Security1 distinct publisher3 min readUpdated
A 40-character SHA-1 string printed in Slovak certification paperwork matches an entry in Russia's state register of measuring instruments. The comparison cost nothing to run.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
A 40-character checksum printed on the type certificate for Slovakia's new stationary speed radar is character-for-character identical to one filed in Russia's state register of measuring instruments for the KORDON-V enforcement system [5][7]. According to Zive.sk, which verified the finding, that makes it near-certain the device now being tested on Slovak roads runs the same measuring software as the Russian system [13].
The paperwork trail is short. The Slovak Metrological Institute issued a certificate dated 30 June 2026 for a road speed meter called NERO R-ONE [4]. On the second page, point 13 gives the measuring software version as simply "5", and point 14 records its SHA-1 checksum: eda7d49e2749f84194cf8448081e870277f02033 [5]. In the Russian register, a document dated 31 December 2020 covers KORDON-V, used in Russia for the same job of recording speed and traffic offences [6]. On its third page, the software identification table lists the measuring program SimFWCordon_V version 5.0 alongside the identical SHA1 string [7]. Two approvals, two national authorities, six years apart, one checksum [15].
Why that is hard to argue with: a SHA-1 hash is always exactly 40 characters, and altering a single character in the input file changes the output completely [8][9]. Zive.sk puts the odds of two independently written programs producing the same SHA-1 value at practically nil, and treats a full match as a technical fact that the code is identical [10][11]. The string in the Slovak certificate is 40 hexadecimal characters, consistent with SHA-1 output [18].
The finding has clear edges, and the publication draws them itself. It does not establish that NERO R-ONE was built by Simicon in St Petersburg [12]. It does establish shared software, and Simicon is named as the maker of KORDON-V and the author of that software [14]. Zive.sk's point is that even if the hardware came from entirely different manufacturers, the software interior is common [17] - and that software is what reads the radar returns, processes speed data and assembles the evidence for fines [16].
This is the part worth copying. Until now the Russian-origin argument around these devices rested on visual similarity: the shape of the plastic housings, where the cameras sit [2]. That is the kind of evidence a supplier can wave away. Legal metrology, by contrast, forces regulators to pin down software identity in the approval file, because a speed meter's measurement chain has to be tamper-evident - which is precisely why both the Slovak and the Russian dossiers print a version number and a checksum in the first place [5][7]. Anyone doing supply-chain review on certified instruments can therefore compare hashes across jurisdictions without a teardown, a subpoena or a lab. In this case the tip came anonymously to several Slovak newsrooms and was verified from public documents [3].
Two things to watch. First, whether the interior ministry, which began the road tests under Matus Sutaj Estok, responds to the software question or only to the hardware question [1] - a denial about where the boxes were assembled does not touch the checksum [12][17]. Second, whether reviewers elsewhere start pulling the software identification tables out of their own instrument approvals. The technique generalises to any certified device whose approval file publishes a hash.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
With practically one hundred percent certainty the match shows that the delivered NERO R-ONE radar runs exactly the same measuring software as the Russian KORDON-V system.
The shared software analyses the radar waves, processes speed data and prepares the supporting material for fines.
Even accepting that the hardware was made by entirely different manufacturers, their software interior is shared, programmed by the same hand.
Slovakia's interior ministry, led by Matus Sutaj Estok, began testing new stationary speed radars on Slovak roads.
From the start the suspicion was that the devices are Russian; the opposition and the public relied mainly on visual similarity to Russian measuring systems, discussing the shape of the plastic covers and the placement of the cameras.
An anonymous source alerted several Slovak newsrooms to the finding, and Zive.sk then verified his claims.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Documentary and reproducible, but single-newsroom and unanswered
The core finding rests on two named official documents — a Slovak type certificate dated 30 June 2026 and a Russian register entry dated 31 December 2020 — each quoted with page, field and the full 40-character checksum, so a third party can re-run the comparison at no cost, and the reproduced string is internally consistent with SHA-1's stated output format. Strength is capped because only one publisher is in the cluster, the documents themselves are not attached, no hash was recomputed from a real device binary, the '5' versus '5.0' version labelling is unexplained, and no ministry, metrology-institute or vendor response is present.
Certified and in road testing; scale undisclosed
Adoption is real but unquantified: the device holds a Slovak state type certificate and the interior ministry has begun testing the radars on public roads, with a Slovak integrator delivering them. The cluster provides no number of units, sites, contract volume, timeline for full rollout, or how many fines have been issued, so deployment breadth cannot be scored higher.
Slightly overstated certainty around a narrow verified fact
The verified fact is narrow and solid: two official registry documents record the same measuring-software digest. The framing runs somewhat ahead of it — 'practically one hundred percent certainty', a fingerprint-uniqueness analogy, and an inference of shared authorship 'by the same hand' — while the cluster contains no recomputation from a shipped binary and no acknowledgement that SHA-1 comparison of two paperwork entries is weaker than comparing verified artefacts. The gap stays small because the publisher explicitly refuses the bigger claim that the device itself was Russian-made and flags the open question about the Cypriot vendor rather than asserting an answer.
Politically charged tip, contested procurement, absent counterparties
The finding originated with an anonymous source who seeded several Slovak newsrooms simultaneously, and it lands inside an existing political fight in which opposition figures and the public had already alleged the radars were Russian — motives for the leak are unknown and unexamined. The publisher, part of the Aktuality group, has a competitive scoop incentive and leans on rival reporting from Denník N and Aktuality.sk for the shell-company and procurement strands. Parties with the strongest counter-incentive — the ministry, the metrology institute, the declared Cypriot manufacturer and the Slovak delivery chain — are not heard from at all in the supplied material.
Moderate: checkable core, thin corroboration
Confidence is anchored by the fact that the central assertion is a public-document comparison anyone can repeat, and by the publisher's own boundary-setting on what the match does not prove. It is held down by the cluster's single-source structure, the absence of any response from the ministry, the Slovak Metrological Institute, Sodasus, Simicon or the Slovak delivery firms, and the fact that surrounding procurement and shell-company details are relayed from other newsrooms rather than independently verified here.
build
Slovakia's EUR 30M camera rollout shipped with an SMS backdoor and a clean paper trail1 distinct publisher
security
Slovakia's speed cameras take orders by SMS: 279 devices, one procurement failure1 distinct publisher
build
Goish ports Go 1.25's runtime into no_std Rust to test what the concurrency model is worth alone1 distinct publisher
build
contenox stopped publishing commits and started publishing a signed tree1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 18, 2026