Live data from Hacker News

OpenWrt Two Approval

openwrt.org

41–50 of 133 posts

Re: OpenWrt Two Approval

#41
post #11

GL.iNet is a popular brand, though I can't find a Wikipedia page for it. https://www.gl-inet.com/about-us/ says: > GL Tech (HK) Ltd: #601, 5W, Hong Kong Science Park, N.T. Hong Kong > GL Intelligence, Inc.: 10400 Eaton Place, Suite 215, Fairfax, VA 22030 I'm a little curious about this. One of the reasons that some people run OpenWrt is for improved security. In the general security space, a Shenzen company isn't the…

Can you recommend Western companies that would be able to produce similar hardware at the same price point?

MicroTik is European (Latvian) and makes some affordable routers. Their own RouterOS is closed source, but many models are supported by OpenWrt (no experience). If you are willing to spend more, OPNsense (Netherlands) also sells hardware. In the old days one could also recommend PFsense hardware, but they are becoming more and more closed (though you can usually run OPNsense on the same hardware).

QNAP is Taiwanese. Their QHora routers use closed software, but I think most models are supported by OpenWrt.

Re: OpenWrt Two Approval

#42

Earlier quoted context omitted.

Can you recommend Western companies that would be able to produce similar hardware at the same price point?

https://store.ui.com/us/en/category/all-cloud-gateways/produ... 4x 2.5GbE (one of them even a PoE port) 1x 10GbE SFP+ WiFi 7 with MLO $279

Ubiquiti gear is great, but does not use open source software like OpenWrt Two. And I think most modern Ubiquiti routers are not supported by OpenWrt.

Re: OpenWrt Two Approval

#43
post #12

What I would want to have some company to make one device that would at the same time be: 1) router 2) smart tv (airplay, chromecast, miracast) 3) smart speaker 4) smart home gateway (matter) 5) wireless charging pad 6) private cloud (nextcloud) 7) private backup (removable nvm) 8) private vpn / dns / pihole / adguard 9) mini server Everything in a nice package and preconfigure and ideally modular (upgradable ssd, wi…

Used Lenovo Tiny PCs with VMs, iGPU and 4-port NICs get close.

Got any specific recommendation for 4-port NIC?

Re: OpenWrt Two Approval

#44
post #12

What I would want to have some company to make one device that would at the same time be: 1) router 2) smart tv (airplay, chromecast, miracast) 3) smart speaker 4) smart home gateway (matter) 5) wireless charging pad 6) private cloud (nextcloud) 7) private backup (removable nvm) 8) private vpn / dns / pihole / adguard 9) mini server Everything in a nice package and preconfigure and ideally modular (upgradable ssd, wi…

Openwrt ticks a lot of those boxes if you add storage. For me, the location of my router makes using it as a charging pad, speaker, and TV device impractical anyway, and I can imagine I'm not alone in that.

Yes I understand in US where a lot of people live in houses this makes less sense but in asia and europe a lot of people live in apartments and they have their router and smart tv box in living room on tv desk. Such router covers whole apartment and direct wired connection to TV would reduce latency with airplay. Many also use 4g usb modem since mobile data providers are cheap there (e.g. in poland you can get 300GB for $7 with 5g included and no contract.

Re: OpenWrt Two Approval

#45
post #37

Earlier quoted context omitted.

Is it really any different than every person who insists on running pfSense for security reasons then immediately suggesting some Chinese shitbox PC off AliExpress as the ideal platform to run it on? Also, since when has having a Wikipedia page proven a company legitimate? You know most companies author their own pages anyway, that's kind of how Wikipedia works.

> suggesting some Chinese shitbox PC off AliExpress as the ideal platform to run it on? How reasonable do you think it is to be this automatically suspicious of any computer coming from China? A generic low-cost barebones Intel PC certainly has plenty of space for compromised firmware to hide, but it's implausible that a Chinese intelligence agency would indiscriminately deploy an attack that made use of a compromise…

> How reasonable do you think it is to be this automatically suspicious of any computer coming from China?

Based on their track record? Pretty fucking reasonable.

I would say that most probably isn't malicious collaboration with the CCP, rather sheer incompetence. Shipping secure anything just isn't part of their culture. Read a comment on HN the other day from someone that evaluated Huawei hardware for a telco and swore it was so full of holes to be unusable.

The ingrained extreme cheapness of Chinese culture doesn't help. Security is viewed as a luxury - why waste time and money on it when that could be better spent elsewhere?

That said, the incompetence gives them plausible deniability when the intelligence agencies take advantage to exploit the holes for their own use.

Re: OpenWrt Two Approval

#46

Earlier quoted context omitted.

https://store.ui.com/us/en/category/all-cloud-gateways/produ... 4x 2.5GbE (one of them even a PoE port) 1x 10GbE SFP+ WiFi 7 with MLO $279

Ubiquiti gear is great, but does not use open source software like OpenWrt Two. And I think most modern Ubiquiti routers are not supported by OpenWrt.

I don’t see how ubiquiti not being open source is relevant here, as the original question was

> Can you recommend Western companies that would be able to produce similar hardware at the same price point?

Besides, I’m yet to see any open source routing software that’s half usable as a complete package. With the sole exception of VyOS, it’s all hot garbage, OpenWRT and pfSense included.

Re: OpenWrt Two Approval

#47

i heard reports that the openwrt one cpu was not fast enough to run cake sqm at line speed. i wonder if the two will be able to.

I don't know about the One. But some of the MediaTek CPUs apparently have hardware fq-codel support, or so I was told. I had a Gl.iNet with a MediaTek SoC (Flint 2) and it had great bufferbloat scores.

Re: OpenWrt Two Approval

#48
post #37

Earlier quoted context omitted.

> suggesting some Chinese shitbox PC off AliExpress as the ideal platform to run it on? How reasonable do you think it is to be this automatically suspicious of any computer coming from China? A generic low-cost barebones Intel PC certainly has plenty of space for compromised firmware to hide, but it's implausible that a Chinese intelligence agency would indiscriminately deploy an attack that made use of a compromise…

> How reasonable do you think it is to be this automatically suspicious of any computer coming from China? Based on their track record? Pretty fucking reasonable. I would say that most probably isn't malicious collaboration with the CCP, rather sheer incompetence. Shipping secure anything just isn't part of their culture. Read a comment on HN the other day from someone that evaluated Huawei hardware for a telco and s…

What kind of security vulnerabilities do you think an incompetent PC OEM is going to accidentally introduce to a barebones PC that's basically shipping an Intel reference platform and no SSD? Or that GL.iNet might be able to introduce to a system where OpenWRT is assembling the firmware image that gets flashed to the board, and if there are any closed-source components they'd be coming from Mediatek and not developed by GL.iNet?

Shipping telco hardware with a massive bespoke software stack implementing an impossibly-complex pile of standards is very different from what we're talking about here.

Re: OpenWrt Two Approval

#49
post #37

Earlier quoted context omitted.

Is it really any different than every person who insists on running pfSense for security reasons then immediately suggesting some Chinese shitbox PC off AliExpress as the ideal platform to run it on? Also, since when has having a Wikipedia page proven a company legitimate? You know most companies author their own pages anyway, that's kind of how Wikipedia works.

> suggesting some Chinese shitbox PC off AliExpress as the ideal platform to run it on? How reasonable do you think it is to be this automatically suspicious of any computer coming from China? A generic low-cost barebones Intel PC certainly has plenty of space for compromised firmware to hide, but it's implausible that a Chinese intelligence agency would indiscriminately deploy an attack that made use of a compromise…

> How reasonable do you think it is to be this automatically suspicious of any computer coming from China? A generic low-cost barebones Intel PC certainly has plenty of space for compromised firmware to hide

The problem seems to be that this firmware doesn’t really get updated once the machine is sold.

That’s legitimate criticism for a security-critical network component.

Re: OpenWrt Two Approval

#50
post #11

GL.iNet is a popular brand, though I can't find a Wikipedia page for it. https://www.gl-inet.com/about-us/ says: > GL Tech (HK) Ltd: #601, 5W, Hong Kong Science Park, N.T. Hong Kong > GL Intelligence, Inc.: 10400 Eaton Place, Suite 215, Fairfax, VA 22030 I'm a little curious about this. One of the reasons that some people run OpenWrt is for improved security. In the general security space, a Shenzen company isn't the…

You’re not making those specs for 250 bucks without shenzen being involved
Post reply on HN