Earlier quoted context omitted.
> But then vendors want to stop issuing them after 3 years Tough shit. You provide updates for the mandated amount of time, or you lose access to the market. No warnings, you're just done. > And "require longer support" doesn't fix it because many of the vendors will go out of business. Source code escrow plus a bond. The bond is set at a level where a third party can pay engineers to maintain the software and distri…
How does this help? 99% of the population aren't technically minded enough. Most people just buy a wifi router, plug it in (maybe having read the instructions) and that's it. They have neither the skills nor the inclination to update firmware. The real problem is: assuming that firmware can be updated, how do you run a nationwide update programme overcoming a population that doesn't really care or have the skills to…
FCC updates covered list to include foreign-made consumer routers
211–220 of 452 posts
Re: FCC updates covered list to include foreign-made consumer routers
#212Earlier quoted context omitted.
Auto-update obviously.
How? The device phones home to the manufacturer's servers to get new updates. Manufacturer goes out of business, servers get shut down. How does it know where to get updates now?
Continue your chain of reasoning: DNS name becomes unmaintained, gets grabbed by open source / foundation / gov agency, pushes open source firmware update.
Same thing happens today with botnet C&C servers.
Re: FCC updates covered list to include foreign-made consumer routers
#213Earlier quoted context omitted.
Just declare that any router that can be flashed to OpenWRT without loss of functionality is allowed to be imported.
Requiring a one-click option to configure to open source would be a sensible across-the-board law.
Re: FCC updates covered list to include foreign-made consumer routers
#214Earlier quoted context omitted.
Requiring a one-click option to configure to open source would be a sensible across-the-board law.
I think we all know that's never going to happen.
Why? You'd need to get someone electorally useful involved. That, unfortunately, elimiates a lot of the nihilistic, holier-than-thou tech types. But that's pretty doable nowadays. You just need an electorally-relevant group of people on your side.
Re: FCC updates covered list to include foreign-made consumer routers
#215Earlier quoted context omitted.
Open firmware would become commercially viable when IP is abolished
I'm no fan of imaginary property, but you're going to have to lay out your reasoning here. Firmware security is such crap precisely because most hardware manufacturers see it as nothing but a cost center they wish they could avoid. The difficulty of installing OpenWRT or Linux in general on hardware comes from that hardware not being documented, or not having straightforward APIs like BIOS/EFI. Or for some devices, c…
Oh, no, not this again!
> But we generally see that as soon as the manufacturer stops their updates, the community versions start lagging behind as well.
Care to demonstrate that?
The reason OpenWrt abandoned most routers was
1) insufficient flash space in the kernel partition, or insufficient total flash space in no-USB, no-SPI routers,
2) unwillingness to repartition flash because it breaks compatibility with official firmware (as if anyone installing OpenWrt would care),
3) insufficient RAM to run newer kernels
and, most importantly,
4) unwillingness to support older kernels like DD-WRT does.
Re: FCC updates covered list to include foreign-made consumer routers
#216Earlier quoted context omitted.
I think we all know that's never going to happen.
> we all know that's never going to happen Why? You'd need to get someone electorally useful involved. That, unfortunately, elimiates a lot of the nihilistic, holier-than-thou tech types. But that's pretty doable nowadays. You just need an electorally-relevant group of people on your side.
Re: FCC updates covered list to include foreign-made consumer routers
#217Because of this, I'm going to plan my next network upgrade based on open source hardware like Banana Pi. My setup is based on WiFi 7 so this might not apply for a few years. From my understanding, the hardware from proprietary manufacturers is sufficiently advanced to do some advanced surveillance and spyware, whereas previous generations didn't require advanced processing to achieve fiber optic speeds. Back to the o…
Besides BananaPi, there are e.g. ODROID (Hardkernel from South Korea), FriendlyElec, Radxa.
Re: FCC updates covered list to include foreign-made consumer routers
#218What the fuck?! I did not sign up to live in some third world shithole where I can't get first-world networking equipment. I do not want some piece of shit closed-source proprietary netgear ameritrash. FUCK! Give me back my god damn chinese routers! Chinese citizens have more computing freedom than American citizens at this point. What the fuck happened to the land of the free?
So much different than the piece of shit closed-source proprietary netgear chinesium.
Consumer routers are shit full stop.
Re: FCC updates covered list to include foreign-made consumer routers
#219Earlier quoted context omitted.
Device that connects multiple networks? Layer 3 of the OSI model? Consumer ones tend to have more than that, but the more specific definition would work fine. Yeah conceivably you could use this to ban any network device that is capable of routing between interfaces, so lots of switches with new firmware could do it, often terribly, as well as PCs with multiple interfaces. But its probably going to involve intention.
Any PC with a NIC is one VLAN and masquerade rule away from being a router
For example, my router/firewall, which also implements various other network services, e.g. hosting my own e-mail server, is an old Intel NUC with 5 Ethernet ports, 4 of which are made with USB Ethernet interfaces.
Re: FCC updates covered list to include foreign-made consumer routers
#220The FCC maintains a list of equipment and services (Covered List) that have been determined to “pose an unacceptable risk to the national security Recently, malicious state and non-state sponsored cyber attackers have increasingly leveraged the vulnerabilities in small and home office routers produced abroad to carry out direct attacks against American civilians in their homes. Vulnerabilities have nothing to do with…
> Manufacturers have never had to care about security because no Gov agency would ever mandate secure firmware. The problem is that "secure firmware" is a relativistic statement. You ship something with no known bugs and then someone finds one. What you need is not a government mandate for infallibility, it's updates. But then vendors want to stop issuing them after 3 years, meanwhile many consumers will keep using t…