• Fizz@lemmy.nz
    link
    fedilink
    arrow-up
    4
    ·
    10 days ago

    There is a business I walk past every day and when you look in the window you can see wifi login creds and her name and password. Ive considered saying something but then I’d have to explain why they shouldn’t do it and argue with them that its important.

    Plus they’re property managers so i would laugh if they got hacked.

    • squaresinger@lemmy.world
      link
      fedilink
      arrow-up
      3
      ·
      10 days ago

      There was a common issue with a local ISP that their default wifi router passwords were based on the router’s MAC address.

      I scanned the wifis I could reach from my flat and found one that was vulnerable. Now I didn’t know who that wifi belonged to. I would have had to knock on everyone’s door, asking everyone if it’s their wifi. Couldn’t be bothered doing that and looking stupid doing so.

      So instead I logged into their wifi and from there into their router config web page (it also had the default credentials admin/admin) and changed the SSID to [old SSID]_hacked.

      The day after they had changed the SSID back and changed the password.

      • Trainguyrom@reddthat.com
        link
        fedilink
        English
        arrow-up
        0
        ·
        10 days ago

        The real problem is there’s not really a better solution that works well for private accounts owned by individuals who only have a single device.

        They say that authentication is using either something you know, something you have or something you are, but in the real world it ends up being something you’ve forgotten, something you’ve lost and something that you were at one time but are no longer

          • Trainguyrom@reddthat.com
            link
            fedilink
            English
            arrow-up
            0
            ·
            9 days ago

            Passkeys rely heavily on at least one device remaining authenticated. You have to remember, the average user of a given web service does not have an ISP, they literally only have their phone and maaaaybe a decade old laptop that they haven’t turned on or charged since ordering plane tickets pre-pandemic. It is critical that any solution replacing passwords has to work for this average user who literally only has their current phone and trades in their phone every 1-4 years for another one, therefore they do not have a second authenticated device to verify when they get a new phone or their phone breaks and they buy a new one at the carrier store.

            I’m happy to be proven wrong, but from my understanding of how passkeys are implemented, they will either lead to account lockout or rely on less secure authentication methods if the only authenticated device becomes inaccessible/inoperable

            • tyler@programming.dev
              link
              fedilink
              arrow-up
              1
              ·
              8 days ago

              If you use a password manager it’s literally no different than passwords. I can use my passkeys on any device through 1Password.

              • Trainguyrom@reddthat.com
                link
                fedilink
                English
                arrow-up
                1
                ·
                7 days ago

                Okay so if the sites actually give you the passkey to manage that’s not as bad as what I remember reading about when passkeys were first announced