Live data from Hacker News

Fixing Weak Wi-Fi Router Security

nytimes.com

41–50 of 69 posts

Re: Fixing Weak Wi-Fi Router Security

#41
post #36

Earlier quoted context omitted.

It's hard to beat a $50 craigslist dual+ core box, a second nic and pfSense. I have a dell optiplex 780. I paid $15 for a second nic. It's great.

> It's hard to beat a $50 craigslist dual+ core box, a second nic and pfSense unless you pay for your own power. An edge router lite uses How much does it cost to run the pfsense box over the course of 2 years?

Those dells pull about 30W at near-idle. Let's assume 40W given an extra NIC and the workload running. US domestic power averages about 12.3 cents per kWh.

So 36 bucks a year versus 8 bucks per year for the ERL.

Re: Fixing Weak Wi-Fi Router Security

#42
post #33

This should be renamed to "Fixing router security". Nothing in the article is actually specific to Wi-Fi. They don't even mention disabling WPS which is the #1 vulnerability in consumer-grade Wi-Fi networks.

Thanks, we've added a “Router”.

Re: Fixing Weak Wi-Fi Router Security

#43

Earlier quoted context omitted.

That's a good solution for geeks, not so much for everyone else. Regular people don't even update their routers, much less flash 3rd party software on them. I don't think most people even know updating your router is even a possibility. I use Google Wifi and it updates itself. In the future I might put in a PFSense, but wifi solutions like Google Wifi/Eero/etc are the way to go if you're not a computer person.

That may be behind the Eero move to go subscription only. Could be good if implemented properly but much more expensive that just buying a high end router.

Plume just announced that you'll need to buy an annual cloud license for their new stuff as well. I just dont see this taking off as a business model. How large is the intersection of people who know give a high enough importance to router security with the people who couldn't roll their own solution?

Re: Fixing Weak Wi-Fi Router Security

#44

Grab a decent microtik router and a few Ubiquiti Unifi AP's, setup automatic updates, and never touch them again.

So... two of the routers affected by the recent VPNFilter malware? Interesting choice.

> So... two of the routers affected by the recent VPNFilter malware? Interesting choice.

If you're looking for a router that's never had a documented security flaw, you're probably going to buy a no-name brand that's full of them (because no one's looked yet, so it has a "clean" record).

The factors that you really need to look for are 1) good engineering practices for security, and 2) prompt and effective response to flaws. 1) can hard to verify completely, but you can get a sense of 2) based on patch cycles.

I have a Mikrotik router at home, and I chose it because their products are inexpensive and aimed at professionals, which means the software support is much better than consumer routers. Mine is quite old, but it still gets patches.

Re: Fixing Weak Wi-Fi Router Security

#45
post #31

Earlier quoted context omitted.

why not Ubiquity edgerouter? I use the ERX, so curious what makes microtik better?

I just haven't used them before, judging from the quality of my AP's they should work just fine. I don't know how flexible they are though, RouterOS might be a bit of a pig to use but it can do pretty much anything you want, the Ubiquiti gear is very user friendly and that usually means less flexible.

Yes, the GUI apps are user-friendly (though UNMS requires a VM and Unifi Controller requires Java; they should merge these 2 which they are doing I think, ditching the latter).

If you want to, you can SSH into the machines. The disabled bash completion will bring you back to the 80s and reevaluate how "user friendly" it is (it does work as root, but then you gotta be root all the time...). I call this part of user-friendliness, and not in a positive way.

Regardless, I'm happy with the Ubiquity gear I got. The entry level hardware is cheap yet good quality. If you want the more advanced stuff, that's expensive though. 16 port managed switch with PoE costs nearly 300 EUR while 8 port costs 100 EUR.

Re: Fixing Weak Wi-Fi Router Security

#46
post #44

Earlier quoted context omitted.

So... two of the routers affected by the recent VPNFilter malware? Interesting choice.

> So... two of the routers affected by the recent VPNFilter malware? Interesting choice. If you're looking for a router that's never had a documented security flaw, you're probably going to buy a no-name brand that's full of them (because no one's looked yet, so it has a "clean" record). The factors that you really need to look for are 1) good engineering practices for security, and 2) prompt and effective response t…

I wasn't aware that the Unifi stuff was vulnerable to the latest VPN stuff. I own a few ER-Xs and a Unifi AP. They're reasonable kit, but I wouldn't recommend them at all as a set it and forget it system.

- Ubiquiti has a track record of GPL violations (e.g. u-boot which dovetails nicely with a security vuln)

- The Unifi AP is tolerable for a simple home env but not much else.

- Ubiquiti support is non-existent. They basically slapped a slick GUI on Vyatta and resold it. It's nice, but they don't have much in the way of developers. So, for instance, they still haven't fixed the hardware acceleration bugs in the ER-X or the WPA2 enterprise issues in the Unifi AP.

- Ubiquiti hardware itself is hit and miss. The ER-L, for instance, is known to overheat and cook itself to death. There was a mixup with some of the PoE stuff (UBNT historically used non-standard PoE) meaning you're not entirely sure what's in the box.

UBNT hardware cheap and you can hack on it, so that's nice. But, being aimed at professionals and actually suitable for professionals are two separate issues.

Re: Fixing Weak Wi-Fi Router Security

#47
post #44

Earlier quoted context omitted.

So... two of the routers affected by the recent VPNFilter malware? Interesting choice.

> So... two of the routers affected by the recent VPNFilter malware? Interesting choice. If you're looking for a router that's never had a documented security flaw, you're probably going to buy a no-name brand that's full of them (because no one's looked yet, so it has a "clean" record). The factors that you really need to look for are 1) good engineering practices for security, and 2) prompt and effective response t…

Same with UBNT, though i really like the functionality Mikrotik offers. Their UI takes a bit of getting used to. My favorite thing was when you made a setting change and it’s validation was to say “Not invalid”. :) My experience with UBNT in the field is pretty solid - no overheating and cooking issues that I’ve seen yet. I’ve RMA’d one device in about 50 deployed, over the course of a few years.

Re: Fixing Weak Wi-Fi Router Security

#48
post #36

Earlier quoted context omitted.

It's hard to beat a $50 craigslist dual+ core box, a second nic and pfSense. I have a dell optiplex 780. I paid $15 for a second nic. It's great.

> It's hard to beat a $50 craigslist dual+ core box, a second nic and pfSense unless you pay for your own power. An edge router lite uses How much does it cost to run the pfsense box over the course of 2 years?

Don't forget that the ERL will cook itself to death unless you improve the cooling. The case itself will reach temps of about 40C under normal operating conditions.

https://community.ubnt.com/t5/EdgeRouter/CPU-fan-mod-cpu-tem...

Re: Fixing Weak Wi-Fi Router Security

#49
there is a linux distribution for wifi-routers:

https://openwrt.org

table of hardware: https://openwrt.org/toh/start

- current master runs kernel 4.14 / 4.9 for most targets, flow offloading, performance fixes, wireguard in base, lua-based ui called uci.

- security fixes land after a few hours/days in master, a few days/weeks for a new stable release

- pretty much only non-commercial and volunteer effort, so be kind and friendly and help - check the wiki and the forum first.

Re: Fixing Weak Wi-Fi Router Security

#50
post #49

there is a linux distribution for wifi-routers: https://openwrt.org table of hardware: https://openwrt.org/toh/start - current master runs kernel 4.14 / 4.9 for most targets, flow offloading, performance fixes, wireguard in base, lua-based ui called uci. - security fixes land after a few hours/days in master, a few days/weeks for a new stable release - pretty much only non-commercial and volunteer effort, so be kind…

> security fixes land after a few hours/days in master, a few days/weeks for a new stable release

The latest stable release seems to be ~8 months old, though, unless I'm looking in the wrong place: https://downloads.openwrt.org/releases/

Post reply on HN