Live data from Hacker News

Security Begins at the Home Router

insights.sei.cmu.edu

81–90 of 177 posts

Re: Security Begins at the Home Router

#81

I'll take this opportunity to ask the community, what is a recommend router? It's going to be me and my roommate only (with friends and family over) and I would like to get something secure and also reliable (and preferably on the cheaper side) Any suggestions? I believe we have Cox if that is any factor....

I'm actually pretty happy with my Netgear Velop mesh system. I had a Netgear Nighthawk X8, but when I moved it was great for the new house. The Velop mesh has been seamless.

Re: Security Begins at the Home Router

#82
post #79
post #55

Earlier quoted context omitted.

You can get the EdgeRouter X for ~$50 and that will scale to symmetric gigabit connections, if your needs are simple (ie. you're just doing basic routing & firewalling, not trying to do traffic shaping, etc). Budget AP option then is a UAP-AC-Lite which you can buy off Amazon for ~$80, bringing your total to $130 all said and done. That's cheaper than most all-in-one routers, and while you won't get the best single-c…

I'm ashamed by this Networking 101 question, but what prevents you from connecting the UAP-AC-Lite directly to the ISP's device? (Assuming you don't want a physical ethernet connection at all). Is it for DHCP and assigning IPs to the clients?

Nothing. I do this. I think the AC-Lite even has it's own DHCP, but I'm using the ISP router for that personally.

Usually the ISP router just sucks at wifi, but I have seen ISP routers which have only 100mbit/s uplink ports when the internet connection is higher. In that case you'd want a custom router also. Or if they ship some router with some features you dislike that you can't disable (like public hotspots, unpatchable insecure config interfaces, etc.)

Re: Security Begins at the Home Router

#83

I'll take this opportunity to ask the community, what is a recommend router? It's going to be me and my roommate only (with friends and family over) and I would like to get something secure and also reliable (and preferably on the cheaper side) Any suggestions? I believe we have Cox if that is any factor....

Do Synology routers count as consumer?

Re: Security Begins at the Home Router

#84

I'll take this opportunity to ask the community, what is a recommend router? It's going to be me and my roommate only (with friends and family over) and I would like to get something secure and also reliable (and preferably on the cheaper side) Any suggestions? I believe we have Cox if that is any factor....

I've had my Google OnHub for three years now and it works flawlessly, regularly updating itself without any detectable downtime. It is by far the longest that I've had any wifi access point, and it is the only one I haven't had to personally check and update for security issues.

Re: Security Begins at the Home Router

#85

I'd like explore making a small ecosystem of open security plugins built on top of OpenWrt. The goal is to make firewalling and controlling network traffic really easy. The UI should be so easy a parent could perform difficult tasks such as limiting an iot devices traffic to local net or maybe just one ip using just an app. Or detecting unusual patterns of traffic from a device or IP addresses. The apis exist I can't…

I think the problem is that it already is really easy. I feel like it'd be hard to simplify the interface of something like UniFi's AP series and still keep the number of knobs it gives you. And you almost certainly will never simplify it to the point that people will stop making youtube bandicam free edition tutorials on how to port forward your minecraft server.

Re: Security Begins at the Home Router

#86

I'd like explore making a small ecosystem of open security plugins built on top of OpenWrt. The goal is to make firewalling and controlling network traffic really easy. The UI should be so easy a parent could perform difficult tasks such as limiting an iot devices traffic to local net or maybe just one ip using just an app. Or detecting unusual patterns of traffic from a device or IP addresses. The apis exist I can't…

It seems obvious that this should be developed, but to take it a step further it would be great if consumers could purchase something that gave them access to these plugins without needing to know how to setup OpenWRT. This will be challenging because most ISPs provide the router and firmware for the majority of their customers.

I would personally love to see the same, and a way of unifying experiences across all open firmwares such as ddwrt.

Another is to limit a device to communicate to a specific country. Easy enough however a possible performance issue.

Re: Security Begins at the Home Router

#87
post #6

Earlier quoted context omitted.

(I'm a Googler, opinions are my own). I think this is one of the awesome things about Google Wifi (aka: OnHub). It's fully managed from a phone app (via "the cloud"), so you get the authentication tied to your gmail account. It's also based on ChromeOs (chromebook OS), and follows a similar auto-update that Chromebooks get. So you are always running the latest firmware. (There are obviously downsides to Google Wifi,…

While your points are valid, it is a bit disconcerting to have the world's largest data monetizer watch all of a home's traffic. Google's promised benevolence may be temporary

While it's amusing to consider that someone cares, the fact is that if someone wanted to specifically surveil you the most likely way to do so would be to crack into your computers and network devices. That's the real threat model. You want the device with the best functional security. I don't think you should rule out any candidates based on imaginary privacy issues.

Re: Security Begins at the Home Router

#88
post #80
post #75

Earlier quoted context omitted.

> That's cheaper than most all-in-one routers, It really isn't. There are plenty of consumer router+AP combos in the $75-90 range that offer equal or better performance to the ER-X + UAP-AC-Lite combination.

Such as ...?

Not OP, but I've been very happy with a $60 Buffalo N300, running since 2015 with no issues. I run DD-WRT on it, 200 Mbit symmetric fiber uplink, 3 devices connected via ethernet and the rest via wifi covering the whole (wooden) house, and I have port forwards for ssh and https to the server in the garage. Does everything I need and more.

I've been looking for an excuse to go down the Ubiquiti route, but I really can't find one.

Re: Security Begins at the Home Router

#89

I'll take this opportunity to ask the community, what is a recommend router? It's going to be me and my roommate only (with friends and family over) and I would like to get something secure and also reliable (and preferably on the cheaper side) Any suggestions? I believe we have Cox if that is any factor....

Since this thread is about security: Google WiFi. It has secure boot and it auto-updates (although there seem to be few updates released lately).

Re: Security Begins at the Home Router

#90

The way I do things, is to treat the cable modem as already compromised and connect it to a router 100% under my control (running Linux) that will perform additional firewalling and/or act as a wireless AP. I will never let a border device have any sort of direct access into my internal network. There is no point in spending lots of time & effort trying to secure half-baked half-open devices that are not under my ful…

There's a worrying trend (I'm looking especially at you, UPC), where the ISP insists that the CPE device must be in router mode, and not in bridge mode. The UPC's current excuse is, that their devices come preconfigured for DS-Lite and that most customers would be unable to configure their own routers for that.

Together with the fact, that you are getting a single /64, it means that you cannot place another router behind their router.

(And for IPv4 part of the DS-Lite, no, they don't support PCP).

Post reply on HN