HomeUpdatesRaspberry Pi: Removes default user to prevent brute-force attacks

Raspberry Pi: Removes default user to prevent brute-force attacks

Raspberry Pi computers are a common hacking target, and this change should make hackers' lives a little more difficult.

Raspberry Pi: Removes default user to prevent brute-force attacks

See also: Microsoft: Blocked billions of brute-force and phishing attacks in 2021

An update to Raspberry Pi OS Bullseye removed the default user "pi" to make it harder for attackers to find and compromise Raspberry Pi devices exposed to the Internet using default credentials.

Starting with this latest version, when installing the operating system, you will first be asked to create an account by choosing a username and password (before this change, the operating system installer only asked for a custom password).

You can no longer skip this step, as the installation wizard will launch upon first boot of the device (previously, you could press Cancel to use the default pi/raspberry credentials).

You can still choose to use a username of "pi" and "raspberry" as your password, you will receive a warning that it is not a good choice.

“We are not removing the “pi” user from existing installations. We are not preventing anyone from entering “pi” and “raspberry” as a username and password on a new installation,” said Simon Long, Senior Principal Engineer at Raspberry Pi.

“All we’re doing is making it easier for people who care about security to not have a default user ‘pi’ – something people have been asking for for quite some time.”

See also: Brute-force attacks by the Russian military target organizations

Raspberry Pi

When launching the software for the first time, Raspberry Pi OS Lite software users will be prompted to create a new account via command line text prompts.

If you want to run the Raspberry Pi headless, you can create the user before booting into the operating system by setting a username and password via the Settings dialog before “writing” the software.

See also: Significant increase in brute-force attacks in Brazil

Existing installations are not affected by this change. However, users can still switch to non-default credentials by updating their existing software and running the sudo rename-user command.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS