Skip to main content

You are not logged in. Your edit will be placed in a queue until it is peer reviewed.

We welcome edits that make the post easier to understand and more valuable for readers. Because community members review edits, please try to make the post substantially better than how you found it, for example, by fixing grammar or adding additional resources and hyperlinks.

8
  • 4
    In the e-waste scenario, it would be necessary to (1) recover the router in sufficient working order to extract its storage, (2) the former owner of the router to re-use the same password in their new router, and (3) have some way to track the disposed router to the original physical location where the new router is installed. This is a fairly unlikely sequence of events to simultaneously be true; it can easily be defeated by the former owner changing the password (good practice anyway), doing a factory reset before disposal, or not disposing it with location identifiers. Commented Aug 19, 2025 at 8:11
  • 1
    And from my experience, 2) involves more effort on part of the former owner then just getting a new password. If owner laziness is enough to stop an attack, it's not a very dangerous attack. Commented Aug 19, 2025 at 8:44
  • 1
    @Miral: And if an attacker has sufficient resources and motivation to carry out those steps, then the fact the password is stored in an obfuscated-but-reversible manner is unlikely to present much of a challenge to them! Commented Aug 19, 2025 at 9:31
  • And "obfuscated" needs to be "encrypted", else there is no point. Commented Aug 19, 2025 at 10:05
  • 1
    @Miral those of us with ISP-provided routers could find ourselves in that position on changing ISP - the old router is (assuming they want it back; I have a couple in my attic that I put there in case they asked for it - years ago) returned, in packaging with the sender's (former user's) address. That's 2 out of your 3. The other - well, if you want all your devices and regular guests' device to seamlessly connect to the new hardware, just set the SSID and password the same and you're done. So it's more likely than you think Commented Aug 19, 2025 at 13:09