Earlier quoted context omitted.
You can check our comment history https://news.ycombinator.com/threads?id=supernetworks
Right; about 20 comments over nearly three years, and nothing substantive in the current thread. The whole point I'm trying to make is that you're qualified to make a substantive comment in the current thread and instead you've just posted a low-substance promotional comment.
FCC updates covered list to include foreign-made consumer routers
441–450 of 452 posts
Re: FCC updates covered list to include foreign-made consumer routers
#442Earlier quoted context omitted.
how is that different from any computer with a network card and wifi support? routers really are not special here.
It's quite different. The transceiver in your device is mainly a low-power receiver, transmit power is limited to ~100mW at best. Meanwhile a typical AP can go up to 1W per antenna for transmit. Also, the firmware that operates the wifi stack on your network card is not open source or user-modifiable beyond firmware updates issued by the manufacturer. I suggest reading up on wifi and RF before going further.
I'd suggest neither matter in the face of how the problem is solved in the consumer cards the OP was talking about. They solve it by locking down the firmware that controls the radios.
The reality is most routers do that too. You can replace the firmware in most of them with OpenWRT or something similar. You still can't exceed regulatory limits because of the signed blobs of firmware in the radios.
Nonetheless, here we are getting comments like yours, which imply all firmware in the device must be behind a proprietary wall because a relatively small blob of firmware in them must be protected. It has its own protections. It doesn't need to be protected by the OS or the application that runs on top of it.
Yet it's in those applications where most of the vulnerabilities show up. Making them consumer replaceable would help in solving the problem. Protecting the firmware is not a good reason to not do it.
Re: FCC updates covered list to include foreign-made consumer routers
#443Earlier quoted context omitted.
> They key point remains, however: They're not just hardware—even though they should be! This is the most thoughtful comment I've seen on this topic. I hadn't even considered this approach, but you're right. The hardware needs to be commoditized in a way that makes the software a layer that can be replaced. Someone else said this but in a way that described flashing a third-party package as HN nerds would. That's too…
> Every router manufacturer should build devices that can run the OSes of all their competitors' devices and vice versa. Or they could just run an existing open source OS, like openwrt.
I had to verify that OpenWRT was compatible when I bought it _to be a backup_. Re-read what I said about everything being commodity hardware that can run any other device firmware / OS.
Re: FCC updates covered list to include foreign-made consumer routers
#444Earlier quoted context omitted.
"You ship something with no known bugs and then someone finds one." You managed to say that with a straight face! Let's keep this ... non partisan. You might recall that many vendors have decided to embed static creds in firmware and only bother patch them out when caught out. How on earth is embedded creds in any way: "no known bugs"? I think we are on the same side (absolutely) but please don't allow the buggers an…
> How on earth is embedded creds in any way: "no known bugs"? You misunderstand how organizational knowledge works. You see, it doesn't. Some embeds the credentials, someone else ships the product. The first person doesn't even necessarily still work there at that point. Remember that time NASA sent a Mars orbiter to Mars and then immediately crashed it because some of them were using pounds and the others newtons? L…
"As reconstructed by Spectrum, ground controllers ignored a string of indications that something was seriously wrong with the craft's trajectory, over a period of weeks if not months. But managers demanded that worriers and doubters "prove something was wrong," even though classic and fundamental principles of mission safety should have demanded that they themselves, in the presence of significant doubts, properly "prove all is right" with the flight.
Quoting https://web.archive.org/web/20210730150049/https://spectrum.... linked to from https://en.wikipedia.org/wiki/Mars_Climate_Orbiter .
Plus, navigators, had concerns about the trajectory,which were dismissed because they "did not follow the rules about filling out [the incident surprise and analysis procedure] form to document their concerns" - from a trajectory team which was understaffed and overworked.
Re: FCC updates covered list to include foreign-made consumer routers
#445The FCC maintains a list of equipment and services (Covered List) that have been determined to “pose an unacceptable risk to the national security Recently, malicious state and non-state sponsored cyber attackers have increasingly leveraged the vulnerabilities in small and home office routers produced abroad to carry out direct attacks against American civilians in their homes. Vulnerabilities have nothing to do with…
> Vulnerabilities have nothing to do with country of manufacture. They have always been due to manufacturers' crap security practices. Sorry but this is merely a convenient excuse. Source: I have hard evidence of a Chinese IoT device where crap security practices were later leveraged by the same company to inject exploit code. It's called plausible deniability and it's foolish to tell me it's a coincidence. You're no…
Banning foreign-made devices will not stop any of that.
Re: FCC updates covered list to include foreign-made consumer routers
#446Earlier quoted context omitted.
My sister in laws xfinity router / app has a new feature banner for “detecting motion in your house with WiFi for no additional cost” I took a screenshot to share if anyone is interested
Questions of mass surveillance aside, I always wonder how useful these things (motion detection when you're not home) actually are given how many American households have dogs and cats.
I'm assuming you really meant "detect human motion", which I don't think is a solvable problem at this point in time, at least with high accuracy.
Re: FCC updates covered list to include foreign-made consumer routers
#447Can't wait to see the price of the first US made home router. We [USA] really need a formal designation of trusted supply chain partners. Would improve security and make a useful bargaining chip.
No one would trust a US made router for fears of backdoors. Even if they did manage to make one, the market would be minuscule for it.
Re: FCC updates covered list to include foreign-made consumer routers
#448Earlier quoted context omitted.
It's quite different. The transceiver in your device is mainly a low-power receiver, transmit power is limited to ~100mW at best. Meanwhile a typical AP can go up to 1W per antenna for transmit. Also, the firmware that operates the wifi stack on your network card is not open source or user-modifiable beyond firmware updates issued by the manufacturer. I suggest reading up on wifi and RF before going further.
> I suggest reading up on wifi and RF before going further. I'd suggest neither matter in the face of how the problem is solved in the consumer cards the OP was talking about. They solve it by locking down the firmware that controls the radios. The reality is most routers do that too. You can replace the firmware in most of them with OpenWRT or something similar. You still can't exceed regulatory limits because of th…
We don't have to look far. The embedded space with Arduinos, ESP32s and even RPis is a hacker's paradise. Yet the radio stack is restricted in all of them. For instance, it's not possible to take an ESP32 board and turn it's single antenna into a MIMO configuration, even if you make a custom PCB with trace antennas.
Re: FCC updates covered list to include foreign-made consumer routers
#449Earlier quoted context omitted.
> I suggest reading up on wifi and RF before going further. I'd suggest neither matter in the face of how the problem is solved in the consumer cards the OP was talking about. They solve it by locking down the firmware that controls the radios. The reality is most routers do that too. You can replace the firmware in most of them with OpenWRT or something similar. You still can't exceed regulatory limits because of th…
I was responding to the original post about open standards. My point is that anything with an RF transceiver will never be as open as a standard PC with replaceable components. The radio portion will always be blocked off. That relatively small blob will always limit how much control you can exert over the device. We don't have to look far. The embedded space with Arduinos, ESP32s and even RPis is a hacker's paradise…
sure, but again, why would the RF transceiver on my desktop PC or in my laptop be any different than the one in my router?
Re: FCC updates covered list to include foreign-made consumer routers
#450Earlier quoted context omitted.
I was responding to the original post about open standards. My point is that anything with an RF transceiver will never be as open as a standard PC with replaceable components. The radio portion will always be blocked off. That relatively small blob will always limit how much control you can exert over the device. We don't have to look far. The embedded space with Arduinos, ESP32s and even RPis is a hacker's paradise…
My point is that anything with an RF transceiver will never be as open as a standard PC with replaceable components. The radio portion will always be blocked off. sure, but again, why would the RF transceiver on my desktop PC or in my laptop be any different than the one in my router?