Hacker News new | past | comments | ask | show | jobs | submit login

Sounds like an opportunity..

Why don't we design one that is foolproof? i.e. security is always enabled, and it requires a complex password? Perhaps there is even a readout + little keyboard built into it so the end user can go through a simple wizard to ensure security. The readout would give them the keys to type into their PC.

And on top of it there would be a large green + red indicators.. Red would glow if there was any security issue, with the error on the readout + sent to the end user as a text message. Green would indicate all is secure.

The only real question is what to name port forwarding. While I'm a huge fan of the obvious and clear "Applications and gaming", being a router manufacturer I would be obligated to create yet another new name for it, like "wormhole port" or "you fool, just call your geek nephew already".

Seriously, I have trouble going from a linksys to a netgear to a dlink, not to mention the OEM routers sold by ISP's now that often lock down features.. How can we expect these pieces of fail to be installed correctly?




AT&T already does the most important parts of that. In my complex every network is named and secured uniformly because AT&T sells cable models with built-in wireless routers. They have an installation process that is totally automated and automatically configures them for WPA or WEP. The users don't even (get to) choose the network name. As a result, I couldn't leech off another network even if I wanted to.

Secure networks make perfect business sense for internet providers; otherwise, they'd end up with customers with wide-open networks that neighbors could share together (unwittingly or otherwise).

As for port forwarding, typical users never need to configure that, and when they do, UPNP usually can do it for them.


Yes, AT&T's DSL setups are a triumph of proper defaults. They come in, plug everything in, give you the password (or set up your computer), and go away once everything is working and safe. Easy setup, safe installation.

Of course, I've had WPA and WEP hacked enough times to not trust either of them. MAC address filtering is a bit safer if you want to lock down access to the internet, but at least the password has to be changed. Default router passwords put users so badly at risk, there's really no excuse.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: