nanog mailing list archives
Re: Default Passwords for World Wide Packets/Lightning Edge Equipment
From: Steven Bellovin <smb () cs columbia edu>
Date: Wed, 6 Jan 2010 20:26:07 -0500
On Jan 6, 2010, at 6:24 PM, Jeffrey I. Schiller wrote:
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 An option I saw years ago (I forgot on whose equipment) was a default password which was a function of the equipment's serial number. So you had to have the algorithm and you needed the serial number which was not related to the MAC. So if you didn't have physical access, you were not in a good position to learn the password. I suspect this was a support nightmare for the vendor and I bet they went to a more standard (read: the same) factory password. At the end of the day, minimizing support costs for the vendor (not to mention likely annoyance for the customer) trumps providing "default" security for the folks who won't change the default password.
The MyFi apparently does this. According to http://www.nytimes.com/2009/05/07/technology/personaltech/07pogue.html "The network password is printed right there on the bottom of the MiFi itself." --Steve Bellovin, http://www.cs.columbia.edu/~smb
Current thread:
- Re: Default Passwords for World Wide Packets/Lightning Edge Equipment, (continued)
- Re: Default Passwords for World Wide Packets/Lightning Edge Equipment Graeme Fowler (Jan 13)
- RE: Default Passwords for World Wide Packets/Lightning Edge Equipment Nathan Eisenberg (Jan 13)
- Re: Default Passwords for World Wide Packets/Lightning Edge Equipment Valdis . Kletnieks (Jan 13)
- Re: Default Passwords for World Wide Packets/Lightning Edge Equipment Joel Jaeggli (Jan 13)
- Re: Default Passwords for World Wide Packets/Lightning Edge Equipment Valdis . Kletnieks (Jan 13)
- Re: Default Passwords for World Wide Packets/Lightning Edge Equipment Jon Lewis (Jan 13)
- RE: Default Passwords for World Wide Packets/Lightning Edge Equipment Nathan Eisenberg (Jan 13)
- Re: Default Passwords for World Wide Packets/Lightning Edge Equipment Barry Shein (Jan 13)
- Re: Default Passwords for World Wide Packets/Lightning Edge Equipment Matthew Palmer (Jan 13)
- Re: Default Passwords for World Wide Packets/Lightning Edge Equipment gordon b slater (Jan 12)
- Re: Default Passwords for World Wide Packets/Lightning Edge Equipment Steven Bellovin (Jan 06)
- Re: Default Passwords for World Wide Packets/Lightning Edge Equipment Joel Esler (Jan 06)
- Re: Default Passwords for World Wide Packets/Lightning Edge Equipment Mark Foster (Jan 06)
- Re: Default Passwords for World Wide Packets/Lightning Edge Equipment Matthew Palmer (Jan 06)
- Re: Default Passwords for World Wide Packets/Lightning Edge Equipment Joe Hamelin (Jan 06)
- Re: Default Passwords for World Wide Packets/Lightning Edge Equipment Dobbins, Roland (Jan 06)
- Re: Default Passwords for World Wide Packets/Lightning Edge Equipment Dobbins, Roland (Jan 06)
- RE: Default Passwords for World Wide Packets/Lightning Edge Equipment George Bonser (Jan 06)
- Re: Default Passwords for World Wide Packets/Lightning Edge Equipment Sean Donelan (Jan 07)
- RE: Default Passwords for World Wide Packets/Lightning Edge Equipment Jason Shearer (Jan 07)
- Re: Default Passwords for World Wide Packets/Lightning Edge Equipment Joe Hamelin (Jan 06)