17 ms·
Raspberry Pi update removes the default user
- londons_explore 4y agoI'm pretty sure the law discourages default passwords. I don't see anything wrong with default users, especially on systems which are usually single-user.
- batch12 4y agoI wonder if removing root is on the roadmap :)
- jimmaswell 4y agoI could easily see the UK trying to ban root access to personal devices.
- djbusby 4y agoWhich law? Oh, this: https://www.bbc.com/news/technology-59400762 https://www.bbc.com/news/technology-59400762
- CamperBob2 4y agoDidn't you hear? Every system has to be designed with full multiuser authentication capabilities. Never mind your threat model or lack thereof. We're all IBM customers now.
- ruined 4y agosite is down for me but there's an archive snapshot https://archive.ph/gxhCC https://archive.ph/gxhCC
- ajsnigrutin 4y agoWtf? So how do I install this headlessly, without needing a separate piece of software (imager?)? I used to just dd the image, touch the 'ssh' file on the boot partition, and then change stuff over ssh.
- _joel 4y agoloopback mount and chroot into the fs, passwd. I'm sure there are probably easier ways though
- ajsnigrutin 4y agoI'm not sure that the arm binary "passwd" will run on x86/_64
- _joel 4y agoAhh yes, there's qemu-arch64 but that's probably another rabbithole :)
- usr1106 4y agoI have used qemu-static a lot to work with ARM images and it works surprisingly well. That was before arm64 was a thing, but unless someone tells me the opposite I would not assume it makes a difference. The only thing that I remember not working is strace(1) because ptrace(2) is unimplemented. But even for that there is a special qemu option to get something similar.
- qbasic_forever 4y agoQEMU and binfmt_misc should do the trick: https://wiki.debian.org/QemuUserEmulation https://wiki.debian.org/QemuUserEmulation
- simongr3dal 4y agoMaybe you can pipe a username and password, or maybe an ssh publickey, into the ssh file and it will create that user? I wouldn’t be too worried, there will likely be a solution for “power users” who use the ssh file.
- shakna 4y ago> There are also mechanisms to preconfigure an image without using Imager. To set up a user on first boot and bypass the wizard completely, create a file called userconf or userconf.txt in the boot partition of the SD card; this is the part of the SD card which can be seen when it is mounted in a Windows or MacOS computer. > This file should contain a single line of text, consisting of username:encrypted- password – so your desired username, followed immediately by a colon, followed immediately by an encrypted representation of the password you want to use. > To generate the encrypted password, the easiest way is to use OpenSSL on a Raspberry Pi that is already running – open a terminal window and enter echo 'mypassword' | openssl passwd -6 -stdin > This will produce what looks like a string of random characters, which is actually an encrypted version of the supplied password. From the anouncement [0], under "Headless setup". [0] https://www.raspberrypi.com/news/raspberry-pi-bullseye-update-april-2022/ https://www.raspberrypi.com/news/raspberry-pi-bullseye-updat...
- deleted 4y ago[deleted]
- vault 4y agoI thought it was still April 1st
- alar44 4y agoGood. 8ish years ago, I wrote a script to search out Pis with port 22 opened to the internet with default un and pw. Let it run overnight. The next morning I checked the log and it found thousands of Pis that I could have just logged into with root privileges if I wanted. Never trust users.
- jbaczuk 4y agoI know you logged in to some of them... :)
- teaearlgraycold 4y agoCareful now. That's a felony.
- simondotau 4y agoPhew, good to know my Pi is safe from meddling Americans.
- teaearlgraycold 4y agoThrow some US legalese in the SSH MOTD.
- deleted 4y ago[deleted]
- exfascist 4y agoLol I thought I was being bad just shoulder surfing for ssh commands.
- abnry 4y agoHow can you know that they had the default un and pw without logging into them?
- alerighi 4y agoThis is good because I always ended up removing the defualt user and creating another or just using root. You can always mount the SD card partition and put your ssh key into /root to log in with that. An improvement could be to also load ssh key from the /boot partition so also windows/mac users could do that easily. By the way using root with an ssh key is fine and not a problem in terms of security.
- imoverclocked 4y agoThis would be a great option. The first run script could easily do that too. If you wanted to make some users really happy, support a hook script in the same way. /boot/first-run.sh — or something to that effect
- wanderer_ 4y agoNow it's just a matter of time before I start losing installs because I can't remember passwords...
- MarkusWandel 4y agoThe FS is not encrypted. So just plug the SD card into another computer and edit the password file to replace the encrypted password with a null string.
- sofixa 4y agoOr just boot into rescue mode ( e when it asks which kernel you want to boot with, and append init=/bin/bash ; on newer OSes there's a special systemd rescue mode but no idea if it's present on Raspbian).
- Karellen 4y agoWait, is this an update to the OS, or an update to the installer? If I upgrade my existing Pis, are the currently in-use `pi` users (which have non-default passwords) going to be removed? About half the article makes it sound like it's an OS update, but the other half makes it sound like an installer update, and there's a big difference between those two scenarios.
- LeoPanthera 4y agoThis is an update to the OS image, which adds a first-run script prompting you to create a new user. Existing installations will not be affected. Raspberry Pi OS does not have an "installer".
- 542458 4y agoIt has an graphical imager tool that presents options for configuration onto your SD card - I feel that it’s fair to call that an installer.
- 0des 4y agoIts not though, something else is already named that, and it doesn't have one
- TheDesolate0 4y agoYeah. That's an installer. An installer is a script/program which helps the user install the software, in this case the OS is the software.
- MarkusWandel 4y agoWell, at least the default, non-expert install of the Raspi OS doesn't enable ssh logins.
- op00to 4y agoDamn, I’m so used to googling default passwords for stuff. Now I gotta remember my own?
- edgyquant 4y agoSounds like you’re exactly who this designed for, because that’s a huge security hole.
- FeepingCreature 4y agoDisagree. If someone is already in my LAN, that they can access my OctoPrint is not really my primary concern.
- suyula 4y agoThe ol' LAN-to-houseburning elevation of access.
- FeepingCreature 4y agoI mean, if you're in my LAN you almost certainly got there via my desktop, so you can just keylog my desktop or grab my private keys. So, again, who cares? Not having a default password adds zero security to my RPi. Is a significant fraction of RPis really deployed to the public internet with default passwords?
- exfascist 4y agoThey should have just removed the password. Default passwords are braindead. Default users really aren't that bad. Fun anecdote: I used to log into people's Pis in college and show them that they needed to change the password. People don't react nicely to that.
- op00to 4y agoAt my company pre-COVID if you left your pc unlocked, you’d get your nickname changed in chat to a specific code word so everyone knew you messed up.
- behringer 4y agoThese are all great ideas until one of your coworkers does something nefarious and claims they were just putting a silly nickname if they get caught;)
- hotpotamus 4y agoThese are a soft hazing ritual to remind you of good security practice to prevent anything nefarious from happening.
- speed_spread 4y agoOur trick was to use the unlocked account to message everyone on the general slack channel that we would bring donuts the next morning. The account owner was expected to commit to that.
- dividedbyzero 4y agoWhat a great trick. You make an (effectively) inconsequential oversight, now you have to work for free for hours to days (pizza and drinks for 50-ish people was the worst I've seen), that's so clever. The best part has always been when they try to harass people into complying, especially the low-paid people with kids. /s I'm glad I haven't worked at a place that had such informal "policies" in a while. There have been a few attempts by twenty-something engineers with no commitments to establish such rules, but the culture wasn't that toxic, so they (politely) got told to shut up, and that was that. People's desktop background still get changed sometimes, but respecting people's boundaries goes a long way to make work bearable for everyone. And even with desktop background pranks, if in the slightest bit unsure, communicate beforehand and accept a "no". And don't do what one guy at another company did and use a homophobic meme right before their victim's demo call with an important customer, or you deserve everything that happens afterwards.
- tzs 4y agoThe BBC article that the submitted article cites says of the law requiring this: > Included within its scope are a range of devices, from smartphones, routers, security cameras, games consoles, home speakers and internet-enabled white goods and toys. > But it does not include vehicles, smart meters and medical devices. Desktop and laptop computers are also not in its remit. Wouldn't an RPi be considered to be a desktop computer?
- StillBored 4y agoWhy does the RPi still have its own OS? The major linux distros have been doing this for years in their installers/disk images. It seems like just about every week they announce a feature that already works everywhere else. Its sorta like all the "I got a ssh server running on my Pi articles". Not at all noteworthy, except for the fact that the machine is by default quite dysfunctional. So it was yet another reason for the RPi foundation to stop being stupid, and just conform their firmware to SystemReady, and post their fixes upstream. All these custom hoops they keep jumping through to duplicate what every other OS/firmware already supports just speaks to bad mgmt. So, yah they are the most successful Arm sbc vendor, and this all made sense 10 years ago when none of the distro's had working arm ports and there wasn't much in the way of standard arm system architecture. Those days are long gone, and the people clinging to them are just sticking their head in the sand. Particularly since 3rd parties have basically done 3/4 of the work for them and ported a full blown UEFI/ACPI environment to the darn thing. So, they need to put on the big boy pants and stop playing the NIH game.
- kelnos 4y agoThis doesn't answer the question of why RPi has its own OS, but I don't want to have to run an installer every time I put an OS on a RPi's SD card. I just want to write a disk image, `touch /boot/ssh` on it (so ssh gets enabled on first boot), and then have a fully-functioning system to ssh into.
- jrockway 4y agoYou're the installer in your system. You're doing the exact same thing the official installer does, but the installer has buttons for people to click.
- unfocussed_mike 4y agoYou can now do all of that SSH configuration from within the Raspberry Pi Imager (there's a hidden control panel)
- unfocussed_mike 4y ago> Why does the RPi still have its own OS? Because it's not aimed at the general purpose computer market? The OS -- the features, the documentation, the learning focus, the ease-of-use planning, the designed support for school and code clubs -- is part of the product. It's not just a little cheap linux box for nerds; it has a different focus. Also the hardware itself is different, is it not? It has (for example) no battery-backed clock. It has connectors other distros cannot be expected to support (CSI for example). They achieve all of this with their own slice of Debian; it's as close to being standard as is sensible. They also provide a tool -- pi-gen -- to allow you to roll your own distro off the main; it's quite effective. And they have a mainline OS (Ubuntu) if you want that. But if you really want a tiny SBC without their OS platform -- buy one.
- jimmaswell 4y agoIt feels like a continuation of the anti-self-determination trend of putting rounded corners and foam padding on everything. No passwords allowed on github, no running x program as root, make it as hard as possible to add unapproved browser extensions, etc. and now the raspberry pi has to be less convenient to set up to protect people who don't care enough to know what they're doing from themselves. I hate it.
- p1necone 4y agoThis seems like a perfectly sensible change that will enhance security without any real downsides. Take off your tinfoil hat.
- userbinator 4y agoIt's the general trend of paternalism, and I find it deeply irritating too.
- imwillofficial 4y agoYour irritation at something trivial vs the hours spent recovering from and defending from attacks is a balance I’m ok with.
- FeepingCreature 4y ago"Let's irritate everyone by denying them making their own choices so we can be protected from the mistakes of stupid people" is pretty much the definition of paternalism.
- youngNed 4y ago"Let's irritate everyone by denying them making their own choices" thats an incredibly strange take, like that is literally the complete opposite of what is happening
- 4y ago
- aorth 4y agoThat's an interesting solution. Good luck, future Raspberry Pi users! I know this will make it a little more difficult for the less technical to get their Pi units set up. I can confirm that I have dozens of public Linux servers with SSH exposed and user `pi` is constantly being attempted for login. I ban them all immediately and automatically.
- chmod775 4y ago> In 2017, for example, hackers stole data from a US casino via an internet-connected fish tank. What can I possibly say to make this funnier.
- 2000UltraDeluxe 4y agoRemember Watch Dogs, where you tunnel from device to device to device in order to gain access to stuff normally out of reach? I remember I thought it being too unrealistic. Now, it's just an IoT/outdated device software thing.
- bigDinosaur 4y agoIsn't this a very standard method of exploitation that competent pentesters test for?
- sofixa 4y agoYep. But in theory you shouldn't have your fish tanks and production systems with real world data and money on the same network.
- actionfromafar 4y agoIt's standard, but what is new is there are so many more random devices which can be potentially used, instead of servers and PCs.
- aqfamnzc 4y agoIt always bothered me that in order to connect from camera to camera you had to have line of sight. As if that would matter when exploring a network
- blippage 4y agoAn old firm I worked for had their router switch in the toilet. Not literally /in/ the toilet you understand, but above it, on a shelf. Was that really the only solution they could come up with, I wonder?
- vorticalbox 4y agohttps://web.archive.org/web/20220408000607/http://deepaqua.me/2022/04/07/the-pi-user-is-dead-long-life-the-pi-user/ https://web.archive.org/web/20220408000607/http://deepaqua.m...
- qwerty456127 4y agoOne of the minor things I like the most about Raspbery Pi is it has the default user. Since the days desktop OSes (i.e. Windows 2000 Professional) first started to demand the user to name themselves and sign-in (which didn't protect their data anyway and still doesn't protect today as Windows Home doesn't include BitLocker) I hated this useless complexity. I in fact met many hundreds of PC users and just a minuscule fraction of them (also of those sharing a PC among a number of family members) used an actual multi-user set-up. Linux seemingly did this from the very first day because it's non-PC Unix legacy. Once I tried Raspberry Pi I felt a pleasant relief: it never asked (although allowed) me to personalize it and just worked. I didn't have to invent a nickname nor expose my real name. It was just a handy tool like in good old days when you didn't have to connect your oven to WiFi. PS: I do understand how useful the OS's multi-user mechanism is to limit what untrusted app instances can do.
- nonsince 4y agoI think you have a misunderstanding of what the change is and what the previous situation was.
- qwerty456127 4y agoI probably do. The actual page won't open (there is a Cloudflare error) and the title is all I know.
- gpvos 4y agohttps://archive.ph/gxhCC https://archive.ph/gxhCC
- nonsince 4y agoGood, but frankly it’s pretty embarrassing for them that it took the threat of a multi-million pound fine before they made this change.
- nottorp 4y agoSo I can't set up a headless Pi any more without using that imager tool?
- jdubb 4y agoJust yesterday I've been flashing Raspberry OS to a micro SD card. Not succeeding with Balena Etcher, I opted to use the RPi imager tool, which did work (which might be an issue not in any way related). After that I added the `ssh` file to the boot partition and tried connecting to it via SSH. Providing username pi and password raspberry, connecting fails with invalid password, no matter how many times I tried. Searching all over the internet for whether the password was different nowadays, but coming up with zip, frustrated, I went to bed. Reading this today it hits me that this change might just be the cause. If that turns out to be the case, there should really be some indication in the RPi imager tool.
- jamhan 4y agoThere are/were issues with using the rpi-imager [1] under Windows, which would result in the configuration information not being written to the memory card. They claimed to have fixed it, but it never worked for me. Instead, I downloaded a live Linux dist, kde-neon [2], wrote that to a USB stick with rufus [3], booted my PC with that, and imaged under Linux. Only then did it work. [1] https://github.com/raspberrypi/rpi-imager https://github.com/raspberrypi/rpi-imager [2] https://neon.kde.org/download https://neon.kde.org/download [3] http://rufus.ie/en/ http://rufus.ie/en/
- amelius 4y agoIs this a law in UK only? Do EU and US have something similar?
- air7 4y agoI don't know, I seem to be in the minority according to the comments here, but I like my default credentials, thank you very much. I have tons of gear laying around, some of which is collecting dust in a drawer, and if the default creds don't work I might be in a bind because I'm not organized enough to "do it right". These devices are not open on the internet, obviously, and per my threat model, anything on my local lan is deemed safe. More importantly perhaps, I am willing (and actually want) to have the freedom to do this, and to take responsibility for any problems I might cause for myself. This issue is part of a more general ethical conundrum spanning many areas of life: How much should people be protected from themselves? I guess my personal answer is, not a lot.
- exfascist 4y agoIf they had simply removed the default password entirely without removing the default user both groups would be satisfied. It's not clear to me why they removed both.