A security update for the Raspberry Pi
raspberrypi.org
raspberrypi.org
"Banner The contents of the specified file are sent to the remote user before authentication is allowed. If the argument is ``none'' then no banner is displayed. By default, no banner is displayed."
Match User pi
AcceptEnv
ForceCommand echo 'To enable SSH, do this and that'
EDIT: added an explicit empty "AcceptEnv".> put a file called ssh in the /boot/ directory with any content to enable SSH which we turned off by default to prevent unauthorized access of your devise in public network.
I wonder how many people are going to scratch their head when their headless Raspberry Pi will be unable to connect to their laptop in same way as earlier without this piece of information.
I hope running sudo apt-get update, notifies them of this critical change.
I am not sure if this is the case with the warning telling you that you are still using the default password.
> To update your existing Jessie image with all the bug fixes and these new security changes, type the following at the command line:
I think better implementation would be asking if one is running their device in public or private network and explaining the consequences while setting up for the first time. We are asked of same question when we connect to network for first time in Windows since last several versions. I am sure tutorials made previously will create lot of frustration among newcomers.
-> or just get angry when they reboot and cant get back in without unplugging it from whatever remote location it was plugged into and taking it home to plug into a keyboard mouse and monitor.
great for the effort. i did baulk when i first started a pi to find the defaults were so insecure. But I'm not sure the solutions are that helpful. cant we just set a root password on first boot like every other nix distro.
It's a bit of a hassle for anyone who knows their way around linux, but Pis are marketed toward kids & other "normals". This is what happens to products designed for everyone.
HHHrrrmpf.
If the PI shipped with a little sticker containing the MAC address that would be quite trivial to change the username and password to the mac address as seen by /sbin/ifconfig which optimistically matches the physical sticker.
Of course there aren't many possible MAC addresses however, there are more than just one.
Another entertaining idea is if you're on a private network that can't access 8.8.8.8 or whatever then assume its safe to enable ssh by default.
Or if some sort of "what is my ip address" service returns a public ip addrs that matches /sbin/ifconfig then here be dragons and disable ssh by default.
Another fun idea is when you boot the first time sshd is enabled for.... a little while, and then blocked after some time or a power cycle. Some crontabs support a syntax like @reboot sleep 300 && block_ssh.sh where block_ssh engages a iptables rule that eats incoming ssh port packets. Or whatever time period feels right. So if you're on a public network and worried, simply boot and don't plug in for 6 minutes or whatever, and you're good. Or if you want ssh then you boot, and fast as possible log in via ssh and enable it. For the extra paranoid note its not hard with a script to ensure you get 5 minutes of working ssh only once per burning of the flash image, assuming your flash isn't in write protect mode LOL.
OH edited to add my favorite new idea, if you boot and GPIO port #something is pulled to ground, then enable SSH going forward. Sure would be nice if that GPIO pin were adjacent to gnd pin. Maybe you could code in something that flashes onboard LEDs to provide feedback.
I think it is the best solution because it makes you immediately notice that you might not actually want anybody to login without any password at all. And any other method has worse trade offs.
https://www.raspberrypi.org/blog/a-security-update-for-raspb...
I'm interested in whether this will make a meaningful difference, however. It probably would have been nicer if Raspbian required users to put a root password into /boot/password or similar, and then deleted that file on boot -- or mandated that users change their password on first login. My concern with this is that I suspect most tinkerers will press the "make it work" button, drop /boot/ssh in, and never bother changing the password.
I guess a sufficient number of people have put Pis on the Internet, or the recent wave of IoT-DDOS attacks has spooked the Raspberry people sufficiently to make this change.
Edit: we should remember IPv6 is becoming a real thing, too. If I scan my web logs, see a pi in there, with v6, I might just try to ssh into it as the pi:raspberry user. Maybe I dont even need to decide it's a pi, just try it anyways.
In an alternate universe where they don't make this change and raspberry pis are included in a massive attack because of their intentionally well-known default root account is listening on a running-by-default sshd, everyone would be screaming about the raspi foundations rampant incompetence.
The only place this will sting is in un-maintained 'how to set up your new raspberry pi's SD card' tutorials.
I believe that most users who want to set up a headless pi can handle this change with no problem.