Live data from Hacker News

Please log in with router's password

google.com

11–20 of 265 posts

Re: Please log in with router's password

#11

I think this is more the fault of manufacturers than end users. Routers should be secure by default, and it should be hard to do something that will make it insecure. The router manufacturers are the supposed experts when it comes to networking, expecting every consumer to even know the risks of exposing their router admin interface to the world is not a reasonable assumption.

So it's the car companies fault if I crash my car?

They should limit vehicle speed to 5mph so I don't hurt myself or others.

I have used many of these routers. Admin access on the wan port is blocked by default and must be enabled by the user.

Re: Please log in with router's password

#12

I think this is more the fault of manufacturers than end users. Routers should be secure by default, and it should be hard to do something that will make it insecure. The router manufacturers are the supposed experts when it comes to networking, expecting every consumer to even know the risks of exposing their router admin interface to the world is not a reasonable assumption.

I haven't bought a consumer router in well over a decade that isn't secure by default. Universally they all prohibit accessing the router via the WAN interface, and have reasonable firewall defaults. Many these days even include a randomized unique password for every router, stuck to the side of the device with a sticker.

These routers were put on the internet on purpose, by people that seem to know what they are doing (universities and businesses), and none seem to have default credentials. Seems reasonable to me.

Re: Please log in with router's password

#13
post #8

Earlier quoted context omitted.

People are exposing their routers to the internet. This is not a good idea.

There are legit reasons to have a router be publicly accessible. How else would one remotely manage a router (top results in Google are businesses and universities, for example). Since the default configuration of these routers is not to expose the router on the WAN interface, manually overriding this configuration usually demonstrates a sufficient enough understanding that the default credentials have likely also be…

manually overriding this configuration usually demonstrates a sufficient enough understanding that the default credentials have likely also been changed

I don't think that's a reasonable assumption at all -- the router should ensure that the admin cred has been set to a (reasonably secure) password. Just because someone read on a web page that they should enable remote admin doesn't mean that they understand the risk.

And it should warn that exposing the admin interface to the internet may make the router more vulnerable to remote exploits - basically the same type warning that browsers show for a bad SSL cert should be shown for insecure router configs - tell the user that it's insecure and is a really bad idea before they do it.

Re: Please log in with router's password

#14
post #8

Earlier quoted context omitted.

There are legit reasons to have a router be publicly accessible. How else would one remotely manage a router (top results in Google are businesses and universities, for example). Since the default configuration of these routers is not to expose the router on the WAN interface, manually overriding this configuration usually demonstrates a sufficient enough understanding that the default credentials have likely also be…

manually overriding this configuration usually demonstrates a sufficient enough understanding that the default credentials have likely also been changed I don't think that's a reasonable assumption at all -- the router should ensure that the admin cred has been set to a (reasonably secure) password. Just because someone read on a web page that they should enable remote admin doesn't mean that they understand the risk…

How do you know this router doesn't already do that?

You're making some wild assumptions here.

Even your basic free Comcast router comes with sane defaults, and tons of warnings for every configuration change.

Here's the user manual for the TP-Link AC2300 - The Archer C7 found in the google results this post links to:

https://static.tp-link.com/2019/201912/20191231/7106508598_A...

Step 2 forces the default password to be changed. There is no way around that step.

None of your assumptions are true here.

Re: Please log in with router's password

#15

I think this is more the fault of manufacturers than end users. Routers should be secure by default, and it should be hard to do something that will make it insecure. The router manufacturers are the supposed experts when it comes to networking, expecting every consumer to even know the risks of exposing their router admin interface to the world is not a reasonable assumption.

So it's the car companies fault if I crash my car? They should limit vehicle speed to 5mph so I don't hurt myself or others. I have used many of these routers. Admin access on the wan port is blocked by default and must be enabled by the user.

Lackluster comparison (a modern consumer router should be more like a self steering car), but modern cars indeed have safety features to prevent you from crashing.

Of course, both with the car and the router there are good arguments that you should be able to do the dumb thing if you know you need it. If it has to be explicitly enabled after intense warnings, the protective duty (as someone knowing better) can possibly be considered fulfilled - or you can still argue that it should be especially hard to do to block out people who don’t listen to warnings.

Re: Please log in with router's password

#16

I think this is more the fault of manufacturers than end users. Routers should be secure by default, and it should be hard to do something that will make it insecure. The router manufacturers are the supposed experts when it comes to networking, expecting every consumer to even know the risks of exposing their router admin interface to the world is not a reasonable assumption.

So it's the car companies fault if I crash my car? They should limit vehicle speed to 5mph so I don't hurt myself or others. I have used many of these routers. Admin access on the wan port is blocked by default and must be enabled by the user.

Do you want to require that router users pass a government proficiency test and carry insurance to cover their liability for unsafe network use? Otherwise the analogy with driving a car is not quite complete.

Re: Please log in with router's password

#17
post #5
post #3

I don't understand. What point is being made here?

There are thousands of TP-LINK routers whose WAN port 80/443 is exposed to the Internet, allowing access to their administration interface if you know the password (or a vulnerability is present).

And I'd bet a nice amount that most of them have the default passwords.

Some years ago I wrote a little tool to iterate all of an ISP's ip addresses and around 90% were using default passwords. Mostly homes, but some businesses.

Re: Please log in with router's password

#18
post #8

Earlier quoted context omitted.

People are exposing their routers to the internet. This is not a good idea.

There are legit reasons to have a router be publicly accessible. How else would one remotely manage a router (top results in Google are businesses and universities, for example). Since the default configuration of these routers is not to expose the router on the WAN interface, manually overriding this configuration usually demonstrates a sufficient enough understanding that the default credentials have likely also be…

> There are legit reasons to have a router be publicly accessible.

No, there are not.

> How else would one remotely manage a router

Over a WireGuard connection to a secure management network.

> The only real issue would be using a default password

Uh, no. Try any number of CVEs or 0-days or unknown-until-it's too-late vulnerabilities, depending on what web daemon/frameworks are used by the router's management software.

Re: Please log in with router's password

#19

I think this is more the fault of manufacturers than end users. Routers should be secure by default, and it should be hard to do something that will make it insecure. The router manufacturers are the supposed experts when it comes to networking, expecting every consumer to even know the risks of exposing their router admin interface to the world is not a reasonable assumption.

Is there any mainstream router brand that exposes admin pages to the internet by default?

Re: Please log in with router's password

#20
post #5
post #3

I don't understand. What point is being made here?

There are thousands of TP-LINK routers whose WAN port 80/443 is exposed to the Internet, allowing access to their administration interface if you know the password (or a vulnerability is present).

I was planning to host a simple website on my RasberryPi using Dynamic DNS - which I think requires me to expose port 80 to the internet. Is that safe?
Post reply on HN