Community discussions

MikroTik App
 
pcgy
just joined
Topic Author
Posts: 2
Joined: Mon Oct 16, 2023 2:17 pm

Brave browser can bypass SwOS login page

Mon Oct 16, 2023 2:52 pm

Hi,

Just an FYI for anyone using the Brave browser on Windows with sync enabled, if you browse to the switch IP it will take you straight to the System tab without requesting credentials.
Browser is set to never save passwords, and passwords are not enabled as part of the sync process.

I've just purchased a CSS106-1G-4P-1S and a CSS106-5G-1S switch.

All I've done so far is upgrade from SwOS 2.11 to 2.13, set a static IP for each switch via DCHP, and specify the same IP as the fallback address, and set a password.
I can logout, which gives me a login page, and I can login with my new password.

However, if I log out, then close Brave, reopen it, and browse to the switch IP it bypasses the login request entirely.
This is true for both switches.

Logging onto another device which has never accessed the switch IPs before, but also uses Brave sync, allows direct access to the switches.
Chrome and Edge both always request a password.

I haven't tried Brave on Linux yet, but I suspect it will exhibit the same behaviour.
 
holvoetn
Forum Guru
Forum Guru
Posts: 5528
Joined: Tue Apr 13, 2021 2:14 am
Location: Belgium

Re: Brave browser can bypass SwOS login page

Mon Oct 16, 2023 10:07 pm

Tested in CSS610, I am not seeing that.

Open Brave, login, logout, need to enter credentials again.
Close Brave, open Brave, login credentials again.

BUT ... what you see is NORMAL when you use Brave Sync.
Syncable data includes:

Bookmarks
Passwords
Autofill Data
History
Open Tabs
Extensions
Themes
Apps
So, not a SWOS problem.
 
pcgy
just joined
Topic Author
Posts: 2
Joined: Mon Oct 16, 2023 2:17 pm

Re: Brave browser can bypass SwOS login page

Wed Oct 18, 2023 5:50 am

Agreed, not really a Sw OS problem.

But I thought it may be of interest to others.

In my case Brave is configured to never save passwords, and Sync is configured to not sync passwords, however it is configured to sync history and open tabs so I suspect that's where the issue lies.

I've just tried again using Brave that isn't set to sync, and it demands a login every time.
 
holvoetn
Forum Guru
Forum Guru
Posts: 5528
Joined: Tue Apr 13, 2021 2:14 am
Location: Belgium

Re: Brave browser can bypass SwOS login page

Wed Oct 18, 2023 9:02 am

It will be the same if you allow the browser to save passwords and login automatically using Firefox, Chrome, Edge, ... whatever.

Who is online

Users browsing this forum: No registered users and 1 guest