Live data from Hacker News

Please log in with router's password

google.com

81–90 of 265 posts

Re: Please log in with router's password

#82
post #22

Folks - these routers are secure. There is nothing to see here, move along. Here's the user manual for the TP-Link AC2300 "Archer C7", as found in the google results: https://static.tp-link.com/2019/201912/20191231/7106508598_A... Step 2 of first time setup forces a default password change. There is no way around this step. The defaults for the router also do not allow router access from the WAN port. This means: 1)…

What you say is sensible, except for:

> The estimated 7,000+ results becomes 21. Many of which are HN aggregators reporting on this thread here.

Nope, Google is just collapsing them because they are all identical copies of the same "page", being the same login screen. Most of them look like routers, you can ask Google to "include" them all and see for yourself. https://www.google.com/search?q=%22Please+log+in+with+router...

Re: Please log in with router's password

#85
post #2

To the reader: if this is your first exposure to finding things that aren't supposed to be exposed to the internet and you're finding it interesting enough to want to learn more, there's a tool commonly used among security practitioners called Shodan that enables a much more tunable search for exposed assets. https://en.wikipedia.org/wiki/Shodan_(website) - deeper reading. I'm not affiliated. --- It's also a super ba…

Sadly, Shodan does not appear to index these, seemingly because it attempts an HTTP connection, while the router expects an HTTPS connection.

Edit: I take it back. Looks like the hash is good enough. 47,000 results; the first three that responded are the same kind of routers. https://www.shodan.io/search?query=hash%3A-904286784

Re: Please log in with router's password

#86
post #2

To the reader: if this is your first exposure to finding things that aren't supposed to be exposed to the internet and you're finding it interesting enough to want to learn more, there's a tool commonly used among security practitioners called Shodan that enables a much more tunable search for exposed assets. https://en.wikipedia.org/wiki/Shodan_(website) - deeper reading. I'm not affiliated. --- It's also a super ba…

Some fun things here, as a google search:

site:.gov "for official use only" filetype:pptx

site:.gov "for official use only" filetype:pdf

Re: Please log in with router's password

#87
post #46

Earlier quoted context omitted.

Best practice for remote management of network devices is over a VPN or a remote access application designed for remote management, and it has been that way for decades. Web UIs on routers are designed for use on trusted networks, are notoriously full of vulnerabilities, and aren't typically hardened for exposure to the open internet. They often do not support any security features beyond a password. No fail2ban, no…

Are VPN's, secondary networks, etc reasonable to expect for a $100 MSRP device targeted at consumers? I think not... Given what it is... it's as secure as it can be. Short of a 0-Day lurking somewhere, or an active CVE, the configuration is fine. Not to mention all the top results appear to be operated by organizations that certainly know what they are doing.

If you as a consumer and

- spend 100 bucks on a specific router

- have a static IP

- put your router web ui on the Internet

then yeah, you are definitely the type who should be also able to put a VPN to properly manage it. I don't really get your defense of this practice. It is bad and risky, and there are no good reasons to expect it to be a sane config for a router.

Re: Please log in with router's password

#89
post #22

Folks - these routers are secure. There is nothing to see here, move along. Here's the user manual for the TP-Link AC2300 "Archer C7", as found in the google results: https://static.tp-link.com/2019/201912/20191231/7106508598_A... Step 2 of first time setup forces a default password change. There is no way around this step. The defaults for the router also do not allow router access from the WAN port. This means: 1)…

> So... out of the possible millions of routers TP-Link has sold in this model line, less than 21 are on the public internet

Make that 47,000 of them on Shodan: https://www.shodan.io/search?query=hash%3A-904286784

> 1) These routers all have secured passwords that are non-default.

You have a very interesting definition of "secured" if you think they are all actually secured.

> 2) These routers were deliberately placed on the internet by people that knew enough about them to do so.

Just because they knew enough to click a checkbox doesn't mean they knew enough to do so. If they knew enough, they wouldn't have done so.

You seem to be under the mistaken impression that embedded devices (like consumer routers) don't usually have glaring security holes. But they do.

Post reply on HN