Live data from Hacker News

Netgear 0-day vulnerability analysis and exploit

blog.grimm-co.com

81–90 of 102 posts

Re: Netgear 0-day vulnerability analysis and exploit

#81
post #63
post #23

Earlier quoted context omitted.

The best thing about setting up Google wifi routers for your relatives is you can set yourself up as the manager of them, and manage them with the Google Wifi app from anywhere. So before Uncle Bob calls you about the wifi you'd already have got the notification that his cable service is down again.

Sorry to be "that guy", but how about not giving an advertisement company access to all your network traffic (while paying them for the privilege)... Almost every router supports some form of remote management (or just put TeamViewer on their machine). Most also support dynamic DNS so you can set up a ping check for the "its down" notification.

You are concerned about Google having "access" to network traffic, but you have no concerns about putting TeamViewer on someone else's machine?

Re: Netgear 0-day vulnerability analysis and exploit

#82
post #30

I've used Apple routers for many years, but since they've been discontinued I wonder what I'll do when I need to replace them. All the major alternatives seem to have crap software that requires frequent reboots and has security issues. Can anyone recommend an awesome wireless router that works great off the shelf? I don't want to have to learn how to flash it with DD-WRT.

In my experience, the biggest gain is from separating the router from the wireless AP. It lets you choose among more affordable, purpose built and higher performance devices. Specifically I would recommend the TP-Link EAP line as a wireless AP (the $50 EAP225v3 is very good). Extremely simple to configure. Routers that perform well require configuration unfortunately, especially economical ones like the Microtik ($50…

I'm surprised to hear you recommending TP-Link. They've had several serious security issues that have been discussed on HN[1]-- do they worry you?

Also, why do you dislike Eero? Someone else on this thread recommended them, and they do have many glowing reviews.

[1] https://hn.algolia.com/?q=tp-link

Re: Netgear 0-day vulnerability analysis and exploit

#83
post #81
post #63

Earlier quoted context omitted.

Sorry to be "that guy", but how about not giving an advertisement company access to all your network traffic (while paying them for the privilege)... Almost every router supports some form of remote management (or just put TeamViewer on their machine). Most also support dynamic DNS so you can set up a ping check for the "its down" notification.

You are concerned about Google having "access" to network traffic, but you have no concerns about putting TeamViewer on someone else's machine?

TeamViewer's publicly-known business model has nothing to do with advertising or otherwise monetizing your private data, while Google's does. There's nothing inconsistent about using one while avoiding the other.

That said, I agree TeamViewer in a position to collect & monetize my usage by nature of being cloud-dependent & closed-source. I'd rather use an open-source self-hosted option. Haven't found a good one yet, but that doesn't mean we should ignore privacy hazards where they can be easily avoided.

Re: Netgear 0-day vulnerability analysis and exploit

#84

Earlier quoted context omitted.

I almost went full Unifi, got lazy and got Eero. So far everything has been fantastic. It's not perfect but it works and delivered on its promise. Speed is fast, it's not Wifi 6 but neither are any of my devices. Paid full price too, not a shill here.

Ubiquiti has a consumer/prosumer brand called Amplifi now. It's got the ease of something like Eero but the decade of experience of Unifi. (They also already have a WiFi 6 mesh router at the top of the line on the prosumer side.)

I recommended an Amplifi to some friends that aren’t computer-savvy, and didn’t hear back. (Their previous router was crashing frequently.)

I visited them a few months later and noticed it, so I asked about it.

They had kind of forgotten about it. There were zero problems setting it up and zero problems since. They said they thought it was kind of pricey.

If I remember right, it was $50 more than the cheapest (but terrible) one with similar specs. It was $100 less than an expensive, terrible and comparable one.

I can’t imagine a more favorable review of consumer networking gear. :-)

Also, I have had zero issues with the Ubiquiti access point I use at home. I have a pcengines apu2 OpenBSD router, so I can’t say much about their routers.

Re: Netgear 0-day vulnerability analysis and exploit

#87

Im surprised no one has made the semi-obligitory "buy Ubiquiti Edgerouter X/Lite and throw in a NanoHD" comment.

As someone who recently got the Dream Machine Pro with NanoHD access point, most of the consumers will not want to deal with such a setup. Also, Ubiquiti has their own issues to sort out as well.

Re: Netgear 0-day vulnerability analysis and exploit

#88
post #84

Earlier quoted context omitted.

Ubiquiti has a consumer/prosumer brand called Amplifi now. It's got the ease of something like Eero but the decade of experience of Unifi. (They also already have a WiFi 6 mesh router at the top of the line on the prosumer side.)

I recommended an Amplifi to some friends that aren’t computer-savvy, and didn’t hear back. (Their previous router was crashing frequently.) I visited them a few months later and noticed it, so I asked about it. They had kind of forgotten about it. There were zero problems setting it up and zero problems since. They said they thought it was kind of pricey. If I remember right, it was $50 more than the cheapest (but te…

Very similarly, I recommended Amplifi to my parents. They've had a couple issues with it, but that's due to a complicated bit of their new house more than Amplifi itself.

The house they just moved into had a strange audio LAN wired through the house when it was built. The audio LAN had a couple CAT-5E ports for "expansion" (presumably?) on each floor just about perfectly located for WiFi AP backhaul. So I worked with my parents on a plan to try three of Amplifi's routers rather than one AP and two "Satellites".

This seemed to work alright. The Amplifi phone app wasn't great about setting up a multi-AP mesh of that sort just yet (as opposed to the focused use case of one router/AP and several "satellites") and didn't always have the best experience (in navigation/details), but other than UX complaints, the system just works as expected.

However, my parents then discovered that there were "hidden" components also wired to the Audio LAN somewhere between the primary Audio LAN router and the "expansion ports", which meant that some of the system's speakers stopped operating. (It would have been great to have a wiring diagram of the whole LAN. We did a lot of trial and error discovery on this.)

So my parents decided to "turn off" the backhaul by reconnecting it to the Audio LAN. There was angsty confusion that they "broke" the WiFi because they ignored/forgot my explicit instructions to disconnect the router's WAN cables on the house ports that were now again Audio LAN ports. As I had expected, once disconnected from the confusing (to people and devices alike) Audio LAN, the Amplifi Routers straightened themselves out and switched to a more traditional bridged mode ("wireless backhaul") as if they were mere "satellites".

According to the math I did, my parents paid a lot less for that experiment with all Amplifi routers than if they'd tried it with "full" routers of any of the other brands we'd comparison shopped (and none of them seemed to offer an ala carte buying experience similar to Amplifi's section of Amazon), though obviously more than if they'd bought only one router and two satellites of any of the other brands in the first place. The extra LAN port on the Amplifi router is still critical to them on one of the floors (a home office VOIP system that "requires" a wired connection) and they couldn't easily swap at least one of the routers for a Satellite anyway.

Other than the crazy backhaul experiment confusion, my parents haven't had any problems. I don't think we could have ran that experiment with any of the other brands. My parents seem happy with the purchase and the quality of their WiFi on all three floors, which was the important thing for them, and I get the feeling they were happy with the price despite "over-paying" a tad due to the experiment.

Re: Netgear 0-day vulnerability analysis and exploit

#89

Earlier quoted context omitted.

Sadly not. You generally have to be very technically inclined to use something like Mikrotik (which is what I'm using) and even the Ubiquiti stuff isn't as easy to use as it could be.

Ubiquiti has a consumer/prosumer brand now called Amplifi. I set it up at my parents' and it was a breeze. It's adapted well to some strange network situations they had. (A long story but they moved in to a place with an ancient audio LAN wired through the home and we explored various configurations of detaching portions of the audio LAN for WiFi backhaul.)

Does Amplifi require some cloud login before you can use it? One of my annoyances recently is that the WiFi providers have an iOS app but require you to log into their servers to configure the thing on your local network.

Re: Netgear 0-day vulnerability analysis and exploit

#90
post #85
post #29

Earlier quoted context omitted.

Mikrotik

They are made in china, at least the last I bought (at least the company and the software are not chinese, of course)

Yes, but OS (firmware) is built in EU.

Technically someone somewhere make a electronic plate and sold some elements on it.

But difference is who is wrote a software on top.

Post reply on HN