# Is the default password on apps a risk?

**URL:** <https://community.umbrel.com/t/is-the-default-password-on-apps-a-risk/941>\
**Category:** General Discussions\
**Created:** [May 16, 2021, 12:14pm UTC](https://community.umbrel.com/t/is-the-default-password-on-apps-a-risk/941 "2021-05-16T12:14:11Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![btc\_ln](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.umbrel.com/btc_ln/32/838_2.png) [@btc\_ln](https://community.umbrel.com/u/btc_ln)\
**Post date:** [May 16, 2021, 12:14pm UTC](https://community.umbrel.com/t/is-the-default-password-on-apps-a-risk/941/1 "2021-05-16T12:14:11Z")

</div>

`moneyprintergobrr` is the default password on most apps in Umbrel. In what scenarios is this is a security risk, if any?

Is there a plan to change this default functionality in the future?

---

<div class="post-metadata">

**Author:** ![freshmozz](https://avatars.discourse-cdn.com/v4/letter/f/fbc32d/32.png) [@freshmozz](https://community.umbrel.com/u/freshmozz)\
**Post date:** [June 1, 2021, 3:23pm UTC](https://community.umbrel.com/t/is-the-default-password-on-apps-a-risk/941/2 "2021-06-01T15:23:00Z")

</div>

Bump - I noticed some apps are allowing me to change the password but not all.

---

<div class="post-metadata">

**Author:** ![btc\_ln](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.umbrel.com/btc_ln/32/838_2.png) [@btc\_ln](https://community.umbrel.com/u/btc_ln)\
**Post date:** [June 2, 2021, 3:24pm UTC](https://community.umbrel.com/t/is-the-default-password-on-apps-a-risk/941/3 "2021-06-02T15:24:02Z")

</div>

I think only RTL allows it. What other?

---

<div class="post-metadata">

**Author:** ![freshmozz](https://avatars.discourse-cdn.com/v4/letter/f/fbc32d/32.png) [@freshmozz](https://community.umbrel.com/u/freshmozz)\
**Post date:** [June 2, 2021, 3:40pm UTC](https://community.umbrel.com/t/is-the-default-password-on-apps-a-risk/941/4 "2021-06-02T15:40:44Z")

</div>

My mistake, you’re right it is just RTL currently.

---

<div class="post-metadata">

**Author:** ![freshmozz](https://avatars.discourse-cdn.com/v4/letter/f/fbc32d/32.png) [@freshmozz](https://community.umbrel.com/u/freshmozz)\
**Post date:** [June 9, 2021, 8:58pm UTC](https://community.umbrel.com/t/is-the-default-password-on-apps-a-risk/941/5 "2021-06-09T20:58:01Z")

</div>

Still fairly concerned here: sharing a network with roommates or a group of people is very common. and it seems as long as someone knows you have a node running with umbrel, they can just try umbrel.local:300x and try to find thunderhub or other apps. Accessing them this way does not seem to require you be logged in to umbrel.local first.

---

<div class="post-metadata">

**Author:** ![Full\_node](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.umbrel.com/full_node/32/80_2.png) [@Full\_node](https://community.umbrel.com/u/Full_node)\
**Post date:** [June 10, 2021, 1:47am UTC](https://community.umbrel.com/t/is-the-default-password-on-apps-a-risk/941/6 "2021-06-10T01:47:04Z")

</div>

@freshmozz is correct. Anyone on the same network can just add the correct URL and log in via the default password. Gives full access to any feature in the app. This is very concerning for anyone running an Umbrel on a shared network.

---

<div class="post-metadata">

**Author:** ![btc\_ln](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.umbrel.com/btc_ln/32/838_2.png) [@btc\_ln](https://community.umbrel.com/u/btc_ln)\
**Post date:** [June 10, 2021, 2:41am UTC](https://community.umbrel.com/t/is-the-default-password-on-apps-a-risk/941/7 "2021-06-10T02:41:54Z")

</div>

Yeah, for now, uninstall any apps that use the default password.

---

<div class="post-metadata">

**Author:** ![freshmozz](https://avatars.discourse-cdn.com/v4/letter/f/fbc32d/32.png) [@freshmozz](https://community.umbrel.com/u/freshmozz)\
**Post date:** [June 10, 2021, 10:24pm UTC](https://community.umbrel.com/t/is-the-default-password-on-apps-a-risk/941/8 "2021-06-10T22:24:47Z")

</div>

I’m out of my depth here, but is there a way to limit access of umbrel.local (and by extension umbrel.local:300x) to a single source? either from IP or MACID of the device?
