Live data from Hacker News

Security Begins at the Home Router

insights.sei.cmu.edu

101–110 of 177 posts

Re: Security Begins at the Home Router

#101
post #70
post #46

Earlier quoted context omitted.

In particular, recommendations for consumer routers would be welcome. Last time this came up, the line seemed to be "consumer routers are trash, if you want security you have to use an enterprise router." There might be some truth in this, but it isn't helpful. Surely not all consumer routers are equally bad?

I've found the ASUS RT-AC series to be pretty good (both 56U and 66U can route my gigabit internet connection and provide about 400Mbit worth of wifi). But for a bit more you can get a Ubiquiti router + AP for an even better experience.

Also important, they are popular. Which means more continued support, and more forks.

Re: Security Begins at the Home Router

#102

Earlier quoted context omitted.

Even more than that; I left Google (as a user, never employee) because I was scared of being banned. Seeing stories of users on Amazon / Google getting their account banned due to something related to a business concern, made me realize that if someone flagged a google app I had my whole life could come to a grinding halt. Phone, phone number, email, storage, internet access! All that because maybe I got reports on a…

Similar concerns, I recently used Google Express for a purchase, it worked fine, and then I deleted it. My Google account is my main email, and every new Google service is another opportunity for my whole account to get irreversibly banned. Using Google with their famous lack of customer service to make purchases that I could conceivably need to put a chargeback on felt uncomfortably risky. Tie my home internet conne…

Agree on lack of support. I have an account that is blocked. I forgot the password since it was always logged in. When I try to recover the password, it asks me a bunch of questions that I am pretty sure I am answering correctly. At the end it just tells me that the account cannot be recovered... even if I had the second factor authenticator still working and I punched in the right code. I searched high and low online but since they do not have any kind of support I have no way out. It is depressing.

Re: Security Begins at the Home Router

#103
post #63

For the average consumer / prosumer, The best I've found are Asus routers. I have a 3-4 year old Asus that still gets regular security updates. If you want to go deeper, get any cheap NUC or system with 2 NICs, install OpenBSD and configure it as a firewall / router.

I would have said that too based on our RT-AC68U right up until I read this post and thought "time to update that router" and when I did so, for the first time in many updates I was presented with a license agreement allowing ASUS to send basically every bit of data to a 3rd party (Trend Micro) for features I didn't ask for. I should have captured it but the data they described was basically every bit of data you can imagine not wanting to share with a 3rd party. I had to agree to get into the router management portal and at least they had a way to withdraw that agreement (which also turns off those features).

I can't believe ASUS even considered this idea in this era of privacy concerns but I'm definitely going to research that before I buy another router.

Re: Security Begins at the Home Router

#104
post #49

Earlier quoted context omitted.

Solid firmwares like OpenWRT run on a lot of routers already. It should be possible to have some amount of regular updates, if not automatic.

Do you realize that OpenWrt is not very secure and DD-Wrt is even worse?

Yup, I do. Have used it on and off since my Wrt54gs.

My point was about availability of updates. Third partu firmwares seem to have a lot more updates than factory ones.

LEDE also merged back with OpenWRT so I hope that improves things.

Rather than poke holes, do you have any suggestions?

Re: Security Begins at the Home Router

#106
post #54
post #46

Earlier quoted context omitted.

In particular, recommendations for consumer routers would be welcome. Last time this came up, the line seemed to be "consumer routers are trash, if you want security you have to use an enterprise router." There might be some truth in this, but it isn't helpful. Surely not all consumer routers are equally bad?

So there are two main issues with consumer routers. The first is that the hardware is garbage. This isn't universally true, but it's a strong general rule, and models get released and discontinued all the time so the short list of models that aren't garbage changes every year. The main security issue is that the vendors stop issuing security updates after they stop selling the router even though people are still usin…

I've always wanted to just use an old junk PC as a router instead of paying for what is basically an overpriced Pi with a 4 jack ethernet card attached. But the problem then is that getting enough ethernet ports in the thing to equal the average router is price prohibitive.

I wish there were $20-$30 PCI-E bridge cards of >2 1Gbit ethernet jacks but they don't exist.

Re: Security Begins at the Home Router

#107
post #49

Earlier quoted context omitted.

Solid firmwares like OpenWRT run on a lot of routers already. It should be possible to have some amount of regular updates, if not automatic.

Do you realize that OpenWrt is not very secure and DD-Wrt is even worse?

Have you got links or keywords I can search for details about that? (I'm in the middle of a decision about moving to an OpenWRT or Mikrotik router...)

Re: Security Begins at the Home Router

#108
post #16
post #5

I don't fear rebooting my router because it takes less than 30 seconds to do a complete cycle; TCP sessions can withstand that. It probably helps that it runs Debian stable, too, so security updates are frequent and regular.

Care to share some more information about your setup? I'm a PFsense user currently and am always looking for ways to tinkering with my networks.

Try OPNsense. My choice.

Re: Security Begins at the Home Router

#109
post #49

Earlier quoted context omitted.

Solid firmwares like OpenWRT run on a lot of routers already. It should be possible to have some amount of regular updates, if not automatic.

Do you realize that OpenWrt is not very secure and DD-Wrt is even worse?

One thing I hated about ddwrt was how hard it was to get a TLS download and/or hash. Like seriously, if I'm putting this on my router I don't want it coming down by http!

Re: Security Begins at the Home Router

#110

Just install OPNSense (or its less modern forebear: PFSense). It works great, has a ton of features (e.g. packet filter from FreeBSD, OpenVPN, etc, etc), and it gets security updates. I run mine in a VM, with the WAN adapter passed through to it to make it unavailable to the host.

Second OPNsense. And there are nice fanless x86 mini PCs, router size on aliexpress
Post reply on HN