insecure method to store passwords.

hi

are you aware of this ?
http://felinemenace.org/~andrewg/MikroTik_Router_Security_Analysis_Part3/
and this ?
http://manio.skyboo.net/mikrotik/index.en.php

Yes, we are. Problem was told many times before.

and ? any official statement ?

  1. don’t give your router to somebody who will hack it. lock it away from public.
  2. keep backup files safe

given enough time, any encryption can be cracked. so use also other methods of protection.

normis you’re funny :wink: how can you say that passwords in routeros are encrypted? no they are not, if by encryption you mean simple xor, then it’s not very nice…

It wonders me who in your company made such faux pas when industry standard is password hashed with some random salt.

please read my post again, because you completely missed my point. I said - why even bother encrypting it? it will just take a little more time to read. Better deal with your other security hole - why can somebody take your router and do what he pleases?