Live data from Hacker News

Please log in with router's password

google.com

131–140 of 265 posts

Re: Please log in with router's password

#131
post #22

Folks - these routers are secure. There is nothing to see here, move along. Here's the user manual for the TP-Link AC2300 "Archer C7", as found in the google results: https://static.tp-link.com/2019/201912/20191231/7106508598_A... Step 2 of first time setup forces a default password change. There is no way around this step. The defaults for the router also do not allow router access from the WAN port. This means: 1)…

The UI is using jQuery 1.10.0, released in May 2013. I would be surprised if there have been many bugfixes or security updates on these.

Re: Please log in with router's password

#132
post #50
post #22

Folks - these routers are secure. There is nothing to see here, move along. Here's the user manual for the TP-Link AC2300 "Archer C7", as found in the google results: https://static.tp-link.com/2019/201912/20191231/7106508598_A... Step 2 of first time setup forces a default password change. There is no way around this step. The defaults for the router also do not allow router access from the WAN port. This means: 1)…

> Folks - these routers are secure. There is nothing to see here, move along. If experience is any guide, they are not. Consumer routers have horrible track of embarrassing, easily exploitable vulnerabilities. That are not patched for a long time or ever. And exposing your router to public like that suggests the owner knows very little about security. This typically goes in hand with other neglect. Tell me, how many…

> This typically goes in hand with other neglect.

UPnP is on by default, yeah

Re: Please log in with router's password

#133

Hi folks, not much to see here. These routers are very well designed, receive regular firmware updates and are overall very solid. The only router that I haven't had to reboot since I've owned it (for nearly 18 months now). Had no random configuration resets, interface bugs, WiFi drop-outs, QoS issues ... just, solid. So seeing that people have exposed it to the internet - sure, that's not recommended. But I don't th…

"Regular firmware updates"

Archer C7 v4's last firmware update, Dec 2019. Archer C7 v5's last firmware update, Jan 2021.

Might be solid, but I guess "regular" is relative.

Re: Please log in with router's password

#134
post #99
post #74

Earlier quoted context omitted.

> These routers all have secured passwords that are non-default. Secure passwords is just a tiny subset of non-default passwords. Chances of an average human being being able to come up with a password with enough entropy to be called as secure is pretty low. > These routers were deliberately placed on the internet by people that knew enough about them to do so. This means these people knows how to expose the managem…

> Chances of an average human being being able to come up with a password with enough entropy to be called as secure is pretty low. https://xkcd.com/936/ So you think the chance of human beings to come up with 4 random words is pretty low? You can't brute force millions of guesses per second through a web interface. 40 bits of entropy is already plenty for internet usage especially when the password is properly hashe…

Well, real people won't choose any random 10 characters as a CSPRNG would do. Even when picking words from a dictionary, instead of four words, most people would probably just use one (or maybe two). For those are more inclined, they might mess with the capitalisation and sprinkle some numbers to make it "more secure" and adhere to certain password policies. This does not really contribute to the odds as you might expect.

Anyway, the point is, people are terrible at generating (and remembering) secure passwords. By ruling out the default password just means it is not going to be the most insecure one, but the chances of the custom password being secure is still pretty low.

Re: Please log in with router's password

#135
post #123

Earlier quoted context omitted.

I worked for a government lab some time ago, and FOUO wasn't used to shield against FOIA. Indeed, OUO documents can be released to a FOIA request. It was more or less just the default because no one wants to get in trouble for not making things that are supposed to be marked.

What I've seen used as a shield against FOIA is the label, "DRAFT - For Discussion Purposes Only." This is meant to ivoke the "deliberative process" exemption.

  -draft

Re: Please log in with router's password

#137
post #22

Folks - these routers are secure. There is nothing to see here, move along. Here's the user manual for the TP-Link AC2300 "Archer C7", as found in the google results: https://static.tp-link.com/2019/201912/20191231/7106508598_A... Step 2 of first time setup forces a default password change. There is no way around this step. The defaults for the router also do not allow router access from the WAN port. This means: 1)…

Web server itself could be an attack vector too.

Although not specified to TP-Link, There are many exploits on other brands that can bypass the Authentication. For example this one:

https://medium.com/tenable-techblog/bypassing-authentication...

Even allowing access the web server from internet could be dangerous.

Re: Please log in with router's password

#138
post #5

Earlier quoted context omitted.

There are thousands of TP-LINK routers whose WAN port 80/443 is exposed to the Internet, allowing access to their administration interface if you know the password (or a vulnerability is present).

And I'd bet a nice amount that most of them have the default passwords. Some years ago I wrote a little tool to iterate all of an ISP's ip addresses and around 90% were using default passwords. Mostly homes, but some businesses.

According to a comment above, these routers require an admin password change when setup with no way around that.

Re: Please log in with router's password

#139

How did these routers end up in google results. In the past you could check with link: I am not sure if there is any way you can check now.

One way I suppose is this: there are indexed sites on Google that just basically list all known IP addresses (eg. ip to location services) in hope of SEO juice. If those IPs are linked to by said websites then the Google spider will follow and index them.
Post reply on HN