Need help?
<- Back

Comments (80)

  • grommz
    The US Department of War IP adresses baked into the firmware is the bigger story here. Note to self: never buy a Korean security product.
  • dev_l1x_be
    Not surprised, many of these vendors are doing crazy things, insane defaults, broken security, hardcoded values. Security is not a priority, I get that, but at the very least some baseline check would be nice (no hardcoded credentials for starting)
  • tehlike
    A rule of thumb, put your cameras on a separate VLAN and never give that vlan internet access.Least you can do.
  • caruasdo
    I know you're a mastermind when it comes to security, but you should provide more context about the tools and methods you're using in your article so we can better understand what it's all about and not have to Google every single step you're taking.
  • RyJones
    When I cared, I found out that a lot of OBD-II dongles shipped with the same MAC, which gave you access to everything on a bunch of websites.You can curse the storm, but the wind will come.
  • sodapopcan
    This blog's misuse of the external link icon irks me.
  • IshKebab
    LLMs have truly killed obfuscation. It only worked previously by making things extremely tedious but AI doesn't care about that.
  • whalesalad
    I bought some ambient room lighting recently. You cannot control them without a proprietary app. This bugged me ... so I grabbed an APK from the Google store, unpacked it, and found essentially keys to the kingdom: api keys for the backend, api keys for shopify, etc. Haven't done anything with this knowledge yet.
  • anon
    undefined
  • joka88xj
    [flagged]
  • that_guy_iain
    I bet someone returned that security camera.
  • aizk
    Department of War IP address? I feel this should be making headlines!