So how do we get routers that support open source firmware? It seems these things are getting more difficult to find.
Newer TP-Link Routers send large volumes of requests to Avira servers
11–20 of 121 posts
Re: Newer TP-Link Routers send large volumes of requests to Avira servers
#12The software answer would be easy: use OpenWRT or any other *BSD based alternative, but what about the hardware? A quick search for WAN interfaces for PCs returned nothing.
I would agree that it can be difficult to find quality hardware that supports the open source software stack. For example, what wireless access points are compatible with an openbsd router/firewall? I’ll admit that my initial searches were short but only finding results about wireless chipsets to use in the router were frustrating (I guess if I wanted to build my own access points that information would be valuable).
Re: Newer TP-Link Routers send large volumes of requests to Avira servers
#13So how do we get routers that support open source firmware? It seems these things are getting more difficult to find.
I own an Omnia and despite it having been a bit rough a few years ago, it's now nearly flawless. The MOX is modular and could be more interesting for your use-case but it can also get pretty expensive.
Re: Newer TP-Link Routers send large volumes of requests to Avira servers
#14That's before installing OpenWRT! This kind of shenanigans make (once again) the case for 3rd party post market FLOSS firmware to be installed on every device I own. Sure, I spend some extra time researching which router/AP/phone/ereader/smart appliance will be compatible with OpenWRT/LineageOS/KOReader/Tasmota/ESPHome/etc., but I feel more confortable this way. I have more trust in a bunch of people doing this for o…
Re: Newer TP-Link Routers send large volumes of requests to Avira servers
#15Nothing in your analysis shows this. Moreover unless you explicitly deployed a root certificate on your clients (or if an app on the client did it), the router can't decode TLS traffic (deep inspection) without you getting certificate warnings on the client. In that case, the only thing the router can see is the dns request, the IP and the TLS SNI. In short your title is misleading.
permalinkembedsavereportreply [–]ArmoredCavalry[S] 11 points 14 hours ago*
I agree they couldn't be inspecting the contents of your traffic over TLS, but they could easily view destinations. I also agree, there's nothing in my analysis that proves that all the requests are related to network traffic. However, if you look at the wording of the reply (directly from TP-Link) to XDA in their review, I don't see how it could be interpreted any other way? Regardless, I probably should have made my title "appears that it may send traffic related data". I'll be happy if that isn't the case, but the lack of clear explanation from TP-Link when I've contacted support leads me to assume the worst
permalinkembedsaveparentreportreply [–]2fast2fourier 4 points 12 hours ago I think it's best not to write something that damaging without proof, especially when most people only read titles. Saying they're sending metadata and violating your privacy is all you'd need to hear.
Re: Newer TP-Link Routers send large volumes of requests to Avira servers
#16So how do we get routers that support open source firmware? It seems these things are getting more difficult to find.
Re: Newer TP-Link Routers send large volumes of requests to Avira servers
#17So how do we get routers that support open source firmware? It seems these things are getting more difficult to find.
In the forums [0](Discourse alert) you have many threads with suggestions, too!
[0] https://forum.openwrt.org/c/hardware-questions-and-recommend...
Re: Newer TP-Link Routers send large volumes of requests to Avira servers
#18I remember reading in the UK government's security assessment of Huawei that one of the issues is not necessarily data being sent to bad places or backdoors in the software, it's that the engineering processes behind these devices/software are completely unable to protect against any sort of supply chain attacks. The sorts of things they highlighted were: no version control, no code review, production builds happenin…
Re: Newer TP-Link Routers send large volumes of requests to Avira servers
#19Earlier quoted context omitted.
I would agree that it can be difficult to find quality hardware that supports the open source software stack. For example, what wireless access points are compatible with an openbsd router/firewall? I’ll admit that my initial searches were short but only finding results about wireless chipsets to use in the router were frustrating (I guess if I wanted to build my own access points that information would be valuable).
What does it even mean for an access point to be "compatible" with a specific OS on the router?
Re: Newer TP-Link Routers send large volumes of requests to Avira servers
#20So how do we get routers that support open source firmware? It seems these things are getting more difficult to find.
One alternative could be, instead of buying a router, getting a single board computer designed to run whichever routing software you like. Banana pi is an example that comes to my mind. You'd need to get a case, and it won't be as neat as a commercial router.