Live data from Hacker News

Fixing Weak Wi-Fi Router Security

nytimes.com

51–60 of 69 posts

Re: Fixing Weak Wi-Fi Router Security

#51
post #44

Earlier quoted context omitted.

> So... two of the routers affected by the recent VPNFilter malware? Interesting choice. If you're looking for a router that's never had a documented security flaw, you're probably going to buy a no-name brand that's full of them (because no one's looked yet, so it has a "clean" record). The factors that you really need to look for are 1) good engineering practices for security, and 2) prompt and effective response t…

I wasn't aware that the Unifi stuff was vulnerable to the latest VPN stuff. I own a few ER-Xs and a Unifi AP. They're reasonable kit, but I wouldn't recommend them at all as a set it and forget it system. - Ubiquiti has a track record of GPL violations (e.g. u-boot which dovetails nicely with a security vuln) - The Unifi AP is tolerable for a simple home env but not much else. - Ubiquiti support is non-existent. They…

I'm looking for something to update to. If not Unifi, then what brand would you recommend that would be suitable for home use by a professional, that can be updated and has good support?

Re: Fixing Weak Wi-Fi Router Security

#52
post #34
post #5

Earlier quoted context omitted.

Possibly. The NYT bought The Wirecutter, which did (pretty good) reviews of "best in class" products and then made money from the Amazon affiliate commissions. https://www.recode.net/2016/10/24/13381002/new-york-times-wi... I'd still say the point stands that 99% of the routers out there have awful security and it's just a matter of time (often months) because your router is overtaken by a botnet, especially if you d…

Is there any reason to believe Wirecutter or NYT has compromised the integrity of their reviews? That seems an unfair allegation to throw around absent any evidence beyond it possibly being in their financial interest.

Here is one example allegation:

http://www.evodesk.com/wirecutter-standing-desk-review-pay-t...

With most conflicts you won't know the whole truth, but it's a data point.

The Wirecutter also doesn't give the 'best' in everything. They do have implict budgets.

For example, they won't recommend $5000 stereo speaker pairs, even though they would be better than the KEF Q150s they recommend currently. They don't recommend full frame / medium format cameras either, since they are probably too high end and expensive for their target markets.

I don't really fault them although for having some cost limits although. They would probably make the valid argument that if your buying the full frame cameras and $2500 loudspeakers that you probably know what your doing and don't need the wirecutter. I do wish they pointed it out a bit more in some of their guides although.

Re: Fixing Weak Wi-Fi Router Security

#53
post #22
post #17

Earlier quoted context omitted.

I have one of those as well. As a word of caution, they are dropping support for that in 2.5 [1]. Starting in 2.5, they are requiring AES-NI instructions (like I said in my other post, I am a bit irritated they did that, especially when that is a requirement for something I do not need). [1] https://www.netgate.com/blog/pfsense-2-5-and-aes-ni.html

The APU2 does have AES-NI so no need to worry. Mine is active and working (I use it with OpenVPN right now).

You're right, my mistake, I had the APU1.

Re: Fixing Weak Wi-Fi Router Security

#54
post #50
post #49

there is a linux distribution for wifi-routers: https://openwrt.org table of hardware: https://openwrt.org/toh/start - current master runs kernel 4.14 / 4.9 for most targets, flow offloading, performance fixes, wireguard in base, lua-based ui called uci. - security fixes land after a few hours/days in master, a few days/weeks for a new stable release - pretty much only non-commercial and volunteer effort, so be kind…

> security fixes land after a few hours/days in master, a few days/weeks for a new stable release The latest stable release seems to be ~8 months old, though, unless I'm looking in the wrong place: https://downloads.openwrt.org/releases/

Releases are a fixed point in which packages are updated over top, as I understand it

Similar to installing say, Debian 6.1 and then running apt-get to update packages

Re: Fixing Weak Wi-Fi Router Security

#55

Earlier quoted context omitted.

That's a good solution for geeks, not so much for everyone else. Regular people don't even update their routers, much less flash 3rd party software on them. I don't think most people even know updating your router is even a possibility. I use Google Wifi and it updates itself. In the future I might put in a PFSense, but wifi solutions like Google Wifi/Eero/etc are the way to go if you're not a computer person.

That may be behind the Eero move to go subscription only. Could be good if implemented properly but much more expensive that just buying a high end router.

Plume is the one that switched to subscription only. Eero plus is only extras, the eero’s themselves are still up front and subscription free.

https://reddit.com/r/eero/comments/8qlgbw/_/e0k704c/?context...

Re: Fixing Weak Wi-Fi Router Security

#56

Earlier quoted context omitted.

I wasn't aware that the Unifi stuff was vulnerable to the latest VPN stuff. I own a few ER-Xs and a Unifi AP. They're reasonable kit, but I wouldn't recommend them at all as a set it and forget it system. - Ubiquiti has a track record of GPL violations (e.g. u-boot which dovetails nicely with a security vuln) - The Unifi AP is tolerable for a simple home env but not much else. - Ubiquiti support is non-existent. They…

I'm looking for something to update to. If not Unifi, then what brand would you recommend that would be suitable for home use by a professional, that can be updated and has good support?

Get an apu2 [0] from pcengines and slap OpenBSD on it (or Linux, if you prefer).

Re: Fixing Weak Wi-Fi Router Security

#57
post #7

Earlier quoted context omitted.

That is the reason I run a pfsense router/firewall. You never worry they are going to stop supporting your device cause your device is x86 with FreeBSD base.

And how much money are you bleeding running that machine 24/7?

Not much. Have not noticed a real increase in my electric bill. However, it is a mini desktop and designed to be low power. Probably far less then my Plex Server easily.

There are options for much lower power hardware. I may do an experiment to see. Be kinda interesting but also hard to duplicate traffic effect and CPU loads.

However the reliable updates, advanced firewall, physical multi LAN, and durable VPN can't be understated for my use.

Re: Fixing Weak Wi-Fi Router Security

#58
post #16

Earlier quoted context omitted.

That is the reason I run a pfsense router/firewall. You never worry they are going to stop supporting your device cause your device is x86 with FreeBSD base.

Actually, that is not strictly so [1]. Starting in 2.5, they are requiring AES-NI instructions. I am a bit irritated with that as I bought one of their "official" routers to support them (The one based on the PC Engine APU2) and I use it as a home router, so I really don't need that support. [1] https://www.netgate.com/blog/pfsense-2-5-and-aes-ni.html

[deleted]

Re: Fixing Weak Wi-Fi Router Security

#59
post #34

Earlier quoted context omitted.

Is there any reason to believe Wirecutter or NYT has compromised the integrity of their reviews? That seems an unfair allegation to throw around absent any evidence beyond it possibly being in their financial interest.

Here is one example allegation: http://www.evodesk.com/wirecutter-standing-desk-review-pay-t... With most conflicts you won't know the whole truth, but it's a data point. The Wirecutter also doesn't give the 'best' in everything. They do have implict budgets. For example, they won't recommend $5000 stereo speaker pairs, even though they would be better than the KEF Q150s they recommend currently. They don't recommend…

Fair enough, but you should do the courtesy of posting their response https://thewirecutter.com/our-response-to-nextdesk/

Re: Fixing Weak Wi-Fi Router Security

#60
post #50
post #49

there is a linux distribution for wifi-routers: https://openwrt.org table of hardware: https://openwrt.org/toh/start - current master runs kernel 4.14 / 4.9 for most targets, flow offloading, performance fixes, wireguard in base, lua-based ui called uci. - security fixes land after a few hours/days in master, a few days/weeks for a new stable release - pretty much only non-commercial and volunteer effort, so be kind…

> security fixes land after a few hours/days in master, a few days/weeks for a new stable release The latest stable release seems to be ~8 months old, though, unless I'm looking in the wrong place: https://downloads.openwrt.org/releases/

yes. 17.01.4 is last stable, there is a 17.01.5 planned and this month there will be 18.06 - there a lot of hickup due to the split between active devs - that forked LEDE and the others - they reunited and things should go on more smooth now. You can use snapshot builds for the latest updates: https://downloads.openwrt.org/snapshots/targets/
Post reply on HN