Live data from Hacker News

OpenWrt Two Approval

openwrt.org

71–80 of 133 posts

Re: OpenWrt Two Approval

#71

Earlier quoted context omitted.

In the absence of PC Engines (RIP) Swiss design made in Taiwan, there is the South Korean ODROID from https://hardkernel.com . Compulab in Israel has some customizable IoT boards, https://www.compulab.com/products/sbcs/sbc-iot-imx8-nxp-i-mx... QNAP in Taiwan has QHora routers, but much higher price points.

The irony here is that it's the US who has been proven to break into allied networks and infrastructure and done both political and industrial espionage against their allies.

I hope it isn't a surprise that every country with sufficient resources and motives will do it to everyone else.

Re: OpenWrt Two Approval

#72

Earlier quoted context omitted.

OpenWRT "One" and "Two" are physical routers designed specifically to run OpenWRT. This is describing "Open WRT Two", a physical piece of hardware, that will have a price-tag, rather than some new software release of OpenWRT.

This should be at the top, since it's not clear at all from the RFC.

Yes. I was thinking it will only work or it works on $250 dollar routers but I know for sure that is not the case. And I didn't even know OpenWRT made hardware routers.

I search and looked at that router.... I wish someone from Eero or Ubnt hardware team would lend them a hand.

Re: OpenWrt Two Approval

#73
post #11

GL.iNet is a popular brand, though I can't find a Wikipedia page for it. https://www.gl-inet.com/about-us/ says: > GL Tech (HK) Ltd: #601, 5W, Hong Kong Science Park, N.T. Hong Kong > GL Intelligence, Inc.: 10400 Eaton Place, Suite 215, Fairfax, VA 22030 I'm a little curious about this. One of the reasons that some people run OpenWrt is for improved security. In the general security space, a Shenzen company isn't the…

Can you recommend Western companies that would be able to produce similar hardware at the same price point?

The west is now split, I have the same trust in China, as in US based companies.

Re: OpenWrt Two Approval

#74

Earlier quoted context omitted.

> I would say that most probably isn't malicious collaboration with the CCP, rather sheer incompetence. As opposed to the US, where it's the other way around [1]. You prefer that ? [1] https://en.wikipedia.org/wiki/Room_641A

Not only this, but most US companies do not really have any incentive to focus on security. On HN there is an echo chamber with the shunning of companies who have experienced incompetence based breaches. Your average consumer does not know (beyond the news cycle) or generally even really care. I think you can even look at FBI and NSA public service announcements and guides about consumer electronics security as a sor…

The various 3-letter-agencies really are incentivized to help government and industry be legitimately secure against anything short of the sophisticated attacks they themselves can orchestrate

When you’ve got the sort of reach and resources they have, it does you no good if script kiddies or unsophisticated attacks are causing problems and you don’t need the easily preventable attack vectors they’d use.

Re: OpenWrt Two Approval

#75
post #69

Earlier quoted context omitted.

MicroTik is European (Latvian) and makes some affordable routers. Their own RouterOS is closed source, but many models are supported by OpenWrt (no experience). If you are willing to spend more, OPNsense (Netherlands) also sells hardware. In the old days one could also recommend PFsense hardware, but they are becoming more and more closed (though you can usually run OPNsense on the same hardware). QNAP is Taiwanese.…

Mikrotik devices compete in the mid-tier commercial and prosumer markets (the same market Unifi compete in). GL.Inet are firmly in the personal and budget enthusiast market. The price differences between those two markets is almost 2:1.

What devices are you comparing? I don’t see anything near those price differences.

Re: OpenWrt Two Approval

#76
post #11

GL.iNet is a popular brand, though I can't find a Wikipedia page for it. https://www.gl-inet.com/about-us/ says: > GL Tech (HK) Ltd: #601, 5W, Hong Kong Science Park, N.T. Hong Kong > GL Intelligence, Inc.: 10400 Eaton Place, Suite 215, Fairfax, VA 22030 I'm a little curious about this. One of the reasons that some people run OpenWrt is for improved security. In the general security space, a Shenzen company isn't the…

Is it really any different than every person who insists on running pfSense for security reasons then immediately suggesting some Chinese shitbox PC off AliExpress as the ideal platform to run it on? Also, since when has having a Wikipedia page proven a company legitimate? You know most companies author their own pages anyway, that's kind of how Wikipedia works.

Usually the kind of people installing their own router software are the homelabbers who would buy a netgate appliance or equivalent in a professional setting.

Re: OpenWrt Two Approval

#77
post #37

Earlier quoted context omitted.

> suggesting some Chinese shitbox PC off AliExpress as the ideal platform to run it on? How reasonable do you think it is to be this automatically suspicious of any computer coming from China? A generic low-cost barebones Intel PC certainly has plenty of space for compromised firmware to hide, but it's implausible that a Chinese intelligence agency would indiscriminately deploy an attack that made use of a compromise…

> How reasonable do you think it is to be this automatically suspicious of any computer coming from China? Based on their track record? Pretty fucking reasonable. I would say that most probably isn't malicious collaboration with the CCP, rather sheer incompetence. Shipping secure anything just isn't part of their culture. Read a comment on HN the other day from someone that evaluated Huawei hardware for a telco and s…

Do you have source links to this and how it compares to the US own practice of doing it?

Re: OpenWrt Two Approval

#78
post #48

Earlier quoted context omitted.

> How reasonable do you think it is to be this automatically suspicious of any computer coming from China? Based on their track record? Pretty fucking reasonable. I would say that most probably isn't malicious collaboration with the CCP, rather sheer incompetence. Shipping secure anything just isn't part of their culture. Read a comment on HN the other day from someone that evaluated Huawei hardware for a telco and s…

What kind of security vulnerabilities do you think an incompetent PC OEM is going to accidentally introduce to a barebones PC that's basically shipping an Intel reference platform and no SSD ? Or that GL.iNet might be able to introduce to a system where OpenWRT is assembling the firmware image that gets flashed to the board, and if there are any closed-source components they'd be coming from Mediatek and not develope…

STH has reviewed Chinese PCs that come preloaded with malware. My MSI motherboard force installs Nahimic by default. Not technically malware but the same mechanism exists for malware.

Re: OpenWrt Two Approval

#79
250 sounds like Banana R4 already won. Seeing different no-name boards such specs should be way less or we should have 2 10G fiber, 4-5 10G copper and some great specs in terms of computing... Did I miss anything?

Re: OpenWrt Two Approval

#80
post #48

Earlier quoted context omitted.

What kind of security vulnerabilities do you think an incompetent PC OEM is going to accidentally introduce to a barebones PC that's basically shipping an Intel reference platform and no SSD ? Or that GL.iNet might be able to introduce to a system where OpenWRT is assembling the firmware image that gets flashed to the board, and if there are any closed-source components they'd be coming from Mediatek and not develope…

I’ve reluctantly come to the view that Apple is the best bet for a consumer to get a somewhat reasonable (price notwithstanding) compromise between hardware vertical integration and software that offers substantial bug bounties and large market incentives to not allow bad vulnerabilities to sit for too long. With deep enough pockets to hang tough if needed in various situations.

Apple also ships bloated buggy software with a massive TCB that makes it almost trivially easy for state actors to break in.
Post reply on HN