Live data from Hacker News

OpenWrt Two Approval

openwrt.org

51–60 of 133 posts

Re: OpenWrt Two Approval

#51
post #7

Is there a reasonable scenario where enough people vote "no" here? It seems unlikely, so a nuanced discussion where pros and cons are considered seems more productive. Seems like a yes/no vote makes more sense if there is actual contention or disagreement among internal factions. If you vote no, you'll basically be seen as the stickler person without a good reason. 18 people are missing (abstained?), so could that be…

Probably acts more like a project lead election

Re: OpenWrt Two Approval

#52

i heard reports that the openwrt one cpu was not fast enough to run cake sqm at line speed. i wonder if the two will be able to.

To be fair that’s true for majority of routers that aren’t top end. Cake is pretty resource hungry

Re: OpenWrt Two Approval

#53

Earlier quoted context omitted.

Ubiquiti gear is great, but does not use open source software like OpenWrt Two. And I think most modern Ubiquiti routers are not supported by OpenWrt.

I don’t see how ubiquiti not being open source is relevant here, as the original question was > Can you recommend Western companies that would be able to produce similar hardware at the same price point? Besides, I’m yet to see any open source routing software that’s half usable as a complete package. With the sole exception of VyOS, it’s all hot garbage, OpenWRT and pfSense included.

Ok, you may be in the wrong thread. This is a product for people who consider OpenWRT support to be a positive selling point. The OpenWRT One and OpenWRT Two are not products aimed at people who consider OpenWRT to be "hot garbage". They're not trying to produce generically good router hardware; they're trying to produce good router hardware for use with OpenWRT.

When somebody in this context is asking for similar hardware, it's reasonable to assume that OpenWRT support would still be considered important, or at least worth mentioning.

Re: OpenWrt Two Approval

#54
post #37

Earlier quoted context omitted.

> suggesting some Chinese shitbox PC off AliExpress as the ideal platform to run it on? How reasonable do you think it is to be this automatically suspicious of any computer coming from China? A generic low-cost barebones Intel PC certainly has plenty of space for compromised firmware to hide, but it's implausible that a Chinese intelligence agency would indiscriminately deploy an attack that made use of a compromise…

> How reasonable do you think it is to be this automatically suspicious of any computer coming from China? Based on their track record? Pretty fucking reasonable. I would say that most probably isn't malicious collaboration with the CCP, rather sheer incompetence. Shipping secure anything just isn't part of their culture. Read a comment on HN the other day from someone that evaluated Huawei hardware for a telco and s…

> Read a comment on HN the other day from someone that evaluated Huawei hardware for a telco and swore it was so full of holes to be unusable.

Do you have a link? Would be nice to know more technical details.

Re: OpenWrt Two Approval

#55
post #37

Earlier quoted context omitted.

> suggesting some Chinese shitbox PC off AliExpress as the ideal platform to run it on? How reasonable do you think it is to be this automatically suspicious of any computer coming from China? A generic low-cost barebones Intel PC certainly has plenty of space for compromised firmware to hide, but it's implausible that a Chinese intelligence agency would indiscriminately deploy an attack that made use of a compromise…

> How reasonable do you think it is to be this automatically suspicious of any computer coming from China? A generic low-cost barebones Intel PC certainly has plenty of space for compromised firmware to hide The problem seems to be that this firmware doesn’t really get updated once the machine is sold. That’s legitimate criticism for a security-critical network component.

It's not ideal, but it's not a deal-breaker for every use case. The kind of firmware you get on a barebones industrial-oriented miniPC style router from China doesn't have much potential for a remotely-exploitable vulnerability. Most of the NICs aren't even going to be touched by the boot firmware. The user-supplied OS can take care of applying CPU microcode updates. If the PC doesn't ship with a rootkit already present in the firmware, it's pretty hard for the firmware to be a security problem unless it's secondary to a security vulnerability in the OpenWRT or pfSense software.

Running an up-to-date OpenWRT or pfSense on a normal PC hardware platform with outdated UEFI firmware is still a big step up in security compared to running factory firmware+OS on a cheap consumer wireless router.

Re: OpenWrt Two Approval

#56
post #37

Earlier quoted context omitted.

> suggesting some Chinese shitbox PC off AliExpress as the ideal platform to run it on? How reasonable do you think it is to be this automatically suspicious of any computer coming from China? A generic low-cost barebones Intel PC certainly has plenty of space for compromised firmware to hide, but it's implausible that a Chinese intelligence agency would indiscriminately deploy an attack that made use of a compromise…

> How reasonable do you think it is to be this automatically suspicious of any computer coming from China? Based on their track record? Pretty fucking reasonable. I would say that most probably isn't malicious collaboration with the CCP, rather sheer incompetence. Shipping secure anything just isn't part of their culture. Read a comment on HN the other day from someone that evaluated Huawei hardware for a telco and s…

> I would say that most probably isn't malicious collaboration with the CCP, rather sheer incompetence.

As opposed to the US, where it's the other way around [1]. You prefer that?

[1] https://en.wikipedia.org/wiki/Room_641A

Re: OpenWrt Two Approval

#57
post #43

Earlier quoted context omitted.

Used Lenovo Tiny PCs with VMs, iGPU and 4-port NICs get close.

Got any specific recommendation for 4-port NIC?

Depends on your preference for hypervisor/host, network performance, SR-IOV partitioning, need/avoidance of AMT vPro remote mgnt (e.g. Intel vs. Broadcom), OEM NIC firmware. I've used low-profile Dell quad-port NICs in the past.

Re: OpenWrt Two Approval

#59
post #11

GL.iNet is a popular brand, though I can't find a Wikipedia page for it. https://www.gl-inet.com/about-us/ says: > GL Tech (HK) Ltd: #601, 5W, Hong Kong Science Park, N.T. Hong Kong > GL Intelligence, Inc.: 10400 Eaton Place, Suite 215, Fairfax, VA 22030 I'm a little curious about this. One of the reasons that some people run OpenWrt is for improved security. In the general security space, a Shenzen company isn't the…

Can you recommend Western companies that would be able to produce similar hardware at the same price point?

Similarly, I'd like one from outside both american/european AND chinese influence. I think you'd be absolutely insane to trust either of them.

Honestly, if we're ever going to have a decent open hardware movement, I think it's going to come from a place like Nigeria or Peru, not a wealthy country.

Post reply on HN