Live data from Hacker News

Please log in with router's password

google.com

171–180 of 265 posts

Re: Please log in with router's password

#171

Earlier quoted context omitted.

The Wikipedia article is unfortunately woefully out of date in describing what Shodan does. For example, Shodan collects data on thousands of ports: https://www.shodan.io/search/facet?query=net%3A0%2F0&facet=p... And we don't concentrate on a single type of device/ service (the article mentions SCADA). We identify everything from industrial control systems (1) to Minecraft servers (2). The news coverage makes it soun…

> The Wikipedia article is unfortunately woefully out of date so... did you fix it?

Wikipedia policy discourages entities from editing their own page.

Re: Please log in with router's password

#172
post #171

Earlier quoted context omitted.

> The Wikipedia article is unfortunately woefully out of date so... did you fix it?

Wikipedia policy discourages entities from editing their own page.

Bingo. Many years ago I tried to fix it but it was quickly reverted. I understand their policy though and hopefully it will get fixed at some point.

Re: Please log in with router's password

#173
post #169
post #115

Earlier quoted context omitted.

> these routers are secure. Owner of a C7 v4 here. There has not been a firmware update from TP-Link since December 2019 (note that v4 is the second-most recent HW revision). No way these are not affected by at least some CVE somewhere in their stack. Calling them secure is a leap of faith that TP-Link does not deserve. I recently flashed openwrt exactly to be able to be on a more recent stack. I would never dream ex…

> If they really needed access to the router remotely, it would be much saner to expose an SSH server with pubkey-only access or VPN, both with brute forcing protection, and allow tunnelling to the router UI only from the LAN side. any chance you can explain that to my mum?

> it would be much saner to expose an SSH server with pubkey-only access or VPN

It would be safer to leave open to the public only a secure protocol based on strong cryptographic keys instead of a password. Or you have to be signed in to a VPN to see the page.

> brute forcing protection

Try too many passwords? Try again in 1 minute. Again? 30 minutes

> allow tunnelling to the router UI only from the LAN side

I think this one means don't expose it to the internet at all. Just from your local network. >

Re: Please log in with router's password

#174

Earlier quoted context omitted.

Oh, great! It's stable! That means it couldn't possibly have any 0days or weak passwords.

A security problem is a bug. If their track record is quality (i.e. no bugs), you can extrapolate that their process is pretty good at dealing with security problems as well. Until proven otherwise. Of course, nothing is unhackable. If a state actor wants to get inside your router, you'll lose no matter what. And you don't need to have https:// exposed on WAN to get hacked in that way. The 0-day could just as easily…

> If their track record is quality.

I really don't think that's the case for router manufacturers.

> The only way to protect yourself from a 0-day is to live in a tin foil bubble and simply never use a mobile phone or the internet.

Or have fewer attack surfaces. Like notoriously buggy routers.

Re: Please log in with router's password

#175
I just checked if my router's admin was open to public access by connecting with my public IP. It connected! Oh no! That's embarrassing, I thought. Turns out it was just NAT hairpinning. I can't connect from my mobile network.

Re: Please log in with router's password

#176
post #160
post #50

Earlier quoted context omitted.

> Folks - these routers are secure. There is nothing to see here, move along. If experience is any guide, they are not. Consumer routers have horrible track of embarrassing, easily exploitable vulnerabilities. That are not patched for a long time or ever. And exposing your router to public like that suggests the owner knows very little about security. This typically goes in hand with other neglect. Tell me, how many…

What router does HN recommend for consumers? I personally run Ubiquiti Unifi gear, but they're not exactly consumer friendly (more geared to power users).

Whatever I can keep an updated OpenWRT on.

Re: Please log in with router's password

#177
I've done something similar once to find Dell iDRAC [0] and Exchange Outlook Web App [1] instances open to the internet. Just goes to show how forgetting a simple robots.txt (if it's even an option) can expose something you don't want, even if it's password protected.

[0] https://www.google.com/search?q=%22Type+in+Username+and+Pass...

[1] https://www.google.com/search?q=intitle%3A%22Outlook+web+app...

Re: Please log in with router's password

#178
post #64

Earlier quoted context omitted.

This reminds me of when Sergey Brin explained recursion to Terry Gross in this interview (14:45 seconds into the interview) https://freshairarchive.org/segments/google-founders-larry-p...

Terry Gross is one of the very best interviewers I have ever heard. Her interviews and classical music alone make public radio worthwhile.

[deleted]

Re: Please log in with router's password

#179
post #5

Earlier quoted context omitted.

There are thousands of TP-LINK routers whose WAN port 80/443 is exposed to the Internet, allowing access to their administration interface if you know the password (or a vulnerability is present).

I was planning to host a simple website on my RasberryPi using Dynamic DNS - which I think requires me to expose port 80 to the internet. Is that safe?

> I was planning to host a simple website on my RasberryPi using Dynamic DNS - which I think requires me to expose port 80 to the internet. Is that safe?

See if ngrok can do what you want to do

Re: Please log in with router's password

#180
post #171

Earlier quoted context omitted.

> The Wikipedia article is unfortunately woefully out of date so... did you fix it?

Wikipedia policy discourages entities from editing their own page.

I wonder if you could use a forum post of someone saying what's wrong on their page as a source to edit the page though.

Forum posts aren't outside the realm of valid sources, so where exactly is the line drawn?

Post reply on HN