Live data from Hacker News

My security camera shipped a GitHub admin token in its login page

hhh.hn

211–220 of 265 posts

Re: My security camera shipped a GitHub admin token in its login page

#211

Earlier quoted context omitted.

The point of IPv6 was to make the addresses so long that we don't run out of them in 20 years or so. There fixed that for you.

The problem is NAT solved the same problem more easily and cheaply. It was at the cost of making it difficult for every host to talk directly to every other host, but it turned out most of the people building networks didn't want that feature anyway.

It's been a strong centralisation pressure on the internet. Centralisation is bad.

Re: My security camera shipped a GitHub admin token in its login page

#212

Earlier quoted context omitted.

If you can't remember 192.168 you definitely can't remember a randomly picked ULA. So just use fd00. It's not any worse than 192.168.

True, I was thinking more about the allocation discussion than the "easy to remember". Anyone in IT who allocates 1.1.1.0/24 because 192.168.0.0/24 is hard, should be allocated to trash pickup.

also easy to remember is 10.anything.anything.anything

Re: My security camera shipped a GitHub admin token in its login page

#213
post #35

Earlier quoted context omitted.

192.168.0.0/24 -> fd00:0::/64 192.168.1.0/24 -> fd00:1::/64 192.168.2.0/24 -> fd00:2::/64 192.168.240.0/24 -> fd00:240::/64 It's not a great idea, but its no harder. No need to mess around with setting up DHCP, remembering if your router is top or bottom of the subnet, and if you want 500 devices on a single subnet that's no problem. Now if you still need ipv4 then yes, ipv6 is stupid as you have double the pain for…

The proper way to do ULA is to generate random 40-bit ID. Then your ULA are likely unique. Which means that if you want to connect or merge with another company, the networks are distinct. IPv4 has a lot of trouble since everyone is using 10/8 space for corporate networks.

If someone can't remember 192.168 they definitely can't remember their own chosen random 40 bits.

Re: My security camera shipped a GitHub admin token in its login page

#214
post #35

Earlier quoted context omitted.

192.168.0.0/24 -> fd00:0::/64 192.168.1.0/24 -> fd00:1::/64 192.168.2.0/24 -> fd00:2::/64 192.168.240.0/24 -> fd00:240::/64 It's not a great idea, but its no harder. No need to mess around with setting up DHCP, remembering if your router is top or bottom of the subnet, and if you want 500 devices on a single subnet that's no problem. Now if you still need ipv4 then yes, ipv6 is stupid as you have double the pain for…

One thing I don't appreciate... Is the nature of NAT protected my internal/home network before... now, I have to actually configure firewall settings etc. to protect IPv6 issued addresses internally. I know you can just block inbound non-established connections, but it feels like an extra step and complexity. Not to mention, that I really don't understand how IPs are supposed to be provisioned to devices on IPv6. Is…

Home routers with IPv6 should have this enabled by default, at least by law in Europe, and you can turn it off or add exceptions.

Re: My security camera shipped a GitHub admin token in its login page

#215

Earlier quoted context omitted.

I doubt any endpoints are entirely ipv6. So it seems like it helps ISPs and large networks router… but they never had problems with address space running out at the high levels and almost all likely need to support v4 anyhow. I think it’s been long enough to be honest that ipv6 was a spectacular failure by complicating an already complicated system into something no one actually asked for. No human said “hey, network…

I'm largely with you... I would think they'd take the IPv4 block and have a direct/virtual block that just extends it to more addresses... so it could be an IPv4 NAT or IPv6 direct. like 1.1.1.1/192.168.45.4 ... for a router that understands IPv6, that's the direct route to the sub-network, otherwise it will have to use IPv4, and the subnet route is treated as NAT and otherwise isolated. To me, that would make more s…

AFAIK this was one of several things that was tried, but failed for various reasons. It's called "TUBA" - TCP/UDP with Bigger Addresses - adding extra address bits at a layer above IP so that IP remains compatible.

I think one of the main problems with it is that you have to update the whole internet anyway, just like you do with IPv6, so you make the protocol stack stupider for no real benefit.

Re: My security camera shipped a GitHub admin token in its login page

#216
post #30

Earlier quoted context omitted.

"all that 192 stuff was silly and too complicated... but this fd00: stuff is easy peasy!"

Agreed 100%! I know there's tough challenges to making this reality, but if https://serverspace.io/about/blog/ipv8-explained-what-we-kno... could be an IRL thing, I would buy company network equipment and use computer OSes that supported this draft standard. It's a much better compromise and ergonomics to migrate from IPv4 to an IPv4 respecting successor, where IPv6 is just the academic snobbery and utterly alien men…

ipv8 is a "vibe coded" specification from someone who doesn't understand the problem at all. Just like ipv6, you can't use ipv8 without upgrading the whole internet. The internet is mostly ipv6 capable and not at all ipv8 capable so why do you want to throw away that progress and reset the clock?

It's also just a worse design, centralising a bunch of things and trying to authoritatively define what counts as "a network" on both sides of the communication, unlike v4 and v6 where you just have raw bits and can interpret them how you want. I mean ipv8 defines the internet as a bunch of networks and a network as a bunch of computers. And a network is something that has an ASN. Your computers would be on your ISP's big network, not your small home network because you can't have a network inside a network. It also decreases the number of bits than we already have (in ipv6), limiting futureproofing. It also says every network device will log in with OAuth. Yes, really.

Re: My security camera shipped a GitHub admin token in its login page

#217

Earlier quoted context omitted.

I was working with Raspberry Pis, starting with a college honors project, around 2018. For a while, I thought about building a network of surveillance cameras around the interior of my home. The Raspberry Pi seemed like a tempting platform to hook up a bunch of cameras to it. Sadly, I could not find a backend surveillance app or system that was suitable for running such a network. The best one I found was some kind o…

As an — I am guessing — American, you should feel more comfortable with handing over your domestic surveillance to Russia or China than to a US-based company. They absolutely have no interest in your domestic matters, nor do they have a clear path to monetize your attention. There are non-IP cameras and coax interfaces, which would expose a USB video device on any Linux system, RPi included. Plenty of software to han…

Why should I want to hand mu domestic surveillance over to any company? Why wouldn’t I prefer a private solution that lets me host my own data?

Re: My security camera shipped a GitHub admin token in its login page

#218
post #153

Worthy thread to ask: is there such a thing as a white label IP camera (or similar) with a supported open firmware? Not asking for open source, but something close to plug and play that nonetheless has a way of stripping the rootfs as desired for bespoke use in a manufacturer-supported way. I have looked around before but I only found genuinely dev-oriented kits that weren't even in a shell, and crazy priced. edit: s…

There is also https://thingino.com/ which has a clear set of supported cameras. The installation is straight forward if you choose a cam with SD-Card flashing support. I upgraded two of the Sonoff Slim Gen2 without any issues.

I found Thingino to be very buggy and frustrating to use despite using 2 different supported cameras. The stream would constantly drop out, services would sometimes crash and wouldn't get automatically restarted. I tried tweaking all available parameters, resetting, updating but eventually I just gave up (a few months ago).

e.g. https://github.com/themactep/thingino-firmware/issues/640

Re: My security camera shipped a GitHub admin token in its login page

#220

Earlier quoted context omitted.

I was working with Raspberry Pis, starting with a college honors project, around 2018. For a while, I thought about building a network of surveillance cameras around the interior of my home. The Raspberry Pi seemed like a tempting platform to hook up a bunch of cameras to it. Sadly, I could not find a backend surveillance app or system that was suitable for running such a network. The best one I found was some kind o…

As an — I am guessing — American, you should feel more comfortable with handing over your domestic surveillance to Russia or China than to a US-based company. They absolutely have no interest in your domestic matters, nor do they have a clear path to monetize your attention. There are non-IP cameras and coax interfaces, which would expose a USB video device on any Linux system, RPi included. Plenty of software to han…

> They absolutely have no interest in your domestic matters

This is categorically, not true, I'm afraid. Reaching into domestic networks, where you can find influential people through mass harvesting, is an actively exploited technique by the spy agencies of our world.

How do you find the gardener of someone influential? You target all gardeners.

Post reply on HN