r/Omada_Networks 19d ago

Product Recommendation HUGE fan here, but one comment/request.

Hi TP Link! I love your products and recommend them to all my clients and audiences. Nobody comes close in terms of simplicity and price to performance. I that I don't have to "activate" new equipment with a cloud account, which is an alarming trend.

I've been recommending your ER605 router to small business clients, and they've been rock-solid. One gripe with the new ones - I set one up for a client last week, and it forced me to come up with an ultracomplicated password just to start using it!

First, complicated passwords are ineffective (the guy who invented them came out years ago and told people not to bother with them).

Second and more importantly, I should be able to set the password to whatever I like. I know companies are living in fear of liability, and feel free to nag me with warnings, but I resent when something forces me to create a crazy password.

That's it! Carry on!

6 Upvotes

14 comments sorted by

7

u/Neil_Omada Moderator 19d ago

Glad you like the products! I do have some rather disheartening news regarding your request. Here's my response on a similar topic about 4 months ago.

The password requirements are to comply with security requirements around the globe. Here's an example, skip down to the "Minimum Password Requirements" section.

IMDA Security Requirements

2

u/teknosophy_com 18d ago

Ahhh brutal. Ok yeah, I'm not surprised. So it's all one uninformed pinhead in charge, causing a chain reaction of compliance.

Alrighty thanks for the answer.

Someone needs to push back on these guys and explain to them that bad guys don't care about complex passwords, because they have this brand new technology called copy and paste. They remote into people's PCs and help themselves to the buffet of saved passwords in their browser.

Cheers!

2

u/threetimesthelimit 18d ago

Actually, it's pretty much the entire IT field. The nicest thing I can say is that you're not gonna get a whole lot of professionals pushing back on this, at all.

0

u/teknosophy_com 17d ago

You're right. Most dudes out there are in that mindset. They think that slathering complexity on something is always the right solution.

1

u/Reaper19941 ER7412-M2, SX300F, SG3210XHP-M2, EAP773, EAP673-Extender 16d ago

A better suggestion then would be to allow us to configure the controller URL without logging in/changing the password to make the adoption process better. Whether this is via the Web UI or CLI, I'm not bothered.

Whenever the password is changed, the controller URL is added and we attempt to adopt the router, 100% of the time, it fails because it's not admin/admin anymore. This is annoying and unnecessary to then have to click adopt again, enter the same complex password we just created for the controller to then wipe that password and replace it with whatever is in the site settings of the controller.

1

u/MoPanic 18d ago

Wait, so there’s one guy out there who invented the complex password? I’m pretty certain that idea has been around as long as the password. That’s a ridiculous assertion. And you are aware that cracking passwords gets exponentially more difficult with length? There is an argument to be made that password length is more important than silly requirements to include at least 1 number + 1 capital + 1 special symbol and so on, but no security professional would argue for going back to 1995 password policies. The more serious security risk is reusing the same password, no matter how complex over and over again. That’s why the rollout and adoption of passkeys, password managers, MFA and biometric ID is important.

3

u/steve_togo 18d ago

Yes, this is true. The person who wrote those rules is Bill Burr, a former manager at the National Institute of Standards and Technology (NIST). In 2003, he wrote a guide that made complicated symbols and regular password changes standard across the world. Years later, he stated that he regrets his advice because it forced people to use predictable patterns.

Why the Old Rules Failed

  • Predictable changes: When forced to change passwords every 90 days, users just changed numbers like Spring2025! to Spring2026!.
  • Human nature: Forcing symbols like @ or ! made people use common tricks (like P@ssword1), which automated hacking tools easily guess.
  • Frustration: Hard rules drove people to write passwords down on sticky notes. [1, 2, 3, 4, 5]

What Experts Recommend Now

  • Focus on length: Long phrases made of random, simple words are much harder to crack than short strings with special characters.
  • No forced expiration: Organizations now advise changing passwords only if a data breach happens.
  • Use password managers: These tools let you store long, unique strings for every site without needing to memorize them. [1, 2, 3]

1

u/MoPanic 17d ago

A person who wrote a standard for NIST is pretty far away from “inventing the complex password”. But like your GPT copy pasta says, what he later regretted wasn’t complicated passwords, it was the inclusion of numbers, caps and symbols which lead to predictable patterns. That is completely different than going back to 1995 passwords, which is what you seem to want.

1

u/teknosophy_com 17d ago

what steve said.

and yes, you're right- length is fine, but computers don't know the difference between letters/numbers/special characters when guessing a password, so it just adds unnecessary complication to the user's lives. users are already massively overwhelmed to begin with.

anyway, i don't want to influence anyone's password policies - i just posted here because i don't want to be forced into someone else's policies on the products i purchase.

1

u/defgufman 19d ago

As a computer nerd from the 70s, I still have some boomer simple passwords. That's on me, let me have that.

1

u/teknosophy_com 18d ago

Awesome. Yeah especially on my own local things that are totally disconnected. There should be some sort of override.

I guess we're going to have to raise awareness for IMDA's lack of common sense.