NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
prodport
Oct 17, 2019Initiate
Why isn't ORBI Login Secure
I like the product but why is the browser login for Orbi insecure? (http://orbilogin.net/adv_index.htm). IF I change to HTPPS I get a different error. I don't use the phone app becasue I find t...
- Feb 14, 2020
willemdh wrote:
HTTPS is really important and should also be enabled inside the network. otherwise the password used when logging in, can easily be sniffed by bad actors..
Please add this feature asap...
Done!
It works already. The ugly thing, however, is that Netgear has totally messed up the SSL Certificate on the Orbi line, so modern browsers like Chrome will complain, "The Cert is bad. Don't go there! Oh, no. The sky is falling."
Try it for yourself: https://orbilogin.net. Just ignore the warnings and proceed to the Orbi Home Page. Works great!
FURRYe38
Oct 17, 2019Guru - Experienced User
One issue is that there are certificates that need to be on local devices that would need to be effected for HTTPS to work on any router web page. Most router mfrs don't or probably won't try to support this as this would take more resources and support and with all kinds of various devices, PCs and browsers, this could be a monumental case to solve for just accessing a routers web page with https. Something until something gets exposed with using HTTP on the LAN side of the routers web page, just hasn't been a problem up to this point. Unless you have a known trouble maker on your LAN side, it's something thats not critical. I've never seen any problems stemming from use of HTTP with a routers web page yet.
Those router MFrs that do well, thats good as well. I would be nice if we could use either mode however.
CrimpOn
Oct 17, 2019Guru - Experienced User
I think this is the whole point of the "certificate" issue. Netgear has implemented encrypted web access on the Orbi and included a certificate that was good from August 2, 2016 to August 2, 2019. (Remote Access requires using https.) So, yes, they shipped thousands of products that all had a valid security certificate. Their failure to anticipate the certificate expiring and getting a new certificate out to the routers is what has caused so many web browsers to complain since August 2.
- FURRYe38Oct 17, 2019Guru - Experienced User
Agreed, thats the other thing. NG needs to update the current certificiate.