6 ms·
Telling that the summary advice is “change the default password”, even if some of the other ideas are deployed user involvement is near zero if not completely z
by AustinBGibbons 8y ago
Telling that the summary advice is “change the default password”, even if some of the other ideas are deployed user involvement is near zero if not completely zero. I wonder how impactful it would be to roll out a totally read-only router, or if the necessity of updates and maintenance would generate too much headache for the user
- noja 8y agoPrint the randomly generated password on a sticker on the router. Problem solved.
- frockington 8y agoThe only con I can think to that is the initial influx of support questions. I have no idea why this is not the default now, its simple, user friendly, and way more secure
- j45 8y agoA larger information label specific to each device could be printed to minimize those questions. "START HERE" followed by steps. Communication and comprehension is always a key battle of onboarding.
- tomjakubowski 8y agoCox (Orange County) and Verizon Fios (Los Angeles) delivered routers with good-looking, seemingly randomly generated passwords printed on a label. It's been this way with Cox for at least six years.
- eric_h 8y agoI have Fios in NYC and the password is also available on the account page on Verizon's website, which I find a bit unsettling.
- ipython 8y agoExactly. That’s because FiOS routers allow tech support and their website to acquire information about your network, including your WPA passphrase, devices connected on your local network and more. For that reason alone it’s best to have your own equipment not tied to the ISP, IMO. The ISP can already see all of my plaintext traffic, DNS requests, and MITM all my sessions if they wish. I’d rather not give them full access to my private network on top of that.
- Mister_Snuggles 8y agoThis is what my ISP does for their router/cable modem combo. There's a sticker that tells you the SSID, the password for the SSID, the URL for the web interface along with the user ID and password. The passwords are both randomly generated. They will also put it into bridge mode for you where none of that stuff applies.
- Fnoord 8y agoYeah, mine as well, until recently they figured out that the passwords weren't so randomly generated as they were derived from the SSID. Great entropy... I recommend to use a mnemonic password [1] and just print out the WiFi password (without using Google Cloud...) and use some adhesive tape to attach it on the bottom of the router. The downside is that someone who has physical access to the router can see the password within seconds. Someone's who's plumbing your drain or when you are on the toilet. That they put it into bridge mode when you request is due to EU regulations where EU civilians have free choice of router. [1] https://xkpasswd.net https://xkpasswd.net
- thomastjeffery 8y agoThe problem with that is that they pick awful sets to generate from. Instead of a string of random letters and numbers, they should be a string of words. It's frustrating to visit someone's home, and have to enter (on a phone keyboard, no less) some lengthy gibberish that they never bothered to change.
- ozim 8y agoWhen I have to generate pw for such use case I use: http://www.dinopass.com/ http://www.dinopass.com/
- ateesdalejr 8y agoOnly reason I would be concerned about using that specific generator in particular would be the fact that it severely limits your passwords to the "kid-friendly" set.
- deno 8y agoThat’s the only reason? And the fact that it’s exclusively online?
- ozim 8y agoIf you have to create pw you want use one time and tell it to someone over the phone or use it for "Guest WiFi" network, I don't see why I got downvoted. It is not like I am going to use it for my main email account.
- Operyl 8y agoAT&T and a few others currently deal with this problem by having a random password assigned for the admin user printed on a sticker on the side of their Modem/Router combo boxes. It seems to work pretty well.
- paulie_a 8y agoWhile I do like the idea, att boxes are very low quality and drop wifi connections constantly. I've always installed a ubuqiti router and AP. Apparently it's impossible to disable the firewall on the att box also. I've actually called att and had the conversation: "can you enable some ports". CSR, which ones? Tcp and udp 1-65,535...
- Operyl 8y agoFor most users, this really isn't a problem. I never had many problems using the ATT stock boxes for routing, but like you have moved on to better solutions. But we also understand how to secure our devices. Even newer consumer routers are following this same strategy of printed admin passwords, so if a consumer is deciding to replace it with a newer device it still works! :)
- SubiculumCode 8y agoimo, it's none of my isp's business what I have on my network and so use my own network equipment.
- ryanianian 8y agoGot a new netgear router the other day and it used this. Default admin and default wpa2 key were randomly-generated at the factory and printed on the back of the router. If/when my parents need a new router I'm going to have them get one of these and never have to guide them through the security gui again.
- kyrra 8y ago(I'm a Googler, opinions are my own). I think this is one of the awesome things about Google Wifi (aka: OnHub). It's fully managed from a phone app (via "the cloud"), so you get the authentication tied to your gmail account. It's also based on ChromeOs (chromebook OS), and follows a similar auto-update that Chromebooks get. So you are always running the latest firmware. (There are obviously downsides to Google Wifi, my primary issue being that it doesn't have many of the advanced features that something like UniFi has. But for most people, it works well.).
- billions 8y agoWhile your points are valid, it is a bit disconcerting to have the world's largest data monetizer watch all of a home's traffic. Google's promised benevolence may be temporary
- kyrra 8y agoOne nice thing with Google WiFi being based on CROS, is that it's mostly open source (about the same level as Android, where there are some binary blob board support packages). With that, there is custom firmware you can load know Google Wifis: https://github.com/marcosscriven/galeforce https://github.com/marcosscriven/galeforce As an aside, you can read the Google WiFi privacy details here: https://support.google.com/wifi/answer/6246642?hl=en https://support.google.com/wifi/answer/6246642?hl=en
- bubblethink 8y agoI think there is a pretty big distinction wrt routers, in that an end-user cannot build it. That link states as much under the, "Why not just build Chromium OS from source" section. Has anything changed ? With android at least, google distributes the blobs. This probably (?) explains why openwrt hasn't been ported to any of the google routers, although the availability of chromiumOS source would make you think that it would be straightforward.
- compiler-guy 8y agoGoogle also remotely wiped a bunch of its customers' routers, driving them off line and causing all sorts of problems. Which isn't to say that home customers would have necessarily done better, but most people don't have random maintenance bring them down at random times. https://www.theverge.com/2017/2/23/14722470/google-reset-onhub-wifi-bug https://www.theverge.com/2017/2/23/14722470/google-reset-onh...
- bradenb 8y agoThe idea of a completely read-only router is really interesting. I used to buy hardware that would only work with open firmware -- I used to love to constantly update and mess with DD-WRT. But in more recent years I've just started buying high-performing hardware and skipping the customization beyond SSID and passwords. With faster connections, UPNP, and decent default QoS policies I pretty much never have to configure my access points or routers anymore. I'm pretty sure the average consumer has no desire to configure anything.
- brandonsometig 8y agoUPNP can be an absolute security nightmare however, it's the sole reason so many IP cameras, NAS drives and IOT devices are internet accessible. It's your network of course but it would be the first thing I'd turn off.
- Jonnax 8y agoSure, but if I want to play a game of Mario Kart I don't want to mess around with port forwarding.
- dev_dull 8y agoI don’t know how it’s possible to be read only. It needs to update things like routes and arp tables. That’s exactly the type of stuff that gets poisoned when attacked.