Live data from Hacker News

Shodan: The scariest search engine on the Internet

money.cnn.com

41–50 of 152 posts

Re: Shodan: The scariest search engine on the Internet

#41
post #25
post #15

Hardware manufacturers should ship their devices with a piece of paper printed with a unique UID and password. Not "admin/1234". The owner would have the ability to change these at will, and resets would revert to the original UID/pw combination. Lost your piece of paper? Send the device back. No more trivial hacks.

That would make the devices more costly to produce and would raise prices. I know that ISPs do this with their devices sometimes, but some companies will cheap out and will just ship with a generic username and password since they only have to flash one single ROM image.

They can flash a single ROM image, create a random password on the device , and just by adding a led , they communicate said password to a mobile app, when needed.

Re: Shodan: The scariest search engine on the Internet

#42
post #32

Earlier quoted context omitted.

Look at the username - likely a purpose built troll account. Not the first I've seen on HN, but it's happening more than it used to.

That's funny. I thought cobrausn was a "purpose built troll account."

On the contrary, I think it's simply a snake enthusiant with a maritime affiliation.

Re: Shodan: The scariest search engine on the Internet

#43
post #34
post #22

Earlier quoted context omitted.

I used to be able to tell people like you to go back to Reddit. Unfortunately the quality of HN has declined far enough that your content-free insulting of a decent question is not immediately recognizable as something with no place here. I consider that fact a sad commentary on how far HN has fallen.

I'm a relatively new HN reader (~1 year) and have taken much away from my time here (much reading, few comments). I understand where you're coming from with concerns about quality; however, I resent the fact that I may be considered part of the increased readership responsible for "HN's decline"

I've been lurking HN for awhile now, and complaints about HN's decline were going on even years back when I was first introduced to the site...

Re: Shodan: The scariest search engine on the Internet

#44

mhm sorry as i don't know so much about this, but how is this different from google? meaning that with a specific search in google i can find for example all kinds of cameras or systems one shouldn't find, e.g.: -) http://preview.tinyurl.com/34959u Maybe Shodan "focuses" on that, but they can't possible index more of those things than Google already has... Can you find one single thing over Shodan you can't with a sp…

I could be wrong, but I believe Shodan actually portscans the entire internet, whereas Google only crawls known URLs. They also index HTTP headers, which Google doesn't do. It's run by our very own achillean: https://news.ycombinator.com/threads?id=achillean

Sounds like they also attempt to authenticate using default user/pass combos.

Re: Shodan: The scariest search engine on the Internet

#46
post #25
post #15

Hardware manufacturers should ship their devices with a piece of paper printed with a unique UID and password. Not "admin/1234". The owner would have the ability to change these at will, and resets would revert to the original UID/pw combination. Lost your piece of paper? Send the device back. No more trivial hacks.

That would make the devices more costly to produce and would raise prices. I know that ISPs do this with their devices sometimes, but some companies will cheap out and will just ship with a generic username and password since they only have to flash one single ROM image.

It shouldn't really. I mean, it's not like devices don't come with at least 3 or 4 unique IDs for different purposes. Just using one of those for the default password or adding a new ID shouldn't be that big of a task.

I know that this is how some of the router/modem combos from french DSL providers worked - the admin and WPA passwords are two seperate UUIDs printed on the device.

Re: Shodan: The scariest search engine on the Internet

#49
post #15

Hardware manufacturers should ship their devices with a piece of paper printed with a unique UID and password. Not "admin/1234". The owner would have the ability to change these at will, and resets would revert to the original UID/pw combination. Lost your piece of paper? Send the device back. No more trivial hacks.

My Netgear Router N600 does exactly that. There's a nice laminated sticker on the bottom with the admin password.

Most of those types are some sort of hash of the MAC which are quickly reversed. A quick search will contain many fruitful examples. How else do you think the default password ends up the same on a system reset?

Re: Shodan: The scariest search engine on the Internet

#50

mhm sorry as i don't know so much about this, but how is this different from google? meaning that with a specific search in google i can find for example all kinds of cameras or systems one shouldn't find, e.g.: -) http://preview.tinyurl.com/34959u Maybe Shodan "focuses" on that, but they can't possible index more of those things than Google already has... Can you find one single thing over Shodan you can't with a sp…

...followed the first link and finally learned what people use java applets for :)
Post reply on HN