Earlier quoted context omitted.
Cheaper and older alternative is the Ubiquity Unifi Security Gateway + 8 port switch + UAC AP-PRO if you don't want the Edgerouter X cost. Less customizeable but if you're buying an EdgeRouter you know what you want.
how does power consumption compare with a setup like this vs some consumer all-in-one thing?
D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
81–90 of 306 posts
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#82For national security sake all routers should be required to support open firmwares.
Open source software on routers is a little complicated. FCC requires home router manufacturers to prevent users from modifying transmit settings (primarily to prevent interference with weather systems - which 5G is also going to mess with). While the router manufacturers themselves might not provide features to modify the parameters, allowing third-party open source firmware opens them upto liability, because third-…
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#83Earlier quoted context omitted.
What do you expect from companies that sell kit at $50/£50/€50? You always kind of get what you pay for. If you pay an annual maintenance, then you can expect regular and secure updates, otherwise you are buying the product as is at time of purchase. Then again, I buy stuff that can be flashed with OpenWRT ...
$50 honestly seems expensive considering how long home routers have been around. It's not as if it's novel technology. I'd expect cheap mass-produced routers to be around $15 - $25, like an immersion blender.. I don't quite understand why cheap ones are still $40-$60.
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#84I have a D-Link DIR-655 (which is on this list) as my home router. Ironically, I was going to replace it a few months ago, but the speed is still fast enough for my network. A few posts mentioned installing a different (open source) firmware. But, both OpenWrt and DD-Wrt aren't compatible. Am I missing another option? As an aside, can anyone recommend a wifi router that runs either OpenWrt or DD-Wrt well, for $100-$1…
https://www.amazon.com/Linksys-AC1900-Source-Wireless-WRT190...
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#85I'm aware of the "but what if the router is connected to an ICU bed? A patient's life depends on it!" straw man but let's be honest, it would only be the ICU's admin fault. Having sorted this out, let me clearly state that the only ethical solution is to brick these devices offline.
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#86I have a D-Link DIR-655 (which is on this list) as my home router. Ironically, I was going to replace it a few months ago, but the speed is still fast enough for my network. A few posts mentioned installing a different (open source) firmware. But, both OpenWrt and DD-Wrt aren't compatible. Am I missing another option? As an aside, can anyone recommend a wifi router that runs either OpenWrt or DD-Wrt well, for $100-$1…
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#87OK, let's say I am someone who actually knows "end-of-lifed" is a thing, and a thing you don't want...
How would I check to see if a certain router was end-of-lifed before buying it?
If I can figure that out, and I know it's not end-of-lifed, is there any way for me to see how much time is left in it's life before it's end-of-lifed, how would I check to make sure a router I was buying woudln't become end-of-lifed tomorrow, or next week, but has, say, a year or two of supported life left at least.
Obviously, what D-Link is counting on is that most customers won't know that this is even a thing, wont' know what questions to ask, won't realize their router is end-of-lifed, won't realize their router is vulnerable, won't realize it if their router gets hacked, and it wont' effect their likelyhood of buying another D-link router or telling others to. It's not that they think this kind of support is going to be considered acceptable to their customers -- it's that they think their customers won't even be able to figure out what kind of support or security they are getting, mostly won't even realize this is even a question to ask.
And they're probably right.
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#88Earlier quoted context omitted.
Medical equipment more and more often has networked embedded software that can't be updated. They won't throw away a multimillion-dollar device just because it can't be upgraded from Windows XP.
I'll bet they still have service agreements for those devices though, even if the software is old. Consumer routers do not have support like that.
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#89This is the new normal, folks. Consumer technology is manufactured for six to twelve months, but live in our homes for three to five years. Today's manufacturers cannot afford to update software for hardware devices they have already moved on from. Changing that requires a significant upheaval in their business models. This applies to every "connected device:" printers, cell phones, home routers, refrigerators, therm…
Of course, in reality, this CVE seems almost un-exploitable in the wild, anyway. How will an exploiter get to the login page in the first place? They'd have to know your network password and be in your physical vicinity, or your ISP would have to send traffic to your router's login page from the Internet.
So they'd have to physically drive around looking for these three specific D-Link routers.
And then what would they get out of a successful exploit? Access to your network's traffic and unprotected file shares (most people don't even have any file shares), and even that level of access will be rather useless for getting important information like bank credentials (protected by HTTPS).
Am I wrong about any of this?
A lot of non-technical people use old Android phones, old printers, etc, and never experience any serious security breach. Some of them do experience a security breach, but it's far more likely to happen in a social exploit (phishing, whaling, etc) or institutional breach (your reused password being breached from a database hack of a popular website). In a lot of ways, ignorance is bliss.
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#90Earlier quoted context omitted.
> the only other real possibility is to legislate that such updates be made available for N years as part of the purchase conditions I am unclear why this is not the preferential solution here. "Don't sell lemons" is a societal good.
They're not necessarily lemons at the time of sale though. In general, we don't legislate that products need to upgraded and maintained after they're sold. (Yes, there are lemon laws and warranty requirements for defects--which are at least related.) However, how would you feel about legislation that required five years of dealer service to be included with every automobile sale? Or other products in a similar vein?…
> However, how would you feel about legislation that required five years of dealer service to be included with every automobile sale? Or other products in a similar vein?
This analogy doesn't work for me; software bugs are defects, they aren't something getting old and falling apart. I think that a defect in an automobile should be repaired at manufacturer expense whether it's a year old or twenty.