Live data from Hacker News

Please log in with router's password

google.com

191–200 of 265 posts

Re: Please log in with router's password

#191
post #160
post #50

Earlier quoted context omitted.

> Folks - these routers are secure. There is nothing to see here, move along. If experience is any guide, they are not. Consumer routers have horrible track of embarrassing, easily exploitable vulnerabilities. That are not patched for a long time or ever. And exposing your router to public like that suggests the owner knows very little about security. This typically goes in hand with other neglect. Tell me, how many…

What router does HN recommend for consumers? I personally run Ubiquiti Unifi gear, but they're not exactly consumer friendly (more geared to power users).

Yeah, I love the older Ubiquiti stuff (Edgerouter) and the Unifi access points, but all their new routers (like the UNMS ones) seem to require cloud hook-in which I really don't want.

When the EdgeRouter-4 I have dies, I suspect I'm going to need to find a new hardware brand, this time preferably running OpenWRT. Potentially it could get to the point where I'll have to look for an ARM based server with low enough power usage and a few independent network interfaces and just run pfSense or VyOS or something...

Re: Please log in with router's password

#192
post #2

To the reader: if this is your first exposure to finding things that aren't supposed to be exposed to the internet and you're finding it interesting enough to want to learn more, there's a tool commonly used among security practitioners called Shodan that enables a much more tunable search for exposed assets. https://en.wikipedia.org/wiki/Shodan_(website) - deeper reading. I'm not affiliated. --- It's also a super ba…

People seem to slap legal notices on documents like they’re some sort of magical spell that they don’t actually understand.

In my experience, the labeling such as "{company_name} Confidential" is for internal data classification purposes.

These items being accessible externally via google dorking is just poor site administration.

Re: Please log in with router's password

#193
post #2

To the reader: if this is your first exposure to finding things that aren't supposed to be exposed to the internet and you're finding it interesting enough to want to learn more, there's a tool commonly used among security practitioners called Shodan that enables a much more tunable search for exposed assets. https://en.wikipedia.org/wiki/Shodan_(website) - deeper reading. I'm not affiliated. --- It's also a super ba…

Oh man. I miss Fravia.

Re: Please log in with router's password

#194
post #160
post #50

Earlier quoted context omitted.

> Folks - these routers are secure. There is nothing to see here, move along. If experience is any guide, they are not. Consumer routers have horrible track of embarrassing, easily exploitable vulnerabilities. That are not patched for a long time or ever. And exposing your router to public like that suggests the owner knows very little about security. This typically goes in hand with other neglect. Tell me, how many…

What router does HN recommend for consumers? I personally run Ubiquiti Unifi gear, but they're not exactly consumer friendly (more geared to power users).

I use Synology but admittedly have don't have a deep understanding of networking or security. It works for me and is very user friendly.

Re: Please log in with router's password

#195
post #22

Folks - these routers are secure. There is nothing to see here, move along. Here's the user manual for the TP-Link AC2300 "Archer C7", as found in the google results: https://static.tp-link.com/2019/201912/20191231/7106508598_A... Step 2 of first time setup forces a default password change. There is no way around this step. The defaults for the router also do not allow router access from the WAN port. This means: 1)…

The sensible way to secure it would be to have a device behind the router, in an isolated network which is the only network/device allowed to access the management interface. Then you tunnel/vpn/wire guard into that device.

Re: Please log in with router's password

#196

Earlier quoted context omitted.

I wonder if you could use a forum post of someone saying what's wrong on their page as a source to edit the page though. Forum posts aren't outside the realm of valid sources, so where exactly is the line drawn?

Conflict of interest is totally separate from the reliability of sources issue. I think the thing that would be encouraged in this situation is to detail what you would want changed on the talk page, and have a neutral wikipedian look at it and make the changes if appropriate. See also https://en.wikipedia.org/wiki/Wikipedia:Plain_and_simple_con... That said, as far as where the line is drawn for sources see https://…

Was about to reply with this exact sentiment. If the page is about you or your service, propose the updates in the talk page (ideally with reliable third-party sources).

Re: Please log in with router's password

#197
post #22

Folks - these routers are secure. There is nothing to see here, move along. Here's the user manual for the TP-Link AC2300 "Archer C7", as found in the google results: https://static.tp-link.com/2019/201912/20191231/7106508598_A... Step 2 of first time setup forces a default password change. There is no way around this step. The defaults for the router also do not allow router access from the WAN port. This means: 1)…

If their router login page has been indexed, then the user most likely don’t know what they are doing.

It’s fine to expose router configuration (although it’s not ideal), but if you know that you are doing, you’ll at least place it behind a VPN.

Re: Please log in with router's password

#198
post #155

Earlier quoted context omitted.

+1. I don't think I ever saw a document marked UNCLASSIFIED// that was not marked UNCLASSIFIED//FOUO. I'm not convinced that there is such a thing as a document that should be marked unclassified that should not also be marked FOUO.

Press releases

I'd imagine you could generalize that observation to any intentionally published work of the government. That's also my understanding of FOUO from when I needed to know: the agency I worked with thought of it as a magic word for "not meant for release" (in spirit, not legality).

Re: Please log in with router's password

#199
post #22

Folks - these routers are secure. There is nothing to see here, move along. Here's the user manual for the TP-Link AC2300 "Archer C7", as found in the google results: https://static.tp-link.com/2019/201912/20191231/7106508598_A... Step 2 of first time setup forces a default password change. There is no way around this step. The defaults for the router also do not allow router access from the WAN port. This means: 1)…

If their router login page has been indexed, then the user most likely don’t know what they are doing. It’s fine to expose router configuration (although it’s not ideal), but if you know that you are doing, you’ll at least place it behind a VPN.

I know what I'm doing. I would be fine with this in some circumstances. There are legitimate reasons adding a VPN to a backdoor like this can make it worse. The trick to "knowing what you are doing" in this case is defense in depth and knowing what's actually accessible from a world-open interface, and how much of that would be really annoying to get to while simultaneously fixing your homebrew VPN that fell over six months ago and that you never got around to fixing.

Most routers are perfectly fine with a limited set of knobs accessible to the public Internet behind reasonably secure access ports. Bastion it behind SSH and/or SOCKS if you're paranoid, but seriously, as long as we're not talking a $50 Target 'router', it's probably fine. My Ubiquiti gear is indexed. It also reliably e-mails me when it successfully authenticates a user and can distinguish between inside and outside access to ACL what it can do.

Just saying, easy with the "if you know what you're doing" thing, because opinions differ (particularly with beyondcorp in an IT setting). Gluing a VPN back together through an SSH tunnel so you can get at the "fail over to my DSL connection" button inside your network is a really crappy deal at 3 a.m. with a few beers in you and 200ms in between.

Re: Please log in with router's password

#200

Earlier quoted context omitted.

Why is exposing a web service considered so much worse than exposing a VPN service? WireGuard is respected for low complexity and high quality, sure, but what prevents a web server from having the same characteristics? And there are plenty of VPN services whose huge public surfaces turned out to be vulnerable, why is running one of these any less crazy than running nginx?

One problem is the software on the router is likely to be outdated and vulnerable, and upgrades are not under your control.

Isn't that equally as true of a VPN service as of a web service?
Post reply on HN