Earlier quoted context omitted.
> I wonder if you could use a forum post of someone saying what's wrong on their page as a source to edit the page though. You could. The person themselves couldn't. (There are guidelines about the risk of bias from primary sources, which apply very much to someone talking about themselves or their own company, so you shouldn't just blindly copy what they say into Wikipedia, but you absolutely can use them as a sourc…
Off-topic: this discussion reminds me a bit of what happened about five years ago when I offered to host a reddit AMA about anesthesia and anesthesiology and related subjects (I was board-certified in 1980). The moderator asked me for proof that I was who I was, so I had to spend a couple days digging through my files to find my medical school diploma, board-certification document, medical licenses, etc., then scan a…
Please log in with router's password
251–260 of 265 posts
Re: Please log in with router's password
#252Earlier quoted context omitted.
Off-topic: this discussion reminds me a bit of what happened about five years ago when I offered to host a reddit AMA about anesthesia and anesthesiology and related subjects (I was board-certified in 1980). The moderator asked me for proof that I was who I was, so I had to spend a couple days digging through my files to find my medical school diploma, board-certification document, medical licenses, etc., then scan a…
What's the worst/best part of your position that people outside of it would rarely acknowledge publicly?
Re: Please log in with router's password
#253I (un)fortunately can't remember the certain query needed, but it's not too hard to find it — I'm sure it's been mentioned on various news articles or YouTube videos. If I remember, it relied on the cameras all sharing the same filename for the PHP page to access the interface.
Re: Please log in with router's password
#254Re: Please log in with router's password
#255Re: Please log in with router's password
#256Earlier quoted context omitted.
If their router login page has been indexed, then the user most likely don’t know what they are doing. It’s fine to expose router configuration (although it’s not ideal), but if you know that you are doing, you’ll at least place it behind a VPN.
I know what I'm doing. I would be fine with this in some circumstances. There are legitimate reasons adding a VPN to a backdoor like this can make it worse. The trick to "knowing what you are doing" in this case is defense in depth and knowing what's actually accessible from a world-open interface, and how much of that would be really annoying to get to while simultaneously fixing your homebrew VPN that fell over six…
Maybe it’s just a matter of difference of criteria, but I would certainly not be fine with this. You have a lot of ways to prevent this from happening, and it only opens an attack surface to APTs.
Being indexed means being searchable, being searchable means exposing yourself to automated targeted attacks.
Re: Please log in with router's password
#257Earlier quoted context omitted.
What router does HN recommend for consumers? I personally run Ubiquiti Unifi gear, but they're not exactly consumer friendly (more geared to power users).
Yeah, I love the older Ubiquiti stuff (Edgerouter) and the Unifi access points, but all their new routers (like the UNMS ones) seem to require cloud hook-in which I really don't want. When the EdgeRouter-4 I have dies, I suspect I'm going to need to find a new hardware brand, this time preferably running OpenWRT. Potentially it could get to the point where I'll have to look for an ARM based server with low enough pow…
However, it's likely that your ER-4 will far outlast the majority of devices you can find running OpenWRT. They're very well built units.
Re: Please log in with router's password
#258Earlier quoted context omitted.
What router does HN recommend for consumers? I personally run Ubiquiti Unifi gear, but they're not exactly consumer friendly (more geared to power users).
Buy something well supported by OpenWRT; that typically correlates to at least OK hardware that is known to work well enough. Ideally you'd also install OpenWRT on it, or another choice of OSS rather than factory firmware.
Once you log in it appears to be running a version of OpenWRT, although they don't specify that on their website.
Re: Please log in with router's password
#259Earlier quoted context omitted.
> Folks - these routers are secure. There is nothing to see here, move along. If experience is any guide, they are not. Consumer routers have horrible track of embarrassing, easily exploitable vulnerabilities. That are not patched for a long time or ever. And exposing your router to public like that suggests the owner knows very little about security. This typically goes in hand with other neglect. Tell me, how many…
What router does HN recommend for consumers? I personally run Ubiquiti Unifi gear, but they're not exactly consumer friendly (more geared to power users).