Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Wait.

Do I understand this correctly? Are you saying you removed that root password, such that it wasn't possible to log in with another (but different) root password?

Or are you saying that you merely changed it, to one the customer no longer knew, but was the same password across all of your install base, for every customer?

How would that be any improvement, if the latter?



It was at that moment a simple change of the password. The benefit was that people outside of our company wouldn't have access (thus not sharing it further), and then as a future improvement we could have implemented some better key scheme. But while customers want to have root access it is not an option.

Theoretically we could implement a scheme with individual passwords or keys per device (as someone suggested in the comments above), but such thing is not being prioritized by our company, so that's our fault.


The right scheme would be to require the user to set their own password on first login, and require that to happen before the device would work.


Jesus fuck.

This isn't a Latvian company, by chance, is it? Blink twice if yes.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: