this post was submitted on 17 Feb 2024
433 points (98.0% liked)

Technology

59777 readers
4723 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 64 points 9 months ago (5 children)

Why is the default setting to enable remote administration?

[–] [email protected] 45 points 9 months ago (2 children)

Because these routers went out to everybody. Tech heads and idiots alike. It is far easier for ISPs to simply remote in than rely on the consumer who may be an idiot.

[–] rdyoung 31 points 9 months ago (1 children)

This is why I run my own router. I'm sure my cable modem has a way in but then you'd have to get past my router.

[–] [email protected] 11 points 9 months ago (1 children)

Ditto. I went one step further and put OpenWRT on mine.

Messed up thing is, some ISPs make it an absolute bitch to make this work.

[–] [email protected] 4 points 9 months ago* (last edited 9 months ago) (1 children)

Yup. I used to think it was malicious by the ISPs but really it’s just all the end technology is kinda A mess for them to have control of the network for you. Which I’m gonna be honest 99.9% of customers NEED. lol

[–] [email protected] 1 points 9 months ago (1 children)

agreed my local area isp switched to calix for most of our customers and it's really nice just to have a management interface to all of our customers and be able to fix it without having to roll a truck

[–] [email protected] 1 points 9 months ago

Yup. It’s never perfect but from a customer to tech support perspective it’s a lot easier for almost all end users. And anyone else can usually figure their own shit out anyways so that’s heavily offered also.

[–] EncryptKeeper 7 points 9 months ago* (last edited 9 months ago) (1 children)

I can’t think of a single ISP that was using old Ubiquiti EdgeOS routers as consumer routers.

[–] [email protected] 2 points 9 months ago* (last edited 9 months ago) (1 children)

So if we're not talking about ISPs sending this out, then the reason that remote access gets turned on by default is incase the company sysadmin couldn't physically get to the device, and they assumed the company had a firewall.

Companies almost always prioritise OOTB setup and operationality over security when it comes to defaults.

[–] EncryptKeeper 1 points 9 months ago* (last edited 9 months ago)

They likely weren’t enabled by default at all. Because that’s generally not how company IT departments even remote manage these things. And the affected devices are the firewalls.

Remote administration was turned on manually, by the owners of these devices, because they didn’t know what they were doing.

[–] IphtashuFitz 16 points 9 months ago* (last edited 9 months ago) (1 children)

20+ years ago I managed the installation of a high performance compute cluster purchased from IBM. Their techs did all the initial installation and setup, right down to using their well known default password of “PASSW0RD” (with a zero for the ‘o’) for all root/admin accounts…. It took less than 20 minutes for it to be compromised by an IP address in China.

At least other vendors like HP use random root/admin passwords printed on cards physically attached to new equipment…

[–] AtmaJnana 11 points 9 months ago (1 children)

When I used to rack and stack servers, many moons ago, we would always connect them to a switch with LAN only so we could use SSH/SCP to harden them before they got exposed. This was for .gov stuff that would get attacked instantly.

[–] [email protected] 15 points 9 months ago

Because without it, the DOJ would have no control over you, duh

[–] EncryptKeeper 4 points 9 months ago* (last edited 9 months ago)

It wasn’t. Remote administration was enabled manually on these devices, and the admin passwords left default.

[–] [email protected] 1 points 9 months ago

Because it was infected with malware from hostile countries.