TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Raspberry Pi update removes the default user

210 点作者 ez_mmk大约 3 年前

24 条评论

alar44大约 3 年前
Good.<p>8ish years ago, I wrote a script to search out Pis with port 22 opened to the internet with default un and pw. Let it run overnight.<p>The next morning I checked the log and it found thousands of Pis that I could have just logged into with root privileges if I wanted.<p>Never trust users.
评论 #30951786 未加载
评论 #30953866 未加载
评论 #30953647 未加载
评论 #30951506 未加载
评论 #30956094 未加载
评论 #30951349 未加载
评论 #30952102 未加载
评论 #30951322 未加载
chmod775大约 3 年前
&gt; In 2017, for example, hackers stole data from a US casino via an internet-connected fish tank.<p>What can I possibly say to make this funnier.
评论 #30954858 未加载
评论 #30956244 未加载
评论 #30955182 未加载
jdubb大约 3 年前
Just yesterday I&#x27;ve been flashing Raspberry OS to a micro SD card. Not succeeding with Balena Etcher, I opted to use the RPi imager tool, which did work (which might be an issue not in any way related). After that I added the `ssh` file to the boot partition and tried connecting to it via SSH. Providing username pi and password raspberry, connecting fails with invalid password, no matter how many times I tried. Searching all over the internet for whether the password was different nowadays, but coming up with zip, frustrated, I went to bed.<p>Reading this today it hits me that this change might just be the cause.<p>If that turns out to be the case, there should really be some indication in the RPi imager tool.
评论 #30965304 未加载
Karellen大约 3 年前
Wait, is this an update to the OS, or an update to the installer?<p>If I upgrade my existing Pis, are the currently in-use `pi` users (which have non-default passwords) going to be removed?<p>About half the article makes it sound like it&#x27;s an OS update, but the other half makes it sound like an installer update, and there&#x27;s a <i>big</i> difference between those two scenarios.
评论 #30951345 未加载
ajsnigrutin大约 3 年前
Wtf? So how do I install this headlessly, without needing a separate piece of software (imager?)?<p>I used to just dd the image, touch the &#x27;ssh&#x27; file on the boot partition, and then change stuff over ssh.
评论 #30950950 未加载
评论 #30951309 未加载
评论 #30952051 未加载
评论 #30955964 未加载
评论 #30951010 未加载
评论 #30950976 未加载
评论 #30950937 未加载
评论 #30951060 未加载
评论 #30950932 未加载
评论 #30951331 未加载
tzs大约 3 年前
The BBC article that the submitted article cites says of the law requiring this:<p>&gt; Included within its scope are a range of devices, from smartphones, routers, security cameras, games consoles, home speakers and internet-enabled white goods and toys.<p>&gt; But it does not include vehicles, smart meters and medical devices. Desktop and laptop computers are also not in its remit.<p>Wouldn&#x27;t an RPi be considered to be a desktop computer?
op00to大约 3 年前
Damn, I’m so used to googling default passwords for stuff. Now I gotta remember my own?
评论 #30953101 未加载
londons_explore大约 3 年前
I&#x27;m pretty sure the law discourages default <i>passwords</i>. I don&#x27;t see anything wrong with default users, especially on systems which are usually single-user.
评论 #30951109 未加载
评论 #30950942 未加载
评论 #30952079 未加载
alerighi大约 3 年前
This is good because I always ended up removing the defualt user and creating another or just using root.<p>You can always mount the SD card partition and put your ssh key into &#x2F;root to log in with that. An improvement could be to also load ssh key from the &#x2F;boot partition so also windows&#x2F;mac users could do that easily.<p>By the way using root with an ssh key is fine and not a problem in terms of security.
评论 #30951580 未加载
air7大约 3 年前
I don&#x27;t know, I seem to be in the minority according to the comments here, but I like my default credentials, thank you very much. I have tons of gear laying around, some of which is collecting dust in a drawer, and if the default creds don&#x27;t work I might be in a bind because I&#x27;m not organized enough to &quot;do it right&quot;. These devices are not open on the internet, obviously, and per my threat model, anything on my local lan is deemed safe.<p>More importantly perhaps, I am willing (and actually want) to have the freedom to do this, and to take responsibility for any problems I might cause for myself.<p>This issue is part of a more general ethical conundrum spanning many areas of life: How much should people be protected from themselves? I guess my personal answer is, not a lot.
评论 #30956841 未加载
qwerty456127大约 3 年前
One of the minor things I like the most about Raspbery Pi is it has the default user.<p>Since the days desktop OSes (i.e. Windows 2000 Professional) first started to demand the user to name themselves and sign-in (which didn&#x27;t protect their data anyway and still doesn&#x27;t protect today as Windows Home doesn&#x27;t include BitLocker) I hated this useless complexity. I in fact met many hundreds of PC users and just a minuscule fraction of them (also of those sharing a PC among a number of family members) used an actual multi-user set-up.<p>Linux seemingly did this from the very first day because it&#x27;s non-PC Unix legacy.<p>Once I tried Raspberry Pi I felt a pleasant relief: it never asked (although allowed) me to personalize it and just worked. I didn&#x27;t have to invent a nickname nor expose my real name. It was just a handy tool like in good old days when you didn&#x27;t have to connect your oven to WiFi.<p>PS: I do understand how useful the OS&#x27;s multi-user mechanism is to limit what untrusted app instances can do.
评论 #30954970 未加载
vorticalbox大约 3 年前
<a href="https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20220408000607&#x2F;http:&#x2F;&#x2F;deepaqua.me&#x2F;2022&#x2F;04&#x2F;07&#x2F;the-pi-user-is-dead-long-life-the-pi-user&#x2F;" rel="nofollow">https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20220408000607&#x2F;http:&#x2F;&#x2F;deepaqua.m...</a>
MarkusWandel大约 3 年前
Well, at least the default, non-expert install of the Raspi OS doesn&#x27;t enable ssh logins.
aorth大约 3 年前
That&#x27;s an interesting solution. Good luck, future Raspberry Pi users! I know this will make it a little more difficult for the less technical to get their Pi units set up.<p>I can confirm that I have dozens of public Linux servers with SSH exposed and user `pi` is constantly being attempted for login. I ban them all immediately and automatically.
vault大约 3 年前
I thought it was still April 1st
ruined大约 3 年前
site is down for me but there&#x27;s an archive snapshot<p><a href="https:&#x2F;&#x2F;archive.ph&#x2F;gxhCC" rel="nofollow">https:&#x2F;&#x2F;archive.ph&#x2F;gxhCC</a>
nonsince大约 3 年前
Good, but frankly it’s pretty embarrassing for them that it took the threat of a multi-million pound fine before they made this change.
gpvos大约 3 年前
<a href="https:&#x2F;&#x2F;archive.ph&#x2F;gxhCC" rel="nofollow">https:&#x2F;&#x2F;archive.ph&#x2F;gxhCC</a>
wanderer_大约 3 年前
Now it&#x27;s just a matter of time before I start losing installs because I can&#x27;t remember passwords...
评论 #30951293 未加载
nottorp大约 3 年前
So I can&#x27;t set up a headless Pi any more without using that imager tool?
amelius大约 3 年前
Is this a law in UK only? Do EU and US have something similar?
exfascist大约 3 年前
They should have just removed the password. Default passwords are braindead. Default users really aren&#x27;t that bad.<p>Fun anecdote: I used to log into people&#x27;s Pis in college and show them that they needed to change the password. People don&#x27;t react nicely to that.
评论 #30951897 未加载
评论 #30951330 未加载
评论 #30951367 未加载
评论 #30954987 未加载
评论 #30951338 未加载
jimmaswell大约 3 年前
It feels like a continuation of the anti-self-determination trend of putting rounded corners and foam padding on everything. No passwords allowed on github, no running x program as root, make it as hard as possible to add unapproved browser extensions, etc. and now the raspberry pi has to be less convenient to set up to protect people who don&#x27;t care enough to know what they&#x27;re doing from themselves. I hate it.
评论 #30952876 未加载
评论 #30953148 未加载
StillBored大约 3 年前
Why does the RPi still have its own OS? The major linux distros have been doing this for years in their installers&#x2F;disk images. It seems like just about every week they announce a feature that already works everywhere else. Its sorta like all the &quot;I got a ssh server running on my Pi articles&quot;. Not at all noteworthy, except for the fact that the machine is by default quite dysfunctional.<p>So it was yet another reason for the RPi foundation to stop being stupid, and just conform their firmware to SystemReady, and post their fixes upstream. All these custom hoops they keep jumping through to duplicate what every other OS&#x2F;firmware already supports just speaks to bad mgmt. So, yah they are the most successful Arm sbc vendor, and this all made sense 10 years ago when none of the distro&#x27;s had working arm ports and there wasn&#x27;t much in the way of standard arm system architecture. Those days are long gone, and the people clinging to them are just sticking their head in the sand. Particularly since 3rd parties have basically done 3&#x2F;4 of the work for them and ported a full blown UEFI&#x2F;ACPI environment to the darn thing.<p>So, they need to put on the big boy pants and stop playing the NIH game.
评论 #30956014 未加载
评论 #30953396 未加载