Live data from Hacker News

Please log in with router's password

google.com

31–40 of 265 posts

Re: Please log in with router's password

#31
post #14

Earlier quoted context omitted.

How do you know this router doesn't already do that? You're making some wild assumptions here. Even your basic free Comcast router comes with sane defaults, and tons of warnings for every configuration change. Here's the user manual for the TP-Link AC2300 - The Archer C7 found in the google results this post links to: https://static.tp-link.com/2019/201912/20191231/7106508598_A... Step 2 forces the default password t…

Here's another TP-link manual: https://www.tp-link.com/us/support/faq/66/ 1. Open the web browser and in the address bar type in: http://192.168.1.1 2. Type the username and password in the login page. They are both admin by default. 3. Click Security->Remote Management on the left side 4. To enable this function, please change the Remote Management IP address from 0.0.0.0 to a specific authorized remote IP address.…

That link isn't from the routers this post links to (specifically Archer C7 and C9 routers).

And, your link is old, to say the least. That screenshot is from the Windows XP era.

You're trying to lampoon TP-Link for things that simply are not true anymore, nor have been for a long while.

I'll repeat again - the defaults on these routers is to prohibit WAN access and they force a password change at setup. What more are you complaining about?

Re: Please log in with router's password

#32
post #5

Earlier quoted context omitted.

There are thousands of TP-LINK routers whose WAN port 80/443 is exposed to the Internet, allowing access to their administration interface if you know the password (or a vulnerability is present).

I was planning to host a simple website on my RasberryPi using Dynamic DNS - which I think requires me to expose port 80 to the internet. Is that safe?

If it's a static site? Probably safe-ish, I suppose bots and bored teens could DDOS it. You could also choose a non-standard port, that might cut down on the noise.

Re: Please log in with router's password

#33
post #22

Folks - these routers are secure. There is nothing to see here, move along. Here's the user manual for the TP-Link AC2300 "Archer C7", as found in the google results: https://static.tp-link.com/2019/201912/20191231/7106508598_A... Step 2 of first time setup forces a default password change. There is no way around this step. The defaults for the router also do not allow router access from the WAN port. This means: 1)…

I would love to know how these are secured. I doubt there's MFA or even rate limiting.

> 2) These routers were deliberately placed on the internet by people that knew enough about them to do so.

That's making some very generous assumptions.

Re: Please log in with router's password

#35

Earlier quoted context omitted.

I was planning to host a simple website on my RasberryPi using Dynamic DNS - which I think requires me to expose port 80 to the internet. Is that safe?

If it's a static site? Probably safe-ish, I suppose bots and bored teens could DDOS it. You could also choose a non-standard port, that might cut down on the noise.

Thanks! I want to learn what could go wrong. Can you point me to any resource/book to study this particular matter?

Re: Please log in with router's password

#36

I think this is more the fault of manufacturers than end users. Routers should be secure by default, and it should be hard to do something that will make it insecure. The router manufacturers are the supposed experts when it comes to networking, expecting every consumer to even know the risks of exposing their router admin interface to the world is not a reasonable assumption.

These routers are secure by default. This is only visible because users have chosen to have their routers expose their admin pages to the public internet.

I have never seen a router that had its admin page visible to the WAN by default.

Re: Please log in with router's password

#37
post #22

Folks - these routers are secure. There is nothing to see here, move along. Here's the user manual for the TP-Link AC2300 "Archer C7", as found in the google results: https://static.tp-link.com/2019/201912/20191231/7106508598_A... Step 2 of first time setup forces a default password change. There is no way around this step. The defaults for the router also do not allow router access from the WAN port. This means: 1)…

[deleted]

Re: Please log in with router's password

#38
post #22

Folks - these routers are secure. There is nothing to see here, move along. Here's the user manual for the TP-Link AC2300 "Archer C7", as found in the google results: https://static.tp-link.com/2019/201912/20191231/7106508598_A... Step 2 of first time setup forces a default password change. There is no way around this step. The defaults for the router also do not allow router access from the WAN port. This means: 1)…

SD-WAN / VPN / Many many many other solutions.

Re: Please log in with router's password

#39
post #5

Earlier quoted context omitted.

There are thousands of TP-LINK routers whose WAN port 80/443 is exposed to the Internet, allowing access to their administration interface if you know the password (or a vulnerability is present).

I was planning to host a simple website on my RasberryPi using Dynamic DNS - which I think requires me to expose port 80 to the internet. Is that safe?

If you disable the router's remote administration feature and/or change the router's default administration password, it should be safe.

Re: Please log in with router's password

#40
post #7

Earlier quoted context omitted.

Thanks. How do I make sure I'm not on this list?

Easiest, most practical, 90% good enough: Get your IP address, grab your phone on mobile network and go to http://your.ip.address

So, if I was exposed I will see the router's login page?
Post reply on HN