Infrastructure July 25, 2026 bearish ⇧ 607 pts across 1 thread

Hardware still ships with catastrophic credential leaks

A security researcher found a GitHub admin token embedded in the login page of a consumer security camera, published to a public repository. The thread exploded with similar stories: OBD-II dongles sharing MAC addresses across thousands of devices, smart lighting apps bundling API keys in their APKs, and a broader pattern of IoT manufacturers treating credentials as an afterthought. One commenter flagged that US Department of War IP addresses were baked into the firmware, which they called the bigger story.

This isn't new, but the density of examples in a single thread signals that the problem is getting worse as more manufacturers rush connected devices to market. The supply chain for cheap consumer hardware runs through manufacturers with no security culture, and the people buying these devices have no way to audit them.

The commenter who said 'you can curse the storm, but the wind will come' was being fatalistic, but the fatalism is earned. These vulnerabilities are structural, not accidental, and no individual researcher finding them is going to fix the incentive problem.


So what?

If your product integrates with any third-party hardware, you should assume the firmware contains credentials you didn't know about. For founders building in IoT or home automation, the reputational and legal exposure from a downstream hardware partner's credential leak is real. Auditing your hardware supply chain is now a product risk question, not just a security one.

Read these