Live data from Hacker News

Please log in with router's password

google.com

121–130 of 265 posts

Re: Please log in with router's password

#122
post #22

Folks - these routers are secure. There is nothing to see here, move along. Here's the user manual for the TP-Link AC2300 "Archer C7", as found in the google results: https://static.tp-link.com/2019/201912/20191231/7106508598_A... Step 2 of first time setup forces a default password change. There is no way around this step. The defaults for the router also do not allow router access from the WAN port. This means: 1)…

There is a lot here. Some of these are university routers. Tells me that the sysadmin wanted to open up the router so s/he can manage from home. Nifty. But not secure. And they are no way taking the extra effort to make their system secure.

Re: Please log in with router's password

#123
post #109

Earlier quoted context omitted.

Some fun things here, as a google search: site:.gov "for official use only" filetype:pptx site:.gov "for official use only" filetype:pdf

fyi, "for official use only" or "fouo" is a slightly more than meaningless designation to shield stuff against FOIA inquiries. most of the stuff you'll find is pretty boring. a little more: https://en.wikipedia.org/wiki/For_Official_Use_Only#United_S...

I worked for a government lab some time ago, and FOUO wasn't used to shield against FOIA. Indeed, OUO documents can be released to a FOIA request. It was more or less just the default because no one wants to get in trouble for not making things that are supposed to be marked.

Re: Please log in with router's password

#124
post #36

I think this is more the fault of manufacturers than end users. Routers should be secure by default, and it should be hard to do something that will make it insecure. The router manufacturers are the supposed experts when it comes to networking, expecting every consumer to even know the risks of exposing their router admin interface to the world is not a reasonable assumption.

These routers are secure by default. This is only visible because users have chosen to have their routers expose their admin pages to the public internet. I have never seen a router that had its admin page visible to the WAN by default.

> I have never seen a router that had its admin page visible to the WAN by default.

I'd wager there's a non-zero percentage of routers which have the modem (or ISP router) plugged into a LAN port.

Re: Please log in with router's password

#125
post #64

Earlier quoted context omitted.

This reminds me of when Sergey Brin explained recursion to Terry Gross in this interview (14:45 seconds into the interview) https://freshairarchive.org/segments/google-founders-larry-p...

Terry Gross is one of the very best interviewers I have ever heard. Her interviews and classical music alone make public radio worthwhile.

It seems Jonathan Coulton thinks highly of her too:

https://genius.com/Jonathan-coulton-dance-soterios-johnson-d...

Re: Please log in with router's password

#126
post #123
post #109

Earlier quoted context omitted.

fyi, "for official use only" or "fouo" is a slightly more than meaningless designation to shield stuff against FOIA inquiries. most of the stuff you'll find is pretty boring. a little more: https://en.wikipedia.org/wiki/For_Official_Use_Only#United_S...

I worked for a government lab some time ago, and FOUO wasn't used to shield against FOIA. Indeed, OUO documents can be released to a FOIA request. It was more or less just the default because no one wants to get in trouble for not making things that are supposed to be marked.

What I've seen used as a shield against FOIA is the label, "DRAFT - For Discussion Purposes Only." This is meant to ivoke the "deliberative process" exemption.

Re: Please log in with router's password

#127
post #2

To the reader: if this is your first exposure to finding things that aren't supposed to be exposed to the internet and you're finding it interesting enough to want to learn more, there's a tool commonly used among security practitioners called Shodan that enables a much more tunable search for exposed assets. https://en.wikipedia.org/wiki/Shodan_(website) - deeper reading. I'm not affiliated. --- It's also a super ba…

People seem to slap legal notices on documents like they’re some sort of magical spell that they don’t actually understand.

Re: Please log in with router's password

#129

Hi folks, not much to see here. These routers are very well designed, receive regular firmware updates and are overall very solid. The only router that I haven't had to reboot since I've owned it (for nearly 18 months now). Had no random configuration resets, interface bugs, WiFi drop-outs, QoS issues ... just, solid. So seeing that people have exposed it to the internet - sure, that's not recommended. But I don't th…

Oh, great! It's stable! That means it couldn't possibly have any 0days or weak passwords.

A security problem is a bug. If their track record is quality (i.e. no bugs), you can extrapolate that their process is pretty good at dealing with security problems as well. Until proven otherwise.

Of course, nothing is unhackable. If a state actor wants to get inside your router, you'll lose no matter what. And you don't need to have https:// exposed on WAN to get hacked in that way. The 0-day could just as easily be on the transceiver or on the WAN layer itself.

The only way to protect yourself from a 0-day is to live in a tin foil bubble and simply never use a mobile phone or the internet.

Re: Please log in with router's password

#130
post #2

To the reader: if this is your first exposure to finding things that aren't supposed to be exposed to the internet and you're finding it interesting enough to want to learn more, there's a tool commonly used among security practitioners called Shodan that enables a much more tunable search for exposed assets. https://en.wikipedia.org/wiki/Shodan_(website) - deeper reading. I'm not affiliated. --- It's also a super ba…

i think my first exposure to shodan was from viss https://youtu.be/-T-3buBwMEQ this video is 9 years old now, but id wager the prevalence of pulbic scada and webcams et al is still pretty high.

"115 batshit stupid things you can put on the internet in as fast as I can go"

https://youtu.be/hMtu7vV_HmY

Post reply on HN