5 ms·
> There are legit reasons to have a router be publicly accessible. No, there are not. > How else would one remotely manage a router Over a WireGuard connecti
by larvaetron 5y ago
> There are legit reasons to have a router be publicly accessible.
No, there are not.
> How else would one remotely manage a router
Over a WireGuard connection to a secure management network.
> The only real issue would be using a default password
Uh, no. Try any number of CVEs or 0-days or unknown-until-it's too-late vulnerabilities, depending on what web daemon/frameworks are used by the router's management software.
- ohyeshedid 5y agoEven if all of that is updated and secure; with the services exposed, it's less than trivial to make that service eat the small amount of memory it has to work with, and take down the network it manages.
- closeparen 5y agoWhy is exposing a web service considered so much worse than exposing a VPN service? WireGuard is respected for low complexity and high quality, sure, but what prevents a web server from having the same characteristics? And there are plenty of VPN services whose huge public surfaces turned out to be vulnerable, why is running one of these any less crazy than running nginx?
- code_duck 5y agoOne problem is the software on the router is likely to be outdated and vulnerable, and upgrades are not under your control.
- closeparen 5y agoIsn't that equally as true of a VPN service as of a web service?
- code_duck 5y agoThe issue at hand is which hardware device is exposed to the external network, not which software.
- SturgeonsLaw 5y agoI would (and do) place more trust in a battle-hardened VPN than a router web interface that's designed for local access. Additionally, Wireguard (to pick a favourite) listens for connections on a specific port, and only opens a tunnel if it's presented with the correct string, otherwise it's completely silent, an attacker wouldn't even know it was there. These routers are presenting a full web server and the web UI to an attacker.