Security Camera Shipped with GitHub Admin Token
Executive TL;DR:
- Security camera shipped with GitHub admin token in its login page
- US Department of War IP addresses found baked into the firmware
- Experts warn of similar security risks in other IoT devices
The Internet’s Verdict: 70% Hyped, 30% Skeptical
Forum Reactions
Some users are outraged by the discovery.
The US Department of War IP adresses baked into the firmware is the bigger story here. Note to self: never buy a Korean security product.
Others are not surprised, citing similar experiences with other devices.
When I cared, I found out that a lot of OBD-II dongles shipped with the same MAC, which gave you access to everything on a bunch of websites. You can curse the storm, but the wind will come.
API Keys and Backend Access
One user discovered API keys and backend access credentials in a proprietary app for ambient room lighting.
I bought some ambient room lighting recently. You cannot control them without a proprietary app. This bugged me … so I grabbed an APK from the Google store, unpacked it, and found essentially keys to the kingdom: api keys for the backend, api keys for shopify, etc. Haven’t done anything with this knowledge yet.
Focus Keyword: Security Leak