Live data from Hacker News

Please log in with router's password

google.com

181–190 of 265 posts

Re: Please log in with router's password

#181
post #171

Earlier quoted context omitted.

Wikipedia policy discourages entities from editing their own page.

I wonder if you could use a forum post of someone saying what's wrong on their page as a source to edit the page though. Forum posts aren't outside the realm of valid sources, so where exactly is the line drawn?

> I wonder if you could use a forum post of someone saying what's wrong on their page as a source to edit the page though.

You could. The person themselves couldn't. (There are guidelines about the risk of bias from primary sources, which apply very much to someone talking about themselves or their own company, so you shouldn't just blindly copy what they say into Wikipedia, but you absolutely can use them as a source)

Re: Please log in with router's password

#182
post #171

Earlier quoted context omitted.

Wikipedia policy discourages entities from editing their own page.

I wonder if you could use a forum post of someone saying what's wrong on their page as a source to edit the page though. Forum posts aren't outside the realm of valid sources, so where exactly is the line drawn?

Conflict of interest is totally separate from the reliability of sources issue. I think the thing that would be encouraged in this situation is to detail what you would want changed on the talk page, and have a neutral wikipedian look at it and make the changes if appropriate. See also https://en.wikipedia.org/wiki/Wikipedia:Plain_and_simple_con...

That said, as far as where the line is drawn for sources see https://en.wikipedia.org/wiki/Wikipedia:Reliable_sources i dont think forum posts are usually considered the best sources.

Re: Please log in with router's password

#184
post #2

To the reader: if this is your first exposure to finding things that aren't supposed to be exposed to the internet and you're finding it interesting enough to want to learn more, there's a tool commonly used among security practitioners called Shodan that enables a much more tunable search for exposed assets. https://en.wikipedia.org/wiki/Shodan_(website) - deeper reading. I'm not affiliated. --- It's also a super ba…

The Wikipedia article is unfortunately woefully out of date in describing what Shodan does. For example, Shodan collects data on thousands of ports: https://www.shodan.io/search/facet?query=net%3A0%2F0&facet=p... And we don't concentrate on a single type of device/ service (the article mentions SCADA). We identify everything from industrial control systems (1) to Minecraft servers (2). The news coverage makes it soun…

Entirely unrelated fun fact: my love for your service started a good number of years ago when you worked with me directly on a specific challenge (subject: "Any way to pay for shodan without Paypal?"). Glad to see the service is continuing to thrive! And that you're engaged in conversation/feedback on HN.

Re: Please log in with router's password

#185
post #2

To the reader: if this is your first exposure to finding things that aren't supposed to be exposed to the internet and you're finding it interesting enough to want to learn more, there's a tool commonly used among security practitioners called Shodan that enables a much more tunable search for exposed assets. https://en.wikipedia.org/wiki/Shodan_(website) - deeper reading. I'm not affiliated. --- It's also a super ba…

The Wikipedia article is unfortunately woefully out of date in describing what Shodan does. For example, Shodan collects data on thousands of ports: https://www.shodan.io/search/facet?query=net%3A0%2F0&facet=p... And we don't concentrate on a single type of device/ service (the article mentions SCADA). We identify everything from industrial control systems (1) to Minecraft servers (2). The news coverage makes it soun…

> https://me.shodan.io … this looks up information in the existing Shodan database - it doesn't launch a scan.

But do you discard the IP or save it for future scans? :p

Re: Please log in with router's password

#186
post #2

To the reader: if this is your first exposure to finding things that aren't supposed to be exposed to the internet and you're finding it interesting enough to want to learn more, there's a tool commonly used among security practitioners called Shodan that enables a much more tunable search for exposed assets. https://en.wikipedia.org/wiki/Shodan_(website) - deeper reading. I'm not affiliated. --- It's also a super ba…

Not sure “google-fu” translates to the average user

Re: Please log in with router's password

#187
post #185

Earlier quoted context omitted.

The Wikipedia article is unfortunately woefully out of date in describing what Shodan does. For example, Shodan collects data on thousands of ports: https://www.shodan.io/search/facet?query=net%3A0%2F0&facet=p... And we don't concentrate on a single type of device/ service (the article mentions SCADA). We identify everything from industrial control systems (1) to Minecraft servers (2). The news coverage makes it soun…

> https://me.shodan.io … this looks up information in the existing Shodan database - it doesn't launch a scan. But do you discard the IP or save it for future scans? :p

That's not how it works. Shodan continuously checks all IPs on the Internet. When you visit the website you're checking for existing information in the database. Your use of the Shodan website/ API doesn't change how Shodan crawls the Internet.

Re: Please log in with router's password

#188
post #160
post #50

Earlier quoted context omitted.

> Folks - these routers are secure. There is nothing to see here, move along. If experience is any guide, they are not. Consumer routers have horrible track of embarrassing, easily exploitable vulnerabilities. That are not patched for a long time or ever. And exposing your router to public like that suggests the owner knows very little about security. This typically goes in hand with other neglect. Tell me, how many…

What router does HN recommend for consumers? I personally run Ubiquiti Unifi gear, but they're not exactly consumer friendly (more geared to power users).

Buy something well supported by OpenWRT; that typically correlates to at least OK hardware that is known to work well enough. Ideally you'd also install OpenWRT on it, or another choice of OSS rather than factory firmware.

Re: Please log in with router's password

#189

Earlier quoted context omitted.

> There are legit reasons to have a router be publicly accessible. No, there are not. > How else would one remotely manage a router Over a WireGuard connection to a secure management network. > The only real issue would be using a default password Uh, no. Try any number of CVEs or 0-days or unknown-until-it's too-late vulnerabilities, depending on what web daemon/frameworks are used by the router's management softwar…

Why is exposing a web service considered so much worse than exposing a VPN service? WireGuard is respected for low complexity and high quality, sure, but what prevents a web server from having the same characteristics? And there are plenty of VPN services whose huge public surfaces turned out to be vulnerable, why is running one of these any less crazy than running nginx?

One problem is the software on the router is likely to be outdated and vulnerable, and upgrades are not under your control.

Re: Please log in with router's password

#190
post #185

Earlier quoted context omitted.

> https://me.shodan.io … this looks up information in the existing Shodan database - it doesn't launch a scan. But do you discard the IP or save it for future scans? :p

That's not how it works. Shodan continuously checks all IPs on the Internet. When you visit the website you're checking for existing information in the database. Your use of the Shodan website/ API doesn't change how Shodan crawls the Internet.

"all IPs on the Internet."

I believe all IPV4 addresses. Skeptical on IPV6. Though the ntp pool thing was clever.

Post reply on HN