Live data from Hacker News

Security Begins at the Home Router

insights.sei.cmu.edu

41–50 of 177 posts

Re: Security Begins at the Home Router

#41
post #6

Telling that the summary advice is “change the default password”, even if some of the other ideas are deployed user involvement is near zero if not completely zero. I wonder how impactful it would be to roll out a totally read-only router, or if the necessity of updates and maintenance would generate too much headache for the user

(I'm a Googler, opinions are my own). I think this is one of the awesome things about Google Wifi (aka: OnHub). It's fully managed from a phone app (via "the cloud"), so you get the authentication tied to your gmail account. It's also based on ChromeOs (chromebook OS), and follows a similar auto-update that Chromebooks get. So you are always running the latest firmware. (There are obviously downsides to Google Wifi,…

Sorry but cloud is not an option on routers for me. I've had too many from various manufacturers that completely break if there is no internet.

Re: Security Begins at the Home Router

#42

I'd like explore making a small ecosystem of open security plugins built on top of OpenWrt. The goal is to make firewalling and controlling network traffic really easy. The UI should be so easy a parent could perform difficult tasks such as limiting an iot devices traffic to local net or maybe just one ip using just an app. Or detecting unusual patterns of traffic from a device or IP addresses. The apis exist I can't…

It seems obvious that this should be developed, but to take it a step further it would be great if consumers could purchase something that gave them access to these plugins without needing to know how to setup OpenWRT. This will be challenging because most ISPs provide the router and firmware for the majority of their customers.

Re: Security Begins at the Home Router

#43

Earlier quoted context omitted.

While your points are valid, it is a bit disconcerting to have the world's largest data monetizer watch all of a home's traffic. Google's promised benevolence may be temporary

Even more than that; I left Google (as a user, never employee) because I was scared of being banned. Seeing stories of users on Amazon / Google getting their account banned due to something related to a business concern, made me realize that if someone flagged a google app I had my whole life could come to a grinding halt. Phone, phone number, email, storage, internet access! All that because maybe I got reports on a…

Similar concerns, I recently used Google Express for a purchase, it worked fine, and then I deleted it. My Google account is my main email, and every new Google service is another opportunity for my whole account to get irreversibly banned.

Using Google with their famous lack of customer service to make purchases that I could conceivably need to put a chargeback on felt uncomfortably risky.

Tie my home internet connection to that? How do I know I won't get locked out of the cloud-integrated admin app? Why would I want it connected to anything Google?

The "one account everywhere" thing is convenient and great for their branding, but it's not great for my peace of mind.

Re: Security Begins at the Home Router

#44
post #3

Earlier quoted context omitted.

Print the randomly generated password on a sticker on the router. Problem solved.

The problem with that is that they pick awful sets to generate from. Instead of a string of random letters and numbers, they should be a string of words. It's frustrating to visit someone's home, and have to enter (on a phone keyboard, no less) some lengthy gibberish that they never bothered to change.

When I have to generate pw for such use case I use: http://www.dinopass.com/

Re: Security Begins at the Home Router

#45

I'll take this opportunity to ask the community, what is a recommend router? It's going to be me and my roommate only (with friends and family over) and I would like to get something secure and also reliable (and preferably on the cheaper side) Any suggestions? I believe we have Cox if that is any factor....

I use one is the ASUS ones and like it. But from my understanding is that security wise, all consumer routers are bad. I have nothing to back up that claim with. I keep mine as updated as possible.

Re: Security Begins at the Home Router

#46

I'll take this opportunity to ask the community, what is a recommend router? It's going to be me and my roommate only (with friends and family over) and I would like to get something secure and also reliable (and preferably on the cheaper side) Any suggestions? I believe we have Cox if that is any factor....

In particular, recommendations for consumer routers would be welcome. Last time this came up, the line seemed to be "consumer routers are trash, if you want security you have to use an enterprise router." There might be some truth in this, but it isn't helpful. Surely not all consumer routers are equally bad?

Re: Security Begins at the Home Router

#47
post #4

Telling that the summary advice is “change the default password”, even if some of the other ideas are deployed user involvement is near zero if not completely zero. I wonder how impactful it would be to roll out a totally read-only router, or if the necessity of updates and maintenance would generate too much headache for the user

AT&T and a few others currently deal with this problem by having a random password assigned for the admin user printed on a sticker on the side of their Modem/Router combo boxes. It seems to work pretty well.

Got a new netgear router the other day and it used this. Default admin and default wpa2 key were randomly-generated at the factory and printed on the back of the router. If/when my parents need a new router I'm going to have them get one of these and never have to guide them through the security gui again.

Re: Security Begins at the Home Router

#48
post #35

I agree with Steven Gibson. The biggest defense we can have on this is autoupdating routers. At a minimum, just restart at some fixed time after an update is downloaded. More fancy would be dynamically calculating a low usage day and time to restart. But this would also involve the router manufacturer keeping it up-to-date as well. Which gets me thinking... Does a SOHO (or any) device exist that effectively runs two…

You will probably need more complex hardware to accommodate this and it will be much more complex to implement correctly. For SOHO it is better to simply optimize for quicker boot process. For homes it doesn't even matter, just reboot the thing automatically on schedule during night. My expensive router does this and it is not hard or expensive to implement in all new models, regardless of their price.

Re: Security Begins at the Home Router

#49
post #48
post #35

I agree with Steven Gibson. The biggest defense we can have on this is autoupdating routers. At a minimum, just restart at some fixed time after an update is downloaded. More fancy would be dynamically calculating a low usage day and time to restart. But this would also involve the router manufacturer keeping it up-to-date as well. Which gets me thinking... Does a SOHO (or any) device exist that effectively runs two…

You will probably need more complex hardware to accommodate this and it will be much more complex to implement correctly. For SOHO it is better to simply optimize for quicker boot process. For homes it doesn't even matter, just reboot the thing automatically on schedule during night. My expensive router does this and it is not hard or expensive to implement in all new models, regardless of their price.

Solid firmwares like OpenWRT run on a lot of routers already.

It should be possible to have some amount of regular updates, if not automatic.

Re: Security Begins at the Home Router

#50

I'll take this opportunity to ask the community, what is a recommend router? It's going to be me and my roommate only (with friends and family over) and I would like to get something secure and also reliable (and preferably on the cheaper side) Any suggestions? I believe we have Cox if that is any factor....

Albeit a bit expensive, Turris Omnia is fully open source down to schematics level. It's also pretty beefy with dual-core ARM CPU at 1.6 GHz and 1 GB DDR3.

Its documentation is however a bit lacking unfortunately.

Post reply on HN