Live data from Hacker News

Fixing Weak Wi-Fi Router Security

nytimes.com

61–69 of 69 posts

Re: Fixing Weak Wi-Fi Router Security

#61
post #50

Earlier quoted context omitted.

> security fixes land after a few hours/days in master, a few days/weeks for a new stable release The latest stable release seems to be ~8 months old, though, unless I'm looking in the wrong place: https://downloads.openwrt.org/releases/

Releases are a fixed point in which packages are updated over top, as I understand it Similar to installing say, Debian 6.1 and then running apt-get to update packages

unfortunatly not really - due to the small flash on most devices the rootfs is compressed into a squashfs - but you can checkout the latest stable branch from git and build images with up2date kernel.

Re: Fixing Weak Wi-Fi Router Security

#62
post #23
post #16

Earlier quoted context omitted.

Actually, that is not strictly so [1]. Starting in 2.5, they are requiring AES-NI instructions. I am a bit irritated with that as I bought one of their "official" routers to support them (The one based on the PC Engine APU2) and I use it as a home router, so I really don't need that support. [1] https://www.netgate.com/blog/pfsense-2-5-and-aes-ni.html

Said it below, but the APU2 does support AES-NI. I wanted to make sure you saw this.

Thank you for that, I made a mistake. I was thinking of the APU1.

Re: Fixing Weak Wi-Fi Router Security

#63
post #16

Earlier quoted context omitted.

That is the reason I run a pfsense router/firewall. You never worry they are going to stop supporting your device cause your device is x86 with FreeBSD base.

Actually, that is not strictly so [1]. Starting in 2.5, they are requiring AES-NI instructions. I am a bit irritated with that as I bought one of their "official" routers to support them (The one based on the PC Engine APU2) and I use it as a home router, so I really don't need that support. [1] https://www.netgate.com/blog/pfsense-2-5-and-aes-ni.html

You can always swap to OPNSense.

I'm annoyed they discontinued support for x86-32. My Soekris could run with a VPN board and saturate its 100 mbit ports.

Good news there as well is that OPNSense supports x86-32 just fine though.

Re: Fixing Weak Wi-Fi Router Security

#64

Grab a decent microtik router and a few Ubiquiti Unifi AP's, setup automatic updates, and never touch them again.

So... two of the routers affected by the recent VPNFilter malware? Interesting choice.

This is pure FUD. If you don't patch your Cisco machine running iOS, your Juniper machine running JunOS, your Netgate machine running pfSense, your Deciso machine running OPNSense, your PC running OpenBSD or Windows or Linux or FreeBSD or NetBSD or whatever software you may be vulnerable and someone might write malware for that vulnerability.

Re: Fixing Weak Wi-Fi Router Security

#65

Earlier quoted context omitted.

> It's hard to beat a $50 craigslist dual+ core box, a second nic and pfSense unless you pay for your own power. An edge router lite uses How much does it cost to run the pfsense box over the course of 2 years?

Don't forget that the ERL will cook itself to death unless you improve the cooling. The case itself will reach temps of about 40C under normal operating conditions. https://community.ubnt.com/t5/EdgeRouter/CPU-fan-mod-cpu-tem...

> Don't forget that the ERL will cook itself to death unless you improve the cooling.

It will? No, that implies it is inevitably going to happen with every device which is not the case. A better wording is it might, depending on (unclear) circumstances.

Re: Fixing Weak Wi-Fi Router Security

#66

Great resource: https://routersecurity.org/

thanks for this. i'm contemplating an upgrade of my venerable linksys wrt54g running tomato to something more modern. i'll have to check out their recommended peplink surf router:

https://routersecurity.org/pepwavesurfsofo.php

Re: Fixing Weak Wi-Fi Router Security

#67

> Replace your router every few years How about instead of this, use open source software on your router? It will keep being updated, and with the manufacturer's proprietary software on the device you can't really trust it anyway.

That's a good solution for geeks, not so much for everyone else. Regular people don't even update their routers, much less flash 3rd party software on them. I don't think most people even know updating your router is even a possibility. I use Google Wifi and it updates itself. In the future I might put in a PFSense, but wifi solutions like Google Wifi/Eero/etc are the way to go if you're not a computer person.

google wifi might give you some security and ease of use but you also give up privacy. not a good tradeoff considering the alternatives.

Re: Fixing Weak Wi-Fi Router Security

#68
post #65

Earlier quoted context omitted.

Don't forget that the ERL will cook itself to death unless you improve the cooling. The case itself will reach temps of about 40C under normal operating conditions. https://community.ubnt.com/t5/EdgeRouter/CPU-fan-mod-cpu-tem...

> Don't forget that the ERL will cook itself to death unless you improve the cooling. It will ? No, that implies it is inevitably going to happen with every device which is not the case. A better wording is it might , depending on (unclear) circumstances.

> It will? No, that implies it is inevitably going to happen with every device which is not the case. A better wording is it might, depending on (unclear) circumstances.

At those temperatures (40C exterior temp at idle) cooking to death is pretty certain. Look at the complaints of glitchy ERLs as a proxy for impending death. Meanwhile it's pretty clear that the Octeon runs hot and UBNT didn't provide sufficient cooling.

Re: Fixing Weak Wi-Fi Router Security

#69
post #65

Earlier quoted context omitted.

> Don't forget that the ERL will cook itself to death unless you improve the cooling. It will ? No, that implies it is inevitably going to happen with every device which is not the case. A better wording is it might , depending on (unclear) circumstances.

> It will? No, that implies it is inevitably going to happen with every device which is not the case. A better wording is it might, depending on (unclear) circumstances. At those temperatures (40C exterior temp at idle) cooking to death is pretty certain. Look at the complaints of glitchy ERLs as a proxy for impending death. Meanwhile it's pretty clear that the Octeon runs hot and UBNT didn't provide sufficient cooli…

Again, I am not denying there are people who have issues what I am saying is we don't have enough data to figure what the signal/noise ratio is regarding dying devices.
Post reply on HN