Earlier quoted context omitted.
See my post above: APU2 by pcengines. Put debian on it.
It's a great piece of hardware, of which I've used dozens for various purposes. But they draw ~10 times more power than, say, a cheap Linksys wifi router. So if all you're after is a SoHo wifi router, it might not be the best way to go.
200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware
11–20 of 76 posts
Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware
#12If you have a currency that can be generated via compute power the incentive structure it creates is to take over as much compute power as you can. Does the incentive structure represent a serious design flaw in the system for widespread adoption?
I just had this thought and want to get it down, apologies for the rant: I suspect that philosophically, the basic measure of our economy has been units of energy, but it's transitioning to units of power. The 'subscription model' most businesses are transitioning to seems to be an early recognition of that fact. Server space, similarly, isn't really something one can store as easily as gold or gasoline - it's only valuable while in use and degrading whether it's in use or not. Our whole concept of currency may be based on an idea of 'stored' value, analogous to swapping joules, while we should be thinking about 'sources' of value - swapping watts. I think the trouble is that renting (or hijacking) servers is accounting in terms of watts, while currency is accounting in terms of joules. The accounting of the two types of approaches may not be as easily reconcilable as it seems at firs.
Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware
#13http://pcengines.ch/ APU2 plus debian. Be secure. Maybe I'll tidy up the ansible I use for this and publish it.
Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware
#14So ... which SoHo router manufacturer can we actually trust? It seems pretty common in this industry to either not supply security updates, or to only supply them for a very short amount of time.
Turris omnia. Open source (both hardware and software), lets you ssh into it directly out of the box (well, after you have set a root password in the gui) They provide regular software updates, and it is imho a good hacker/tinkerer router.
One major advantage of Turris Omnia is that CZ.NIC is a non-profit, so they are not as constrained by profitability of this project, and it's a part of a larger strategy (e.g. you may allow reporting statistics back to turris: https://project.turris.cz/en/global-stats/).
Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware
#15Earlier quoted context omitted.
See my post above: APU2 by pcengines. Put debian on it.
It's a great piece of hardware, of which I've used dozens for various purposes. But they draw ~10 times more power than, say, a cheap Linksys wifi router. So if all you're after is a SoHo wifi router, it might not be the best way to go.
There is this one the horizon though: https://up-shop.org/up-ai-edge/233-up-net-plus.html
It'd make a fine router in the same vein, no word on power usage though.
Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware
#16Earlier quoted context omitted.
It's a great piece of hardware, of which I've used dozens for various purposes. But they draw ~10 times more power than, say, a cheap Linksys wifi router. So if all you're after is a SoHo wifi router, it might not be the best way to go.
They don't. Mine draw under 10W, which is well within range of a Linksys thing.
Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware
#17So ... which SoHo router manufacturer can we actually trust? It seems pretty common in this industry to either not supply security updates, or to only supply them for a very short amount of time.
Their routers were also not affected by the KRACK WPA2 exploit last year.
AVM products cost a lot more than their competitors' but they are really worth their money.
Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware
#18Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware
#19Earlier quoted context omitted.
They don't. Mine draw under 10W, which is well within range of a Linksys thing.
Mine draw around 10W idle, about 15W when active. My Linksys and TP-Link trinkets draw under 2W idle (which I'm guessing is my power meter's minimum value), and not much more when active.
Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware
#20So ... which SoHo router manufacturer can we actually trust? It seems pretty common in this industry to either not supply security updates, or to only supply them for a very short amount of time.
Turris omnia. Open source (both hardware and software), lets you ssh into it directly out of the box (well, after you have set a root password in the gui) They provide regular software updates, and it is imho a good hacker/tinkerer router.