Earlier quoted context omitted.
My sister in laws xfinity router / app has a new feature banner for “detecting motion in your house with WiFi for no additional cost” I took a screenshot to share if anyone is interested
This has been shared on Hacker News before: https://github.com/francescopace/espectre
FCC updates covered list to include foreign-made consumer routers
301–310 of 452 posts
Re: FCC updates covered list to include foreign-made consumer routers
#302Earlier quoted context omitted.
My sister in laws xfinity router / app has a new feature banner for “detecting motion in your house with WiFi for no additional cost” I took a screenshot to share if anyone is interested
Questions of mass surveillance aside, I always wonder how useful these things (motion detection when you're not home) actually are given how many American households have dogs and cats.
Re: FCC updates covered list to include foreign-made consumer routers
#303Earlier quoted context omitted.
I have a PC hooked up to my TV in my living room that has been running the latest version of Kubuntu for over 18 years now. It has had many upgrades in that time but it's still the same basic hardware: A CPU, some memory, USB ports, a video card, and an ethernet port on the back. That "genericness" is what's missing in the router space. Literally every consumer router that comes out has some super proprietary design…
> They key point remains, however: They're not just hardware—even though they should be! This is the most thoughtful comment I've seen on this topic. I hadn't even considered this approach, but you're right. The hardware needs to be commoditized in a way that makes the software a layer that can be replaced. Someone else said this but in a way that described flashing a third-party package as HN nerds would. That's too…
Or they could just run an existing open source OS, like openwrt.
Re: FCC updates covered list to include foreign-made consumer routers
#304Earlier quoted context omitted.
My sister in laws xfinity router / app has a new feature banner for “detecting motion in your house with WiFi for no additional cost” I took a screenshot to share if anyone is interested
Questions of mass surveillance aside, I always wonder how useful these things (motion detection when you're not home) actually are given how many American households have dogs and cats.
Re: FCC updates covered list to include foreign-made consumer routers
#305Does anyone even have a list of US produced routers? Like does installing OpenWRT or OPNSense or VyOS matter? I can’t think of a complete start to finish, OS to mosfets, computer that is 100% manufactured in the United States.
If their "made in america" goal was anything but a sham, system76 would be getting huge government contracts right now.
Of course, getting a router SOC with firmware from the factory , soldering on the Ethernet ports and adding RAM and storage, installing an OS, throwing it in a case with a power supply into a box isn’t solving the problem of insecure foreign firmware but is meeting the “Made in US” demand.
So what counts and who gets exemptions will be telling.
Re: FCC updates covered list to include foreign-made consumer routers
#306Re: FCC updates covered list to include foreign-made consumer routers
#307If we wanted secure products, we wouldn't ban devices. We'd mandate they open their firmware to audits.
Not all of the functionality is in the firmware though. You can put stuff in the silicon itself that allows backdoors. It's very difficult to inspect a laid out chip for nefarious elements - there's too much of it to do manually. Having a secure supply chain is probably the best way to prevent that happening. Which is not to say that I support this rule - it sounds like another import weapon trump can swing against p…
Very few companies make the chips too. It'd be very easy for the government to force them to add backdoors.
Re: FCC updates covered list to include foreign-made consumer routers
#308Because of this, I'm going to plan my next network upgrade based on open source hardware like Banana Pi. My setup is based on WiFi 7 so this might not apply for a few years. From my understanding, the hardware from proprietary manufacturers is sufficiently advanced to do some advanced surveillance and spyware, whereas previous generations didn't require advanced processing to achieve fiber optic speeds. Back to the o…
IMHO an underrated comment. The CCP isn't going to break down my door in the middle of the night, but I'm sure I'm on lists at the FBI and ATF just for my political org memberships alone. I think a foreign actor is more likely to use compromised hardware to create service interruptions and general chaos in the event they are attacked by our government, not come put me in a gulag. The only thing I'm missing right now…
Thanks to whistleblowers like Mark Klein and Ed Snowden we know that we're all being monitored by the government. If there are "lists" at all at this point it's the few people that aren't being watched 24/7.
Re: FCC updates covered list to include foreign-made consumer routers
#309The FCC maintains a list of equipment and services (Covered List) that have been determined to “pose an unacceptable risk to the national security Recently, malicious state and non-state sponsored cyber attackers have increasingly leveraged the vulnerabilities in small and home office routers produced abroad to carry out direct attacks against American civilians in their homes. Vulnerabilities have nothing to do with…
> Vulnerabilities have nothing to do with country of manufacture. They have always been due to manufacturers' crap security practices. Sorry but this is merely a convenient excuse. Source: I have hard evidence of a Chinese IoT device where crap security practices were later leveraged by the same company to inject exploit code. It's called plausible deniability and it's foolish to tell me it's a coincidence. You're no…
Re: FCC updates covered list to include foreign-made consumer routers
#310Earlier quoted context omitted.
> Manufacturers have never had to care about security because no Gov agency would ever mandate secure firmware. The problem is that "secure firmware" is a relativistic statement. You ship something with no known bugs and then someone finds one. What you need is not a government mandate for infallibility, it's updates. But then vendors want to stop issuing them after 3 years, meanwhile many consumers will keep using t…
> What you need is not a government mandate for infallibility, it's updates So, we don't need an electrical code to enforce correct wiring. We just need a kind soul driving by our house to notice the company who built our house wired it up wrong. Then that kind person can inform the company of the bad wiring. And if the company agrees it's their wiring at fault, we can wait 3 months for a fix. Then the next month ano…