Live data from Hacker News

Please log in with router's password

google.com

71–80 of 265 posts

Re: Please log in with router's password

#71
post #14

Earlier quoted context omitted.

manually overriding this configuration usually demonstrates a sufficient enough understanding that the default credentials have likely also been changed I don't think that's a reasonable assumption at all -- the router should ensure that the admin cred has been set to a (reasonably secure) password. Just because someone read on a web page that they should enable remote admin doesn't mean that they understand the risk…

How do you know this router doesn't already do that? You're making some wild assumptions here. Even your basic free Comcast router comes with sane defaults, and tons of warnings for every configuration change. Here's the user manual for the TP-Link AC2300 - The Archer C7 found in the google results this post links to: https://static.tp-link.com/2019/201912/20191231/7106508598_A... Step 2 forces the default password t…

> Step 2 forces the default password to be changed. There is no way around that step.

Sure, and you can change that password to "foobar" or whatever bad password you want. And I bet that login page doesn't have any rate limiting or a lockout after too many failed logins.

Fortunately, though, I don't think there are any of these that enable remote admin by default, so the owner would need to do that explicitly. Hopefully they've paired that with a strong password. Even then, I still wouldn't advise anyone actually doing this...

(Your manual link is broken; it takes me to a page that just links to TP-Links main marketing website.)

Re: Please log in with router's password

#72

I think this is more the fault of manufacturers than end users. Routers should be secure by default, and it should be hard to do something that will make it insecure. The router manufacturers are the supposed experts when it comes to networking, expecting every consumer to even know the risks of exposing their router admin interface to the world is not a reasonable assumption.

So it's the car companies fault if I crash my car? They should limit vehicle speed to 5mph so I don't hurt myself or others. I have used many of these routers. Admin access on the wan port is blocked by default and must be enabled by the user.

My car will literally hit the brakes for me if I am about to crash into something. A router marketed to a non-professional should do the same.

Re: Please log in with router's password

#73

I think this is more the fault of manufacturers than end users. Routers should be secure by default, and it should be hard to do something that will make it insecure. The router manufacturers are the supposed experts when it comes to networking, expecting every consumer to even know the risks of exposing their router admin interface to the world is not a reasonable assumption.

[deleted]

Re: Please log in with router's password

#74
post #22

Folks - these routers are secure. There is nothing to see here, move along. Here's the user manual for the TP-Link AC2300 "Archer C7", as found in the google results: https://static.tp-link.com/2019/201912/20191231/7106508598_A... Step 2 of first time setup forces a default password change. There is no way around this step. The defaults for the router also do not allow router access from the WAN port. This means: 1)…

> These routers all have secured passwords that are non-default.

Secure passwords is just a tiny subset of non-default passwords. Chances of an average human being being able to come up with a password with enough entropy to be called as secure is pretty low.

> These routers were deliberately placed on the internet by people that knew enough about them to do so.

This means these people knows how to expose the management interface to the internet. It does not mean these people have enough knowledge on securing their devices -- based on their actions, it is more likely that the opposite is true.

Re: Please log in with router's password

#75
Click "Next Page" folks - estimated 7,000+ results turns into 21 results - many of which are dead, many others are HN aggregators, leaving the total amount of these model routers on the public internet to be a small handful - all of which appear to be professionally managed with CNAMEs, etc.

All the outrage in this thread over nothing...

Re: Please log in with router's password

#76
post #59

Earlier quoted context omitted.

I would love to know how these are secured. I doubt there's MFA or even rate limiting. > 2) These routers were deliberately placed on the internet by people that knew enough about them to do so. That's making some very generous assumptions.

>That's making some very generous assumptions. Disagree. In my current country of living, I'm not even sure how I'd properly expose the router I use to the public internet since I sit behind the ISP's NAT-ing, and even when I lived in the US, I am not confident I could tell you how to publicly expose the modem provided by Comcast for non-local access, much less how someone without any tech experience might do this. I…

> but 7800 out of the billions of routing devices in the world showing

Click "Next Page" - estimated results turns into 21 results in total... of which a bunch are dead links, a bunch are HN aggregators... leaving just a small handful of actual devices on the internet.

Re: Please log in with router's password

#77
post #55

I suggest anyone wanting to see the pages in the search result to click on the google cache version instead of clicking on the link itself exposing your IP address.

I am quite sure there are enough preload/prefetch links in the Google results pages to make this irrelevant (and crash the poor routers' owners' downstream links).

Re: Please log in with router's password

#78
post #2

To the reader: if this is your first exposure to finding things that aren't supposed to be exposed to the internet and you're finding it interesting enough to want to learn more, there's a tool commonly used among security practitioners called Shodan that enables a much more tunable search for exposed assets. https://en.wikipedia.org/wiki/Shodan_(website) - deeper reading. I'm not affiliated. --- It's also a super ba…

i think my first exposure to shodan was from viss

https://youtu.be/-T-3buBwMEQ

this video is 9 years old now, but id wager the prevalence of pulbic scada and webcams et al is still pretty high.

Re: Please log in with router's password

#79
post #75

Click "Next Page" folks - estimated 7,000+ results turns into 21 results - many of which are dead, many others are HN aggregators, leaving the total amount of these model routers on the public internet to be a small handful - all of which appear to be professionally managed with CNAMEs, etc. All the outrage in this thread over nothing...

True claim: When I click on "next page" I get "Page 2 of about 7,520 results" BUT when I click on "next page" again I do get "Page 3 of about 21 results".

Re: Please log in with router's password

#80
post #43

Earlier quoted context omitted.

These are not high end enterprise grade kit, folks. Expecting things like MFA, secondary VPN endpoints, etc is just absurd for the target audience of this device. Again, just because you wouldn't configure it this way doesn't make it wrong. It's as secure as it can be, short of throwing a bunch of other kit in front of it, and then why would you be using a $100 consumer router anyway? The only vulnerability here is t…

> The only vulnerability here is the possibility of a 0-Day. That's not exactly uncommon in cheap consumer routers. No rate limiting is as good as no authentication.

I'm a big fan of rate limiting (and even rate limit my static pages) but if your password is secure enough, the lack of a rate limit isn't going to help attackers.

I kind of agree with the comment that started this thread -- people that have explicitly decided to expose their consumer-grade routers directly to the Internet probably know about password managers. Even if you do guess the password and compromise the router, all you'll have is some remote office that is getting TLS errors because of your MITM, and best case control of some unpatched Windows 3.1 machine and maybe some developer's local MySQL install happily listening on port 3306 somewhere. That's not great, but it's a risk that some people are willing to take.

Post reply on HN