- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
Re: Unencrypted dashboard Login. No https!
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Unencrypted dashboard Login. No https!
How is this secure? What is the problem to enable HTTPS please! All other routers do this. It's almost 2018.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Re: Unencrypted dashboard Login. No https!
Doh.. I do see that in a browser:
Your connection is not private
Attackers might be trying to steal your information from 192.168.1.1 (for example, passwords, messages, or credit cards). Learn more
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Re: Unencrypted dashboard Login. No https!
Just another user.
My network DM200 -> R7800 -> GS316 -> PL1000 -> Orbi RBR40 -> Orbi RBS50Y -> RBS40V- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Re: Unencrypted dashboard Login. No https!
> How is this secure?
How is it vulnerable? If all the unencrypted traffic in on your LAN,
where's the threat? For remote access, I'll admit that it's sub-ideal.
> I guess these do not want to deal with SSL certs on the main admin
> interface?
That'd be my guess, too. With all the firmware bugs I've seen in
these things, securing the Web server would not be my first priority.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Re: Unencrypted dashboard Login. No https!
I agree the threat is minimal on one's LAN . But in a congested neighborhood one must assume there could be teenagers? trying to sniff the wifi. Its really just good security practice.
In the same way NetGear runs telnetd on these for getting in on the command line vs
ssh.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Re: Unencrypted dashboard Login. No https!
This is besides the Samba share weaknesses that Nessus points out on my X6 amongst 4 or 5 other known issues I never expect Netgear to solve. BUT this one (not using https) IS solvable! And if turning on https needs to be a selectable option because Netgear is worried about browsers showing the cert isnt a valid cert according to 3rd party standards, then put the option to turn on HTTPS in the advanced menu area and mention that browsers may warn users of cert validity and that we can ignore it as TLS1.2 encryption will still be active.
Secondly, I don't care if you personally are willing to take the risk. I don't want plain text user and passwords sent inside my network. If I had a better choice I would probably rethink my choice of routers. But Netgear does offer some solutions to issues I have for an affordable price. For now I can't choose a different product.
It's not difficult to solve and if you are fine with it, why are you in this post commenting? Its my problem not yours right? Please don't spread false information stating how it doesn't matter for something you don't even care about. It matters to me and I stated my case clearly.
Thanks.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Re: Unencrypted dashboard Login. No https!
Ouch, I didnt mean to offend or spread false information. I apologize for posting in your thread. Let me see if I can delete my post.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Re: Unencrypted dashboard Login. No https!
I asked the moderator to delete my post. I apologize for posting in your thread.
I do see how my post comes across as declaring its ok... its really not. Heck I did not even see an option on my R7000 or 7800 that would allow the admin UI on a wired connection only.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Re: Unencrypted dashboard Login. No https!
Don't worry. This is a community forum. No one owns it, not even Netgear in the final analysis.
You are free to say what you like, preferably politely. It is only through discussions like this that we learn the intricacies of these things, and that some people have different approaches to security. Some are so paranoid that you wonder why they ever go on line. Others are so laid back that you wonder how they last more than a few minutes before someone hijacks their systems.
It didn't help that the original message was based on a misconception. But hopefully we have all learned something.
I have just remembered where I read that Netgear is getting ready to implement https (see above). I think it was in one of those messages in the "feature request" zone. Sadly, the only discussion I can find has this assigned to "Engineering Investigation".
Just another user.
My network DM200 -> R7800 -> GS316 -> PL1000 -> Orbi RBR40 -> Orbi RBS50Y -> RBS40V- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Re: Unencrypted dashboard Login. No https!
Yes. I am a paranoid Security Engineer.
Sorry
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Re: Unencrypted dashboard Login. No https!
Quite right too.
You've done the best thing by raising it in the "suggestions" bit of this forum. Here it will just get mixed up with issues about getting a router to work.
Modems/Routers : Add HTTPS when connecting to the ... - NETGEAR Communities
Not sure that you have said as much there as you have here.
Just another user.
My network DM200 -> R7800 -> GS316 -> PL1000 -> Orbi RBR40 -> Orbi RBS50Y -> RBS40V- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Re: Unencrypted dashboard Login. No https!
https://techcrunch.com/2017/10/16/heres-what-you-can-do-to-protect-yourself-from-the-krack-wifi-vuln...
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Re: Unencrypted dashboard Login. No https!
Hi CyberTri,
NETGEAR has released a KB article for Krack issue.
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Re: Unencrypted dashboard Login. No https!
Thanks.