Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You know, I'm actually surprised we haven't solved this particular problem yet. We have autoconfiguration protocols for stupidly complex things, like UPNP. It's a wonder nobody has created either a daemon (to run on domain controllers), or a network appliance, which:

1. heuristically detects unconfigured/default-passworded L2/L3 hardware (e.g. routers) on the network;

2. generates and sets a strong password for that hardware itself;

3. proxies all further access to that hardware, keeping the password only between it and the captured devices (and hopefully delivered only over TLS, if that's possible);

and 4. has actually-sensible security itself (e.g. using SSH keys, HTTPS client certificates, or any other non-repudiatable token type.)

Effectively, it'd act as an automatic password vault and security gateway for all the devices too simple to have good security themselves.



I really like the idea, but if people aren't buying the vulnerability scanning appliances available today (that would just report the open devices), why would they start buying if one was for sale with the value-add you describe?


Because vulnerability scanning is a vitamin, not a painkiller. This type of thing addresses a specific pain--IT having to generate, keep track of, and manage access to[1] device passwords--and just happens to increase security as a side-effect.

[1] This part is important. In most companies, whenever you have a tech leave who knew a password? You've got to reset that password. You might not even know which passwords they knew, so you have to reset everything to be safe. And then the passwords other techs have memorized are invalidated. Incredibly painful.


I can think of at least one product that will do, basically, what you describe. It's insanely expensive to license and setup.

It would probably be feasible to fork the RANCID network device configuration version control application to create something that could do what you're describing out of FLOSS components, too.


So, that would have prevented the Target breach? Makes you feel sorry for the word hack.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: