Simple Attack Against Home Routers

(Image used under: Creative Commons 2.0 [SRC])

Schneier writes about a recent attack against home routers that takes advantage of the fact that most people never change the default passwords on their equipment.

One of his commenters said it best:

It has long been standard security practice that when logging in to a new system with a default password, the first required step is to have the user create a new password. If routers did this and refused to function until a customized password was set, none of these problems would occur.

Or more simply put, it's a problem that would never exist and would disappear tomorrow if router manufacturers would bother to make a simple and practically free programming change before shipping them out.

