RC RANDOM CHAOS

IoT security

10 posts

LG TVs recorded audio and mapped your network
Article

LG TVs recorded audio and mapped your network

LG smart TVs captured audio with the screen off and scanned local devices. The control users operate governs the display, not the microphone.

A robot dog moves on command inside your network
Article

A robot dog moves on command inside your network

The Creepy Crawlies robot dog is a networked device that moves on command. Its control channel and actuator define the risk, not its label.

One grep, full repo access
Article

One grep, full repo access

A security camera shipped a full-scope GitHub PAT in its login page bundle. The credential exposure, supply-chain exploit path, GitHub audit-log telemetry, and why rotation - not removal - is the only fix.

The camera on your shelf handed out your GPS
Article

The camera on your shelf handed out your GPS

A TP-Link Kasa camera returned home GPS over unauthenticated UDP for six years. The mechanism, the pattern it exposes, and what must now be true.

Flock's real attack surface was never the camera
Article

Flock's real attack surface was never the camera

Flock ALPR cameras are a national sensor grid - the security risk isn't recording, it's a queryable movement database reachable by thousands of weak accounts.

Mirai's hardcoded logins still answer on 554
Article

Mirai's hardcoded logins still answer on 554

Open webcams indexed by Shodan and Censys are not a privacy footnote - they map insecure OEM firmware, exposed services, and supply chain risk.

The device is the inventory
Article

The device is the inventory

Smart TV apps embed residential proxy SDKs that turn devices into exit nodes. The trust failure lives in the build pipeline, not the hardware.

Motorola signed its own kill switch
Article

Motorola signed its own kill switch

Motorola's silent firmware push bricked its WiFi router line. The mechanism is identical to AcidRain. Here is what failed and why it repeats.

Baby monitors exposed one million streams
Article

Baby monitors exposed one million streams

One million baby monitors and cameras were viewable by unauthorised parties. What it reveals about IoT enforcement and the owner-side blindness behind it.

?auth=YWRtaW46MTEK and a million open cameras
Article

?auth=YWRtaW46MTEK and a million open cameras

Technical breakdown of the auth bypass, P2P relay, and default-credential failures that exposed over a million IP cameras and baby monitors.