Live data from Hacker News

Newer TP-Link Routers send large volumes of requests to Avira servers

old.reddit.com

101–110 of 121 posts

Re: Newer TP-Link Routers send large volumes of requests to Avira servers

#101
post #64

Earlier quoted context omitted.

"But would it be significantly harder to do, easier to detect, and easier to resolve? Yes, and that makes them better suited to critical infrastructure. " But like what is that conclusion based on? I'm not saying you're wrong - just curious why you hold HP and Cisco in high esteem. At least in terms of engineering talent I'd expect them to be much worse. Huawei is prolly the Google of China paying huge salaries and g…

> But like what is that conclusion based on? It's based on a few assumptions, but ones I feel are reasonable to make. The fact these companies will have been audited in the same way, but that the concerns have not been raised (by government, industry, security consultants) suggests that these processes are very different. Version control, code auditing, code review, reproducible builds, etc, those will all contribute…

It all sounds very reasonable untill you remember that multiple backdoors and hardcoded hidden admin accounts have been found in Cisco products. I have yet to see any proof that Huawei are worse (or better) than Cisco. IMO absolutely nothing have been proven in terms of quality versus other manufacturers outside of political standpoints in all this. As far as I can tell this audit have not been done (or at least not published) to any other manufacturer than Huawei. It's 100 % politics and zero evidence of quality when only one side gets tested and published.

Re: Newer TP-Link Routers send large volumes of requests to Avira servers

#102

I remember reading in the UK government's security assessment of Huawei that one of the issues is not necessarily data being sent to bad places or backdoors in the software, it's that the engineering processes behind these devices/software are completely unable to protect against any sort of supply chain attacks. The sorts of things they highlighted were: no version control, no code review, production builds happenin…

Also a perfect environment to slip in back doors that look like mistakes.

Yes, it has happened multiple times at Cisco.

Re: Newer TP-Link Routers send large volumes of requests to Avira servers

#103
post #31

The software answer would be easy: use OpenWRT or any other *BSD based alternative, but what about the hardware? A quick search for WAN interfaces for PCs returned nothing.

That's because there is no single "WAN interface". The WAN port on the router is often just a differently labelled Ethernet port.

Sorry, used the wrong term. By WAN I meant the broadband telephone line. Modem cards for dial up connections were common back in the day, but since ADSL and beyond I don't recall any commonly available products, USB winmodems aside. VDSL/Fiber capable cards would be very handy to build 100% FOSS broadband routers, but they seem next to unobtanium.

Re: Newer TP-Link Routers send large volumes of requests to Avira servers

#104
post #27

Earlier quoted context omitted.

The WRT1200AC family (WRT3200ACM etc) support it out of the box as a first-class feature. https://www.linksys.com/nz/wireless-routers/wrt-wireless-rou...

The WRT1200AC family is not well supported. The Ethernet part should work fine, but the Wifi is unsupported since some years now, see here the repository: https://github.com/kaloz/mwlwifi The vendors are not interested in this hardware any more, but they have very good marketing and sales. Linksys and Marvell also did not really support the OpenWrt community, they just had good marketing. If your WRT1200AC device doe…

Neat! Looks like that just became my new front-runner.

I'm still happy with OpenWRT on my WNDR3800 for now either way.

Re: Newer TP-Link Routers send large volumes of requests to Avira servers

#105
I never rued the day when I switched off the last "appliance" router after switching to a virtual router - OpenWRT running in a container on a Proxmox-managed host. I use a number of repurposed "appliance" routers (also running OpenWRT) as access points, some of them connected to additional "dumb" PoE-switches for IP-camera's. Those camera's run over their own VLAN and never get to touch the 'net, the same goes for "IoT" things (heat pump, PV-inverter etc). Xi and friends will be disappointed, even if they built backdoors in their equipment these only lead to a dead-end street.

Re: Newer TP-Link Routers send large volumes of requests to Avira servers

#106

Earlier quoted context omitted.

I was just wondering about this the other day. Are there still no options other than to buy/build a grossly overpowered x86 machine?

I use a Qotom. They are cheap and low powered. Runs opnSense.

Thanks, I saw them mentioned elsewhere here as well. How was the setup experience? Is it something I can set up if I'm not a BSD or networking expert? Do you use a wireless AP with it?

Re: Newer TP-Link Routers send large volumes of requests to Avira servers

#107

So how do we get routers that support open source firmware? It seems these things are getting more difficult to find.

My go to home router is the pcengines apu2. I run openbsd on them(not for security but because I really enjoy using openbsd), But just about any os will work well. They have opensource firmware.

https://pcengines.github.io/

Full disclosure, I have never built the firmware but I take great comfort that it is developed in an open source manner, and that I could build it if I wanted to.

Re: Newer TP-Link Routers send large volumes of requests to Avira servers

#108

I remember reading in the UK government's security assessment of Huawei that one of the issues is not necessarily data being sent to bad places or backdoors in the software, it's that the engineering processes behind these devices/software are completely unable to protect against any sort of supply chain attacks. The sorts of things they highlighted were: no version control, no code review, production builds happenin…

I had/have a Gemini (Android) from Planet Computers. I disabled wifi and forced its network connections through an ethernet adapter that I connected to a mirror port->wireshark and through a proxy after putting in my own root certificates. My goal was to silence its network activity when I wasn't using it. One by one I removed APKs and blackholed IPs and domains, starting with everything from Google. I was disturbed…

Would like to see this writeup somewhere, both for the results and for the methodology.

Re: Newer TP-Link Routers send large volumes of requests to Avira servers

#109

Earlier quoted context omitted.

One alternative could be, instead of buying a router, getting a single board computer designed to run whichever routing software you like. Banana pi is an example that comes to my mind. You'd need to get a case, and it won't be as neat as a commercial router.

I would love to replace these "routers" with a normal computer. The thing is these computers would need special ports for either phone lines or fiber optic connections, as well as built-in modems. I've never seen a computer with this sort of hardware built into it. Even on dedicated network cards I only ever see ethernet ports, nothing compatible with whatever it is my ISP is using (SFP?). Decades ago in the dial up…

My ISP gives me a box that terminates the fiber and has ethernet on the other side. They also rent and sell routers that are configured to handle the pppoe and vlan settings needed for the WAN interface to this box. Plenty of routers can do this, and a dedicated Linux box like you are proposing should work, or you can throw a cheap managed switch in between if not. The hardest part is knowing what settings are needed (e.g. I had to call my ISP to ask for the pppoe password).

DSL standalone termination is still widely available, as are standalone DOCSIS cable modems.

Re: Newer TP-Link Routers send large volumes of requests to Avira servers

#110
post #81
post #62

Earlier quoted context omitted.

Newer TP-Links use broadcom chips which have no drivers on Linux, so it makes using openwrt basically impossible.

openwrt is not possible to use on a lot of new hardware, it's also not possible to use new versions on older hardware, they started to require more minimum RAM/FLASH. DSL or GPON is of the table

> it's also not possible to use new versions on older hardware, they started to require more minimum RAM/FLASH.

You shouldn't imply that OpenWRT is in any way bloated.

The kind of hardware that doesn't have enough RAM or storage for OpenWRT is truly pathetic. Those devices don't have enough CPU power to route traffic at reasonable speeds, their WiFi radios are so outdated that operating them in a crowded 2.4GHz band is an obscene waste of airtime, and even with the manufacturer's firmware those devices usually can't support features like IPv6. A router that old is usually only worth using as a managed Ethernet switch, if it even supports gigE.

Post reply on HN