Live data from Hacker News

Shodan: The scariest search engine on the Internet

money.cnn.com

51–60 of 152 posts

Re: Shodan: The scariest search engine on the Internet

#51
post #43
post #34

Earlier quoted context omitted.

I'm a relatively new HN reader (~1 year) and have taken much away from my time here (much reading, few comments). I understand where you're coming from with concerns about quality; however, I resent the fact that I may be considered part of the increased readership responsible for "HN's decline"

I've been lurking HN for awhile now, and complaints about HN's decline were going on even years back when I was first introduced to the site...

Complaints about HN decline have been going on since I first started visiting this site in 2007.

Re: Shodan: The scariest search engine on the Internet

#52
post #15

Hardware manufacturers should ship their devices with a piece of paper printed with a unique UID and password. Not "admin/1234". The owner would have the ability to change these at will, and resets would revert to the original UID/pw combination. Lost your piece of paper? Send the device back. No more trivial hacks.

Good luck with that model. There are many better ways to approach this via things like captive portal that does good enforcement of the user setting good parameters up front before just plugging and playing. The vendors should not allow any Internet access until the device is secured appropriately or the user acknowledges insecure defaults.

Re: Shodan: The scariest search engine on the Internet

#53
post #46
post #25

Earlier quoted context omitted.

That would make the devices more costly to produce and would raise prices. I know that ISPs do this with their devices sometimes, but some companies will cheap out and will just ship with a generic username and password since they only have to flash one single ROM image.

It shouldn't really. I mean, it's not like devices don't come with at least 3 or 4 unique IDs for different purposes. Just using one of those for the default password or adding a new ID shouldn't be that big of a task. I know that this is how some of the router/modem combos from french DSL providers worked - the admin and WPA passwords are two seperate UUIDs printed on the device.

The gateways provided by the cable ISPs here in Western Canada tend to have unique passwords. It would be prudent on the part of the device manufacturer to just create a scheme for creating default passwords based on the unique serial that the device has and then just print labels for each and have the default ROM just sort it out upon it being powered up for the first time.

Re: Shodan: The scariest search engine on the Internet

#54
post #42
post #32

Earlier quoted context omitted.

That's funny. I thought cobrausn was a "purpose built troll account."

On the contrary, I think it's simply a snake enthusiant with a maritime affiliation.

Hah, half right and a good guess. Since we're on the topic, I always read your name as 'Max Payne'.

Re: Shodan: The scariest search engine on the Internet

#55
post #8

Eagerly awaiting the moment someone at CNN finds out about Metasploit. I'd like to think of it as a kind of "Dark Firefox".

Love this:

http://www.metasploit.com/about/penetration-testing-basics/

"You can become a penetration tester at home by testing your own server and later make a career out of it."

Sounds like the old style correspondence school ads - a bit hokey.

http://www.thefreedictionary.com/correspondence+school

I would have rewritten that as:

"Many people have actually made a career out of being a penetration tester by first testing their own home server"

Re: Shodan: The scariest search engine on the Internet

#56
post #43
post #34

Earlier quoted context omitted.

I'm a relatively new HN reader (~1 year) and have taken much away from my time here (much reading, few comments). I understand where you're coming from with concerns about quality; however, I resent the fact that I may be considered part of the increased readership responsible for "HN's decline"

I've been lurking HN for awhile now, and complaints about HN's decline were going on even years back when I was first introduced to the site...

That's how all communities work though. As a community grows and attracts new members, the old guard moan about how it was better when they were noobs.

In fact this is true for real -"offline"- life as well.

Re: Shodan: The scariest search engine on the Internet

#57

Earlier quoted context omitted.

Crazy idea, if you don't know what you're talking about, shut the hell up.

actually people have been posting google searches to find exposed home ip camera systems and the like for years.

Affirmative. I've been using Google "Dorks" for years.

Re: Shodan: The scariest search engine on the Internet

#58
post #55
post #8

Eagerly awaiting the moment someone at CNN finds out about Metasploit. I'd like to think of it as a kind of "Dark Firefox".

Love this: http://www.metasploit.com/about/penetration-testing-basics/ "You can become a penetration tester at home by testing your own server and later make a career out of it." Sounds like the old style correspondence school ads - a bit hokey. http://www.thefreedictionary.com/correspondence+school I would have rewritten that as: "Many people have actually made a career out of being a penetration tester by first tes…

You can absolutely learn to do penetration testing on your own time with your own servers. We have a script we give people to do the same thing. If you feel like you have a knack for systems programming, being a good systems programmer is 1/2 the hard part of appsec; the other 1/2 is literally "taking pleasure in finding creative ways to break things", and you can find out if you have that personality streak in just a couple hours of trying attacks.

Re: Shodan: The scariest search engine on the Internet

#59
post #42

Earlier quoted context omitted.

On the contrary, I think it's simply a snake enthusiant with a maritime affiliation.

Hah, half right and a good guess. Since we're on the topic, I always read your name as 'Max Payne'.

Well, that's far better-sounding than the reality, so please continue to do so!

Re: Shodan: The scariest search engine on the Internet

#60

This is awesome, I never knew such a thing existed! But it's also quite alarming that so many devices are connected to the internet/computers that probably shouldn't be. So my big question is: Is there a way to solve this 'security failure'? And if so, what is it/is it feasible? For someone with malintentions, Shodan seems to be golden.

It used to be fairly costless to ship products without security. It still is but the more attacks there are the more incentive there is to fix stuff. But there are so many more online devices shipping...
Post reply on HN