Hacker News new | ask | show | jobs
24,650 internet-accessible BMCs leak password-derived hashes before login (lavahq.io)
20 points by ilreb 15 hours ago
1 comments

Who exactly wrote this spec?

How sure are we that it was an accident to share password hashes with the world?

The great mistake is that those servers have a management Ethernet interface connected to the Internet.

The management Ethernet port of a server, on which it listens for the IPMI protocol, is supposed to be connected only to a dedicated internal management network, which must be separated from the Internet, and also from the normal internal networks.

It is not expected that IPMI is secure. Security is supposed to be achieved by physical separation.