news.volyx.in

My security camera shipped a GitHub admin token in its login page (hhh.hn)

642 points by hhh · 34 days ago · 243 comments on HN

Article summary

A security researcher discovered a GitHub admin token in the login page of a Hanwha security camera, which had admin privileges to hundreds of repositories. The token was found in the camera's firmware, which was extracted and analyzed. The researcher notified Hanwha, and the token was revoked within 12 hours. The camera's firmware also contained IP addresses assigned to the US Department of Defense, raising questions about the company's relationship with the DoD.

Main themes

  • Security camera vulnerabilities
  • Firmware analysis
  • GitHub token exposure
  • IoT security
  • IP address allocation
  • US Department of Defense

What commenters say

  • The use of a single MAC address across multiple devices can lead to security vulnerabilities and unauthorized access to online services.
  • IPv6 is a more secure and efficient protocol than IPv4, but its adoption has been slow due to its complexity and lack of backwards compatibility.
  • Using IP addresses reserved for private networks, such as those assigned to the US Department of Defense, can cause conflicts and security issues in certain situations.
  • The allocation of IP addresses and subnetting can be complex and prone to errors, leading to security vulnerabilities and conflicts.
  • Some argue that IPv6's large address space makes it less likely to experience collisions and security issues, while others believe that its complexity and low adoption rates are major drawbacks.
  • The use of NAT and firewalls is necessary to protect internal networks, but can be complex to configure and manage, especially with IPv6.
  • There is a need for a more straightforward and backwards-compatible successor to IPv4, rather than the complex and alien mental model of IPv6.