Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I wonder how much it is worth to crack the root password that was left embedded in all the Barracuda devices even with the patch applied?


Is it the same in all devices? Is it ever changed? How many people know it?


To a competitor? Depends if people blame barracuda or can trace the cracking back to you.

Are you thinking of switching a bitcoin mining operation into a cracking-passwords-to-put-companies-out-of-business operation?


I'm more afraid of the nebulous criminal underground or national entities than I am of Barracuda's competitors. I'm not referring at all to Bitcoin (or putting companies out of busines...), it's surely cheaper to just use available "cloud cracking" assets directly (which I'm also sure is already being done).

Since it's apparently unclear, I'm not talking about taking action myself, but I will say that due diligence for any company using Barracuda hardware means that they should be asking the same question themselves.


There's services that already do this, but it's not really necessary in most cases. Even with my lonely workhorse I can smash through hundreds of millions of hashes a second. You only need additional reinforcements for more computationally harder hashes.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: