Live data from Hacker News

Newer TP-Link Routers send large volumes of requests to Avira servers

old.reddit.com

111–120 of 121 posts

Re: Newer TP-Link Routers send large volumes of requests to Avira servers

#111

Before you say anything about this feature (which is apparently called HomeCare, https://www.tp-link.com/homecare/ ), you should probably know that Asus also has a AiProtection feature powered by Trend Micro ( https://www.asus.com/content/aiprotection/ ) and D-Link having McAfee Secure Home Platform built-in ( https://www.dlink.com/en/latest-news/d-link-introduces-new-e... ). Definitely not vindicating TP-Link here (…

Damn. Seems like they have all "discovered" a new revenue model - harvest and sell user data to third-parties / data brokers.

These are all premium features you have to sign up for.

Re: Newer TP-Link Routers send large volumes of requests to Avira servers

#112

This was alarming since I use a TP-Link router, so I tried figuring out to what extent it's able to inspect and record regular (encrypted) traffic. My TP-Link Archer AX50, running software version "1.0.11 Build 20210730 rel.54485(4A50)" is doing at least some sort of DPI on outgoing connections. I found a page in its settings (Advanced -> Security -> Antivirus -> History) that contains a log of connections I've made…

Looking at DNS traffic isn't generally considered DPI.

Re: Newer TP-Link Routers send large volumes of requests to Avira servers

#113

From the comments Nothing in your analysis shows this. Moreover unless you explicitly deployed a root certificate on your clients (or if an app on the client did it), the router can't decode TLS traffic (deep inspection) without you getting certificate warnings on the client. In that case, the only thing the router can see is the dns request, the IP and the TLS SNI. In short your title is misleading. permalinkembedsa…

There is really no excuse for any network equipment to be sending anything at all to external parties, unless you've specifically subscribed to some service where it becomes necessary. Which the OP said they don't.

Let's be careful to not normalize this type of data exfiltration from equipment that's supposed to be yours.

Re: Newer TP-Link Routers send large volumes of requests to Avira servers

#114

Earlier quoted context omitted.

You could also buy an SBC with a few network ports and use that as your router.

IME small ARM SBCs generally have a miserably slow bus arrangement for this sort of thing (and no hardware switch chip, of course). People have had some success with routers built on x86 mini-PCs[1], but these lean towards the “flexible and performant” side, not the cheap side. [1] https://arstechnica.com/gadgets/2016/04/the-ars-guide-to-bui...

I just installed the x86 version on a used (ebay) Dell Optiplex 790 with a quad 1gbe ethernet card, total was about $80. It's far faster than any off-the-shelf wifi router, and will let me easily upgrade to 10gbit when Frontier FIOS rolls that out (it's in their roadmap). I still use my same wifi routers but now only for wifi. Also, total power consumption is about 18 watts at idle, so it's not going to cost me much more on my electric bill.

Re: Newer TP-Link Routers send large volumes of requests to Avira servers

#115

Earlier quoted context omitted.

With ublock origin. DNS level ad blocking is rubbish and mostly circumvented by providers now.

I heard that ads were able to circumvent DNS by using canonical names. But uBlock origin and PiHole both do CNAME inspection to block this. Is there other ways that ads are circumventing DNS ad-blockers such as PiHole?

I have found that rather than finding a way to sneak ads in, most non browser apps will just detect that the ads are missing and throw up an error refusing to display the content.

Re: Newer TP-Link Routers send large volumes of requests to Avira servers

#116

Earlier quoted context omitted.

Damn. Seems like they have all "discovered" a new revenue model - harvest and sell user data to third-parties / data brokers.

These are all premium features you have to sign up for.

So why is the first line of their marketing material says "lifetime subscription for the life of the device" and not for a monthly fee? Also, I have an Asus Router with AiProtect and it didn't upsell me, and definitely no monthly dues (I'm not shocked if the data collected is resold however though).

Re: Newer TP-Link Routers send large volumes of requests to Avira servers

#117
post #26

Earlier quoted context omitted.

This is true of the US too: https://en.m.wikipedia.org/wiki/United_States_Foreign_Intell...

Only partially: Rejecting the request won't get you killed. You also have the option to close your company to avoid jail, see https://en.m.wikipedia.org/wiki/Lavabit as a good case study. Thus, I would prefer the US to China in this regard.

As a purchaser of equipment, the risk is basically the same though. It's just about which government you want to trust with your data.

Re: Newer TP-Link Routers send large volumes of requests to Avira servers

#118
post #113

From the comments Nothing in your analysis shows this. Moreover unless you explicitly deployed a root certificate on your clients (or if an app on the client did it), the router can't decode TLS traffic (deep inspection) without you getting certificate warnings on the client. In that case, the only thing the router can see is the dns request, the IP and the TLS SNI. In short your title is misleading. permalinkembedsa…

There is really no excuse for any network equipment to be sending anything at all to external parties, unless you've specifically subscribed to some service where it becomes necessary. Which the OP said they don't. Let's be careful to not normalize this type of data exfiltration from equipment that's supposed to be yours.

This case is not that, but for instance update services and time servers are defensible reasons to connect to external parties.

Re: Newer TP-Link Routers send large volumes of requests to Avira servers

#120

Earlier quoted context omitted.

I use a Qotom. They are cheap and low powered. Runs opnSense.

Thanks, I saw them mentioned elsewhere here as well. How was the setup experience? Is it something I can set up if I'm not a BSD or networking expert? Do you use a wireless AP with it?

It’s quite easy to set up if you use opnSense. I do not use it as a wireless AP; I have a separate Nest mesh for home wifi behind the Qotom.
Post reply on HN