My security camera shipped a GitHub admin token in its login page
Summary
A security researcher reveals that HanwhaVision security cameras shipped a GitHub admin token inside firmware. The analysis includes reverse-engineering the updater, uncovering hardcoded AES keys/IVs, and discovering a GitHub token with admin access scattered across many files, likely exposed via build-time environment data. The researcher disclosed the issue to Hanwha, who revoked the token, highlighting credential management and supply-chain risks in IoT devices.