• Free CIO-level whitepapers



    [ad] Check out these whitepapers published by IDC and HP to help you make tough decisions about your IT environment.

    Leveraging the Always On support experience for IT transformation: This IDC whitepaper outlines the importance of support services in IT environments. IT organisations are now required to support everything from legacy systems and storage to virtualised configurations and cloud-based computing in complex, heterogeneous environments. The increasingly critical role of vendor-supplied external support services is discussed and highlighted in addressing these emerging IT environments going forward.

    Conquering the challenges of data center complexity: Virtualisation and cloud are two popular IT trends that lower costs and make computing more secure and efficient. However, they also add complexity. Read this thought leadership paper and learn new ways to conquer your data center complexity challenges.

  • Great articles on other sites
  • RSS Delicious/delimiterau


  • Save up to $200 on ThinkPad laptops



    [ad] Lenovo ThinkPad Edge laptops boast best-in-class voice and video conferencing capabilities to help you stay in touch and HDMI, stereo speakers and a HD screen to keep you entertained on-the-go. Grab this coupon and save up to $200 each on each laptop.

  • 5 months FREE on phone system rental



    [ad] Rent a new phone system and connect your phone lines with Commander to receive 5 months rent free. Why rent with Commander?

    -Tailored complete solutions
    -Great offers from leading phone system brands
    -Rental & communication on a single bill
    -Renting systems conserves cash flow

    Hurry – act before 30 June!
  • News - Written by on Wednesday, February 23, 2011 10:40 - 22 Comments

    BoB security is ‘standard practice’, says iiNet

    National broadband provider iiNet this week said the default setup of its new BoB Lite ADSL router – which leaves its Wi-Fi functionality open and the device’s administration password publicly available – was “standard practice” used by router manufacturers.

    “… your network is laid bare for the world to access. iiNet concedes this point with a slim leaflet in the box that suggests you set up a wireless access password. Call us picky, but even a simple predefined password would be a better bet for a product that’s pitched squarely at network novices,” consumer technology site CNET.com.au wrote in its review of the device.

    An iiNet spokesperson disagreed the issue was a problem. “It is standard practice for wireless routers to follow the same set up protocols as BoB Lite when logging into the user interface,” they said in a statement, noting that the company also emphasised the need for customers to change their passwords regularly and follow safe online practices.

    “We send out regular reminders about the importance of secure passwords and detailed information is available on our website and from our support team,” they added.

    Security analyst James Turner – an an advisor with Intelligent Business Research Services – said ISPs needed to be thinking about and planning for the future when it came to security – as when Australia had a nationwide fibre network in the form of the National Broadband Network, they would be “creating a rod for our own backs” if they didn’t get consumers used to the idea of implementing security features in their devices.

    Turner didn’t consider it likely that many iiNet customers would have their BoB Lite broken into in the sparse minutes between turning on the device and setting up a Wi-Fi password and encryption such as the commonly used WPA2 standard — as that would require an attacker to be in the right place at precisely the right time and to log in to the router.

    But it would be a different matter if users simply left the Wi-Fi open permanently, he said – noting he wouldn’t personally leave an unsecured Wi-Fi router set up that way.

    The analyst pointed out there were groups in the community who would exploit such open systems – such as the Anonymous network of individuals who have recently been wreaking havoc on the technology systems of financial institutions and governments alike.

    Turner noted as well that there were some people in the community who had what he described as “some very unusual fetishes” — adding that if such individuals had a modicum of knowledge about computer security, they wouldn’t download illegal content through their own home internet connection. Open Wi-Fi networks could provide such people with the anonymity they needed.

    Image credit: iiNet

    Related posts:

    1. Will Dropbox’s security hole boost Aussie rivals?
    2. Vodafone investigates reported security breach
    3. iiNet offers Wi-Fi in Perth CBD
    4. NSW Govt can’t guarantee IT security
    5. Gillard hack a “wake-up call”, say security experts
    submit to reddit Print Friendly and PDF

    22 Comments

    You can follow any responses to this entry through the RSS 2.0 feed. You can skip to the end and leave a response. Pinging is currently not allowed.

    1. Posted 23/02/2011 at 10:55 am | Permalink | Reply

      Standard Practice != Good Practice

    2. @moldor
      Posted 23/02/2011 at 10:58 am | Permalink | Reply

      Unfortunately, iiNet is right – it *is* standard practice – irresponsible, IMHO, but every router manufacturer either leaves the admin password blank or sets it to something simple like “admin” or “password”.

      The major problem is that they do little, if anything, to educate the user in the necessity of securin their access point IMMEDIATELY. They fall back on a the old “it’s the user’s responsibility to secure their environment” excuse – which, technically, it *is*, I guess – but many users are so technologically inept they may not possess the minor skills necessary to do this without guidance.

      What the router manufacturers should be compelled to do is have a “scripted” configuration environment built in that will not allow the device to be used without a suitable admin password being set. As for wifi access, that’s less of an issue as some people deliberately leave their wifi unsecured to “share the wealth”, but the dangers of this should be clearly emphasized in the documentation.

      I see many local businesses with completely insecure routers it is staggering – so after checking my email (as you do), if I can locate the business I’ll offer to show them how dangerous their setup is and why. Most are appreciative, but I’ve had one sporting goods chain connect me to their IT people who actually said “it’s easier to leave it unprotected, then we don’t have to remember passwords, etc”

      WTF, PEOPLE !!! That’s like writing your ATM card PIN on the card itself !! I showed one store franchisee how easy it was to access his wireless cash registers from my iPad and see bank information, and then how to lock it down and he couldn’t believe that their corporate people didn’t consider this a security risk !!!

    3. None
      Posted 23/02/2011 at 11:15 am | Permalink | Reply

      Anonymous now targeting iiNet customers? lol

      • James
        Posted 23/02/2011 at 5:00 pm | Permalink | Reply

        No, Anonymous targeting their normal targets through an ii user’s connection.

        • None
          Posted 23/02/2011 at 5:01 pm | Permalink | Reply

          Anonymous is hardly going yo be tracking down iiNet customers for the purpose suggested.

          What a joke.

    4. Posted 23/02/2011 at 11:26 am | Permalink | Reply

      Standard practice for some vendors maybe. When I was over in Germany in December my inlaws had a Samsung ADSL router. Rather than having no WPA password or some stupid default, the password was written on the bottom of the router. It was actually just the serial number.

      Would be good if all providers started standardising on something similar.

    5. Posted 23/02/2011 at 11:38 am | Permalink | Reply

      Regardless, most people – (read: average mum and dad user) – don’t have the knowledge to do all this work. It’s all well and good for us tech-inclined to say this and that about how secure or insecure they should be by default.

      People don’t know.

      Finding the balance between REALLY SECURE default settings, and allowing BASIC USERS to get up and running is very difficult.

    6. Retro
      Posted 23/02/2011 at 12:49 pm | Permalink | Reply

      There is a huge label on the front of every bob lite and bob sold that clearly states
      Your wireless is unsecured and you need to secure it.
      I have seen this on both bob and bob lite units I purchased.

      Users need to take this on board and configure their security.
      Most probably just want to get their shiny device online and then forget to
      go back and configure their modem.

    7. myne
      Posted 23/02/2011 at 2:06 pm | Permalink | Reply

      Netgear don’t do it this way.
      At least not for the Optus supplied routers.
      Each and every router uses WPA2 and has the default key on a sticker on the base of the router.

      It can be considered an oversight by iiNet to not do this, but it is shameful that they are basically denying the problem.
      You’re number 2 now. Smarten up.

      • R
        Posted 23/02/2011 at 4:40 pm | Permalink | Reply

        netgear modems dont have security by default – i know. i have 3 of them. optus preconfigure their modems, as do telstra (wheres that link to breaking into the telstra SECURED modems?). manufacturers, and companies who dont preconfigure them, are all the same. require user setup. since modems that arent preconfigured also require user intervention to get online theres no reason why wireless cant be done at the same time.

      • Mic
        Posted 23/02/2011 at 10:37 pm | Permalink | Reply

        It’s not just the Netgear modems that Optus sends out like this – the wifi-enabled cisco cable modems they send out all have unique details, too.

        • Posted 23/02/2011 at 10:44 pm | Permalink | Reply

          Lol the day a Cisco modem ships with an open Wi-Fi connection is the day I eat my shoe … I am sure they are specifically configured to be secure by default.

          • Cherry
            Posted 24/02/2011 at 6:07 pm | Permalink | Reply

            Cisco’s dont come with wireless on at el ,at all ,it has to be configured deliberately .

            • Posted 24/02/2011 at 10:42 pm | Permalink | Reply

              +1 — Cisco is usually the gold standard when it comes to this kind of stuff.

    8. greg
      Posted 23/02/2011 at 2:31 pm | Permalink | Reply

      Anyone with half a brain knows that 95% of people will expect to plug the unit in and have it work. If this is the case they almost certainly won’t bother touching it beyond that point, including any wireless security.

      They are losing credibility by the day by stepping back from the issue rather than acknowledging and addressing it. No shame in admitting you messed up if you actively do something to resolve it.

      And number 2 in DSL – isn’t that like saying you’re 2nd best of the mediocre?

    9. Jayden
      Posted 23/02/2011 at 2:34 pm | Permalink | Reply

      I agree Standard Practice != Good Practice.

      But can someone please tell me why iiNet being made an example of here?

      Why not any of the other modem manufacturers who ship 100 fold more devices than iiNet does?

      You can disagree with their official practice response all you want, the fact remains that it is true.

      Why are we targeting iiNet at all? Surely if the practice is the problem, then that is what needs to change?

      Leave iiNet out of it.

      • R
        Posted 23/02/2011 at 4:43 pm | Permalink | Reply

        Its so all their downloaders can say ‘it wasnt me’ to AFACT :) – they got hacked over wireless

    10. Andrew
      Posted 23/02/2011 at 2:39 pm | Permalink | Reply

      Ok,

      I moved to the UK couple of years ago, and found out they did something really simple there. All the ADSL wireless routers, that are shipped from a ISP have a sticker on the bottom of the device with a SSID and a Wireless key presetup.

      Most of the time it was WPA or higher, now this makes serious sense. Pretty much everyone left it as it was, so when someone needed it you just found your modem and looked at the sticker.

      It blew me away how simple it was, I could never find a open wireless network there. It those providers can do it im sure iiNet can, and yes i am aware it generates the code from the MAC address, and it can be hacked with some good work, but security on by default and not WEP is better than nothing at all!

    11. Liron
      Posted 23/02/2011 at 5:35 pm | Permalink | Reply

      Standard practice for router manufactures it may be, but it is not standard practice for ISPs.

      For example, Big Pond’s wireless routers come with an SSID and shared key built in, and it’s written on the modem and on a card. Myne commented that Optus’ Netgear modems also come with built in security.

    12. Jarrad
      Posted 23/02/2011 at 6:55 pm | Permalink | Reply

      Bigpond’s modem’s also happen to use part of their serial number for the PSK and SSID – which means with a little reverse engineering you can break into them.

      There was a great article on this last year.

    13. Benno Rice
      Posted 24/02/2011 at 12:03 pm | Permalink | Reply

      Just received my FRITZ!Box from Internode. Defaults to WPA/WPA2 with an initial key on a label on the underside of the unit.

    14. Jobst
      Posted 27/02/2011 at 3:09 pm | Permalink | Reply

      Rubbish! There are PLENTY of ISP’s and router manufacturers who use higher encryption by default (and yes I hate to say this even some BogPond equipment) and different keys for each device. One more time: Because its standard practice it does not mean everyone SHOULD do it, we would still be in the stone ages.

    Leave a Comment

    Comment

    Get our daily newsletter

    Get our new articles every day by signing up to our daily newsletter.

    Email address:



  • Anonymous tips

    Got some inside information on something that should be made public? Use our anonymous tips form. Even Delimiter won't have a clue as to your real identity.

  • Most Popular Content


  • Three lessons ING's private cloud teaches us
    sponsored post ING Direct recently implemented a private cloud solution to virtualise its entire banking platform, allowing it to provision a new copy of itself -- a so-called 'bank in a box' -- within minutes. Here's three things other organisations can learn from this interesting deployment.
  • Enterprise IT news & views

    • Microsoft beats Salesforce to utility CRM deal microsoft1

      Energy retailer Australian Power & Gas has picked Microsoft’s Dynamics CRM system over rivals Salesforce.com and Right CRM as the base platform for a customer relationship management overhaul to tackle incoming email complaints.

    • NSW finalises colossal datacentre consolidation cableguy

      The New South Wales State Government this week announced the Leighton subsidiary Metronode as the winner of its long-running and wide-ranging datacentre overhaul project, with the company to construct two new substantial facilities which will allow the state to consolidate its IT operations drastically.

    • Two good Australian CIO interviews IT-manager-cio

      There have been a couple of good interviews with Australian chief information officers done by various media outlets over the past couple of days — good enough that we thought them worth highlighting to readers on Delimiter.

    • Three lessons ING’s private cloud teaches us Cloud computing

      If you could provision a new copy of your organisation’s entire internal application environment for development purposes in just ten minutes, and you could do whatever you liked with it, what sort of new systems and processes would you build?

    • SAP considers Aussie datacentre sap1

      The Financial Review has reported that German software giant SAP is likely to build an Australian datacentre to provide services to Australian organisations, should new privacy legislation pass that could affect vendors’ ability to sell cloud computing services locally from global facilities.

    • How much more do servers cost in Australia? 1RUrackmountserver

      How much more do the hardware servers used by small businesses and large organisations cost in Australia? Quite a lot more than in the US, according to a report by small business technology media outlet BIT, in yet another case of the Australian technology tax striking fear into Australian wallets.

    • NSW agencies push very hard for SaaS rollouts Cloud computing

      Several major New South Wales Government agencies have unveiled major and wide-ranging plans to imminently purchase Software as a Service-style IT solutions, in moves which have the potential to re-cast the dynamics of the perceived relationship between Australia’s public sector and the burgeoning class of SaaS-delivered IT packages.

    • Technology and planned obsolescence lightbulbs

      Very insightful blog post here by Longhaus managing director Peter Carr, who has made a sophisticated argument regarding planned obsolescence with respect to implementing technology in organisations.

  • Enterprise IT, News - May 17, 2012 15:20 - 0 Comments

    Microsoft beats Salesforce to utility CRM deal

    More In Enterprise IT


    Photo Galleries, Telecommunications - May 17, 2012 12:14 - 23 Comments

    Pristine Telstra network photos: We sourced our own

    More In Telecommunications


    Blog, Gadgets - May 17, 2012 15:38 - 1 Comment

    Will Telstra skip Nokia’s Lumia 900?

    More In Gadgets


    Reviews - May 7, 2012 18:16 - 2 Comments

    Telstra Mobile Wi-Fi 4G: Review

    More In Reviews