Top
Best
New

Posted by hhh 10 hours ago

My security camera shipped a GitHub admin token in its login page(hhh.hn)
443 points | 156 commentspage 3
joka88xj 7 hours ago|
[flagged]
hnscum 4 hours ago||
[dead]
that_guy_iain 8 hours ago||
I bet someone returned that security camera.
mikey_p 7 hours ago|
No, if you read the article the author was downloading firmware from their website and still found the token.
aizk 7 hours ago||
Department of War IP address? I feel this should be making headlines!
CodesInChaos 6 hours ago|
Abusing IP ranges which were assigned to an organization but aren't actually used on the public Internet as private addresses is pretty common. Sure, it's bad practice, but not a big deal.
TeMPOraL 4 hours ago||
Of course this looks entirely different when your corporate superstructure has a long and active history of developing military equipment.
caruasdo 6 hours ago|
I know you're a mastermind when it comes to security, but you should provide more context about the tools and methods you're using in your article so we can better understand what it's all about and not have to Google every single step you're taking.
dust-jacket 6 hours ago||
Oh I thought exactly the opposite!

I feel like every security blog (or even just tech blog) I've read recently has had paragraphs and paragraphs of largely LLM generated explainer waffle. This felt refreshingly focused and to the point.

hhh 6 hours ago|||
i’m not a mastermind, and I agree it could be more accessible. I treat this blog as somewhere to just dump my thoughts as unfiltered as I can while still being useful or entertaining, maybe for some other posts I will go more into depth
sophacles 6 hours ago||
Seemed perfectly reasonable to me. Not everything has to be written for a target audience that includes you, besides you were able to look up what you needed it seems. Another tactic is to feed the article to your favorite LLM and interrogate it about what you don't understand.