When it comes to budget routers I still turn to TP-Links when I can easily find a decent model on the market that is supported by openwrt.
Newer TP-Link Routers send large volumes of requests to Avira servers
51–60 of 121 posts
Re: Newer TP-Link Routers send large volumes of requests to Avira servers
#52This is why for home and small office use, I usually get AVM Fritz [1] network devices. They have been around for since forever, provide regular updates for their devices and over a long period. Their web interface allows for a lot of fine-grained configuration and their devices have been rock solid for me. They are a German company and as far as I know software development is also done in Germany, so I expect that t…
Re: Newer TP-Link Routers send large volumes of requests to Avira servers
#53This is why for home and small office use, I usually get AVM Fritz [1] network devices. They have been around for since forever, provide regular updates for their devices and over a long period. Their web interface allows for a lot of fine-grained configuration and their devices have been rock solid for me. They are a German company and as far as I know software development is also done in Germany, so I expect that t…
- 8< - I was wrong - 8< -
Re: Newer TP-Link Routers send large volumes of requests to Avira servers
#54My solution is running those devices as a Wi-Fi to LAN bridge, also setup my own NAT gateway (by bare-metal Linux, Openwrt... etc). Then blocking there devices from accessing Internet at gateway.
If I have more IoT devices at home, I will apply such policy to all of them.
Re: Newer TP-Link Routers send large volumes of requests to Avira servers
#55Earlier quoted context omitted.
Like the ability for the ap to understand how the vlans the router setup work. I’m still quite the network novice but it seems like if I wanted a bsd firewall -> managed switch -> wireless ap I would need to confirm some level of interoperability for decent performance?
That kind of interoperability has nothing to do with the OSes though if you straight-up configure things. VLANs are VLANs, regardless if it's Linux, Windows, BSD, Cisco, ... on the other end of the cable. (And if you expect some kind of automatic configuration sync etc the answer is in reverse "doesn't work unless you buy everything from one vendor", for that part there is little standardization)
Re: Newer TP-Link Routers send large volumes of requests to Avira servers
#56The software answer would be easy: use OpenWRT or any other *BSD based alternative, but what about the hardware? A quick search for WAN interfaces for PCs returned nothing.
https://www.draytek.co.uk/products/business/vigor-130
“The DrayTek Vigor 130 is a VDSL2 and ADSL modem with an Ethernet connection; it is not a router but a true ADSL/VDSL Ethernet Modem (bridge).”
Re: Newer TP-Link Routers send large volumes of requests to Avira servers
#57Re: Newer TP-Link Routers send large volumes of requests to Avira servers
#58I remember reading in the UK government's security assessment of Huawei that one of the issues is not necessarily data being sent to bad places or backdoors in the software, it's that the engineering processes behind these devices/software are completely unable to protect against any sort of supply chain attacks. The sorts of things they highlighted were: no version control, no code review, production builds happenin…
[0] https://www.dailymail.co.uk/news/article-7935905/MI5-MI6-GCH...
[1] https://www.cnbc.com/2019/10/09/former-uk-spymaster-john-saw...
[2] https://www.reuters.com/article/us-britain-huawei-tech-five-...
[3] https://www.ft.com/content/90c07bbe-38ce-11e9-b856-5404d3811...
[4] https://www.euractiv.com/section/politics/short_news/uk-bann...
Re: Newer TP-Link Routers send large volumes of requests to Avira servers
#59Earlier quoted context omitted.
IME small ARM SBCs generally have a miserably slow bus arrangement for this sort of thing (and no hardware switch chip, of course). People have had some success with routers built on x86 mini-PCs[1], but these lean towards the “flexible and performant” side, not the cheap side. [1] https://arstechnica.com/gadgets/2016/04/the-ars-guide-to-bui...
I was just wondering about this the other day. Are there still no options other than to buy/build a grossly overpowered x86 machine?
Re: Newer TP-Link Routers send large volumes of requests to Avira servers
#60From the comments Nothing in your analysis shows this. Moreover unless you explicitly deployed a root certificate on your clients (or if an app on the client did it), the router can't decode TLS traffic (deep inspection) without you getting certificate warnings on the client. In that case, the only thing the router can see is the dns request, the IP and the TLS SNI. In short your title is misleading. permalinkembedsa…
... and I don't get your point in this useless pedantry? Sure that the data in of itself is not sent, but you seemed to imply that DNS queries don't reveal anything. In practice, you can build a good enough picture to decode what's their interests, what type of places they visit etc., which is worrying of itself. It's like saying to not worry because they didn't know you ordered a Big Mac while the fact that you went…
If I’m reading this correctly, it’s not sending every password and username it discovers.
It’s invasive but not to the point of being a complete set of malware.