| My security camera shipped a GitHub admin token in its login page(hhh.hn) | |
| 603 points by hhh 1 day ago | 204 comments | |
tl;dr: A researcher extracted the encrypted firmware of Hanwha Vision security cameras by reverse-engineering their `fwupgrader` binary (with Claude Code's help), recovering hardcoded AES keys shared across the model line. Inside the rootfs, a Vite build had dumped the entire CI environment—including an admin-level GitHub token with access to hundreds of repos—into ~30 UI files, alongside internal IPs belonging to DoD address space. Hanwha revoked the token within 12 hours of disclosure. | |
HN Discussion:
| |