Live data from Hacker News

Fixing Weak Wi-Fi Router Security

nytimes.com

11–20 of 69 posts

Re: Fixing Weak Wi-Fi Router Security

#11

> Replace your router every few years How about instead of this, use open source software on your router? It will keep being updated, and with the manufacturer's proprietary software on the device you can't really trust it anyway.

That's a good solution for geeks, not so much for everyone else. Regular people don't even update their routers, much less flash 3rd party software on them. I don't think most people even know updating your router is even a possibility.

I use Google Wifi and it updates itself. In the future I might put in a PFSense, but wifi solutions like Google Wifi/Eero/etc are the way to go if you're not a computer person.

Re: Fixing Weak Wi-Fi Router Security

#13
post #7

Earlier quoted context omitted.

That is the reason I run a pfsense router/firewall. You never worry they are going to stop supporting your device cause your device is x86 with FreeBSD base.

And how much money are you bleeding running that machine 24/7?

Not OP but I run a PC Engines APU2[1] as my pfsense box. It's 6-10 watts.

Updates are easy to manage, I use Pfblocker which is similar functionality to PiHole, and have cloudflares DNS (1.1.1.1) set up.

As for wireless I attach a Ubiquiti AP through a switch.

I've done this at a couple different sites for relatives and it's comforting to know there's some semblence of security and privacy for them.

[1] http://www.pcengines.ch/apu2.htm

Re: Fixing Weak Wi-Fi Router Security

#14
post #7

Earlier quoted context omitted.

That is the reason I run a pfsense router/firewall. You never worry they are going to stop supporting your device cause your device is x86 with FreeBSD base.

And how much money are you bleeding running that machine 24/7?

Shouldn't be too much. You can buy one [SG-1000] linked from pfsense that is only 2.5W (idle) draw.

Re: Fixing Weak Wi-Fi Router Security

#15

Grab a decent microtik router and a few Ubiquiti Unifi AP's, setup automatic updates, and never touch them again.

What do you recommend router-wise? I'm currently using an EdgeRouter PoE and have been happy with it, but I'm setting up a home network at a condo and am researching options.

Re: Fixing Weak Wi-Fi Router Security

#16
post #4

Earlier quoted context omitted.

Your odds might be better, but there's no guarantee that the software will keep being updated. DD-WRT for many models is simply defunct, for example.

That is the reason I run a pfsense router/firewall. You never worry they are going to stop supporting your device cause your device is x86 with FreeBSD base.

Actually, that is not strictly so [1]. Starting in 2.5, they are requiring AES-NI instructions. I am a bit irritated with that as I bought one of their "official" routers to support them (The one based on the PC Engine APU2) and I use it as a home router, so I really don't need that support.

[1]https://www.netgate.com/blog/pfsense-2-5-and-aes-ni.html

Re: Fixing Weak Wi-Fi Router Security

#17
post #13
post #7

Earlier quoted context omitted.

And how much money are you bleeding running that machine 24/7?

Not OP but I run a PC Engines APU2[1] as my pfsense box. It's 6-10 watts. Updates are easy to manage, I use Pfblocker which is similar functionality to PiHole, and have cloudflares DNS (1.1.1.1) set up. As for wireless I attach a Ubiquiti AP through a switch. I've done this at a couple different sites for relatives and it's comforting to know there's some semblence of security and privacy for them. [1] http://www.pce…

I have one of those as well. As a word of caution, they are dropping support for that in 2.5 [1]. Starting in 2.5, they are requiring AES-NI instructions (like I said in my other post, I am a bit irritated they did that, especially when that is a requirement for something I do not need).

[1]https://www.netgate.com/blog/pfsense-2-5-and-aes-ni.html

Re: Fixing Weak Wi-Fi Router Security

#18

Grab a decent microtik router and a few Ubiquiti Unifi AP's, setup automatic updates, and never touch them again.

What do you recommend router-wise? I'm currently using an EdgeRouter PoE and have been happy with it, but I'm setting up a home network at a condo and am researching options.

I'm actually just running a hAP lite for home use, one of my friends works for a WISP and they're using EdgeRouter's on their towers, he seems pretty damn happy with them.

I don't have much going on with my router, a few open ports, blocked domains and its running a L2TP over IPsec VPN for when I want to access my home IP cams.

I bought the older RB2011UiAS-RM years ago for work to replace their two crappy BT business hubs and setup dual DSL failover with a 3G dongle as a backup. I've never had to reboot any of them due to a malfunction or crash, they just keep going and the performance is top notch for the medium size business they're servicing.

Re: Fixing Weak Wi-Fi Router Security

#19
post #7

Earlier quoted context omitted.

That is the reason I run a pfsense router/firewall. You never worry they are going to stop supporting your device cause your device is x86 with FreeBSD base.

And how much money are you bleeding running that machine 24/7?

For 100 MBit/s firewall all you need is Raspberry PI. Most people’s WAN connection is probably less than that. And if you need gigabit then there’s still plenty of options, anything from ODROID-C to 10W Goldmont, the latter a little expensive but it can double as HTPC etc. Idk how any of those work with BSDs but they work fine on Linux.

Also the nic.cz people have a neat new product[1]. It’s really cool, but I think still too pricey.

[1] https://www.indiegogo.com/projects/turris-mox-modular-open-s...

Re: Fixing Weak Wi-Fi Router Security

#20
post #19
post #7

Earlier quoted context omitted.

And how much money are you bleeding running that machine 24/7?

For 100 MBit/s firewall all you need is Raspberry PI. Most people’s WAN connection is probably less than that. And if you need gigabit then there’s still plenty of options, anything from ODROID-C to 10W Goldmont, the latter a little expensive but it can double as HTPC etc. Idk how any of those work with BSDs but they work fine on Linux. Also the nic.cz people have a neat new product[1]. It’s really cool, but I think…

RPi systems die too frequently unless you get the right kind of sd cards and power adapters.
Post reply on HN