icon irks me.

kyle-rb 4 hours ago

The CSS selector they used (`a[href*="://"]::after`) is meant to only target only external links, but assumes any internal links will be using relative paths like `href="/about"`. The problem is that this site uses absolute URLs (`href="https://hhh.hn/about"`) for its nav links, so every link ends up with an icon.

You could fix this by adding an exception to the CSS rule so it skips links starting with your site's name:

  a[href*="://"]:not([href^="https://hhh.hn"])::after

AlienRobot 4 hours ago

rel="external" solves this.

hhh 4 hours ago

will fix it tomorrow

IshKebab 6 hours ago

LLMs have truly killed obfuscation. It only worked previously by making things extremely tedious but AI doesn't care about that.

llm_nerd 6 hours ago

And it's worth considering that obfuscation only ever worked against casuals for whom tedious was a bridge too far. Nation state actors and criminal hacker groups, on the other hand, consider the tedious entirely worth it.

phh 6 hours ago

Yes, obfuscation was always a matter of cost: how much money do you need to break the protection? LLM just decreased that amount by a lot.

(Yes ok, RSA4096 is technically a matter of cost, you just need an infinite amount of money)

TeMPOraL 3 hours ago

jaggederest 4 hours ago

inigyou 6 hours ago

Pirates checked Denuvo, once considered the king of DRM.

walrus01 6 hours ago

> consider the tedious entirely worth it.

Entirely without LLMs, I'm imagining an office of North Korean compsci graduates doing astonishingly tedious tasks, for whom an office job on a basic Linux computer and slightly better diet and nice apartment put them in the top 1-2% of living standard in the country.

p-e-w 6 hours ago

On the bright side, even a small local LLM can easily improve garbage code like that.

orbital-decay 5 hours ago

I'm 100% confident in hardware companies' ability to make infinitely incompetent software given infinitely smart agents. They do it because they don't care about software, not because they lack tools. No agent can turn them into software companies if they don't want it themselves.

whalesalad 6 hours ago

I bought some ambient room lighting recently. You cannot control them without a proprietary app. This bugged me ... so I grabbed an APK from the Google store, unpacked it, and found essentially keys to the kingdom: api keys for the backend, api keys for shopify, etc. Haven't done anything with this knowledge yet.

Ecsta 6 hours ago

There's a lot of public keys that don't give you any special access, unless the dev is really bad.

Anyone who cares about security will be using App Attest or the Google store equivalent.

JTbane 6 hours ago

>Anyone who cares about security

I have something hilarious to tell you about IoT apps

tclancy 5 hours ago

sophacles 4 hours ago

cute_boi 4 hours ago

CodesInChaos 4 hours ago

> Anyone who cares about security will be using App Attest or the Google store equivalent.

Why? I rarely have security objectives where remote attention would help, and it has a huge impact on user freedom. For B2C attestation is just an evil captcha.

tehlike 5 hours ago

Another rule of thumb - i know it's not always the best since some products are really nice aesthetically - is to buy only local smart stuff, for example, zigbee/zwave.

petepete 5 hours ago

I live by this rule*. Being able to pick up stuff from IKEA that's well supported, well designed and really affordable is a huge advantage.

*almost, I have two things that need an app. My Vaillant boiler and my Yale alarm system. Both apps are terrible, but I have a 10 year warranty on the boiler and my alarm is up to scratch from a home insurance point of view.**

tehlike 4 hours ago

dev_l1x_be 6 hours ago

In many cases it is bad to publish this info because they might come after you. There used to be a company who shielded the “researcher” from the legal consequences, can’t remember the name though.

fragmede 5 hours ago

@stake or L0pht?

inigyou 6 hours ago

Everything can be controlled without a proprietary app. Hope you reverse engineer the protocol and publish how to do it.

tehlike 5 hours ago

Or claude/codex can.

fragmede 5 hours ago

Have you actually tried to do anything with them though? The keys are in there, but may not grant you any real extra access beyond what your user is actually allowed to do via the app.

avgDev 5 hours ago

It is still pretty nice, you don't have to install yet another app to do something. People did this with Mazda app as it allowed them to start the car without subscription. They 'fixed' it.

jwithington 4 hours ago

I've seen these systems at US defense industry tradeshows so I'm guessing they are in use somewhere.

dare944 2 hours ago

> Why would Hanwha Vision need anything remotely related to the DoD? Is it possible that their CI is provided by some centralized team at their parent company Hanwha, where the needs of their sister company Hanwha Aerospace cause the shared platform to have these entries in the CI environment variables? Or maybe because of their other sister company, Hanwha Defense USA, where they make other large scary steel machines

Or... the Department of Warmongers (nee DoD) addresses on the device are evidence of a supply-side attack targeting the DoW and carried out using the aforementioned github admin token.

... I mean, while we're in here speculating about truffles and all.

asveikau 3 hours ago

My cameras are analog rather than PoE or IP based, but that's just because I set up the initial iteration of the system a long time ago. The standard now is to give your camera an IP address.

With many IoT type things I block access to the public internet. I think with cameras specifically a lot of people even set it up physically on a different network that can only talk to the NVR.

But tldr, basing the cameras on IP invites some of the things in this article. Anyone deploying these devices needs to think about securing them.

kiddico 4 hours ago

I have yet to find a pattern for when the author chooses to capitalize things.

limsungkee 3 hours ago

This kind of open source expands the world.

hexxt-git 4 hours ago

true open source!

qweqwe14 3 hours ago

Why would you write like that? Not capitalizing the first word of a sentence makes the whole thing less readable. So that you can feel special? Really?

explorigin 3 hours ago

Who hurt you? It's his own blog. Let him write the way he wants.

that_guy_iain 6 hours ago

I bet someone returned that security camera.

mikey_p 5 hours ago

No, if you read the article the author was downloading firmware from their website and still found the token.

aizk 5 hours ago

Department of War IP address? I feel this should be making headlines!

CodesInChaos 5 hours ago

Abusing IP ranges which were assigned to an organization but aren't actually used on the public Internet as private addresses is pretty common. Sure, it's bad practice, but not a big deal.

TeMPOraL 2 hours ago

Of course this looks entirely different when your corporate superstructure has a long and active history of developing military equipment.

caruasdo 4 hours ago

I know you're a mastermind when it comes to security, but you should provide more context about the tools and methods you're using in your article so we can better understand what it's all about and not have to Google every single step you're taking.

dust-jacket 4 hours ago

Oh I thought exactly the opposite!

I feel like every security blog (or even just tech blog) I've read recently has had paragraphs and paragraphs of largely LLM generated explainer waffle. This felt refreshingly focused and to the point.

hhh 4 hours ago

i’m not a mastermind, and I agree it could be more accessible. I treat this blog as somewhere to just dump my thoughts as unfiltered as I can while still being useful or entertaining, maybe for some other posts I will go more into depth

sophacles 4 hours ago

Seemed perfectly reasonable to me. Not everything has to be written for a target audience that includes you, besides you were able to look up what you needed it seems. Another tactic is to feed the article to your favorite LLM and interrogate it about what you don't understand.