4 ms·
All but one make for an undesirable UX during initial setup before WAN is up, which is probably the only time most users login to their router.
by berti 7y ago
All but one make for an undesirable UX during initial setup before WAN is up, which is probably the only time most users login to their router.
- vbezhenar 7y agoYeah, that's why I think that movement to HTTPS everywhere must at least exclude private IP addresses. While it's expected to have HTTPS on public resources, what happens in my local network is my business and should not be considered insecure.
- ajsnigrutin 7y agoThe problem is, that someone setting up a public wifi (in a restaurant for example), will be vulnerable to sniffing attacks (if they don't know what they're doing).
- franga2000 7y agoSo get a cert before setting up wifi. This is not a hard problem. 1. Connect to AP with random key from the box 2. Open admin panel over HTTP 3. Follow instructions to get Internet access 4. As soon as it has a connection, the router obtains a cert and redirects you to HTTPS 5. Now you can make all your poor security decisions
- Terretta 7y agoHave you met ‘normals’? Everything is a hard problem if it’s any steps at all.
- franga2000 7y agoI meant that "how to make router setup secure without making it more difficult" is not a hard problem. My system is no more difficult than the currently most common ones and about as secure as it gets. Although, one could argue that setting up a router really shouldn't be left to people who don't understand how they work...