Before you say anything about this feature (which is apparently called HomeCare, https://www.tp-link.com/homecare/ ), you should probably know that Asus also has a AiProtection feature powered by Trend Micro ( https://www.asus.com/content/aiprotection/ ) and D-Link having McAfee Secure Home Platform built-in ( https://www.dlink.com/en/latest-news/d-link-introduces-new-e... ). Definitely not vindicating TP-Link here (…
Damn. Seems like they have all "discovered" a new revenue model - harvest and sell user data to third-parties / data brokers.
Newer TP-Link Routers send large volumes of requests to Avira servers
111–120 of 121 posts
Re: Newer TP-Link Routers send large volumes of requests to Avira servers
#112This was alarming since I use a TP-Link router, so I tried figuring out to what extent it's able to inspect and record regular (encrypted) traffic. My TP-Link Archer AX50, running software version "1.0.11 Build 20210730 rel.54485(4A50)" is doing at least some sort of DPI on outgoing connections. I found a page in its settings (Advanced -> Security -> Antivirus -> History) that contains a log of connections I've made…
Re: Newer TP-Link Routers send large volumes of requests to Avira servers
#113From the comments Nothing in your analysis shows this. Moreover unless you explicitly deployed a root certificate on your clients (or if an app on the client did it), the router can't decode TLS traffic (deep inspection) without you getting certificate warnings on the client. In that case, the only thing the router can see is the dns request, the IP and the TLS SNI. In short your title is misleading. permalinkembedsa…
Let's be careful to not normalize this type of data exfiltration from equipment that's supposed to be yours.
Re: Newer TP-Link Routers send large volumes of requests to Avira servers
#114Earlier quoted context omitted.
You could also buy an SBC with a few network ports and use that as your router.
IME small ARM SBCs generally have a miserably slow bus arrangement for this sort of thing (and no hardware switch chip, of course). People have had some success with routers built on x86 mini-PCs[1], but these lean towards the “flexible and performant” side, not the cheap side. [1] https://arstechnica.com/gadgets/2016/04/the-ars-guide-to-bui...
Re: Newer TP-Link Routers send large volumes of requests to Avira servers
#115Earlier quoted context omitted.
With ublock origin. DNS level ad blocking is rubbish and mostly circumvented by providers now.
I heard that ads were able to circumvent DNS by using canonical names. But uBlock origin and PiHole both do CNAME inspection to block this. Is there other ways that ads are circumventing DNS ad-blockers such as PiHole?
Re: Newer TP-Link Routers send large volumes of requests to Avira servers
#116Earlier quoted context omitted.
Damn. Seems like they have all "discovered" a new revenue model - harvest and sell user data to third-parties / data brokers.
These are all premium features you have to sign up for.
Re: Newer TP-Link Routers send large volumes of requests to Avira servers
#117Earlier quoted context omitted.
This is true of the US too: https://en.m.wikipedia.org/wiki/United_States_Foreign_Intell...
Only partially: Rejecting the request won't get you killed. You also have the option to close your company to avoid jail, see https://en.m.wikipedia.org/wiki/Lavabit as a good case study. Thus, I would prefer the US to China in this regard.
Re: Newer TP-Link Routers send large volumes of requests to Avira servers
#118From the comments Nothing in your analysis shows this. Moreover unless you explicitly deployed a root certificate on your clients (or if an app on the client did it), the router can't decode TLS traffic (deep inspection) without you getting certificate warnings on the client. In that case, the only thing the router can see is the dns request, the IP and the TLS SNI. In short your title is misleading. permalinkembedsa…
There is really no excuse for any network equipment to be sending anything at all to external parties, unless you've specifically subscribed to some service where it becomes necessary. Which the OP said they don't. Let's be careful to not normalize this type of data exfiltration from equipment that's supposed to be yours.
Re: Newer TP-Link Routers send large volumes of requests to Avira servers
#119I setup cloudflare zero trust and started pointing my AC4000 to it, let's see what happens.
Re: Newer TP-Link Routers send large volumes of requests to Avira servers
#120Earlier quoted context omitted.
I use a Qotom. They are cheap and low powered. Runs opnSense.
Thanks, I saw them mentioned elsewhere here as well. How was the setup experience? Is it something I can set up if I'm not a BSD or networking expert? Do you use a wireless AP with it?