Live data from Hacker News

OpenWrt Two Approval

openwrt.org

111–120 of 133 posts

Re: OpenWrt Two Approval

#111

Earlier quoted context omitted.

> How reasonable do you think it is to be this automatically suspicious of any computer coming from China? Based on their track record? Pretty fucking reasonable. I would say that most probably isn't malicious collaboration with the CCP, rather sheer incompetence. Shipping secure anything just isn't part of their culture. Read a comment on HN the other day from someone that evaluated Huawei hardware for a telco and s…

Im curious how you are currently writing those comments. Other than most of the hardware is made in CN or TW, there is not so much records targeting normal people. Also you get good hardware cheap, it just works and helps us going forward. Enterprise crap from companies like Intel (especially their server disks) are nightmare for years now and last Juniper and Cisco hardcore bugs in software causing soft-drops withou…

As someone who was personally a victim of the 1-2 punch of vulnerable HW and unquestionable malware that took advantage of said vulnerability from the same vendor (and I have the pcaps to prove it), I have sworn off CN garbage forever, I don't care if I have to pay 3x the price.

No one stops you from doing so, just know you will probably be part of a botnet sooner or later.

Re: OpenWrt Two Approval

#112
post #37

Earlier quoted context omitted.

Is it really any different than every person who insists on running pfSense for security reasons then immediately suggesting some Chinese shitbox PC off AliExpress as the ideal platform to run it on? Also, since when has having a Wikipedia page proven a company legitimate? You know most companies author their own pages anyway, that's kind of how Wikipedia works.

> suggesting some Chinese shitbox PC off AliExpress as the ideal platform to run it on? How reasonable do you think it is to be this automatically suspicious of any computer coming from China? A generic low-cost barebones Intel PC certainly has plenty of space for compromised firmware to hide, but it's implausible that a Chinese intelligence agency would indiscriminately deploy an attack that made use of a compromise…

VERY reasonable , if not a total piece of crap with fake copied hardware, a security nightmare with hardware level integrated spyware.

Don’t bother importing. They should start seizing these at the port

Re: OpenWrt Two Approval

#113
post #11

GL.iNet is a popular brand, though I can't find a Wikipedia page for it. https://www.gl-inet.com/about-us/ says: > GL Tech (HK) Ltd: #601, 5W, Hong Kong Science Park, N.T. Hong Kong > GL Intelligence, Inc.: 10400 Eaton Place, Suite 215, Fairfax, VA 22030 I'm a little curious about this. One of the reasons that some people run OpenWrt is for improved security. In the general security space, a Shenzen company isn't the…

[deleted]

Re: OpenWrt Two Approval

#114

Earlier quoted context omitted.

Im curious how you are currently writing those comments. Other than most of the hardware is made in CN or TW, there is not so much records targeting normal people. Also you get good hardware cheap, it just works and helps us going forward. Enterprise crap from companies like Intel (especially their server disks) are nightmare for years now and last Juniper and Cisco hardcore bugs in software causing soft-drops withou…

As someone who was personally a victim of the 1-2 punch of vulnerable HW and unquestionable malware that took advantage of said vulnerability from the same vendor (and I have the pcaps to prove it), I have sworn off CN garbage forever, I don't care if I have to pay 3x the price. No one stops you from doing so, just know you will probably be part of a botnet sooner or later.

If you have proof, then why wouldn't you name and shame the vendor in question, or at least be less vague about what kind of product you're talking about? Talking about how you determined that you were being attacked through a combination of hardware and software vulnerabilities would be way more interesting and appropriate for this forum than generic anti-China complaints.

Re: OpenWrt Two Approval

#115

Earlier quoted context omitted.

> With OpenWrt Two, I bet they're going to make the same mistakes as OpenWrt One: not enough memory and not upgradable, wifi not replaceable, no usable expansion slots (mini-PCI, M.2) and, of course, no (e)SATA. Another e-waste product that will be obsolete even before it's available to buy. Those are only mistakes if you ignore the realities of what hardware is available. A highly-integrated SoC designed specificall…

For another approach to open source networking by Linux Foundation please check DENT OS [1]. > OpenWRT is not yet in a position to influence the hardware design decisions made by companies like Mediatek, Qualcomm, Broadcom for their consumer WiFi product families. Perhaps I'm biased, but I do believe DENT is in much better position and has more chance of influencing the white-box networking vendor than OpenWRT with r…

That doesn't even appear to be attempting to address anything relevant to consumer networking. It's a purely enterprise-focused project, mostly about putting a Debian-based OS onto rackmount ethernet switches.

Re: OpenWrt Two Approval

#117
post #83

I wonder why they are including a 5G port. There does not seem to be a lot of gear that uses it. An additional 1/2.5G or 10G SFP would make more sense.

tl;dr RTL8251B does not need a firmware blob https://lists.openwrt.org/pipermail/openwrt-devel/2025-Febru...

It figures that Realtek is a key part of the story. The availability of Realtek PHYs and NICs is what's finally allowing 2.5GbE and 5GbE to go mainstream for consumer equipment. Aquantia got bought by Marvell and ended up with enterprise-level pricing on all their stuff. Intel completely tanked their reputation for NICs with a few failed attempts to implement 2.5GbE support, and haven't even tried to introduce a consumer-grade 5GbE option. But now that Realtek is in the game, 2.5GbE is widespread in new desktop motherboards and fairly cheap in USB Ethernet adapters.

Re: OpenWrt Two Approval

#118

This is awesome! I've been using OpenWRT for more than a decade, and I think it's great that they're designing their own hardware now. I'm on a GL.iNet MT-6000 right now, and it's a great router. The stock firmware is based on openwrt, and they make it very easy to upgrade to an official openwrt release. I bought it before the OpenWRT One became available, but I probably would have gone with it anyways because it has…

There is experimental support for the Asus BT8 which is a be14000 device, there are snapshot builds for it but issues going back to the Asus firmware. Also banana pi R4 development board and it's got a be14000 WiFi card. These are all the devices I know that have support but many of the mt7988s should get added in time.

Re: OpenWrt Two Approval

#119

Earlier quoted context omitted.

STH has reviewed Chinese PCs that come preloaded with malware. My MSI motherboard force installs Nahimic by default. Not technically malware but the same mechanism exists for malware.

Do you think any of that is relevant to the case of buying a barebones PC that doesn't include SSD or RAM, then adding those components yourself and installing a non-Windows OS? If your MSI motherboard is installing Nahimic without an internet connection, it is doing so through a mechanism where the installer is made available to the OS in an ACPI table that Windows checks. That check can be disabled with a registry…

I think if a company is willing to ship windows malware they're also willing to ship UEFI malware.

Re: OpenWrt Two Approval

#120

Earlier quoted context omitted.

Do you think any of that is relevant to the case of buying a barebones PC that doesn't include SSD or RAM, then adding those components yourself and installing a non-Windows OS? If your MSI motherboard is installing Nahimic without an internet connection, it is doing so through a mechanism where the installer is made available to the OS in an ACPI table that Windows checks. That check can be disabled with a registry…

I think if a company is willing to ship windows malware they're also willing to ship UEFI malware.

Please don't ignore the points I've already made about how a firmware-based attack against a non-Windows OS is a lot hardware to pull off. I'm not asking if you think a company would be willing to ship such malware, I'm asking what kind of malware you think is realistically possible. What do you expect a UEFI-based malware to be capable of doing in this context, given the constraints of the hardware we're talking about?
Post reply on HN