Updated: 4/4/06; 5:54:47 PM.
Ted's Radio Weblog
Mission: Interoperable. Competition breeds Innovation. Monopolies breed stagnation. Working Well with Others is Good.
        

Friday, January 24, 2003

Sprint DSL's Gaping Security Hole. An easy-as-1-2-3 admin password on Sprint DSL modems puts users' e-mail logins at risk, a hacker finds. Security experts say Sprint's solution -- posting a notice on its support site -- doesn't do enough to solve the problem. By Brian McWilliams. [Wired News] Nonsense. Linksys wireless access points come with security turned off and a default site id of "linksys." Most of the other APs do the same. Software installs with blank or default passwords and the "READ ME FIRST!!!" packaging and files shown to the installer tell the owner to change the setup. OTOH, if you ship with a random password, how do you tell the user? A sticker attached to the device might work. But you can still anticipate the tech support calls will double, and you'll need a new script for your front line support people with "Okay, now look on the package for a bright yellow sticker labeled PASSWORD. You found it. Okay, now..." Reminds me of The Internet Help Desk from Three Dead Trolls in a Baggie. *Sigh* There are no easy solutions.
12:05:20 PM    comment []

© Copyright 2006 Ted Roche.   

Creative Commons License This work is licensed under a Creative Commons License.

  

 

January 2003
Sun Mon Tue Wed Thu Fri Sat
      1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30 31  
Dec   Feb


Click here to visit the Radio UserLand website.

Subscribe to "Ted's Radio Weblog" in Radio UserLand.

Click to see the XML version of this web page.

Click here to send an email to the editor of this weblog.
Blogroll