5 ms·
Negligent or malicious, no matter which, I would not want to deploy devices that had hardcoded ssh private keys. Default passwords can be dealt with.
by btbuilder 7y ago
Negligent or malicious, no matter which, I would not want to deploy devices that had hardcoded ssh private keys.
Default passwords can be dealt with.
- trickstra 7y agoHow many companies would be left on the market if a default password or hardcoded account or sloppy programming was enough to put them out of business? If we treated them all the same.
- BubRoss 7y agoA default password and hardcoding a private key are two very different things.
- trickstra 7y agoYes, it is. I'm just pointing out that defaul password was a common practice couple of years ago, and one of the companies caught with hardcoded private key is Cisco. If we treated them all like Huawei, we wouldn't have much of the infrastructure left. Which means the whole affair around Huawei is blown out of proportions.