Defaults are Dangerous

“Don’t just read it, say it. Out loud. Repeat it. Defaults are not your friend. Defaults should be changed. Why? Defaults. Are. Dangerous


We live in an era where convenience is king. In fact, we’ve grown so accustomed to it, that even minor inconveniences are oftentimes seen to be the end of the world as we know it. God forbid we have to do one extra step, endure a few minutes of delay. Well, hate to be the bearer of bad news (not really), but oftentimes being secure means having to be inconvenienced in one way or another.

For instance, let’s talk default passwords. I know, I know, you don’t want to take the extra five to ten minutes to set up a new password on that device. It’s advertised to work right out of the box, plug and play. I should be able to power it up, click a few buttons and just walk away and be done with it shouldn’t I?

Forgive me for taking this tone of voice with you but I need you to understand what’s at stake here. Passwords are supposed to be for the user to know and only the user. They should also have some sort of complexity to them. More on these things later. The problem is that default passwords don’t really meet those criteria by default (pun intended). Which makes them bad. We don’t like bad things in security.

But you know who really likes default passwords? Intruders.

A wise man once said, “The convenience of a default is the architect’s invitation to an intruder “A Wise Man, 2026. Factory-set credentials are usually one of two things (sometimes both): They are either extremely weak, sometimes borderline public knowledge (such as “admin” or “password”) or they’re written down either physically on the device, in the manufacturer’s database, and or within the devices memory. That last one may be hard to believe, and while I don’t have the time to go into technical details about embedded systems, I will say this: if you were to “factory reset” say your router, I’m willing to bet it would reset its password back to the default settings.

So now if I was an intruder that wanted access to some of your goodies, I have a couple options. My first option doesn’t require anything too elaborate. I can simply compile a list of commonly known passwords, such as “admin” or “password123”, and cycle through them to try and login or connect to a device. This is actually something commonly referred to as a Dictionary Attack.

Or perhaps I don’t need to target you specifically, but rather I can go after the manufacturers. If I know a majority of people have let’s say TP-Link routers (sorry for the stray), I may attempt to gain access to their databases to see if there are any records of products and their default passwords. If I strike gold, it would simply be a matter of matching a default password to the serial number of your device, and if you in fact did not change that password, I’ll make sure to thank you for leaving the backdoor open for me as I make myself at home.

Like I said, you don’t intentionally leave the physical doors to your home unlocked, so why would you leave the digital doors open?

Now in my experience, I’ve observed that it’s really what goes into the process of making a good password that makes people go nope, I’ll just stick with the default option. So, in an effort to make it simple, I’ll share with you my technique that I use for all of my passwords.

First, I choose a phrase or sentence. It doesn’t have to be incredibly long, but also, we don’t want it to be too short. Typically, I pick something that’s about seven words long, but it may differ based on the password requirements. I feel like I am inclined to say that we typically want to focus more on length then complexity, but a 15-character password that consists of just the letter “a” is still not an ideal password, so there does need to be some complexity. For our example, we will use the following phrase: “Every day I get up and drive to work in the morning”.

Now, this phrase alone could give us a pretty solid password: “EveryDayIGetUpAndDriveToWorkInTheMorning“. But admittedly, that’s a lot to type. How about instead of using the full words, we just use the first letter instead?

ediguadtwitm“. Not too bad! Looks like complete gibberish, but also this seemingly random combination of letters would probably never be in something like a dictionary attack. Not to mention, it is still about 12 characters long, so that gives us quite a bit of length.

Now finally, a lot of password requirements are going to include one or maybe all of the following; at least one capital letter, one number, and one special character. If we think about it, we can easily integrate that into our phrase without doing a whole lot. For the capital letter, we can make it the first letter in our “phrase”, just like a regular sentence would be. For the special character, let’s just use an exclamation mark for punctuation. And for the number, we can just throw in your favorite one at the end!

Seemingly immune to a dictionary attack, and almost impossible to recognize in a pattern, I’d say we’ve got ourselves a pretty good one here. This password is also about 14 characters in length. While I’ve seen some password requirement lengths reach up to 15 characters, typically you may not need to go that high. Give it a shot yourself! Come up with a phrase on your own (Do not use this one) and give it a shot. If it works out, let me know!

And I don’t mean the password. Let me know if the method works. Do not comment the password. Seriously, keep that to yourself.

And by the way, for the bit more technically inclined, I do realize that password managers are now becoming the more secure option. But you do still need to create passwords, and have one for the manager itself, so I would say this method is still relevant!

Now I don’t want you to leave this post without doing your own hygiene check. While this list may not be entirely inclusive, I’ve tried to include some common household and or small business points of possible compromise. Please, I know it may be inconvenient, but for your own safety, check and make sure none of your devices are using their default passwords. If so, try out my above method for an easy way to come up with a secure, easy to remember password. It could be the difference between being secure and leaving yourself vulnerable. Close that backdoor!

Check out these devices:

  • Wi-Fi Routers
  • Switches and Firewalls
  • Security Cameras
  • Smart devices
    • Any and I mean ANY device with the name smart in front of it…though they’re getting better they are notorious for having overall poor security hygiene
  • Printers

Leave a comment