My security camera shipped a GitHub admin token in its login page

616 points · 205 comments on HN · read original →

Points and comments are a snapshot, not live.

A researcher found an admin GitHub token in Hanwha security camera firmware.

The author downloaded Hanwha camera firmware, decrypted it, and discovered a GitHub token with admin privileges to hundreds of repos. The token was in ~30 files, injected from CI environment variables during a Vite build. Also found were DoD IP addresses: SWARM_MASTER_NFS_ADDRESS 55.101.212.23, OTEL_ELASTIC_URL at 55.101.212.21, CIMIP 55.101.211.213. Hanwha revoked the token within 12 hours of disclosure. The author speculates Hanwha's shared CI may include variables from sister companies like Hanwha Aerospace or Hanwha Defense USA.

What commenters are saying

Commenters focused on the DoD IP addresses in the firmware. Some noted companies misuse public IP space for internal networks, one citing a bank using 5.0.0.0/8. Others advised against buying Korean security cameras, referencing recent Canadian Navy decisions. The OBD-II dongle thread revealed cheap dongles share a hardcoded MAC used as auth, granting access to companion apps. A user found API keys in an ambient lighting app's APK, calling out typical IoT security failings.