Raspberry Pi update removes the default user
deepaqua.me
deepaqua.me
8ish years ago, I wrote a script to search out Pis with port 22 opened to the internet with default un and pw. Let it run overnight.
The next morning I checked the log and it found thousands of Pis that I could have just logged into with root privileges if I wanted.
Never trust users.
He did say it, though indirectly :)
[edit: And then I got downvoted. Oh humans. Lol.]
You don’t care about security or don’t understand the implications, and why would you!? You’re having fun!
Fun is the deal. If you focus on the fun path you will jump right past any non fun, which is security.
Think about smart kids who get hurt. Were they capable of preventing the injury? Definitely. We’re they having fun? Absolutely. Fun wins every time.
"Access your raspberry pi from the internet" probably doesn't sound to the layman like anyone can access your raspberry pi with zero effort
I was supposed to be a "knowledgeable" IT expert, but back in the 90's I managed to open-relay my company's mail server...
I did so many and different walks of shame that week.
But just search for "raspberry pi hosting" on your favorite search engine. There are tons of companies providing hosting on Pis, as crazy as it sounds and those come with IPs (but for a semi professional hosting place hopefully with different credentials ... but given how cheap many of those are it's more hope than expectation)
fail2ban is nice and all, but irrelevant to this post about a default login.
My entire point being that any client that tries a default account should be insta-banned. That’s what I get from this.
Any IPs that are trusted, put ahead of that logic.
Now its possible to change the agent name of software running behind a port, and Shodan almost certainly have some rules which throws up results as per their criteria.
Maybe you should ask their support dept for a comment to your specific question? support@shodan.io
Still, it’s nice that you can get it online so wails but it was obviously not a good idea. Some software they sets WiFi and user info while flashing would be nice.
What can I possibly say to make this funnier.
Now, it's just an IoT/outdated device software thing.
LG, Samsung, or some other brand of dishwasher that happens to be inside Korea? /hj
In more serious discussion, I'm still unconvinced of the benefits of connecting your appliances to the internet considering that appliance makers are more likely to just abandon the "smart" part while the hardware is still in full working order.
Reading this today it hits me that this change might just be the cause.
If that turns out to be the case, there should really be some indication in the RPi imager tool.
Instead, I downloaded a live Linux dist, kde-neon [2], wrote that to a USB stick with rufus [3], booted my PC with that, and imaged under Linux. Only then did it work.
[1] https://github.com/raspberrypi/rpi-imager
If I upgrade my existing Pis, are the currently in-use `pi` users (which have non-default passwords) going to be removed?
About half the article makes it sound like it's an OS update, but the other half makes it sound like an installer update, and there's a big difference between those two scenarios.
Existing installations will not be affected.
Raspberry Pi OS does not have an "installer".
An installer is a script/program which helps the user install the software, in this case the OS is the software.
I used to just dd the image, touch the 'ssh' file on the boot partition, and then change stuff over ssh.
I wouldn’t be too worried, there will likely be a solution for “power users” who use the ssh file.
> This file should contain a single line of text, consisting of username:encrypted- password – so your desired username, followed immediately by a colon, followed immediately by an encrypted representation of the password you want to use.
> To generate the encrypted password, the easiest way is to use OpenSSL on a Raspberry Pi that is already running – open a terminal window and enter
echo 'mypassword' | openssl passwd -6 -stdin
> This will produce what looks like a string of random characters, which is actually an encrypted version of the supplied password.From the anouncement [0], under "Headless setup".
[0] https://www.raspberrypi.com/news/raspberry-pi-bullseye-updat...
The only people to understand the comment, are the ones it won't help.
For all other kind of early sys admin tasks for a headless system you can mount the image to your Linux workstation and chroot into it using binfmt_misc and qemu-static. https://wiki.debian.org/RaspberryPi/qemu-user-static seems to describe it. (I haven't used those instructions, but my own 10 year old cheatsheet.)
https://9to5linux.com/raspberry-pi-imager-now-lets-you-contr...
> Included within its scope are a range of devices, from smartphones, routers, security cameras, games consoles, home speakers and internet-enabled white goods and toys.
> But it does not include vehicles, smart meters and medical devices. Desktop and laptop computers are also not in its remit.
Wouldn't an RPi be considered to be a desktop computer?
Is a significant fraction of RPis really deployed to the public internet with default passwords?
Oh, this:
You can always mount the SD card partition and put your ssh key into /root to log in with that. An improvement could be to also load ssh key from the /boot partition so also windows/mac users could do that easily.
By the way using root with an ssh key is fine and not a problem in terms of security.
If you wanted to make some users really happy, support a hook script in the same way.
/boot/first-run.sh — or something to that effect
More importantly perhaps, I am willing (and actually want) to have the freedom to do this, and to take responsibility for any problems I might cause for myself.
This issue is part of a more general ethical conundrum spanning many areas of life: How much should people be protected from themselves? I guess my personal answer is, not a lot.
Since the days desktop OSes (i.e. Windows 2000 Professional) first started to demand the user to name themselves and sign-in (which didn't protect their data anyway and still doesn't protect today as Windows Home doesn't include BitLocker) I hated this useless complexity. I in fact met many hundreds of PC users and just a minuscule fraction of them (also of those sharing a PC among a number of family members) used an actual multi-user set-up.
Linux seemingly did this from the very first day because it's non-PC Unix legacy.
Once I tried Raspberry Pi I felt a pleasant relief: it never asked (although allowed) me to personalize it and just worked. I didn't have to invent a nickname nor expose my real name. It was just a handy tool like in good old days when you didn't have to connect your oven to WiFi.
PS: I do understand how useful the OS's multi-user mechanism is to limit what untrusted app instances can do.
I can confirm that I have dozens of public Linux servers with SSH exposed and user `pi` is constantly being attempted for login. I ban them all immediately and automatically.
Fun anecdote: I used to log into people's Pis in college and show them that they needed to change the password. People don't react nicely to that.
I'm glad I haven't worked at a place that had such informal "policies" in a while. There have been a few attempts by twenty-something engineers with no commitments to establish such rules, but the culture wasn't that toxic, so they (politely) got told to shut up, and that was that. People's desktop background still get changed sometimes, but respecting people's boundaries goes a long way to make work bearable for everyone. And even with desktop background pranks, if in the slightest bit unsure, communicate beforehand and accept a "no". And don't do what one guy at another company did and use a homophobic meme right before their victim's demo call with an important customer, or you deserve everything that happens afterwards.
But if you're effectively harassing people out of a part of their salary, I'd expect the reason to be something truly overridingly critical, and in all settings where I've seen this sort of rule instituted, it was far from that – and if it were, why would you resort to bottom-up hazing to control that risk? That disincentivizes actually improving security (by giving people another pretext to depend on uncompromised user machines), oversights absolutely will still happen and any damage that actually does occur will be hidden and conceiled even harder, since now you've created an emotional link to public shaming and people respond to that viscerally.
Don't you mean (effectively) harassing?
Also, nothing was said about having to bring donuts for _everybody_. A single box of a dozen fresh assorted donuts left on the kitchen counter would do it. You'd then announce donuts to be available on a first come first serve on the same Slack channel and leave the hungriest ones fend for themselves in the hallways.
I also heard of one other company where the tradition was to send an email out to the rest of the company offering to bring in donuts.
Change their desktop picture to My Little Pony. (Some folks just left it.)
On macOS, put this into cron `5 */2 * * * sleep $$((RANDOM % 7200 )) ; creepily_say_random_words.sh` :
#!/usr/bin/env bash
words=$(awk 'BEGIN {srand()} !/^$/ { if (rand() <= .000015) print $0}' /usr/share/dict/words)
echo "${words}"
for voice in junior ralph whisper; do
say -r 70 -v "${voice}" "${words}" &
done
I was talking about this kind of thing with a US Santa Cruz researcher and she said they changed the default runlevel to 6.If the former, we have different colleagues
We've been doing this with pictures of Mariusz Pudzianowski (a Polish weightlifter), most people learned to set up their screen lockers pretty quickly. Definitely more effective than spamming people with reminders about security policy. Fun times.
Once, when again she left for lunch without locking her computer, a colleague of ours got up, made a Screenshot of her desktop, put everything on her desktop into the download folder and replaced the background with the screenshot. When she returned from lunch she was very quickly irritated that her computer had stopped working, as she could no longer click any of her files and programs.
It was a blast. And she never let her computer unlocked again.
echo 'pi:raspberry' | chpasswd
There you go. Secure defaults matter.thats an incredibly strange take, like that is literally the complete opposite of what is happening
So it was yet another reason for the RPi foundation to stop being stupid, and just conform their firmware to SystemReady, and post their fixes upstream. All these custom hoops they keep jumping through to duplicate what every other OS/firmware already supports just speaks to bad mgmt. So, yah they are the most successful Arm sbc vendor, and this all made sense 10 years ago when none of the distro's had working arm ports and there wasn't much in the way of standard arm system architecture. Those days are long gone, and the people clinging to them are just sticking their head in the sand. Particularly since 3rd parties have basically done 3/4 of the work for them and ported a full blown UEFI/ACPI environment to the darn thing.
So, they need to put on the big boy pants and stop playing the NIH game.
Because it's not aimed at the general purpose computer market?
The OS -- the features, the documentation, the learning focus, the ease-of-use planning, the designed support for school and code clubs -- is part of the product.
It's not just a little cheap linux box for nerds; it has a different focus.
Also the hardware itself is different, is it not? It has (for example) no battery-backed clock. It has connectors other distros cannot be expected to support (CSI for example).
They achieve all of this with their own slice of Debian; it's as close to being standard as is sensible.
They also provide a tool -- pi-gen -- to allow you to roll your own distro off the main; it's quite effective.
And they have a mainline OS (Ubuntu) if you want that.
But if you really want a tiny SBC without their OS platform -- buy one.
"The OS -- the features, the documentation, the learning focus, the ease-of-use planning, the designed support for school and code clubs"
It reminds me of the class a family member took recently where they were learning basic shell scripting using c-shell on a bunch of 15 year old Solaris machines. Interesting, but also somewhat harmful because they now have to translate what they have learned to linux/macos/etc should they actually get a job/etc that involves any shell scripting because bash tends to be the default.Similarly with the RPi, the install process needs custom tools, instructions, and images because the normal distro install process (which are overwhelmingly UEFI based) simply don't work. So they are basically teaching everyone how to perform actions that any students that go into IT related fields will need to relearn.
https://ubuntu.com/tutorials/install-ubuntu-desktop#1-overvi...
And there isn't an argument that they are making it simpler either, since its entirely possible to create ubuntu/etc disk images as well while still burying a proper boot/etc interface in the firmware.
So, as I said earlier what they are doing made sense 10 years ago but today looks out of place vs what everyone else is doing.
PS: And as far as the hardware, normal distro's don't seem to have problems with missing RTCs (they all enable NTP AFAIK), and none of the interfaces on the board are that weird. Mainline Linux supports GPIO, and MIPI/CSI, etc.
https://www.kernel.org/doc/html/v4.10/media/kapi/csi2.html
If those don't work on the RPi in mainline, that is where the foundation should be focusing, in order to land their drivers upstream, or provide binary packages for the main distos (or both as some vendors do). They aren't special in this regard, they are only special because instead of doing what everyone else does, they created a custom linux distro.
Sure, they will. But who cares? They can do that on the job, can't they?
Why is there an obligation to teach, you know, ten/eleven/twelve year olds professional skills?
The same kids are also learning MicroPython for the BBC micro:bit -- that's not really a professional skill either is it?
The point of the Raspberry Pi is not to breed sysadmins; it is not even to breed coders. It is to breed technically literate young people.
It genuinely sounds like the Raspberry Pi is simply not for you. And that is OK.
Same with the pi, which despite your insistence its only a teaching tool, I suspect that is actually a small fraction of their sales. The compute modules and their carriers make that point along with the popular HATs.
As do a few other posters on this forum noting how they show up on the internet connected to peoples various IoT devices. Pi holes, Kodi boxes, cheap security cameras, on and on. Pretty much everyone I know in IT has a few of them they are using for those purposes or sitting in their junk boxes. One guy I knew literally purchased thousands of them because he was running a little hobby security business and they are great (cheap!) little security cameras given a PoE hat and a camera.
The number of students I know with them? Two, both of which were getting CS/etc style degrees, and I purchased for them to play around with. High schoolers/etc zero. Despite asking quite a number of them on the robotics teams/etc. Frankly, they aren't very good IoT devices either, wemos/arduino/etc are far more approachable if all you want to learn how to do is blink a led, or connect a moisture sensor to the internet.
So, at least where I live and the people I talk to, they are basically hacker devices.
Also, note the questions in: https://old.reddit.com/r/raspberry_pi/
You diverge because you're designing a product and you want to. (The Raspberry Pi desktop, for example, is available to run on non-linux platforms; there is a continuum for them.)
There are plenty of Ubuntu-based Linux distros with diverging requirements; which ones do you not approve of?
They have their own intent to develop a distro with a particular focus; so does Raspberry Pi.
If you disregard intent as a factor, sure; there's no justification for any of those distros. But then if you disregard intent as a factor there's no inherent justification for _any_ distros at all.
> So, at least where I live and the people I talk to, they are basically hacker devices.
OK. But we should probably stipulate that the Foundation intends them to also be used by people who want to learn computing on a very low budget, and that is why they have chosen to create their own (reconfigurable) OS.
> Also, note the questions in: https://old.reddit.com/r/raspberry_pi/
And? Reddit is not for people under 13, for one thing.