Root password is published in a public repository #1
Labels
No labels
blocked-physical
cleanup
hardware
infra
kernel
P1-critical
P2-high
P3-normal
P4-later
reliability
security
upstream
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
tiagoagueda/a80#1
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
23-sd-boot.mdline 244 documents the console root password in plain text:The note has said "change it" since it was written, and it has not been changed.
Why this is worse than a stale note. The repository at
source.tiagoagueda.com/tiagoagueda/a80is public (private: false; unauthenticatedGET /api/v1/repos/tiagoagueda/a80returns 200). And the board currently accepts passwordlogins as root:
So this is a working credential, not documentation. The rescue SD was cloned from the eMMC
system, so the same password very likely works on both.
Mitigating: the board is on a private LAN (
192.168.27.0/24) and is not internet-facing, soan attacker needs to be on the network first.
Done when
23-sd-boot.mdno longer contains a real credential204884e, soremoving it from the working tree does not remove it from the repo. Requires a force
push, so it needs an explicit decision.
Half done 2026-08-29, and the half that is done is the half that matters least.
The literal password is removed from
23-sd-boot.mdand16-ethernet-broken.md, and SSH nolonger accepts passwords at all (#2):
PasswordAuthentication no, verified asPermission denied (publickey)from a fresh session.But the credential itself is unchanged and still works on the serial console, and it
remains in git history, so this stays open. Two commands, and only you should run them:
sudowill ask fordraco's password, which does not exist yet - so runpasswd dracofromthe existing root session first, or do both as root:
Until
passwd rootruns, the password published in this repository still opens a serialconsole on this board. SSH is closed; the physical path is not.
Git history is #6 and is a separate, larger job. Rotating the credential is what makes the
published copy worthless, and that is the important half.
⚠️ The rescue SD card is a clone from before this and still accepts root over SSH with that
password. It needs a re-sync.
Done 2026-08-29. The published credential no longer works anywhere on this board.
Both accounts were given fresh 28-character random passwords. The plaintext never crossed the
network: generated locally, hashed locally with
openssl passwd -6, and only the SHA-512crypt hashes were sent, staged in tmpfs and shredded after
chpasswd -e.Verified rather than assumed - the old password was checked against the stored hashes directly:
and the new ones confirmed by recomputing the hash from the stored salt:
The credentials are in an untracked
secrets/directory, ignored before the file existed, forthe owner to move into a password manager.
The literal is removed from
23-sd-boot.mdand16-ethernet-broken.md. It remains in githistory - that is #6 and is untouched. Rotating the credential is what makes the published
copy worthless, and that is now done.
⚠️ The rescue SD card is a clone from before this and still carries the old password and
unhardened sshd.
tools/sync-rescue-sd.shnow copies the hardening drop-in and the admin key,but the card is not safe until it is re-synced - and it is a full system with a shell.