Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • Perhaps they should just drop the 'security' from the name and simply call it a camera.
  • LLMs have truly killed obfuscation. It only worked previously by making things extremely tedious but AI doesn't care about that.
  • When I cared, I found out that a lot of OBD-II dongles shipped with the same MAC, which gave you access to everything on a bunch of websites.

    You can curse the storm, but the wind will come.

  • I bought some ambient room lighting recently. You cannot control them without a proprietary app. This bugged me ... so I grabbed an APK from the Google store, unpacked it, and found essentially keys to the kingdom: api keys for the backend, api keys for shopify, etc. Haven't done anything with this knowledge yet.
  • A rule of thumb, put your cameras on a separate VLAN and never give that vlan internet access.

    Least you can do.

  • Not surprised, many of these vendors are doing crazy things, insane defaults, broken security, hardcoded values. Security is not a priority, I get that, but at the very least some baseline check would be nice (no hardcoded credentials for starting)
  • The US Department of War IP adresses baked into the firmware is the bigger story here. Note to self: never buy a Korean security product.
  • Worthy thread to ask: is there such a thing as a white label IP camera (or similar) with a supported open firmware? Not asking for open source, but something close to plug and play that nonetheless has a way of stripping the rootfs as desired for bespoke use in a manufacturer-supported way.

    I have looked around before but I only found genuinely dev-oriented kits that weren't even in a shell, and crazy priced.

    edit: seems there are some options now (or I missed them before), e.g. https://www.goodcam.io/#for-independent-developers

Explore Birbla archives

My security camera shipped a GitHub admin token in its login page · Birbla