Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Speaking of how wifi works, I learned something interesting about wifi and Verizon's partner in many things, Comcast: Last night I notified my home Internet acting funny, and learned that the admin interface for my Comcast router had username "admin", password "password". SMH.


I mean, I just got a 10-gig router,[1] and the stock username/password was "ubnt"/"ubnt." It's always the installer's job to set up a new username/password.

[1] https://community.ubnt.com/t5/EdgeMAX-Stories/EdgeRouter-Inf...


ER-XG is quite far from home WiFi router though :)

UBNT's new-ish home router series (AmpliFi) doesn't have default username/password- it needs to be set-up before using. I do think it's possible to have an open-network default configuration, but the LCD will nag you to set-up the device, and the first step of the setup is choosing a password (both for management and WiFi).

Disclaimer: I work at UBNT.


Why not generate a long password and print it on the backside? My DSL provider can do it (for my DSL router)


All the WiFi routers I've bought in recent memory do that for the network connection password, but not for the admin page.

My NEC router had no default password and required you to make one up yourself on initial setup.


People might be less inclined to change it. And they should change it, because some firm knowing your password isn't safe either.


It's worth noting that all the ISPs that encourage you to change your password have a separate maintenance account ("backdoor") with its own password.


I think the difference here is that someone buying Ubiquiti is knowingly getting a slightly more in depth initial setup.

Your grandma is getting a Comcast router and probably doesn't know it can be logged into and configured or how to do it.


ISP's like spectrum discourage dispatching techs and opt for customer setup. And every model they give you has an 'admin/admin' or 'admin/password' setup.


... which is "okay", since you can only access it (the admin web console) from within your wlan/lan (and not the internet) and ofc you can/should change it during setup


Most people (esp non-HNers) don't, they just let Comcast set it up. To make matters worse, they set the SSID to my last name, and the password was my address. Maybe that's one-off, but if standard, seems problematic.


I can confirm that two different ISPs have done this with my initial WiFi setup over the last few years. AT&T made it the initials of everyone staying in that house with the password set to their 800 number for service calls. Time Warner made it one person's first name and the password was his cell number.

On the other hand, a Midcontinent Communications (aka Midco) tech told me the password I wanted to use wasn't secure enough and brainstormed with me for a couple minutes on good SSIDs and passwords while he showed me the web admin interface on my laptop. I was very pleased with his visit and called the local office afterwards to pass along kudos!


I haven't seen a telecom-provided wireless setup in forever that didn't have the default password be fairly long and random, printed on a sticker on the back of the router.

Seems fairly secure to me.


When I had AT&T it was definitely a more secure setup.


> ... which is "okay"

Nope. Anyone within range of your wifi router can connect to it and most possibly the first username and password that they will try is admin\admin or admin\password


The parent posts here are talking about the admin interface to the router, not the wireless password. While it's technically true that anyone within range can connect, they can't authenticate without the wireless password, and so cannot access the admin interface.


My ISP just set me up with gigE fiber. The installer was a bit clueless, didn't really want to provide me with the gateway IP for the router. Then I looked at the wifi settings; a 2.4Ghz and 5 Ghz setup, both with SSIDs that included the provider's name as a prefix. The password was a 9 digit password, all numerical...

I called the support line and got through quickly to an admin who could change the password and SSID for me (unless you pay for a public IP, the mgmt interface is locked down). I mentioned that having such a short, all numerical password would mean that any access point they set up would be trivial to crack. Just wardrive looking for similarly named access points, and you'd be able to jump on their connection in just a few minutes. He didn't seem to care, which is too bad.


If you want to hear something else scary, I dumped the firmware on my modem a little while back and started exploring it:

https://twitter.com/joshumax/status/860712276717748225


Did you need to do anything special to get shell access?


Just the basics.

Plugged in my 'scope and started probing some debug headers that looked a lot like they'd be for UART, check if one is Tx and is sending out data, figure out the baud rate, hook up Rx, Tx, and GND on my UART dongle to the correct headers, and modify the bootsting in Cisco preboot to spawn a serial console which landed me into busybox as root :)


> Just the basics.

Followed by the use of >=$100 of hardware and some not-beginner skills. Snark aside, I highly recommend anyone remotely interested in what is going on in your modem/router to have a go at this. You don't need the scope if you're okay with trial and error and it's pretty hard to break anything as long as you don't connect the 3.3/5V line to start with.


I think he means people-who-work-with-routers basics :)


Nice, I would have assumed there would be additional security for production units honestly.


Also there was a time when Verizon's modem/router had generated passwords based on the SSID https://aruljohn.com/fios/


Why can't it be "admin", "<random string of x number of nums chars etc>". Could even print it in the bottom of the device.


It's bad practice to assume things are set up properly by someone else. This applies to more than just computers, fwiw.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: