Worthy thread to ask: is there such a thing as a white label IP camera (or similar) with a supported open firmware? Not asking for open source, but something close to plug and play that nonetheless has a way of stripping the rootfs as desired for bespoke use in a manufacturer-supported way. I have looked around before but I only found genuinely dev-oriented kits that weren't even in a shell, and crazy priced. edit: s…
Not exactly open firmware, but something like ONVIF on an isolated network is pretty close. An ONVIF camera should talk to basically any NVR (network video recorder), there are several open-source ones available. There are tons of ONVIF-compliant and cheap PoE cameras, and with this setup you really don't care about the security of the manufacturer firmware since you aren't exposing them to the network publicly. Howe…
My security camera shipped a GitHub admin token in its login page
251–260 of 265 posts
Re: My security camera shipped a GitHub admin token in its login page
#252Re: My security camera shipped a GitHub admin token in its login page
#253Earlier quoted context omitted.
how is it a different mental model? instead of opening the port in NAT via forward feature, you open the port in the firewall. it is in fact significantly simpler while overall being the same actions you take when you want to "forward"
You’re right. That’s why everybody uses it and nobody is confused by it.
perhaps you could explain how its such a new paradigm and mental model that it simply confuses people? because I dont buy it, its without exaggerating a smaller difference in so far as this goes, than when people get a new microwave oven, and substantially less difference than when people switch phone brands.
Re: My security camera shipped a GitHub admin token in its login page
#254Re: My security camera shipped a GitHub admin token in its login page
#255Earlier quoted context omitted.
LOL, they should have just used a 10.x space instead if they wanted slightly simpler numbers. On the shotgun, or adjacent, I do tend to prefer ammo classes for my nets... 10.22.x.y, where x may be 1, 38, 45, etc. Allows for site to site vpn with friends/family a bit easier to remember.
I dunno, seems like it could be a bit vague. Does 45 refer to 45 Webley or 45 GAP? Could possibly also refer to 45 Colt I guess, if you're boring. But 45 Colt, 45 ACP, 45 Colt Government? Also, just in case this comment isn't pedantic enough, 10.22 would be a firearm range, not an ammo range. And AFAIK they only ever chambered that for .22 rimfire cartridges. ;)
I made me smile.
Re: My security camera shipped a GitHub admin token in its login page
#256Earlier quoted context omitted.
I doubt any endpoints are entirely ipv6. So it seems like it helps ISPs and large networks router… but they never had problems with address space running out at the high levels and almost all likely need to support v4 anyhow. I think it’s been long enough to be honest that ipv6 was a spectacular failure by complicating an already complicated system into something no one actually asked for. No human said “hey, network…
I'm largely with you... I would think they'd take the IPv4 block and have a direct/virtual block that just extends it to more addresses... so it could be an IPv4 NAT or IPv6 direct. like 1.1.1.1/192.168.45.4 ... for a router that understands IPv6, that's the direct route to the sub-network, otherwise it will have to use IPv4, and the subnet route is treated as NAT and otherwise isolated. To me, that would make more s…
That's a perfectly valid IPv6 address and can be set up, if you own 1:1:1:1/32
Re: My security camera shipped a GitHub admin token in its login page
#257Earlier quoted context omitted.
I'm largely with you... I would think they'd take the IPv4 block and have a direct/virtual block that just extends it to more addresses... so it could be an IPv4 NAT or IPv6 direct. like 1.1.1.1/192.168.45.4 ... for a router that understands IPv6, that's the direct route to the sub-network, otherwise it will have to use IPv4, and the subnet route is treated as NAT and otherwise isolated. To me, that would make more s…
1:1:1:1::192.168.45.4 That's a perfectly valid IPv6 address and can be set up, if you own 1:1:1:1/32
The former is somewhat serious a question... I want some devices statically assigned and others dynamically, and I'd love to have them match, so where desired I can directly route to/from external over IPv6.
Re: My security camera shipped a GitHub admin token in its login page
#258Earlier quoted context omitted.
I'm largely with you... I would think they'd take the IPv4 block and have a direct/virtual block that just extends it to more addresses... so it could be an IPv4 NAT or IPv6 direct. like 1.1.1.1/192.168.45.4 ... for a router that understands IPv6, that's the direct route to the sub-network, otherwise it will have to use IPv4, and the subnet route is treated as NAT and otherwise isolated. To me, that would make more s…
An alternate to IPv6 would have been to store the NAT addresses in IPv4 somehwere. But the IPv4 options are fragile and normal NAT would likely destroy them. It would still require rewriting all of the networking and software. It would have engrained NAT everywhere and made lots of routing problems, like is that your or mine 10. network.
Difference is it's all public after, it would ease the transition dramatically, and then you can just use whatever you want internally making /32 the minimal assigned block or whatever the prefix size is.
Re: My security camera shipped a GitHub admin token in its login page
#259Earlier quoted context omitted.
I'm largely with you... I would think they'd take the IPv4 block and have a direct/virtual block that just extends it to more addresses... so it could be an IPv4 NAT or IPv6 direct. like 1.1.1.1/192.168.45.4 ... for a router that understands IPv6, that's the direct route to the sub-network, otherwise it will have to use IPv4, and the subnet route is treated as NAT and otherwise isolated. To me, that would make more s…
>limited to 10. and 102.168 I assume you meant 10.x.x.x and 192.168.x.x -- (and 172.16.x.x?), ie the standard subnets for home router-modems (which are non-routing and so can't be used on the internet).
Re: My security camera shipped a GitHub admin token in its login page
#260Earlier quoted context omitted.
1:1:1:1::192.168.45.4 That's a perfectly valid IPv6 address and can be set up, if you own 1:1:1:1/32
Cool... now, what do I need to do to configure say OpnSense to give out my internal IPv4/6 addresses that way... and then what pain do I need to go through to secure my internal devices from externally oriented connection attempts? The former is somewhat serious a question... I want some devices statically assigned and others dynamically, and I'd love to have them match, so where desired I can directly route to/from…
My ISP gives me an ipv6 range of 2001:abc:ab23:: (well something very similar) routed down the pppoe tunnel (which autoestablishes ipv6 with a /128 IP, just like my ipv4 establishes with a /32)
I thus have my ipv6 vlan 2301 as 2001:abc:ab23:2301::/64
The router is at 2001:abc:ab23:2301:: (which is 2001:abc:ab23:2301:0:0:0:0)
My DNS server on that vlan is statically configured as 2001:abc:ab23:2301::53
My phone when I connect gets a slacc address 2001:abc:ab23:2301:so.me:thi.ng
I can't reach my DNS server from the outside world on 2001:abc:ab23:2301::53 because my firewall blocks it, but if I did allow it t would route through just fine
Remember none of this works with v4 though, you'd have to configure your router to do nat46 and nat64. I've never used such a router, but looks like its supported
https://docs.opnsense.org/manual/how-tos/tayga.html
As such if your public IPv4 was 23.45.67.89 address
You'd forward 23.45:67.89 -> 2001:abc:ab23:2301::53
And vice versa.
Now the next issue is multi-homing.
My backup router is ipv4 only, so when 192.168.231.0/24 gets routed out my main ISP as normal, it's hidden behind an IP like 81.187.123.45. If I route traffic out of my backup 5g ISP it gets hidden behind that (it actually gets src-natted to a 10.x range, as it's a 4g ISP, it gets converted to a real public IP later)
My 4g doesn't support ipv6, and ipv6 is just a toy, but I expect I would use nat66 to map
2001:abc:ab23:2301::53
behind whatever IP range I was given for the backup route. I've not looked into nat66.
The other aspect is changing ISP. I don't plan on doing that, and ipv6 is only a toy protocol, hence I can just use my global address range. I could however use fd00:2301::53 for my internal DNS server (equivalent of 192.168.231.53) and nat66 it at the boundary, hiding fd00:2301:: behind 2001:abc:ab23:2301::
As the hide address is a /64 there's no need for port mapping, my traffic would emerge from 2001:abc:ab23:2301::53
ipv6 proponents talk about advertising half a dozen IPs to your end devices and renumbering them all dynamically and using mdns instead of static IPs. And they wonder why people thing ipv6 is crap.