Worthy thread to ask: is there such a thing as a white label IP camera (or similar) with a supported open firmware? Not asking for open source, but something close to plug and play that nonetheless has a way of stripping the rootfs as desired for bespoke use in a manufacturer-supported way.
I have looked around before but I only found genuinely dev-oriented kits that weren't even in a shell, and crazy priced.
The US Department of War IP adresses baked into the firmware is the bigger story here. Note to self: never buy a Korean security product.
show comments
dev_l1x_be
Not surprised, many of these vendors are doing crazy things, insane defaults, broken security, hardcoded values. Security is not a priority, I get that, but at the very least some baseline check would be nice (no hardcoded credentials for starting)
show comments
tehlike
A rule of thumb, put your cameras on a separate VLAN and never give that vlan internet access.
Least you can do.
RyJones
When I cared, I found out that a lot of OBD-II dongles shipped with the same MAC, which gave you access to everything on a bunch of websites.
You can curse the storm, but the wind will come.
show comments
pak9rabid
Perhaps they should just drop the 'security' from the name and simply call it a camera.
bryanrasmussen
it's not a bug, it's a freebie!
sodapopcan
This blog's misuse of the external link icon irks me.
show comments
IshKebab
LLMs have truly killed obfuscation. It only worked previously by making things extremely tedious but AI doesn't care about that.
show comments
whalesalad
I bought some ambient room lighting recently. You cannot control them without a proprietary app. This bugged me ... so I grabbed an APK from the Google store, unpacked it, and found essentially keys to the kingdom: api keys for the backend, api keys for shopify, etc. Haven't done anything with this knowledge yet.
show comments
jwithington
I've seen these systems at US defense industry tradeshows so I'm guessing they are in use somewhere.
dare944
> Why would Hanwha Vision need anything remotely related to the DoD? Is it possible that their CI is provided by some centralized team at their parent company Hanwha, where the needs of their sister company Hanwha Aerospace cause the shared platform to have these entries in the CI environment variables? Or maybe because of their other sister company, Hanwha Defense USA, where they make other large scary steel machines
Or... the Department of Warmongers (nee DoD) addresses on the device are evidence of a supply-side attack targeting the DoW and carried out using the aforementioned github admin token.
... I mean, while we're in here speculating about truffles and all.
asveikau
My cameras are analog rather than PoE or IP based, but that's just because I set up the initial iteration of the system a long time ago. The standard now is to give your camera an IP address.
With many IoT type things I block access to the public internet. I think with cameras specifically a lot of people even set it up physically on a different network that can only talk to the NVR.
But tldr, basing the cameras on IP invites some of the things in this article. Anyone deploying these devices needs to think about securing them.
kiddico
I have yet to find a pattern for when the author chooses to capitalize things.
limsungkee
This kind of open source expands the world.
hexxt-git
true open source!
qweqwe14
Why would you write like that? Not capitalizing the first word of a sentence makes the whole thing less readable. So that you can feel special? Really?
show comments
that_guy_iain
I bet someone returned that security camera.
show comments
aizk
Department of War IP address? I feel this should be making headlines!
show comments
caruasdo
I know you're a mastermind when it comes to security, but you should provide more context about the tools and methods you're using in your article so we can better understand what it's all about and not have to Google every single step you're taking.
Worthy thread to ask: is there such a thing as a white label IP camera (or similar) with a supported open firmware? Not asking for open source, but something close to plug and play that nonetheless has a way of stripping the rootfs as desired for bespoke use in a manufacturer-supported way.
I have looked around before but I only found genuinely dev-oriented kits that weren't even in a shell, and crazy priced.
edit: seems there are some options now (or I missed them before), e.g. https://www.goodcam.io/#for-independent-developers
The US Department of War IP adresses baked into the firmware is the bigger story here. Note to self: never buy a Korean security product.
Not surprised, many of these vendors are doing crazy things, insane defaults, broken security, hardcoded values. Security is not a priority, I get that, but at the very least some baseline check would be nice (no hardcoded credentials for starting)
A rule of thumb, put your cameras on a separate VLAN and never give that vlan internet access.
Least you can do.
When I cared, I found out that a lot of OBD-II dongles shipped with the same MAC, which gave you access to everything on a bunch of websites.
You can curse the storm, but the wind will come.
Perhaps they should just drop the 'security' from the name and simply call it a camera.
it's not a bug, it's a freebie!
This blog's misuse of the external link icon irks me.
LLMs have truly killed obfuscation. It only worked previously by making things extremely tedious but AI doesn't care about that.
I bought some ambient room lighting recently. You cannot control them without a proprietary app. This bugged me ... so I grabbed an APK from the Google store, unpacked it, and found essentially keys to the kingdom: api keys for the backend, api keys for shopify, etc. Haven't done anything with this knowledge yet.
I've seen these systems at US defense industry tradeshows so I'm guessing they are in use somewhere.
> Why would Hanwha Vision need anything remotely related to the DoD? Is it possible that their CI is provided by some centralized team at their parent company Hanwha, where the needs of their sister company Hanwha Aerospace cause the shared platform to have these entries in the CI environment variables? Or maybe because of their other sister company, Hanwha Defense USA, where they make other large scary steel machines
Or... the Department of Warmongers (nee DoD) addresses on the device are evidence of a supply-side attack targeting the DoW and carried out using the aforementioned github admin token.
... I mean, while we're in here speculating about truffles and all.
My cameras are analog rather than PoE or IP based, but that's just because I set up the initial iteration of the system a long time ago. The standard now is to give your camera an IP address.
With many IoT type things I block access to the public internet. I think with cameras specifically a lot of people even set it up physically on a different network that can only talk to the NVR.
But tldr, basing the cameras on IP invites some of the things in this article. Anyone deploying these devices needs to think about securing them.
I have yet to find a pattern for when the author chooses to capitalize things.
This kind of open source expands the world.
true open source!
Why would you write like that? Not capitalizing the first word of a sentence makes the whole thing less readable. So that you can feel special? Really?
I bet someone returned that security camera.
Department of War IP address? I feel this should be making headlines!
I know you're a mastermind when it comes to security, but you should provide more context about the tools and methods you're using in your article so we can better understand what it's all about and not have to Google every single step you're taking.