RP4 and security (25 Jun, 2019)

Postby aardvark_admin »

This column is archived at: https://aardvark.co.nz/daily/2019/0625.shtml

Are you going to buy an RPi 4?

If you have any RPi connected to your network, have you taken the time to check that the password defaults have been changed and that unnecessary services disabled?

What percentage of RP-based Kodi installations do you think might be wide-open and inviting hackers?

What would you do with the new RPi 4 if you bought one?

Isn't this simply insane value and a great indicator of how those things we once dreamed of have now become a reality?
Re: RP4 and security (25 Jun, 2019)

Postby GSVNoFixedAbode »

Tricky - the Pi as as open as any standard *nix system, but is pitched towards those getting started so initial security is relaxed. Even so, all the how-tos have big prompts saying 'remember to change your admin password'.

Love the idea of a decentralised network of videos, but I'm sure you'll remember the phrase 'The Slashdot Effect' Bruce. Given your global reach, be prepared for it! :D
Re: RP4 and security (25 Jun, 2019)

Postby Malcolm »

The default Linux distribution for the Pi has had a number of security improvements since the first release. Most importantly it no longer starts with SSH open by default, and when you enable SSH or other remote access it prompts you to change the password. Most people also will have the Pi sitting behind a NAT firewall so chances are it won't be listening directly on the internet unless the owner has deliberately done it.
As for the Pi 4 I am hoping to get one or more before long. Although the 4GB model is about $100NZ from Core Electronics, the lower options are a better price but once you know there is a better version you really want that one. I wasn't expecting to see it so soon. I think Eben had said as recently as March this year not to expect anything until 2020. USB3 and true Gigabit ethernet is great. As is 4K support. Not sure on the dual screen since it seems it comes at a cost of requiring micro-HDMI to HDMI adapters. Early benchmarks look like about double SD card throughput so that is great. As for a wishlist, I think POE power without the HAT would be nice. So would native PXE boot. Maybe another storage option to get away from SD cards, although not sure where you could fit an M.2 slot, maybe USB3 boot drive is an option.
Re: RP4 and security (25 Jun, 2019)

Postby greven »

How did the hacker get through the NASA firewall? Was the pi checking in with an external service?
