TP-Link has already fallen victim to this.
You can take openwrt, ddwrt, tomato and padavan from my cold dead hands.
TP-Link has already fallen victim to this.
You can take openwrt, ddwrt, tomato and padavan from my cold dead hands.
Consumer networking hardware needs to be secure out of the box, and automatically keep itself updated without any end-user intervention.
Installing alternate firmware should be an option, but it shouldn't be necessary.
Yep. New hardware is shipped first with proprietary drivers, then shitty open-source code dumps. When the hardware vendors don't participate in the open-source process, it takes the community quite a lot of time to clean things up enough to be merged upstream. Usually by the time that happens the vendors will have secretly changed all the guts of the model with completely incompatible hardware at least once.
Just requiring a new model number for new hardware would get rid of most of the confusion. If the router and chipset vendors would actually maintain their operating systems as flavors of current OpenWRT instead of 5+ year old private branches, most of the problems wouldn't exist in the first place.
Then you should be teaching them, much like how I've taught friends and family to reformat and reinstall the OS on any prebuilt device before actually using it.
The only way things will get better for everyone is if we, the ones who know how, try our hardest to educate the ones who don't. If we remain complacent and want others to solve our problems for us, we're implicitly giving up our freedoms to the governments and corporations who are more than willing to take control of more and more aspects of our lives. Asking for "secure out of the box" will make them interpret it to mean secured against their owners. It certainly won't be easy, but that doesn't mean we should give up.
It's like asking everyone to change their car's oil. Sure, it's easy enough to learn to do and will save you money, but some folks would just rather pay somebody else to deal with the problem. Both options are valid.
We need both integrity protection for firmware and user control of the signing keys.
Try Tomato for a friendlier newbie environment. Google your router to see what alternate firmwares are available for it and never buy a new router unless you know one of the alternatives is available for it because most factory firmware is full of holes.
Powerful and flexible, yes. Newbie or casual-user friendly, no.
If Tomato is not enough, then DD-WRT, but Tomato being more stripped down becomes more newbie friendly by default.
They've all got web interfaces that present a status summary upon log-in and have pages for configuring different categories of settings (WAN, WiFi, port forwarding, etc.). Unless you think Tomato's default color scheme makes it vastly more usable, you'll have to point to something specific.
(And while it's been a while since I last used DD-WRT, my experience was that it had a multitude of options that were non-functional or incorrectly documented, so I'll need some pretty strong convincing that it's got any advantage over OpenWRT.)
I used Tomato (various flavours, including this one) for a long time until finally succumbing to OpenWRT.
The web interface is lacking compared to Tomato, but in return you get a recent LTS kernel built with the latest GNU toolchain and a superb package manager + collection.
OpenWRTs CLI config system is very slick, the web interface just doesn't yet hook into all possible settings (which may vary between devices).
I hope the pieces and supply chain are not locked up to the point that there is no way around.