Live data from Hacker News

Security Begins at the Home Router

insights.sei.cmu.edu

61–70 of 177 posts

Re: Security Begins at the Home Router

#61
post #45

I'll take this opportunity to ask the community, what is a recommend router? It's going to be me and my roommate only (with friends and family over) and I would like to get something secure and also reliable (and preferably on the cheaper side) Any suggestions? I believe we have Cox if that is any factor....

I use one is the ASUS ones and like it. But from my understanding is that security wise, all consumer routers are bad. I have nothing to back up that claim with. I keep mine as updated as possible.

I have an Asus router too. (RT-AC68W - W => white) It used to provide my security and as near as I can tell it did a reasonably good job of it. Things that lead me to believe it rates as above average: - Does not enable management on the WAN port by default. - Reasonably frequent updates - Not named as often as some other brands when security problems are publicized. - I think it made me enter a management password when I first set it up, but it's been a while and I can't be certain about that. OTOH I just searched "RT-AC68W security problems" and there seems to be no shortage of problems. :(

Some time ago I decided to get a little more serious about security and put a mini-PC running pfsense between my home LAN and the Internet. Hopefully that is more secure though a similar search wouldn't prove that. Perusing some of the critical vulnerabilities at cvedetails.com seems to show that the only critical vulnerability for either of these is for versions of the software older than what I'm running. And I also see the flashing yellow "!" on the Asus management page that indicates an update is available.

That latter part is really a concern. I don't get a notification for an update unless I go look for it. Logging to either is not something I do every day.

Re: Security Begins at the Home Router

#62
post #50

I'll take this opportunity to ask the community, what is a recommend router? It's going to be me and my roommate only (with friends and family over) and I would like to get something secure and also reliable (and preferably on the cheaper side) Any suggestions? I believe we have Cox if that is any factor....

Albeit a bit expensive, Turris Omnia is fully open source down to schematics level. It's also pretty beefy with dual-core ARM CPU at 1.6 GHz and 1 GB DDR3. Its documentation is however a bit lacking unfortunately.

Been running a home network with over ten devices and a fast internet connection with an Omnia Turris for almost two years now. It gets regular updates automatically, is fast and the UI is nice. Fixing things like bufferbloat was easy with the community instructions.

Oh and it's openwrt under the hood, with lxc containers for things such as grafana.

Re: Security Begins at the Home Router

#63
For the average consumer / prosumer, The best I've found are Asus routers. I have a 3-4 year old Asus that still gets regular security updates.

If you want to go deeper, get any cheap NUC or system with 2 NICs, install OpenBSD and configure it as a firewall / router.

Re: Security Begins at the Home Router

#64

I'll take this opportunity to ask the community, what is a recommend router? It's going to be me and my roommate only (with friends and family over) and I would like to get something secure and also reliable (and preferably on the cheaper side) Any suggestions? I believe we have Cox if that is any factor....

I have always used consumer routers and they worked great. I finally got persuaded by the "consumer routers are garbage" attitude and bought an Ubiquiti edgerouter and instantly regretted it. Yes I can now do very complex configurations and control lots of things I couldn't before. But I really dont want to do that and I can't notice the difference in performance so it was a bit of a waste.

My guess the if you get a wireless router, wifi signal strength is most important part, aside from that any mainstream router is probably OK.

Re: Security Begins at the Home Router

#65
post #54
post #46

Earlier quoted context omitted.

In particular, recommendations for consumer routers would be welcome. Last time this came up, the line seemed to be "consumer routers are trash, if you want security you have to use an enterprise router." There might be some truth in this, but it isn't helpful. Surely not all consumer routers are equally bad?

So there are two main issues with consumer routers. The first is that the hardware is garbage. This isn't universally true, but it's a strong general rule, and models get released and discontinued all the time so the short list of models that aren't garbage changes every year. The main security issue is that the vendors stop issuing security updates after they stop selling the router even though people are still usin…

My first firewall was a Thinkpad 750Cs. ;) I can't recall the distro I was running at the time - likely Debian or Slackware. At one point I returned from vacation to find that the hard drive had failed a couple days earlier. Since the firewalling was in the kernel, all I lost was logging. IIRC the last log message was that it was remounting the root filesystem readonly. It continued operating for a couple more weeks until I could arrange to replace it.

Re: Security Begins at the Home Router

#66

Earlier quoted context omitted.

Can you elucidate just _why_ it is necessary for a router to be managed through the cloud?

It’s useful but not necessary. It’s hard to offer the simplicity described above while keeping the control in your hands, but some folks working on wireless mesh are working on it: https://blog.eero.com/mesh-trust-public-key-infrastructure-e...

Could you be more specific regarding why it's "hard"? I reject the premise that such a limited feature set can be "hard" to support without "cloud". Seems like some combination of NFC/QR codes, WPS and Android/iOS ought to be able to do the job. Mesh set-ups are known to work just fine on-prem. Moreover, a fully local system will almost certainly be more reliable, and will last longer. Certainly beyond the date when Google inevitably cancels the project on their end.

Re: Security Begins at the Home Router

#67

I'll take this opportunity to ask the community, what is a recommend router? It's going to be me and my roommate only (with friends and family over) and I would like to get something secure and also reliable (and preferably on the cheaper side) Any suggestions? I believe we have Cox if that is any factor....

Ubiquiti makes great prosumer stuff, if you're willing to pay ~$120 for the 'router', and then another ~$100 for the wireless access point. That's not 'cheap', but it's about on par what you'd pay for a fancy consumer router that looks like a spaceship. You'll get a great interface, frequent firmware updates with new features and security fixes, and you'll have a good strong signal at your neighbour's house if you're…

How do you like the netgate pfSenses in comparison?

Re: Security Begins at the Home Router

#68

I'll take this opportunity to ask the community, what is a recommend router? It's going to be me and my roommate only (with friends and family over) and I would like to get something secure and also reliable (and preferably on the cheaper side) Any suggestions? I believe we have Cox if that is any factor....

Ubiquiti makes great prosumer stuff, if you're willing to pay ~$120 for the 'router', and then another ~$100 for the wireless access point. That's not 'cheap', but it's about on par what you'd pay for a fancy consumer router that looks like a spaceship. You'll get a great interface, frequent firmware updates with new features and security fixes, and you'll have a good strong signal at your neighbour's house if you're…

Can I use Ubiquiti devices with some kind of slave or WDS mode with my ISP's wifi AP/router?

I just want to extend the range without monkeying with the existing router or running cables. Ideally configuring the slaves to use the existing SSID/WPS config if that's possible.

I don't care (much) about the impact to latency or throughput, it seems like there's excess capacity now.

EDIT: downvoters please join the discussion, seems like an innocuous question to me.

Re: Security Begins at the Home Router

#69

Earlier quoted context omitted.

Ubiquiti makes great prosumer stuff, if you're willing to pay ~$120 for the 'router', and then another ~$100 for the wireless access point. That's not 'cheap', but it's about on par what you'd pay for a fancy consumer router that looks like a spaceship. You'll get a great interface, frequent firmware updates with new features and security fixes, and you'll have a good strong signal at your neighbour's house if you're…

Can I use Ubiquiti devices with some kind of slave or WDS mode with my ISP's wifi AP/router? I just want to extend the range without monkeying with the existing router or running cables. Ideally configuring the slaves to use the existing SSID/WPS config if that's possible. I don't care (much) about the impact to latency or throughput, it seems like there's excess capacity now. EDIT: downvoters please join the discuss…

You really want to get rid of any kind of ISP provided router and Wifi as soon as possible.

Re: Security Begins at the Home Router

#70
post #46

I'll take this opportunity to ask the community, what is a recommend router? It's going to be me and my roommate only (with friends and family over) and I would like to get something secure and also reliable (and preferably on the cheaper side) Any suggestions? I believe we have Cox if that is any factor....

In particular, recommendations for consumer routers would be welcome. Last time this came up, the line seemed to be "consumer routers are trash, if you want security you have to use an enterprise router." There might be some truth in this, but it isn't helpful. Surely not all consumer routers are equally bad?

I've found the ASUS RT-AC series to be pretty good (both 56U and 66U can route my gigabit internet connection and provide about 400Mbit worth of wifi). But for a bit more you can get a Ubiquiti router + AP for an even better experience.
Post reply on HN