Live data from Hacker News

OpenWrt Two Approval

openwrt.org

101–110 of 133 posts

Re: OpenWrt Two Approval

#101
post #48

Earlier quoted context omitted.

What kind of security vulnerabilities do you think an incompetent PC OEM is going to accidentally introduce to a barebones PC that's basically shipping an Intel reference platform and no SSD ? Or that GL.iNet might be able to introduce to a system where OpenWRT is assembling the firmware image that gets flashed to the board, and if there are any closed-source components they'd be coming from Mediatek and not develope…

STH has reviewed Chinese PCs that come preloaded with malware. My MSI motherboard force installs Nahimic by default. Not technically malware but the same mechanism exists for malware.

Do you think any of that is relevant to the case of buying a barebones PC that doesn't include SSD or RAM, then adding those components yourself and installing a non-Windows OS?

If your MSI motherboard is installing Nahimic without an internet connection, it is doing so through a mechanism where the installer is made available to the OS in an ACPI table that Windows checks. That check can be disabled with a registry key to prevent such software from being re-installed, and the motherboard may have a BIOS option to disable the anti-feature (though the registry key method is generally more effective, since BIOS settings often get reset to defaults).

Re: OpenWrt Two Approval

#102
post #48

Earlier quoted context omitted.

What kind of security vulnerabilities do you think an incompetent PC OEM is going to accidentally introduce to a barebones PC that's basically shipping an Intel reference platform and no SSD ? Or that GL.iNet might be able to introduce to a system where OpenWRT is assembling the firmware image that gets flashed to the board, and if there are any closed-source components they'd be coming from Mediatek and not develope…

> What kind of security vulnerabilities do you think an incompetent PC OEM is going to accidentally introduce to a barebones PC that's basically shipping an Intel reference platform and no SSD? Historically remote code execution in the IME. > an incompetent PC OEM And then it never gets patched.

> Historically remote code execution in the IME.

That's only a problem if the Active Management Technology feature is correctly supported by the OEM including wiring it up to a supported NIC, and the feature is enabled and provisioned by default, and the NIC in question is connected to a network that is a potential attack vector.

From what I can tell, the current NIC of choice for Chinese router PCs is the Intel i226-V, and such PCs come with 4-8 of those. In order to work with the Active Management Technology feature, those would have to be the more expensive i226-LM or i226-IT parts. So AMT is impossible to enable on those PCs and there's no part of the boot firmware that continues interacting with any NIC after the OS has taken over managing PCIe peripherals.

Re: OpenWrt Two Approval

#103
post #90

Earlier quoted context omitted.

You should be aware of how much collaboration the OpenWRT folks have with -say- Ubiquiti Networks. [0] And yet, OpenWRT runs fine on the UAP-AC-LITE and -LR. I'd wager there's nearly zero collaboration between the overwhelming majority of the hardware manufacturers that create hardware that OpenWRT runs on and the OpenWRT folks. Your concern is entirely unwarranted and -if I might be a little uncharitable- seems to c…

What does that have to do with anything? I'm speaking about experience of deploying existing gl.inet devices, marketed as "fully open source" with OpenWrt being front-and-center in marketing, as well as being promoted on the OpenWrt wiki. That someone from the community has made OpenWrt run fine on Ubiquiti gear has nothing to do with my comment and is not indicative of anything (if anything perhaps supporting the no…

In fact I'm quite surprised by this announcement. Gl.inet is famous for claiming that their os is based on openwrt, while it can be some vendor SDK that is based on some decade-old version of openwrt and have little in common today

Re: OpenWrt Two Approval

#104
post #37

Earlier quoted context omitted.

> suggesting some Chinese shitbox PC off AliExpress as the ideal platform to run it on? How reasonable do you think it is to be this automatically suspicious of any computer coming from China? A generic low-cost barebones Intel PC certainly has plenty of space for compromised firmware to hide, but it's implausible that a Chinese intelligence agency would indiscriminately deploy an attack that made use of a compromise…

> How reasonable do you think it is to be this automatically suspicious of any computer coming from China? A generic low-cost barebones Intel PC certainly has plenty of space for compromised firmware to hide The problem seems to be that this firmware doesn’t really get updated once the machine is sold. That’s legitimate criticism for a security-critical network component.

I would say that there is no special value to firmware updates when you have no visibility into or control over the authors of the updates.

We need adversarial competitive firmware that comes from different sources the same as we have for software.

I know why we don't have that. It doesn't change the fact that that is what we need.

Re: OpenWrt Two Approval

#105
OpenWrt went crazy in the last few years. OpenWrt (the OS) is a mess:

- bugs are ignored,

- bug fixes ignored,

- improvements to core OpenWrt are ignored (although package PRs are still accepted somehow),

- almost no new documentation,

- no reply for documentation clarifications on the forum,

- significant parts of OpenWrt are not accessible for PRs or bug reports: fstools, procd, ubus, etc.

- no improvements to critical routing features, such as hardware acceleration,

- routers abandoned left and right (kernel no longer fits in the factory partition) and absolutely no support for older kernels,

But now they have video acceleration, mesa, X, wayland, Doom, etc.

With OpenWrt Two, I bet they're going to make the same mistakes as OpenWrt One: not enough memory and not upgradable, wifi not replaceable, no usable expansion slots (mini-PCI, M.2) and, of course, no (e)SATA. Another e-waste product that will be obsolete even before it's available to buy.

I wish they got back to routing.

Re: OpenWrt Two Approval

#106

250 sounds like Banana R4 already won. Seeing different no-name boards such specs should be way less or we should have 2 10G fiber, 4-5 10G copper and some great specs in terms of computing... Did I miss anything?

I saw a post a couple of days ago that due to some component selection r4 radios weaker than previous model

Re: OpenWrt Two Approval

#107
post #105

OpenWrt went crazy in the last few years. OpenWrt (the OS) is a mess: - bugs are ignored, - bug fixes ignored, - improvements to core OpenWrt are ignored (although package PRs are still accepted somehow), - almost no new documentation, - no reply for documentation clarifications on the forum, - significant parts of OpenWrt are not accessible for PRs or bug reports: fstools, procd, ubus, etc. - no improvements to crit…

> With OpenWrt Two, I bet they're going to make the same mistakes as OpenWrt One: not enough memory and not upgradable, wifi not replaceable, no usable expansion slots (mini-PCI, M.2) and, of course, no (e)SATA. Another e-waste product that will be obsolete even before it's available to buy.

Those are only mistakes if you ignore the realities of what hardware is available. A highly-integrated SoC designed specifically for wireless router usage is a more cost-effective platform than a generic x86 PC. Basing OpenWRT One and Two on such hardware means work to improve support for those systems is more likely to benefit OpenWRT support for mainstream consumer networking equipment that also uses purpose-built SoCs.

OpenWRT is not yet in a position to influence the hardware design decisions made by companies like Mediatek, Qualcomm, Broadcom for their consumer WiFi product families. Those chips are still designed around what's best for the big brands that are the primary customers: Netgear, Linksys, TP-Link, etc. Adding SATA controllers to a WiFi router SoC does not benefit Netgear, et al., nor does splitting out all the radios to separate chips that could be installed onto M.2 cards (miniPCI and miniPCIe being long obsolete and bandwidth-starved). Asking for eSATA is laughably unrealistic.

A focus on the kind of modular, expandable and upgradable hardware platforms that actually currently exist (namely, PCs) is what leads to the distractions you're complaining about: "video acceleration, mesa, X, wayland, Doom, etc."

Re: OpenWrt Two Approval

#108
post #105

OpenWrt went crazy in the last few years. OpenWrt (the OS) is a mess: - bugs are ignored, - bug fixes ignored, - improvements to core OpenWrt are ignored (although package PRs are still accepted somehow), - almost no new documentation, - no reply for documentation clarifications on the forum, - significant parts of OpenWrt are not accessible for PRs or bug reports: fstools, procd, ubus, etc. - no improvements to crit…

> With OpenWrt Two, I bet they're going to make the same mistakes as OpenWrt One: not enough memory and not upgradable, wifi not replaceable, no usable expansion slots (mini-PCI, M.2) and, of course, no (e)SATA. Another e-waste product that will be obsolete even before it's available to buy. Those are only mistakes if you ignore the realities of what hardware is available. A highly-integrated SoC designed specificall…

For another approach to open source networking by Linux Foundation please check DENT OS [1].

> OpenWRT is not yet in a position to influence the hardware design decisions made by companies like Mediatek, Qualcomm, Broadcom for their consumer WiFi product families.

Perhaps I'm biased, but I do believe DENT is in much better position and has more chance of influencing the white-box networking vendor than OpenWRT with regards to their design decisions.

From the website:

"As a Linux Foundation project, DENT utilizes the Linux Kernel, Switchdev, and other Linux based projects as the basis for building a new standardized network operating system without abstractions or overhead. All underlying infrastructure — including ASIC and Silicon for networking and datapath — is treated equally; while existing abstractions, APIs, drivers, low-level overhead, and other open software are simplified. DENT unites silicon vendors, ODMs, SIs, OEMs, and end users across all verticals to enable the transition to disaggregated networks."

[1] DENT:

https://dent.dev/

Re: OpenWrt Two Approval

#109
post #54

Earlier quoted context omitted.

> How reasonable do you think it is to be this automatically suspicious of any computer coming from China? Based on their track record? Pretty fucking reasonable. I would say that most probably isn't malicious collaboration with the CCP, rather sheer incompetence. Shipping secure anything just isn't part of their culture. Read a comment on HN the other day from someone that evaluated Huawei hardware for a telco and s…

> Read a comment on HN the other day from someone that evaluated Huawei hardware for a telco and swore it was so full of holes to be unusable. Do you have a link? Would be nice to know more technical details.

https://news.ycombinator.com/item?id=43343233

https://news.ycombinator.com/item?id=43342304

Re: OpenWrt Two Approval

#110
post #11

GL.iNet is a popular brand, though I can't find a Wikipedia page for it. https://www.gl-inet.com/about-us/ says: > GL Tech (HK) Ltd: #601, 5W, Hong Kong Science Park, N.T. Hong Kong > GL Intelligence, Inc.: 10400 Eaton Place, Suite 215, Fairfax, VA 22030 I'm a little curious about this. One of the reasons that some people run OpenWrt is for improved security. In the general security space, a Shenzen company isn't the…

Is it really any different than every person who insists on running pfSense for security reasons then immediately suggesting some Chinese shitbox PC off AliExpress as the ideal platform to run it on? Also, since when has having a Wikipedia page proven a company legitimate? You know most companies author their own pages anyway, that's kind of how Wikipedia works.

The people who source no-name/random-name computer/networking hardware off of AliExpress to use for routers aren't the security-conscious people I'm talking about.

As I said, GL.iNet is a popular company.

I didn't say that having a Wikipedia page proves that a company is legitimate.

I know how Wikipedia works.

Post reply on HN