HomeSecurityCISA: Asks technology product manufacturers to stop default passwords

CISA: Asks technology manufacturers to stop default passwords

CISA urged technology product manufacturers to stop providing software and devices to customers with default passwords (default passwords).

CISA technology product manufacturers

The reason is that cybercriminals can use such default credentials to compromise vulnerable devices exposed to the internet. Default passwords are commonly used to streamline the manufacturing process. They also help system administrators more easily deploy a large number of devices in a corporate environment.

However, not changing these passwords is considered dangerous because hackers can bypass authentication measures. Through such an attack, the security of an organization's entire network could be compromised.

See also: The most used passwords of 2023, are yours on the list?

This SbD Alert urges technology manufacturers to proactively eliminate the risk of default password exploitation ,” CISA said

Software manufacturers should ensure the security of their design, development, and delivery processes to prevent the exploitation of static default passwords on their customers' systems.

According to the data CISA has collected over the past few years, we cannot rely on customers changing default passwords . Onlyvendors technology will adequately address the serious risks facing organizations related to critical infrastructure.”

What changes need to be made?

CISA advised manufacturers to provide their customers with unique setup passwords, tailored to each product instance, rather than using a default password across all product lines and versions.

See also: What mistakes are you making with passwords?

Additionally, they can implement , passwords time-limiteddesigned to expire once the setup phase is complete, and require administrators to enable more secure authentication methods (e.g., multi-factor authentication).

Another option includes requiring physical access for initial setup and defining distinct credentials for each case.

CISA warns about the risks of default passwords for many years:

Attackers can easily identify and gain access to Internet-connected systems that use shared default passwords. It is imperative to change manufacturer default passwords and restrict network access to critical and important systems.“.

See also: AutoSpill: Steals credentials from Android password managers

default passwords

Impacts of using default passwords

One of the implications of using default passwords is the threat to user privacy. When manufacturers use generic passwords, and users do not change them, there is a risk of privacy being violated, as malicious users can gain access to their personal information.

Additionally, using default passwords can lead to easier attacks and compromises of devices. Malicious users can use known default passwords to access devices and perform attacks, such as installing malware or stealing sensitive information.

Finally, the use of default passwords can have broader implications, not just for users but for the internet as a whole. The use of default passwords on a large scale can lead to mass attacks and security breaches, affecting millions of users and devices.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS