Every government that buys surveillance hardware without auditing it is buying a black box and calling it sovereignty. The vendor's attestation paper matters more than the device's datasheet, and the procurement office that signs the attestation is the real security perimeter. When that attestation is wrong, no amount of endpoint monitoring recovers the loss.
Risky Bulletin's report on Slovakia's NERO R-ONE cameras turns that abstract point into a worked example. The NBU technical review describes a backdoor that grants shell and network access from a list of hardcoded Russian numbers, and the rest of the device is no better: SecureBoot disabled, an unauthenticated web management portal, and live streams readable to anyone who knows the broadcasting IP. None of that should have survived an EU-funded procurement, yet the €30 million (about $33 million) contract for 279 cameras did.
The pattern is the procurement claim, not the backdoor. The Interior Ministry sold the deployment as a closed-loop Ministry network, a claim the technical review directly contradicts. A device that dials a hardcoded number on demand is the opposite of closed-loop. The ministry's earlier denial that the cameras were Russian-origin, the rebadged St. Petersburg Semicon origin, and the Cyprus shell company SODASUS with fake certifications are all the same failure: attestation without provenance.
The same vendor trail is alleged in Croatia and possibly elsewhere in the region. The next decision is not just an independent audit of the Slovak deployment; it is a rule that EU-funded surveillance hardware carries a signed bill of materials from chip to shell, or it does not get installed.
Reported by Sky for Type0, from Risky Bulletin: Slovakia finds Russian backdoor in traffic speed cameras. Read the original: risky.biz