Are there any routers that come out by default with Tomato or OpenWRT?
The Turris Omnia and soon-to-be Turris Mox are the only ones that I'm aware of. I know Linksys has a special line of WRT "open source ready" routers that are supposedly OpenWRT compatible, but the Amazon reviews are completely trash. They're a little more pricey, but my next router will be a Turris. https://www.turris.cz/en/turris-omnia/
Over 25k Linksys routers vulnerable to sensitive information disclosure flaw
31–38 of 38 posts
Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw
#32Linksys just doesn't give a shit. At all. I specifically bought one of their top end routers to use it as a NAS with USB storage, only to discover that their best of the best router serves files over.....Samba 1.0. Even though Samba 2.0 has been available for over a decade and Samba 3.0 is common place now. Which means that Windows 10 doesn't allow you to actually browse it by default anymore, since it's a huge secur…
Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw
#33Linksys just doesn't give a shit. At all. I specifically bought one of their top end routers to use it as a NAS with USB storage, only to discover that their best of the best router serves files over.....Samba 1.0. Even though Samba 2.0 has been available for over a decade and Samba 3.0 is common place now. Which means that Windows 10 doesn't allow you to actually browse it by default anymore, since it's a huge secur…
Yeah I wouldn't trust Linksys to do even what their core competency is ... securely. Let alone any NAS. Sadly the only good home NAS solutions are build it your own (time, hassle) or pay for something more expensive from Synology.
This suggests a GUI is coming, not sure how it will be supported. I'd hope they'd make it possible to wrap that up as a Cockpit plugin. Cockpit is very cool, and is standard with Fedora Server.
https://www.samba.org/samba/GUI/ https://github.com/cockpit-project/cockpit/issues/3534
Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw
#34Once again embedded device security is a joke. Firmware updates are provided for 2 years or less on devices that end up lingering, acting as the core of networks for 5 to 15 years. Repeat offenders should be held accountable, standards should be enforced (like running point releases of OpenWRT, providing vendor skins as a package, thus the vendor doesn't have to deal with software updates).
> Once again embedded device security is a joke. Have you seen the state of salaries in the firmware dev industry? That pretty much explains why firmware security is such a mess. You pay peanuts you get peanuts.
Only TI ever really went all in with a fully open stack that had support mainlined, problem being by the time their chips had full support upstream they'd be lagging 1 to 2 years behind Qualcomm, Nvidia, Mediatek, Allwinner, Spreadtrum, etc while having a much higher cost per chip, most of said cost being the decently written and upstreamed drivers.
For longer lived architectures (eg: AMD/Intel CPUs) totally new device drivers aren't needed on launch day, in part due to older upstreamed drivers still mostly working with newer hardware.
None of the aforementioned vendors besides TI ever got into this virtuous cycle of having upstreamed drivers, thus they've trapped their devices on sketchy, unstable & insecure BSPs that hurt the reliability, performance and sometimes the market image of the final product (eg: when the device randomly crashes or gets exploited due to latent bugs).
Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw
#35Earlier quoted context omitted.
You bought a router to use as a NAS? I think that's your problem right there. How is this even voted to the top? Edit: Looks like I hit a nerve. God forbid anyone buy hardware for a purpose it was actually designed for.
You may be lucky enough to have avoided learning about the shitshow that is consumer grade "routers". They seem to constantly be trying to come up with stupid shit they can do. Many of the "high end" of the spectrum of garbage have things like OpenVPN servers and samba shares off the included USB port. They are all hot garbage and should not be used.
However, a router acting as a file server just sounds plain wrong.
Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw
#36Earlier quoted context omitted.
You may be lucky enough to have avoided learning about the shitshow that is consumer grade "routers". They seem to constantly be trying to come up with stupid shit they can do. Many of the "high end" of the spectrum of garbage have things like OpenVPN servers and samba shares off the included USB port. They are all hot garbage and should not be used.
I have no problem with a router offering a VPN server; it's another network service after all and I see a router as a device that offers network services. On the other hand, I wouldn't trust the default software stack and wouldn't use it myself personally. However, a router acting as a file server just sounds plain wrong.
Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw
#37Earlier quoted context omitted.
I have no problem with a router offering a VPN server; it's another network service after all and I see a router as a device that offers network services. On the other hand, I wouldn't trust the default software stack and wouldn't use it myself personally. However, a router acting as a file server just sounds plain wrong.
But....why. What is it about it that makes it wrong. These are really powerful devices, sometimes with dual or quad core CPUs and gigabytes of ram, so what's wrong with using them as a NAS? Especially since all I want to do is share a single USB drive on the network so I can watch some films on my TV or just run a backup from my main PC to it. Using my router as a NAS allows me to do that with very little space taken…
Also, there are small, quiet[er] NAS devices around. A bit of searching found me this: https://nascompares.com/top-5-silent-and-low-noise-nas-of-th...
Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw
#38Earlier quoted context omitted.
But....why. What is it about it that makes it wrong. These are really powerful devices, sometimes with dual or quad core CPUs and gigabytes of ram, so what's wrong with using them as a NAS? Especially since all I want to do is share a single USB drive on the network so I can watch some films on my TV or just run a backup from my main PC to it. Using my router as a NAS allows me to do that with very little space taken…
You've already experienced it yourself. Once you find yourself in a situation that needs more than what is offered by the device you find yourself trapped. A dedicated NAS device, even a really basic one, wouldn't have the issues you have. Also, there are small, quiet[er] NAS devices around. A bit of searching found me this: https://nascompares.com/top-5-silent-and-low-noise-nas-of-th...
How so? What's stopping a NAS maker providing shitty support and/or firmware? I actually used to own a Netgear ReadyNAS Duo and I got rid of it mostly because of how loud it was and Netgear stopped releasing updates, which meant that things like Timemachine backup stopped working. And it was super slow for transfer speeds compared to what the drives could do.
For comparison sake, that Linksys router I have is super duper quick - it can actually do 100MB/s reads and writes on the connected drives which is very impressive(I thought) - this Samba issue is the only thing separating it from being great at it. And then I could install OpenWRT and then just install the newest version of Samba - it's just that I'm a bit lazy to do that.