My security camera shipped a GitHub admin token in its login page
hhh
550 points
186 comments
July 24, 2026
Related Discussions
Found 5 related stories in 371.1ms across 14,736 title embeddings via pgvector HNSW
- Tell HN: GitHub might have been leaking your webhook secrets. Check your emails. ssiddharth · 24 pts · April 14, 2026 · 59% similar
- Grafana says stolen GitHub token allowed attackers to download its codebase p_stuart82 · 14 pts · May 18, 2026 · 57% similar
- 1-Click GitHub Token Stealing via a VSCode Bug ammar2 · 228 pts · June 02, 2026 · 56% similar
- Ask HN: Is GitHub preparing to go behind a login wall? reconnecting · 44 pts · July 07, 2026 · 54% similar
- GitHub is investigating unauthorized access to their internal repositories splenditer · 321 pts · May 20, 2026 · 53% similar
Discussion Highlights (20 comments)
RyJones
When I cared, I found out that a lot of OBD-II dongles shipped with the same MAC, which gave you access to everything on a bunch of websites. You can curse the storm, but the wind will come.
grommz
The US Department of War IP adresses baked into the firmware is the bigger story here. Note to self: never buy a Korean security product.
whalesalad
I bought some ambient room lighting recently. You cannot control them without a proprietary app. This bugged me ... so I grabbed an APK from the Google store, unpacked it, and found essentially keys to the kingdom: api keys for the backend, api keys for shopify, etc. Haven't done anything with this knowledge yet.
that_guy_iain
I bet someone returned that security camera.
IshKebab
LLMs have truly killed obfuscation. It only worked previously by making things extremely tedious but AI doesn't care about that.
dev_l1x_be
Not surprised, many of these vendors are doing crazy things, insane defaults, broken security, hardcoded values. Security is not a priority, I get that, but at the very least some baseline check would be nice (no hardcoded credentials for starting)
aizk
Department of War IP address? I feel this should be making headlines!
sodapopcan
This blog's misuse of the external link icon irks me.
tehlike
A rule of thumb, put your cameras on a separate VLAN and never give that vlan internet access. Least you can do.
caruasdo
I know you're a mastermind when it comes to security, but you should provide more context about the tools and methods you're using in your article so we can better understand what it's all about and not have to Google every single step you're taking.
hexxt-git
true open source!
jwithington
I've seen these systems at US defense industry tradeshows so I'm guessing they are in use somewhere.
badatnames
Worthy thread to ask: is there such a thing as a white label IP camera (or similar) with a supported open firmware? Not asking for open source, but something close to plug and play that nonetheless has a way of stripping the rootfs as desired for bespoke use in a manufacturer-supported way. I have looked around before but I only found genuinely dev-oriented kits that weren't even in a shell, and crazy priced. edit: seems there are some options now (or I missed them before), e.g. https://www.goodcam.io/#for-independent-developers
kiddico
I have yet to find a pattern for when the author chooses to capitalize things.
asveikau
My cameras are analog rather than PoE or IP based, but that's just because I set up the initial iteration of the system a long time ago. The standard now is to give your camera an IP address. With many IoT type things I block access to the public internet. I think with cameras specifically a lot of people even set it up physically on a different network that can only talk to the NVR. But tldr, basing the cameras on IP invites some of the things in this article. Anyone deploying these devices needs to think about securing them.
limsungkee
This kind of open source expands the world.
qweqwe14
Why would you write like that? Not capitalizing the first word of a sentence makes the whole thing less readable. So that you can feel special? Really?
pak9rabid
Perhaps they should just drop the 'security' from the name and simply call it a camera.
dare944
> Why would Hanwha Vision need anything remotely related to the DoD? Is it possible that their CI is provided by some centralized team at their parent company Hanwha, where the needs of their sister company Hanwha Aerospace cause the shared platform to have these entries in the CI environment variables? Or maybe because of their other sister company, Hanwha Defense USA, where they make other large scary steel machines Or... the Department of Warmongers (nee DoD) addresses on the device are evidence of a supply-side attack targeting the DoW and carried out using the aforementioned github admin token. ... I mean, while we're in here speculating about truffles and all.
bryanrasmussen
it's not a bug, it's a freebie!