Live data from Hacker News

Please log in with router's password

google.com

251–260 of 265 posts

Re: Please log in with router's password

#251
post #181

Earlier quoted context omitted.

> I wonder if you could use a forum post of someone saying what's wrong on their page as a source to edit the page though. You could. The person themselves couldn't. (There are guidelines about the risk of bias from primary sources, which apply very much to someone talking about themselves or their own company, so you shouldn't just blindly copy what they say into Wikipedia, but you absolutely can use them as a sourc…

Off-topic: this discussion reminds me a bit of what happened about five years ago when I offered to host a reddit AMA about anesthesia and anesthesiology and related subjects (I was board-certified in 1980). The moderator asked me for proof that I was who I was, so I had to spend a couple days digging through my files to find my medical school diploma, board-certification document, medical licenses, etc., then scan a…

What's the worst/best part of your position that people outside of it would rarely acknowledge publicly?

Re: Please log in with router's password

#252

Earlier quoted context omitted.

Off-topic: this discussion reminds me a bit of what happened about five years ago when I offered to host a reddit AMA about anesthesia and anesthesiology and related subjects (I was board-certified in 1980). The moderator asked me for proof that I was who I was, so I had to spend a couple days digging through my files to find my medical school diploma, board-certification document, medical licenses, etc., then scan a…

What's the worst/best part of your position that people outside of it would rarely acknowledge publicly?

Huh?

Re: Please log in with router's password

#253
iirc, there's a certain query that's similar to this one which you could type into Google and control various security cameras around the world which are all on the WAN. Not only can you view the picture being recorded by the cameras, but you could rotate the cameras right from the web interface too.

I (un)fortunately can't remember the certain query needed, but it's not too hard to find it — I'm sure it's been mentioned on various news articles or YouTube videos. If I remember, it relied on the cameras all sharing the same filename for the PHP page to access the interface.

Re: Please log in with router's password

#255

Earlier quoted context omitted.

Mikrotik

https://news.ycombinator.com/item?id=18200119 https://news.ycombinator.com/item?id=17908028

Oh well, "Let s/he who has not sinned cast the first stone". One can very well install OpenWrt on any Mikrotik.

Re: Please log in with router's password

#256

Earlier quoted context omitted.

If their router login page has been indexed, then the user most likely don’t know what they are doing. It’s fine to expose router configuration (although it’s not ideal), but if you know that you are doing, you’ll at least place it behind a VPN.

I know what I'm doing. I would be fine with this in some circumstances. There are legitimate reasons adding a VPN to a backdoor like this can make it worse. The trick to "knowing what you are doing" in this case is defense in depth and knowing what's actually accessible from a world-open interface, and how much of that would be really annoying to get to while simultaneously fixing your homebrew VPN that fell over six…

> I would be fine with this in some circumstances.

Maybe it’s just a matter of difference of criteria, but I would certainly not be fine with this. You have a lot of ways to prevent this from happening, and it only opens an attack surface to APTs.

Being indexed means being searchable, being searchable means exposing yourself to automated targeted attacks.

Re: Please log in with router's password

#257
post #160

Earlier quoted context omitted.

What router does HN recommend for consumers? I personally run Ubiquiti Unifi gear, but they're not exactly consumer friendly (more geared to power users).

Yeah, I love the older Ubiquiti stuff (Edgerouter) and the Unifi access points, but all their new routers (like the UNMS ones) seem to require cloud hook-in which I really don't want. When the EdgeRouter-4 I have dies, I suspect I'm going to need to find a new hardware brand, this time preferably running OpenWRT. Potentially it could get to the point where I'll have to look for an ARM based server with low enough pow…

They still sell the ER series, but Microtik sounds like what you want.

However, it's likely that your ER-4 will far outlast the majority of devices you can find running OpenWRT. They're very well built units.

Re: Please log in with router's password

#258
post #160

Earlier quoted context omitted.

What router does HN recommend for consumers? I personally run Ubiquiti Unifi gear, but they're not exactly consumer friendly (more geared to power users).

Buy something well supported by OpenWRT; that typically correlates to at least OK hardware that is known to work well enough. Ideally you'd also install OpenWRT on it, or another choice of OSS rather than factory firmware.

Funny enough, I recently purchased one of the latest TP-Link Archer 5400x (AX73) routers. Ended up not needing it, so I opened it up and connected via UART.

Once you log in it appears to be running a version of OpenWRT, although they don't specify that on their website.

Re: Please log in with router's password

#259
post #160
post #50

Earlier quoted context omitted.

> Folks - these routers are secure. There is nothing to see here, move along. If experience is any guide, they are not. Consumer routers have horrible track of embarrassing, easily exploitable vulnerabilities. That are not patched for a long time or ever. And exposing your router to public like that suggests the owner knows very little about security. This typically goes in hand with other neglect. Tell me, how many…

What router does HN recommend for consumers? I personally run Ubiquiti Unifi gear, but they're not exactly consumer friendly (more geared to power users).

has anyone had good experiences with the Turris Omnia?
Post reply on HN