{"id":2132,"date":"2009-08-02T15:26:10","date_gmt":"2009-08-02T19:26:10","guid":{"rendered":"http:\/\/blogs.n1zyy.com\/n1zyy\/?p=2132"},"modified":"2009-08-02T15:26:10","modified_gmt":"2009-08-02T19:26:10","slug":"default-passwords","status":"publish","type":"post","link":"https:\/\/blogs.n1zyy.com\/n1zyy\/2009\/08\/02\/default-passwords\/","title":{"rendered":"Default Passwords"},"content":{"rendered":"<p>When you build a piece of hardware with a web management GUI, you&#8217;ve got to set a default password. Otherwise no one could get into it.<\/p>\n<p>The problem is that it seems not many people bother to change it. If you know the model of the thing you&#8217;re trying to connect to, there&#8217;s probably a greater-than-50% chance that you can Google &#8220;modelname default password&#8221; and get in. Things that people might not normally think of logging into, like VoIP phones, network printers\/copiers, and network infrastructure, are generally left wide open.<\/p>\n<p>There&#8217;s a fairly easy way to solve the problem, though: make the default password be the device&#8217;s serial number. This isn&#8217;t infallible, since you know the password will fall within a certain range, but it makes getting in much harder. For those who want to set the password, they need only see the big label saying &#8220;Serial Number \/ Default Password: ABC123XYZ&#8221; or read the manual. And for the 75% of people who never bother, they won&#8217;t be insecure by default.<\/p>\n<p>As an alternative, for things that require setup before they work, demand that a password be set before networking is enabled. The problem with this is that most people will probably use &#8220;password&#8221; to get past the screen, with some thinking &#8220;I&#8217;ll set that later, but for now I want to get this up and running,&#8221; and most never thinking twice.<\/p>","protected":false},"excerpt":{"rendered":"<p>When you build a piece of hardware with a web management GUI, you&#8217;ve got to set a default password. Otherwise no one could get into it. The problem is that it seems not many people bother to change it. If &hellip; <a href=\"https:\/\/blogs.n1zyy.com\/n1zyy\/2009\/08\/02\/default-passwords\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-2132","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/blogs.n1zyy.com\/n1zyy\/wp-json\/wp\/v2\/posts\/2132","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.n1zyy.com\/n1zyy\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.n1zyy.com\/n1zyy\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.n1zyy.com\/n1zyy\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.n1zyy.com\/n1zyy\/wp-json\/wp\/v2\/comments?post=2132"}],"version-history":[{"count":0,"href":"https:\/\/blogs.n1zyy.com\/n1zyy\/wp-json\/wp\/v2\/posts\/2132\/revisions"}],"wp:attachment":[{"href":"https:\/\/blogs.n1zyy.com\/n1zyy\/wp-json\/wp\/v2\/media?parent=2132"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.n1zyy.com\/n1zyy\/wp-json\/wp\/v2\/categories?post=2132"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.n1zyy.com\/n1zyy\/wp-json\/wp\/v2\/tags?post=2132"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}