Live data from Hacker News

Please log in with router's password

google.com

41–50 of 265 posts

Re: Please log in with router's password

#41
post #31

Earlier quoted context omitted.

Here's another TP-link manual: https://www.tp-link.com/us/support/faq/66/ 1. Open the web browser and in the address bar type in: http://192.168.1.1 2. Type the username and password in the login page. They are both admin by default. 3. Click Security->Remote Management on the left side 4. To enable this function, please change the Remote Management IP address from 0.0.0.0 to a specific authorized remote IP address.…

That link isn't from the routers this post links to (specifically Archer C7 and C9 routers). And, your link is old, to say the least. That screenshot is from the Windows XP era. You're trying to lampoon TP-Link for things that simply are not true anymore, nor have been for a long while. I'll repeat again - the defaults on these routers is to prohibit WAN access and they force a password change at setup. What more are…

Also from the page I linked to:

Updated 04-18-2019 07:10:55 AM

This Article Applies to: TL-WR841N (and a couple dozen others).

You can buy a TL-WR841N today for $20. It was released in 2015, so it may be an "old" router, but old routers never die, they just get cheaper.

Re: Please log in with router's password

#42
post #8

Earlier quoted context omitted.

People are exposing their routers to the internet. This is not a good idea.

There are legit reasons to have a router be publicly accessible. How else would one remotely manage a router (top results in Google are businesses and universities, for example). Since the default configuration of these routers is not to expose the router on the WAN interface, manually overriding this configuration usually demonstrates a sufficient enough understanding that the default credentials have likely also be…

Best practice for remote management of network devices is over a VPN or a remote access application designed for remote management, and it has been that way for decades. Web UIs on routers are designed for use on trusted networks, are notoriously full of vulnerabilities, and aren't typically hardened for exposure to the open internet. They often do not support any security features beyond a password. No fail2ban, no 2FA, no SSO, etc. Most router manufacturers will warn you against doing this for these exact reasons, even if they don't elaborate on why, and let you do otherwise.

The businesses and universities you see in the list are likely:

* a result of people hooking up rouge devices

* organizations operating without competent IT management

* honeypots

Re: Please log in with router's password

#43
post #22

Folks - these routers are secure. There is nothing to see here, move along. Here's the user manual for the TP-Link AC2300 "Archer C7", as found in the google results: https://static.tp-link.com/2019/201912/20191231/7106508598_A... Step 2 of first time setup forces a default password change. There is no way around this step. The defaults for the router also do not allow router access from the WAN port. This means: 1)…

I would love to know how these are secured. I doubt there's MFA or even rate limiting. > 2) These routers were deliberately placed on the internet by people that knew enough about them to do so. That's making some very generous assumptions.

These are not high end enterprise grade kit, folks. Expecting things like MFA, secondary VPN endpoints, etc is just absurd for the target audience of this device.

Again, just because you wouldn't configure it this way doesn't make it wrong. It's as secure as it can be, short of throwing a bunch of other kit in front of it, and then why would you be using a $100 consumer router anyway?

The only vulnerability here is the possibility of a 0-Day. Everything else is either misguided or screaming for the sake of it.

Re: Please log in with router's password

#44
post #31

Earlier quoted context omitted.

That link isn't from the routers this post links to (specifically Archer C7 and C9 routers). And, your link is old, to say the least. That screenshot is from the Windows XP era. You're trying to lampoon TP-Link for things that simply are not true anymore, nor have been for a long while. I'll repeat again - the defaults on these routers is to prohibit WAN access and they force a password change at setup. What more are…

Also from the page I linked to: Updated 04-18-2019 07:10:55 AM This Article Applies to: TL-WR841N (and a couple dozen others). You can buy a TL-WR841N today for $20. It was released in 2015, so it may be an "old" router, but old routers never die, they just get cheaper.

OK so what? Nothing you've stated here applies to the original post. You're fabricating some outrage about nothing relevant. The original post shows Archer C7 and C9 routers...

Re: Please log in with router's password

#46
post #8

Earlier quoted context omitted.

There are legit reasons to have a router be publicly accessible. How else would one remotely manage a router (top results in Google are businesses and universities, for example). Since the default configuration of these routers is not to expose the router on the WAN interface, manually overriding this configuration usually demonstrates a sufficient enough understanding that the default credentials have likely also be…

Best practice for remote management of network devices is over a VPN or a remote access application designed for remote management, and it has been that way for decades. Web UIs on routers are designed for use on trusted networks, are notoriously full of vulnerabilities, and aren't typically hardened for exposure to the open internet. They often do not support any security features beyond a password. No fail2ban, no…

Are VPN's, secondary networks, etc reasonable to expect for a $100 MSRP device targeted at consumers? I think not...

Given what it is... it's as secure as it can be. Short of a 0-Day lurking somewhere, or an active CVE, the configuration is fine. Not to mention all the top results appear to be operated by organizations that certainly know what they are doing.

Re: Please log in with router's password

#47
post #43

Earlier quoted context omitted.

I would love to know how these are secured. I doubt there's MFA or even rate limiting. > 2) These routers were deliberately placed on the internet by people that knew enough about them to do so. That's making some very generous assumptions.

These are not high end enterprise grade kit, folks. Expecting things like MFA, secondary VPN endpoints, etc is just absurd for the target audience of this device. Again, just because you wouldn't configure it this way doesn't make it wrong. It's as secure as it can be, short of throwing a bunch of other kit in front of it, and then why would you be using a $100 consumer router anyway? The only vulnerability here is t…

> The only vulnerability here is the possibility of a 0-Day.

That's not exactly uncommon in cheap consumer routers.

No rate limiting is as good as no authentication.

Re: Please log in with router's password

#48
post #46

Earlier quoted context omitted.

Best practice for remote management of network devices is over a VPN or a remote access application designed for remote management, and it has been that way for decades. Web UIs on routers are designed for use on trusted networks, are notoriously full of vulnerabilities, and aren't typically hardened for exposure to the open internet. They often do not support any security features beyond a password. No fail2ban, no…

Are VPN's, secondary networks, etc reasonable to expect for a $100 MSRP device targeted at consumers? I think not... Given what it is... it's as secure as it can be. Short of a 0-Day lurking somewhere, or an active CVE, the configuration is fine. Not to mention all the top results appear to be operated by organizations that certainly know what they are doing.

Yes, there are many consumer routers that support VPNs, including the ones we're talking about here.

https://www.tp-link.com/us/user-guides/Archer-C7/chapter-12-...

Although, remote management isn't much of a consumer feature to begin with.

Re: Please log in with router's password

#49
post #44

Earlier quoted context omitted.

Also from the page I linked to: Updated 04-18-2019 07:10:55 AM This Article Applies to: TL-WR841N (and a couple dozen others). You can buy a TL-WR841N today for $20. It was released in 2015, so it may be an "old" router, but old routers never die, they just get cheaper.

OK so what? Nothing you've stated here applies to the original post. You're fabricating some outrage about nothing relevant. The original post shows Archer C7 and C9 routers...

What original post? It was a google search that reveals some router's remote admin page, that search doesn't mention any specific router brand or model.

But regardless, I was responding specifically to your comment:

manually overriding this configuration usually demonstrates a sufficient enough understanding that the default credentials have likely also been changed

(That's why I quoted it in my reply)

And the point I was trying to make is that merely being able to override the default remote admin setting does not ensure that the user has any idea what the ramifications are. I'm surprised you're even arguing against that.

Re: Please log in with router's password

#50
post #22

Folks - these routers are secure. There is nothing to see here, move along. Here's the user manual for the TP-Link AC2300 "Archer C7", as found in the google results: https://static.tp-link.com/2019/201912/20191231/7106508598_A... Step 2 of first time setup forces a default password change. There is no way around this step. The defaults for the router also do not allow router access from the WAN port. This means: 1)…

> Folks - these routers are secure. There is nothing to see here, move along.

If experience is any guide, they are not.

Consumer routers have horrible track of embarrassing, easily exploitable vulnerabilities. That are not patched for a long time or ever.

And exposing your router to public like that suggests the owner knows very little about security. This typically goes in hand with other neglect. Tell me, how many home users that are not security conscious keep their routers regularly patched and will replace the router when the manufacturer stops supporting them?

Post reply on HN