this post was submitted on 03 Jan 2025
33 points (100.0% liked)

Pulse of Truth

519 readers
48 users here now

Cyber Security news and links to cyber security stories that could make you go hmmm. The content is exactly as it is consumed through RSS feeds and wont be edited (except for the occasional encoding errors).

This community is automagically fed by an instance of Dittybopper.

founded 1 year ago
MODERATORS
 

Misconfigurations remain a popular compromise point — and routers are leading the way. According to recent survey data, 86% of respondents have never changed their router admin password, and 52% have never adjusted any factory settings. This puts attackers in the perfect position to compromise enterprise networks. Why put the time and effort into creating phishing […] The post Router reality check: 86% of default passwords have never been changed appeared first on Security Intelligence.

top 4 comments
sorted by: hot top controversial new old
[–] d00ery 4 points 3 days ago (1 children)

Aren't routers usually provided with random default passwords these days?

[–] [email protected] 3 points 3 days ago

Usually is a strong word, I'd be surprised if it was over 50% of current models

[–] [email protected] 2 points 2 days ago

The old AT&T router I had came with a pretty obscure SSID password on a label printed on the side of it. The admin password was also a mix of punctuation and mixed case alphanumerics. I saw a neighbor's router and it's SSID password was different. So if these were being machine generated and set, that means there's some sort of service access and port into the router from AT&T's side.

Comcast Business Router, however came with a fixed username and password which I had to change when I set it up. I can't imagine a non-techie person going through this step.

[–] [email protected] 2 points 3 days ago

Anyone got a list of default passwords handy?