Earlier quoted context omitted.
And I'd bet a nice amount that most of them have the default passwords. Some years ago I wrote a little tool to iterate all of an ISP's ip addresses and around 90% were using default passwords. Mostly homes, but some businesses.
According to a comment above, these routers require an admin password change when setup with no way around that.
Please log in with router's password
261–265 of 265 posts
Re: Please log in with router's password
#262Earlier quoted context omitted.
Yeah, I love the older Ubiquiti stuff (Edgerouter) and the Unifi access points, but all their new routers (like the UNMS ones) seem to require cloud hook-in which I really don't want. When the EdgeRouter-4 I have dies, I suspect I'm going to need to find a new hardware brand, this time preferably running OpenWRT. Potentially it could get to the point where I'll have to look for an ARM based server with low enough pow…
They still sell the ER series, but Microtik sounds like what you want. However, it's likely that your ER-4 will far outlast the majority of devices you can find running OpenWRT. They're very well built units.
I expect I will eventually move to embedded server hardware (even maybe Xeon-D) on a machine running vSphere or something with a router VM and other VMs for stuff I want to run. Just have a few separate NICs and pair it with a separate managed switch (which I already have anyway).
Re: Please log in with router's password
#263Earlier quoted context omitted.
Oh, great! It's stable! That means it couldn't possibly have any 0days or weak passwords.
A security problem is a bug. If their track record is quality (i.e. no bugs), you can extrapolate that their process is pretty good at dealing with security problems as well. Until proven otherwise. Of course, nothing is unhackable. If a state actor wants to get inside your router, you'll lose no matter what. And you don't need to have https:// exposed on WAN to get hacked in that way. The 0-day could just as easily…
They're a (consumer) router manufacturer. I don't care how good they are within that field, no, their track record is NOT quality. Worse yet, 90% of their code comes from the same vendors as every other router manufacturer.
> you can extrapolate that their process is pretty good at dealing with security problems as well.
That is a complete non sequitur; plenty of businesses have made useable, functional (widely-used!) software but had a head-in-the-sand approach to security.
> Of course, nothing is unhackable.
Exactly, which is why only things which must be exposed to the public should be exposed to the public.
The rest of your argument is assuming the attack surface is the same whether remote management is on or off; or that the amount of attack surface doesn't matter. Either way is simply not correct. By the way, an issue in the "transceiver" would require physical proximity. I'm not sure what the "WAN layer" is, but if you mean like... the Ethernet port and interface, that would require physical access.
If the remote management was off, you would likely be targeting nothing more than the units IP/TCP, UDP, whatever stack. With the remote management ON, you could target that, you could target the HTTP server, or you could target the admin panel running on it. Each of those are much more likely to have security holes for several reasons, but moreover there's simply no reason for them to be accessible publicly, while the routing and NAT functions are necessary to the purpose of the device.
Re: Please log in with router's password
#264Earlier quoted context omitted.
I wonder if you could use a forum post of someone saying what's wrong on their page as a source to edit the page though. Forum posts aren't outside the realm of valid sources, so where exactly is the line drawn?
Conflict of interest is totally separate from the reliability of sources issue. I think the thing that would be encouraged in this situation is to detail what you would want changed on the talk page, and have a neutral wikipedian look at it and make the changes if appropriate. See also https://en.wikipedia.org/wiki/Wikipedia:Plain_and_simple_con... That said, as far as where the line is drawn for sources see https://…
But, of course, none of those posts specifically targeted their Wikipedia articles.
Re: Please log in with router's password
#265Earlier quoted context omitted.
True claim: When I click on "next page" I get "Page 2 of about 7,520 results" BUT when I click on "next page" again I do get "Page 3 of about 21 results".
Does this mean that our beloved search engine is narcissist. Overqualifying its capabilities. Or thinks that it found everything useful already.