Comments

Hacker News

Perhaps they should just drop the 'security' from the name and simply call it a camera.

by pak9rabid

LLMs have truly killed obfuscation. It only worked previously by making things extremely tedious but AI doesn't care about that.

by IshKebab

When I cared, I found out that a lot of OBD-II dongles shipped with the same MAC, which gave you access to everything on a bunch of websites.

You can curse the storm, but the wind will come.

by RyJones

I bought some ambient room lighting recently. You cannot control them without a proprietary app. This bugged me ... so I grabbed an APK from the Google store, unpacked it, and found essentially keys to the kingdom: api keys for the backend, api keys for shopify, etc. Haven't done anything with this knowledge yet.

by whalesalad

A rule of thumb, put your cameras on a separate VLAN and never give that vlan internet access.

Least you can do.

by tehlike

Not surprised, many of these vendors are doing crazy things, insane defaults, broken security, hardcoded values. Security is not a priority, I get that, but at the very least some baseline check would be nice (no hardcoded credentials for starting)

by dev_l1x_be

The US Department of War IP adresses baked into the firmware is the bigger story here. Note to self: never buy a Korean security product.

by grommz

Worthy thread to ask: is there such a thing as a white label IP camera (or similar) with a supported open firmware? Not asking for open source, but something close to plug and play that nonetheless has a way of stripping the rootfs as desired for bespoke use in a manufacturer-supported way.

I have looked around before but I only found genuinely dev-oriented kits that weren't even in a shell, and crazy priced.

edit: seems there are some options now (or I missed them before), e.g. https://www.goodcam.io/#for-independent-developers

by badatnames

Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • Perhaps they should just drop the 'security' from the name and simply call it a camera.
  • LLMs have truly killed obfuscation. It only worked previously by making things extremely tedious but AI doesn't care about that.
  • When I cared, I found out that a lot of OBD-II dongles shipped with the same MAC, which gave you access to everything on a bunch of websites.

    You can curse the storm, but the wind will come.

  • I bought some ambient room lighting recently. You cannot control them without a proprietary app. This bugged me ... so I grabbed an APK from the Google store, unpacked it, and found essentially keys to the kingdom: api keys for the backend, api keys for shopify, etc. Haven't done anything with this knowledge yet.
  • A rule of thumb, put your cameras on a separate VLAN and never give that vlan internet access.

    Least you can do.

  • Not surprised, many of these vendors are doing crazy things, insane defaults, broken security, hardcoded values. Security is not a priority, I get that, but at the very least some baseline check would be nice (no hardcoded credentials for starting)
  • The US Department of War IP adresses baked into the firmware is the bigger story here. Note to self: never buy a Korean security product.
  • Worthy thread to ask: is there such a thing as a white label IP camera (or similar) with a supported open firmware? Not asking for open source, but something close to plug and play that nonetheless has a way of stripping the rootfs as desired for bespoke use in a manufacturer-supported way.

    I have looked around before but I only found genuinely dev-oriented kits that weren't even in a shell, and crazy priced.

    edit: seems there are some options now (or I missed them before), e.g. https://www.goodcam.io/#for-independent-developers