Live data from Hacker News

Security Begins at the Home Router

insights.sei.cmu.edu

141–150 of 177 posts

Re: Security Begins at the Home Router

#141

I'll take this opportunity to ask the community, what is a recommend router? It's going to be me and my roommate only (with friends and family over) and I would like to get something secure and also reliable (and preferably on the cheaper side) Any suggestions? I believe we have Cox if that is any factor....

Ubiquiti makes great prosumer stuff, if you're willing to pay ~$120 for the 'router', and then another ~$100 for the wireless access point. That's not 'cheap', but it's about on par what you'd pay for a fancy consumer router that looks like a spaceship. You'll get a great interface, frequent firmware updates with new features and security fixes, and you'll have a good strong signal at your neighbour's house if you're…

Another +1 for Ubiquiti. Had a bunch of high end prosumer stuff, ddwrt/tomato, etc. It really is fantastic stuff at least on part with ddwrt and well matched hardware to boot.

Their cloud management stuff is solid(and free with spare PC!) which is great if you help your family set anything up.

Ars did a great deep-dive a whole back[1], it's a pretty good read.

[1] https://arstechnica.com/information-technology/2018/07/enter...

Re: Security Begins at the Home Router

#142
post #67

Earlier quoted context omitted.

Ubiquiti makes great prosumer stuff, if you're willing to pay ~$120 for the 'router', and then another ~$100 for the wireless access point. That's not 'cheap', but it's about on par what you'd pay for a fancy consumer router that looks like a spaceship. You'll get a great interface, frequent firmware updates with new features and security fixes, and you'll have a good strong signal at your neighbour's house if you're…

How do you like the netgate pfSenses in comparison?

Well, I like it, but I have obvious bias.

Re: Security Begins at the Home Router

#143

Earlier quoted context omitted.

It sure sounds like you are describing Turris OS. https://project.turris.cz/en/software

Why did not they add the features to OpenWrt trying to make it better? Almost all the forks of OpenWrt die in months. Some lasted only few years. I am afraid that it is a wasted effort.

I think mainline openwrt runs on turris hardware now. From what I remember, the main feature of their fork is/was snapshot management through btrfs. Updates are quite lacking in general on openwrt, so I think it's good that they are doing something about it. Ideally, I would like to run a full distro on routers, and manage it through standard distro tools, now that we have reasonably powerful hardware (like the Turris).

Re: Security Begins at the Home Router

#144
post #35

I agree with Steven Gibson. The biggest defense we can have on this is autoupdating routers. At a minimum, just restart at some fixed time after an update is downloaded. More fancy would be dynamically calculating a low usage day and time to restart. But this would also involve the router manufacturer keeping it up-to-date as well. Which gets me thinking... Does a SOHO (or any) device exist that effectively runs two…

>.. Does a SOHO (or any) device exist that effectively runs two firmware instances at once to allow minimal downtime as it switches over to new firmware? I imagine larger routers do, or at least, two identical physical routers accomplishes as much.

Quite likely that google-wifi (chromeos) does, or at least is capabale of doing that given good enough hardware. All of google's products have moved to this sort of A/B layout.

Re: Security Begins at the Home Router

#145
post #19

Earlier quoted context omitted.

While your points are valid, it is a bit disconcerting to have the world's largest data monetizer watch all of a home's traffic. Google's promised benevolence may be temporary

One nice thing with Google WiFi being based on CROS, is that it's mostly open source (about the same level as Android, where there are some binary blob board support packages). With that, there is custom firmware you can load know Google Wifis: https://github.com/marcosscriven/galeforce As an aside, you can read the Google WiFi privacy details here: https://support.google.com/wifi/answer/6246642?hl=en

I think there is a pretty big distinction wrt routers, in that an end-user cannot build it. That link states as much under the, "Why not just build Chromium OS from source" section. Has anything changed ? With android at least, google distributes the blobs. This probably (?) explains why openwrt hasn't been ported to any of the google routers, although the availability of chromiumOS source would make you think that it would be straightforward.

Re: Security Begins at the Home Router

#146

I'd like explore making a small ecosystem of open security plugins built on top of OpenWrt. The goal is to make firewalling and controlling network traffic really easy. The UI should be so easy a parent could perform difficult tasks such as limiting an iot devices traffic to local net or maybe just one ip using just an app. Or detecting unusual patterns of traffic from a device or IP addresses. The apis exist I can't…

It seems obvious that this should be developed, but to take it a step further it would be great if consumers could purchase something that gave them access to these plugins without needing to know how to setup OpenWRT. This will be challenging because most ISPs provide the router and firmware for the majority of their customers.

Where the ISP forces use of their modem (like mine does), you can still set it up as a gateway and make it a pure modem, using a second router for your local network.

It's what I've done for years and it works fine. I have a Pi-hole off my ISP modem, and the Pi-hole does DHCP, DNS, VPN, and more for our network at the same time as doing it's normal filtering job.

I'd love a better device where my Pi-hole is though, which I can configure easier, set up for my friends and family then they can manage it themselves, etc. There's definitely a market for this at least from me!

Re: Security Begins at the Home Router

#147
Raising the security bar of routers is indeed a priority of many ISPs, organizations and consumers. But IMHO, securing the router isn't enough, because once you close the huge security and privacy hole created by vulnerable and outdated home routers, IoT devices like IP cameras will take the router's place as the weakest link in terms of a home network's security, so the problem of malware targeting embedded devices with no security software is still there. (Also, if any guest who connects to a WiFi network can guess admin:admin or admin:12345678 and infect IoT devices, NAT is not enough to provide a reasonable level of security in many home networks. In addition, having open-source firmware or reputable open-source components is not enough to assert that a certain device is secure by design, because most home routers run outdated and vulnerable versions of Linux/uClibc/whatever, often with network stack patches and proprietary drivers from the SoC manufacturer's BSP that make it impossible to upgrade to recent, stable versions of everything; this also applies to the router manufacturers that fork OpenWRT and don't pull changes. Moreover, completely separate from the question of how to develop security updates, the problem of testing and deploying them in time on customer premises, without user intervention, still remains and detracts from the ISP's motivation to provide security: it's very expensive). A copy-paste-based software development lifecycle, unsafe C code, the cost of built-in security and the risks & costs of deploying updates in scale are here to stay for the foreseeable future. A more radical solution is needed to protect today's devices against today's and future threats: that's why in https://www.securingsam.com, we're putting a security-as-a-service umbrella on the existing, consumer-grade router which hardens and protects the router and all devices connected to it using DPI, traffic anomaly detection, auto-updated (independently of the router firmware) vulnerability mitigation patches and much much more.

Re: Security Begins at the Home Router

#148
post #14

Earlier quoted context omitted.

The idea of a completely read-only router is really interesting. I used to buy hardware that would only work with open firmware -- I used to love to constantly update and mess with DD-WRT. But in more recent years I've just started buying high-performing hardware and skipping the customization beyond SSID and passwords. With faster connections, UPNP, and decent default QoS policies I pretty much never have to configu…

UPNP can be an absolute security nightmare however, it's the sole reason so many IP cameras, NAS drives and IOT devices are internet accessible. It's your network of course but it would be the first thing I'd turn off.

Sure, but if I want to play a game of Mario Kart I don't want to mess around with port forwarding.

Re: Security Begins at the Home Router

#149
post #46

I'll take this opportunity to ask the community, what is a recommend router? It's going to be me and my roommate only (with friends and family over) and I would like to get something secure and also reliable (and preferably on the cheaper side) Any suggestions? I believe we have Cox if that is any factor....

In particular, recommendations for consumer routers would be welcome. Last time this came up, the line seemed to be "consumer routers are trash, if you want security you have to use an enterprise router." There might be some truth in this, but it isn't helpful. Surely not all consumer routers are equally bad?

> consumer routers are trash, if you want security you have to use an enterprise router

These are trash too, full of closed code with backdoors. Buying small x86 mini PC and flashing it with OPNsense will take an hour. You get open source with GUI on FreeBSD, bulletproof.

Re: Security Begins at the Home Router

#150
post #35

I agree with Steven Gibson. The biggest defense we can have on this is autoupdating routers. At a minimum, just restart at some fixed time after an update is downloaded. More fancy would be dynamically calculating a low usage day and time to restart. But this would also involve the router manufacturer keeping it up-to-date as well. Which gets me thinking... Does a SOHO (or any) device exist that effectively runs two…

If you start making my router autoupdate and autoreboot like Windows does you will alienate a very large number of customers. Instead: stop making shit routers.

Unlike with Windows I seriously doubt that. Windows reboot is unpredictable and a) can break your work flow and b) can possible corrupt your unsaved data, calculations etc.

Router reboot is simply a network outage for 2-3 minutes and routers that can do auto-update also always support configuration it. E.g. Reboot at 3am in the night, only on Monday and only if there had been new firmware in the last week. I can assure you that it is neither disrupting nor noticeable at all. Router boots neither break work flows nor corrupt your data (in SOHO segment).

Post reply on HN