Live data from Hacker News

FCC updates covered list to include foreign-made consumer routers

fcc.gov

211–220 of 452 posts

Re: FCC updates covered list to include foreign-made consumer routers

#211
post #184

Earlier quoted context omitted.

> But then vendors want to stop issuing them after 3 years Tough shit. You provide updates for the mandated amount of time, or you lose access to the market. No warnings, you're just done. > And "require longer support" doesn't fix it because many of the vendors will go out of business. Source code escrow plus a bond. The bond is set at a level where a third party can pay engineers to maintain the software and distri…

How does this help? 99% of the population aren't technically minded enough. Most people just buy a wifi router, plug it in (maybe having read the instructions) and that's it. They have neither the skills nor the inclination to update firmware. The real problem is: assuming that firmware can be updated, how do you run a nationwide update programme overcoming a population that doesn't really care or have the skills to…

Automatic updates. Now it also applies to cars.

Re: FCC updates covered list to include foreign-made consumer routers

#212
post #185
post #85

Earlier quoted context omitted.

Auto-update obviously.

How? The device phones home to the manufacturer's servers to get new updates. Manufacturer goes out of business, servers get shut down. How does it know where to get updates now?

> Manufacturer goes out of business, servers get shut down.

Continue your chain of reasoning: DNS name becomes unmaintained, gets grabbed by open source / foundation / gov agency, pushes open source firmware update.

Same thing happens today with botnet C&C servers.

Re: FCC updates covered list to include foreign-made consumer routers

#213

Earlier quoted context omitted.

Just declare that any router that can be flashed to OpenWRT without loss of functionality is allowed to be imported.

Requiring a one-click option to configure to open source would be a sensible across-the-board law.

I think we all know that's never going to happen.

Re: FCC updates covered list to include foreign-made consumer routers

#214
post #213

Earlier quoted context omitted.

Requiring a one-click option to configure to open source would be a sensible across-the-board law.

I think we all know that's never going to happen.

> we all know that's never going to happen

Why? You'd need to get someone electorally useful involved. That, unfortunately, elimiates a lot of the nihilistic, holier-than-thou tech types. But that's pretty doable nowadays. You just need an electorally-relevant group of people on your side.

Re: FCC updates covered list to include foreign-made consumer routers

#215

Earlier quoted context omitted.

Open firmware would become commercially viable when IP is abolished

I'm no fan of imaginary property, but you're going to have to lay out your reasoning here. Firmware security is such crap precisely because most hardware manufacturers see it as nothing but a cost center they wish they could avoid. The difficulty of installing OpenWRT or Linux in general on hardware comes from that hardware not being documented, or not having straightforward APIs like BIOS/EFI. Or for some devices, c…

> not having straightforward APIs like BIOS/EFI.

Oh, no, not this again!

> But we generally see that as soon as the manufacturer stops their updates, the community versions start lagging behind as well.

Care to demonstrate that?

The reason OpenWrt abandoned most routers was

1) insufficient flash space in the kernel partition, or insufficient total flash space in no-USB, no-SPI routers,

2) unwillingness to repartition flash because it breaks compatibility with official firmware (as if anyone installing OpenWrt would care),

3) insufficient RAM to run newer kernels

and, most importantly,

4) unwillingness to support older kernels like DD-WRT does.

Re: FCC updates covered list to include foreign-made consumer routers

#216
post #213

Earlier quoted context omitted.

I think we all know that's never going to happen.

> we all know that's never going to happen Why? You'd need to get someone electorally useful involved. That, unfortunately, elimiates a lot of the nihilistic, holier-than-thou tech types. But that's pretty doable nowadays. You just need an electorally-relevant group of people on your side.

Like I said, not going to happen.

Re: FCC updates covered list to include foreign-made consumer routers

#217

Because of this, I'm going to plan my next network upgrade based on open source hardware like Banana Pi. My setup is based on WiFi 7 so this might not apply for a few years. From my understanding, the hardware from proprietary manufacturers is sufficiently advanced to do some advanced surveillance and spyware, whereas previous generations didn't require advanced processing to achieve fiber optic speeds. Back to the o…

There are several vendors of small computers usable as routers/firewalls and who provide complete hardware documentation, including schematics and PCB layout. Some of them also provide an extensive list of accessories, including cases with good passive cooling.

Besides BananaPi, there are e.g. ODROID (Hardkernel from South Korea), FriendlyElec, Radxa.

Re: FCC updates covered list to include foreign-made consumer routers

#218

What the fuck?! I did not sign up to live in some third world shithole where I can't get first-world networking equipment. I do not want some piece of shit closed-source proprietary netgear ameritrash. FUCK! Give me back my god damn chinese routers! Chinese citizens have more computing freedom than American citizens at this point. What the fuck happened to the land of the free?

> I do not want some piece of shit closed-source proprietary netgear ameritrash.

So much different than the piece of shit closed-source proprietary netgear chinesium.

Consumer routers are shit full stop.

Re: FCC updates covered list to include foreign-made consumer routers

#219

Earlier quoted context omitted.

Device that connects multiple networks? Layer 3 of the OSI model? Consumer ones tend to have more than that, but the more specific definition would work fine. Yeah conceivably you could use this to ban any network device that is capable of routing between interfaces, so lots of switches with new firmware could do it, often terribly, as well as PCs with multiple interfaces. But its probably going to involve intention.

Any PC with a NIC is one VLAN and masquerade rule away from being a router

That is true, but you can also add USB Ethernet interfaces to any PC, which is even simpler.

For example, my router/firewall, which also implements various other network services, e.g. hosting my own e-mail server, is an old Intel NUC with 5 Ethernet ports, 4 of which are made with USB Ethernet interfaces.

Re: FCC updates covered list to include foreign-made consumer routers

#220

The FCC maintains a list of equipment and services (Covered List) that have been determined to “pose an unacceptable risk to the national security Recently, malicious state and non-state sponsored cyber attackers have increasingly leveraged the vulnerabilities in small and home office routers produced abroad to carry out direct attacks against American civilians in their homes. Vulnerabilities have nothing to do with…

> Manufacturers have never had to care about security because no Gov agency would ever mandate secure firmware. The problem is that "secure firmware" is a relativistic statement. You ship something with no known bugs and then someone finds one. What you need is not a government mandate for infallibility, it's updates. But then vendors want to stop issuing them after 3 years, meanwhile many consumers will keep using t…

The government obviously cares less about citizens running firmware China can hack than it does about citizens potentially running firmware the government can't hack.
Post reply on HN