Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>Advisory helps organizations protect against PRC-linked actors hiding in router firmware

The most popular router brand is TP-Link which is a Chinese Brand. Both Eero and Nest from Amazon to Google aren't available worldwide. Netgear and Linksys has poor Firmware update frequency. That is pretty much left with ASUS which I have a decade old unfix bug with my ISP that randomly fails to get new IP.

I only wish Apple would come back with new AirPort Extreme.



This is a... very consumer-centric view of the landscape of routers, not really all that applicable to businesses and enterprises.


You may be surprised how many SME, heck even branches of large enterprise uses Top Range Consumer Router in their office.


For select small/home plastic routers, there's always OpenWrt.

OpenWrt is generally more trustworthy than the stock firmware, but I wouldn't expect any of these solutions to keep out a state actor, nor even a script kiddie with a lot of time on their hands. Trust level is more like not having a known stock firmware botnet motel, and maybe keeping some cruddy US IoT products on their own VLAN.


If a SoC has a co-processor with proprietary firmware, potentially for things like security, remote management, bringing up the main CPU, etc, peripherals with proprietary firmware, potentially with DMA access, or firmware operating at ring -2/-3, they can sidestep OpenWRT and you wouldn't even know it from the OpenWRT side of things.


But... How do you know that's not back doored as well? I would just assume that everything is back doored or has a zero day until proven otherwise. And yes, how do you prove a negative? I refer you back to my first point.


It might well be backdoored. I said what I thought the trust level is.


Everyone's throwing out suggestions, so I'll say what I've found to work well after years of sampling the options.

pfSense box + Ruckus WAP

I went with a Netgate SG-1100 and am happy with it for 200/100 WAN. I have a Ruckus R610 (used on ebay for $100) that gets regular Unleashed firmware updates and is far and away the best WAP I have ever owned.


Another option is to build your own. You could buy a small ARM board like a NanoPi R6S (<$100) with 2.5GbE ports and run pfSense on it.


The NanoPi is of Chinese origin, all the way down to the silicon, how do you know the bootloader or the CPU isn't compromised?

If someone told you a cup may contain poison, would your first reaction be to drink it just to be sure?


We have photographic evidence of the NSA intercepting Cisco routers. I'm not sure the country of origin matters if you have a red spot painted on your back.

https://arstechnica.com/tech-policy/2014/05/photos-of-an-nsa...


What's being proposed here - as an alternative solution to mass-produced Chinese equipment of unknown trustworthiness - is to purchase different mass-produced Chinese equipment of unknown trustworthiness.

Your example of highly-targeted physical interception by state-level actors is irrelevant here.


You are really bringing your own OS here. The nanopi can run mainline linux and u-boot[0]. If you suspect an Intel ME-style component with ring -3 access, it should show up in the initialization sequence - there are no blobs here. Features like these are not cheap to implement, especially when Chinese vendors are so keen on cutting costs.

Essentially, this means that there is zero risk, unless you are a target, at which point any unintentional hardware bug caused by the aforementioned corner-cutting will become a concern.

[0] https://linux-sunxi.org/Linux_mainlining_effort

https://linux-sunxi.org/U-Boot

https://linux-sunxi.org/H3


How do you guarantee there isn't some logic flashed onto the chip that overrides the bootloader sequence?

btw, I asked about this 5 months ago [0] and got some interesting replies. I ended up purchasing a PCEngines board (just before they went out of business)

[0] https://news.ycombinator.com/item?id=35568984


From what I've seen, networking peripherals you can attach to a Pi via USB, or whatever, can't really compete with networking peripherals in routers that are integrated on SoCs/SoMs.


The suggested NanoPi R6S has two 2.5G ports connected to PCIe and one 1G port built in to the SoC, it doesn't use USB for networking.


I figure people are using them for router things, like using it as a wireless AP and switch, and the hardware available for those use cases usually fall short of what's available on router SoCs.


you mean buy it from China? Guangzhou,GuangDong China. That's great advice.


Or better yet OPNSense.


> I only wish Apple would come back with new AirPort Extreme

The same Apple that refuses to publish official EOL support dates?


Does any consumer router manufacturer publish that?


Yes.


Such as???…


I'm scratching my head as to why I don't hear about more people running Raspberry Pis as APs off the built-in WiFi for smaller (in terms of number of clients) networks.

I chucked up hostapd on Debian at one point and was surprised to see how good coverage it got. Outperformed devices in higher price-range without even attaching an antenna.


I prefer unifi though lately they've been pretty disappointing. Still no budget wifi 6E (6Ghz) access point and more and more stuff needs their cloud.


Same here Unifi isn’t perfect but I still prefer the single pane of glass view with Unifi and Protect. My biggest gripes are silly defaults they cause massive issues with 2.4g devices and subpar outdoor cameras and doorbells that fail after 1-2 years.


I'm running Unifi cameras here outdoors just fine with 6 years of use and different generations (I get bored and need new toys)

The only one I've ever had fail is a 7 year old G3 Flex indoors.


Thoughts on Arris for modems? I could use a router recommendation honestly.


If you are like me and don't want to keep messing with the router, then Firewalla Gold 1Gb [1] or Gold Plus 2.5Gb [2] should be good for a home router.

Docker can also be used. Don't get the SE or other cheaper versions, they use ARM chips. Gold/Gold Plus use x86.

[1] https://firewalla.com/products/firewalla-gold [2] https://firewalla.com/products/firewalla-gold-plus


The Turris Omnia is pretty great. Open source.

https://www.turris.com/en/products/omnia/


Mikrotik?


Do those things come setup for a normal smb out of the box yet or is it build your own NAT still to use one?


Almost nothing about MicroTik can be described as "out of the box" or easy, but they can be configured to do SMB using the onboard USB connector.

https://www.youtube.com/watch?v=YDdTSswDu8I


They have a default configuration applied when they are first powered on after a reset which includes wan, lan and nat setup. Possibly some basic firewall setup though I cant recall.


Unifi


The UDM SE has a bug where if you max out 1 Gbps for a bit, at some point the WAN interface is going to crash and you have to either 1) restart, 2) unplug and replugin the cable, 3) restart the interface the WAN port was on.

This bug has existed for over a year, with no fix in sight.

Unifi's quality is dropping day by day. I'm convinced they don't use their own networking tools.


I have a UDM SE with 1.2ish gigabit connection through Xfinity and I’ve never had to restart or unplug ports.


Have you been maxing it out for an hour or two at a time?


I don't think those are conditions required to reproduce whatever this is.


the linked documents indicate several brands, none of which are tp-link.


Unifi has both enterprise and consumer routers...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: