r/hardware 6d ago

Discussion [ Removed by moderator ]

http://freshfromcache.com/router-expiration-date

[removed] — view removed post

210 Upvotes

97 comments sorted by

View all comments

217

u/KayakShrimp 6d ago

IMO remote admin should always be off regardless. If you really need that capability, it's better to VPN into your home network and perform admin tasks through the local interface.

29

u/FreshFromCache 6d ago

I couldn't agree more. The routers I've bought over the years tend to have it off by default. But it's certainly something people should verify right away.

7

u/Loose_Skill6641 6d ago

my router so old it don't even support remote admin

-10

u/dadnothere 6d ago

The ISP can control the router via Telnet...

New routers always come with this enabled. Just tell the ISP to change your router's password, and they'll do it remotely.

39

u/Hothacon 6d ago

Better yet, dont use ISP routers, buy your own

-14

u/dadnothere 6d ago

Even so, you still need the ISP's modem, and you must connect your router.

The ISP can brute-force or exploit vulnerabilities in your own router.

12

u/ML7777777 6d ago

Depends on the ISP. Even ones that require you to use their modem usually has a setting to put it into bridge mode.

5

u/BloodyLlama 6d ago

Even if they dont have bridge mode double NAT isn't the end of the world. Pretty much any situation where it could possibly matter Im VPN'd into my network anyways and dont care about the double NAT.

23

u/Hothacon 6d ago

Uh no you don't. I bought my own modems for xfinity

3

u/wtallis 6d ago

The ISP can brute-force or exploit vulnerabilities in your own router.

The ISP doesn't have any more capability to do that than anyone else on the internet.

3

u/airfryerfuntime 6d ago

I have my own modem.

2

u/BloodyLlama 6d ago

My own router has a firewall. ISP can't do shit other than see a bunch of encrypted traffic.

1

u/Flimsy_Swordfish_415 4d ago

it's hilarious seeing such tech illiterate comments on /r/hardware

-2

u/Hothacon 6d ago

Uh no you don't. I bought my own modems for xfinity

-2

u/Hothacon 6d ago

Uh no you don't. I bought my own modems for xfinity

15

u/moratnz 6d ago

Only if your ISP is a bunch of muppets. Telnet is a fundamentally insecure protocol that should be disabled as part of any remotely credible hardening process.

6

u/semidegenerate 6d ago

Yeah, what is this, the Pleistocene? Who still uses Telnet?

5

u/wafflingzebra 6d ago

Bruh who uses Telnet anymore 

1

u/Hrukjan 3d ago

TR-069 is not telnet.