× Introducing the Orbi 970 Series Mesh System with WiFi 7 technology. For more information visit the NETGEAR Press Room.
Orbi WiFi 7 RBE973
Reply

Serious Login Security Question???!!!??.

Rubikscube
Aspirant

Serious Login Security Question???!!!??.

I am a newbie here and I am seeking assistance from those of you with more experience on this subject.       

When logging into my routers settings today utilizing the 192.168.1.1 to gain access, I noticed the following message:

 

" YOUR PASSWORD WILL BE SENT UNENCRYPTED."

 

User Name -

Password-

 

Is it me, or should it say Encrypted?  

 

 

Message 1 of 5
Razor512
Prodigy

Re: Serious Login Security Question???!!!??.

You can use either a http connection or an https one. By default if you just type in the router's IP, it will simply use the unencrypted connection, but you can force a secured one, though your browser will warn you about the self signed certificate.

 

Often if you are on your local home network, it is unlikely for someone to be trying to capture that traffic.

If they have that level of access, then your network and devices are likely already deeply compromised.

 

Message 2 of 5
Rubikscube
Aspirant

Re: Serious Login Security Question???!!!??.

Thank you for your reply, It appears that you have much experience in this matter. 

your last sentence though was very troubling and I am hoping you can assist further.

 

1-How would i be able to determine if that was the case?

2- I read elsewhere that when routers are compromised, things like the "DNS" settings as well as other things are changed. How do I determine this?

Message 3 of 5
Razor512
Prodigy

Re: Serious Login Security Question???!!!??.

It was more of pointing out why it is not as much of a concern to not use HTTPS over the LAN to the router on a home network.

If you are not sharing your network with someone you do not trust, then it is not too much of a concern since for the unencrypted connection to be expired, an attacker will need to already be on your LAN, e.g., physically connected to the router, or at least connected to the WiFi and then attempt to do an ARP poison attack in an attempt to capture the traffic related to the unencrypted login.

Assuming you have a decently strong WiFi password, cracking it will be extremely difficult, especially since even with WPA2, you cannot really have a set of precomputed hashes to speed up the process.

If one of your computers is compromised to allow for remote access, then the attacker already has a level of access that would make HTTPS meaningless at least for that system, since they will have essentially have access to info before it is ever encrypted.

It is unlikely that any of this has happened with your network, thus unless you are sharing your network with a bunch of people who you do not want accessing the router's web UI, and you suspect they will attempt to intercept traffic on the network in an attempt to gather the admin login, then there is not much of a need to go out of your way to use the HTTPS page.
Message 4 of 5
Rubikscube
Aspirant

Re: Serious Login Security Question???!!!??.

Wealth of information. Thank you.

Message 5 of 5
Top Contributors
Discussion stats
  • 4 replies
  • 1044 views
  • 2 kudos
  • 2 in conversation
Announcements

Orbi WiFi 7