Live data from Hacker News

Security Begins at the Home Router

insights.sei.cmu.edu

21–30 of 177 posts

Re: Security Begins at the Home Router

#21
post #6

Earlier quoted context omitted.

(I'm a Googler, opinions are my own). I think this is one of the awesome things about Google Wifi (aka: OnHub). It's fully managed from a phone app (via "the cloud"), so you get the authentication tied to your gmail account. It's also based on ChromeOs (chromebook OS), and follows a similar auto-update that Chromebooks get. So you are always running the latest firmware. (There are obviously downsides to Google Wifi,…

While your points are valid, it is a bit disconcerting to have the world's largest data monetizer watch all of a home's traffic. Google's promised benevolence may be temporary

Google also remotely wiped a bunch of its customers' routers, driving them off line and causing all sorts of problems.

Which isn't to say that home customers would have necessarily done better, but most people don't have random maintenance bring them down at random times.

https://www.theverge.com/2017/2/23/14722470/google-reset-onh...

Re: Security Begins at the Home Router

#23
post #6

Telling that the summary advice is “change the default password”, even if some of the other ideas are deployed user involvement is near zero if not completely zero. I wonder how impactful it would be to roll out a totally read-only router, or if the necessity of updates and maintenance would generate too much headache for the user

(I'm a Googler, opinions are my own). I think this is one of the awesome things about Google Wifi (aka: OnHub). It's fully managed from a phone app (via "the cloud"), so you get the authentication tied to your gmail account. It's also based on ChromeOs (chromebook OS), and follows a similar auto-update that Chromebooks get. So you are always running the latest firmware. (There are obviously downsides to Google Wifi,…

It will be particularly awesome on the day that Google's complaints system decides to close your account without recourse.

Not that that has ever happened, of course.

Re: Security Begins at the Home Router

#24
I mostly blame cable and docsis for this state of things, on top of the router manufacturers. Which is why I am happy to hear of increasing fiber rollouts.

Docsis gives the ISP the ability to control the router, but they are very bad at it and even if they aren't it's often the manufacturers who are the problem. So I always have bought my own cable modems instead of renting from the ISP. The last time I did this I went with a good Motorola, but come to find out arris has bought them out, I did some scans, notice it's vulnerable and needs and update, so I go to the arris website. Can't find the update anywhere. End up calling them and get told, even though I own the equipment, they only release updates to ISPs or "partners" and no I can't have it! Wtf!?

Docsis, even 3, is a shitty spec that needs to die.

So really the best thing you can do and what I suggest to people is to put the cable modem in bridge/passthrough mode after checking all settings, and then hit your own router.

Except most people, as the article states, just go get some crappy linksys (cisco owned), netgear, Asus, belkin, etc, which have their own set of problems. It's better with openwrt/ddwrt/tomato but there is a better way.

My favorite setup is thus:

ISP Router in passthrough

Ubiquiti edgerouter

Ubiquiti APs

Re: Security Begins at the Home Router

#25
post #16
post #5

I don't fear rebooting my router because it takes less than 30 seconds to do a complete cycle; TCP sessions can withstand that. It probably helps that it runs Debian stable, too, so security updates are frequent and regular.

Care to share some more information about your setup? I'm a PFsense user currently and am always looking for ways to tinkering with my networks.

The most important thing is to go into your BIOS and boot loaders and turn off any delaying options. The second most important thing is to boot from a SATA SSD.

You should be able to tune it from there to get a reboot under 30 seconds.

Re: Security Begins at the Home Router

#26

Telling that the summary advice is “change the default password”, even if some of the other ideas are deployed user involvement is near zero if not completely zero. I wonder how impactful it would be to roll out a totally read-only router, or if the necessity of updates and maintenance would generate too much headache for the user

I don’t know how it’s possible to be read only. It needs to update things like routes and arp tables. That’s exactly the type of stuff that gets poisoned when attacked.

Re: Security Begins at the Home Router

#27
post #6

Telling that the summary advice is “change the default password”, even if some of the other ideas are deployed user involvement is near zero if not completely zero. I wonder how impactful it would be to roll out a totally read-only router, or if the necessity of updates and maintenance would generate too much headache for the user

(I'm a Googler, opinions are my own). I think this is one of the awesome things about Google Wifi (aka: OnHub). It's fully managed from a phone app (via "the cloud"), so you get the authentication tied to your gmail account. It's also based on ChromeOs (chromebook OS), and follows a similar auto-update that Chromebooks get. So you are always running the latest firmware. (There are obviously downsides to Google Wifi,…

Perhaps it's just because I'm not in the target demographic, but this is exactly the reason that Google Wifi is completely out of consideration if I ever need to buy a new router.

Give me local ssh and WebUI. No cloud, no phone apps.

Re: Security Begins at the Home Router

#28
post #5

I don't fear rebooting my router because it takes less than 30 seconds to do a complete cycle; TCP sessions can withstand that. It probably helps that it runs Debian stable, too, so security updates are frequent and regular.

> TCP sessions can withstand that.

But connection tracking tables for NAT may not. Plus the ISP might assign a new IP to your CPE on ppp auth.

Re: Security Begins at the Home Router

#29
post #6

Earlier quoted context omitted.

(I'm a Googler, opinions are my own). I think this is one of the awesome things about Google Wifi (aka: OnHub). It's fully managed from a phone app (via "the cloud"), so you get the authentication tied to your gmail account. It's also based on ChromeOs (chromebook OS), and follows a similar auto-update that Chromebooks get. So you are always running the latest firmware. (There are obviously downsides to Google Wifi,…

While your points are valid, it is a bit disconcerting to have the world's largest data monetizer watch all of a home's traffic. Google's promised benevolence may be temporary

Even more than that; I left Google (as a user, never employee) because I was scared of being banned. Seeing stories of users on Amazon / Google getting their account banned due to something related to a business concern, made me realize that if someone flagged a google app I had my whole life could come to a grinding halt. Phone, phone number, email, storage, internet access! All that because maybe I got reports on a phone app I wrote (hypothetical).

I'm doing nothing illegal or unethical, nothing wrong. Nevertheless, I ran from Google asap due to that reason alone. Google represented a massive single point of failure to my digital life.

I now use separate products for just about everything I own. While it's not as convenient as Google, I feel far more secure.

Re: Security Begins at the Home Router

#30
post #14

Telling that the summary advice is “change the default password”, even if some of the other ideas are deployed user involvement is near zero if not completely zero. I wonder how impactful it would be to roll out a totally read-only router, or if the necessity of updates and maintenance would generate too much headache for the user

The idea of a completely read-only router is really interesting. I used to buy hardware that would only work with open firmware -- I used to love to constantly update and mess with DD-WRT. But in more recent years I've just started buying high-performing hardware and skipping the customization beyond SSID and passwords. With faster connections, UPNP, and decent default QoS policies I pretty much never have to configu…

UPNP can be an absolute security nightmare however, it's the sole reason so many IP cameras, NAS drives and IOT devices are internet accessible.

It's your network of course but it would be the first thing I'd turn off.

Post reply on HN