TP-Link firmware sends six DNS requests and one NTP query every 5 seconds
ctrl.blog
ctrl.blog
firmware sends six DNS requests and
one NTP query every 5 seconds
(...snip...)
TP-Link has hardcoded the following non-configurable
NTP servers and server pools in their firmware:
(...snip...)
au.pool.ntp.org, nz.pool.ntp.org
Wait... so TP-Link is effectively DDoSing NTP pool?Also, as pointed out in another thread here, vendor using country prefix instead of applying for their own prefix is a violation of:
http://www.pool.ntp.org/en/vendors.html
..which was put in place as a reaction to incidents just like this one:
https://en.wikipedia.org/wiki/NTP_server_misuse_and_abuse#No...
If they can't do that maybe they can just detect IPs that are making requests every 5 seconds as the TP-Link products are doing and block those since they're in violation of the once-every-10-minutes-maximum rule for the NTP servers)?
Aside: maybe there should be a governing body for comm protocol behavior? (Semi sarcastic)
Security audits have found some issues with abusing the KoD so I'm not sure if it still works like that or if it tends to be disabled. (I was on one of the teams doing the audit, I found the "Skeleton Key" defect)
https://www.eecis.udel.edu/~mills/ntp/html/rate.html#kiss
If you wanted to help the server deal with DoS even better, I would guess the best solution is to put a rate limiting firewall in front of it.
Anyone with commodity routers, repeaters, etc. please check out LEDE project https://lede-project.org. Check if your device has support here - https://lede-project.org/toh/start
LEDE firmware is amazing. You will be able to do a lot more with your router and they have quick security fixes. The recent krack vulnerability was fixed within 2 days after the announcement.
The future of the project is uncertain, however. They may or may not be around much longer.
Can you elaborate on this?
Just a counter point to this. Lede on its own doesn't have a very smooth in place upgrade system. If you are in the loop, sure you can do upgrades, but most people would never log in to their routers after setting it up. I think something like google wifi is not a bad solution either, with the obvious privacy tradeoff. It runs chromium os, and will update reliably on its own.
Security wise, sure, great idea. But there's so much data to collect at the router level. From wireless MAC addresses (which it already does), and to every single IP address visited by every device in the household.
I might sound paranoid, but with continuous news of Google's privacy intrusive choices on Android, iOS etc. I will not trust them with that data, ever.
I really hope they will have an 802.11ax version once they iron out all the crap that is going on in there.
2. The correct report was Router team folded into Apple TV team. Sounds like Apple TV adding router function to me.
3. Apple is still selling Airport, and stocks level are still very healthy. i.e No signs or discontinue.
I have an AirPort Extreme, and while I'm not opposed to having Apple devices, I also don't exclusively buy from them, but rather what I deem to be the best product for my purposes at the time of purchase. That currently means an iPhone, an iPad, and a Dell laptop running Linux, but has in the past included both Apple laptops and Android phones and tablets. Because of my choice of router, I need to make sure that I always have at least one Apple device, preferably as a main device for convenience (because running a server means I need to mess with ports now and then).
A simple web interface would've solved this. They could still have their own app to make it just as user friendly for people who don't have an Apple device immediately at hand.
I will likely never buy a Mac again becauss I absolutely need Linux, and they're making their Macs worse and worse for Linux. I plan to eventually replace my need for a tablet with one of those Dell XPS convertible machines with a touch screen. That means there will come a time when I need to choose between letting the router be a factor in what phone I buy, or get a new, non-Apple router, and that kinda sucks.
Besides, the only system I have with Windows is my gaming desktop, and that's only runnin Windows because there's a couple of games I play which don't support Linux. My laptop runs Linux, and while it's not running Overwatch, my gaming desktop is running Linux.
I think a more likely solution is to just keep an iOS device around while router is in use.
---
Edit: To be clear, there's nothing inherently wrong with affiliate links. To me, though, it's the same as someone here mentioning their product or service in a comment without disclosing their affiliation.
It's one thing to tell another person "The FooBar 9000 is a good router.". It's quite another to say, "The FooBar 9000 is the BEST router on the market. Oh, look, here's Joe. He sells those and you can buy one from him right now.", without mentioning you have previously worked out a deal with Joe.
It's not the affiliation that's the issue. It's the lack of transparency about the affiliation. (And, in this case, for me personally, it's that the OP apparently tries to work in a link to his page anywhere he can in HN conversations.)
added after the parent modified his post:
Even after you changed your comment, I fail to see a problem. The poster explicitly says "I maintain", openly disclosing his affiliation with the site. The site does not recommend a specific device as "the best", it provides a list, ranked by a disclosed set of criteria from which you can pick. You can actually change the filters and the sort order - cheapest, graded by performance, ... We can agree or disagree on the specific sort criteria picked or the completeness of the list, but the grandparent actually does sometimes engage into discussions about this, soliciting feedback (and I presume implementing it). It adds value over the device lists that LEDE and OpenWRT provide.
The grandparent does mention the page every time the context makes sense, but alas, when else would he mention it? Would you prefer if the grandparent just posts the link as a reply to each and every post? He built something that adds value, so why not mention it? It's not like it's the only thing the GP ever posts. Seems more like a lurker from the comment history, but come on, the last mention was 141 days ago, it's not like it's spammy.
All in all your comment comes off as being jealous someone built something that provides a little income.
Did it? I was on an iPad and only realized they were affiliate links after I clicked on one and it took to Amazon. Immediately, I looked at the URL to see if there was a referral tag in there. I then went back and noticed "DISCLOSURE" at the very bottom, in the footer, but I don't recall seeing any mention of it before that.
> If you think that all for-profit pages should be banned from mention then this here would be a barren place, devoid of links to useful services.
Did I say anything even remotely close to that?
It says first thing on the top that links go to amazon. There's a link at the bottom to the full discussion. What's the issue if the links to amazon are affiliate links? It's not like they're forcing you to buy or that the value you get from the site is reduced by that. They don't hype a specific device either.
> Did I say anything even remotely close to that?
I very much understood your complaint about "spammy, since he links to a page that he's affiliated with" to go in the direction that nobody should link to a monetized service he's somehow affiliated with, yes.
The issue is that there's a conflict of interest when a page that gives you advice on what to buy uses affiliate links. If they get a cut of my purchase, then they're incentivized to get me to buy the most expensive alternative rather than the best one, and to buy something rather than stick with what I have if what I have is adequate.
This is not an insurmountable problem, but disclosure is important so I know what's going on.
Anyways, the "disclosures" page has no references to Amazon because I removed them several years ago when I quit being a part of the Amazon Affiliate program. I thought I had removed the affiliate tags as well but apparently not. They were still there but they haven't been valid for at least three or four years now (and, thus, not generating any commissions).
Here's a screenshot showing that the account was closed: https://imgur.com/c3rmZ5F
Regardless, I have removed them from the page. The page is cached and I don't remember the magic incantation to force varnish to purge the cached version but rest assured it'll get refreshed in the near future.
I'm sorry you had to spend your time searching through my web sites to try to find something that made me look hypocritical. Also, I'll point out that I don't go around posting links to that "bookshelf" page on HN comments. That is what would have made my statements hypocritical, not the fact that I had affiliate links on some random web page somewhere.
I also feel like the following is possibly _slightly_ misleading, or at least intended to induce the use of the provided links:
> By using any link on this site – affiliate or not – you will get a better deal by purchasing a corresponding product through that link than you would by going directly through the linked company’s site
I don’t consider the comment as a display of jealousy. It appears (to me) that it originates from a dislike of self-promotion.
Note: I am not taking a position on the matter of self-promotion, but on the conclusion of jealousy.
Lousy of not, it’s still self-promotion. This is true whether it occurs once or many times.
> I believe that proctor genuinely believes he built something useful and wants to share it.
I agree.
> The snark in jlgaddis post rubs me the wrong way.
Clearly. However, you aren’t defending your accusation of jealousy. Jealousy was the key word that I was addressing.
If a few mentions of something you built counts as self promotion, then even the description and the link to the blog that jlgaddis has on his profile page is self-promotion. It promotes a blog that he writes, possibly to further his professional career.
> Clearly. However, you aren’t defending your accusation of jealousy. Jealousy was the key word that I was addressing.
Ok, let me rephrase that to be more clear: It rubs me in a way that makes me personally believe that something more than "I don't like self promotion" is at play. And I believe that it's jealousy. You obviously don't, but that's personal perception I guess.
Would you feel better if I removed the info in my HN profile?
Note also that blog has been mostly neglected for the last ~5 years.
But still self-promotion if people want to be dogmatic about it. Some people, and some discussion forums, have an absolutely zero tolerance attitude to self-promotion.
I have no issue with it if:
* It isn't almost all that the account is for (caveat: personally I don't care enough in this case to have checked the account's comment history), i.e. the person contributes usefully to discussions noticably beyond what is needed for the self-promotion.
* The posts are at least relevant to the discussion at hand (which it appears to be here)
* The page/post/other is sufficiently honest about the affiliate links, because otherwise they could represent a conflict of interests (recommending what makes most out of affiliate relations rather than what is actually best by a good objective measure). This last part can be quite subjective, and again I've not looked at this particular case myself yet.
If you want to be dogmatic about it, then no links to your bio, no mention of the good work you do, no link to a company that employs or employed you, no link to your blog, ...
That page has affiliate links, IIRC, which you probably block with ublock/adaware, should I not have shared it?
In part the page is about my reaction, which is inter alia what was pertinent, that info definitely isn't elsewhere.
But they are remerging again, it just takes some time, so use LEDE if you install something now.
You can get dissent1's pull request here: https://github.com/lede-project/source/pull/1269
The cleaner patch, taken from QSDK upstream is here: https://github.com/lede-project/source/pull/1269
There's also a third router, an old TP-Link 1043ND running as a wireless bridge to connect devices in my AV setup, once again running LEDE.
DD-WRT and Tomato are both old tried-and-true alternatives to vendor firmwares, and they require less tinkering to get into the state that you want, but they both tend to have weird crufty edge cases that never get properly fixed and don't seem to have any clear direction or leadership - they are both a hodgepodge of forks that you have to spend time digging through hundred-page forum threads to find information about. Development schedules are sporadic, and you often end up with dozens of potential builds in varying states of beta and testing which fix this or that but break this or that other thing. When they work, they're great, but my experience with LEDE has been consistently superior than my experience with DD-WRT or Tomato.
Then the dd-wrt folks mentioned that Linksys never actually gave them hardware ... and if I recall, hadn't really been included in the plans to support it at all.
So then I waited and found whenever I looked for the dd-wrt firmware, it always had lots of caveats and known issues.
I gave up. Shelved it and bought a pfsense box for the internet and use a Ubiquity wifi AP.
OpenWRT/LEDE is great assuming your device is well-supported and well-tested. Unfortunately, the wrt1900ac line was never as open as Linksys claimed it was, the LEDE devs didn't get the support they needed from Linksys when they needed it, and so certain things still don't seem to work.
https://lwn.net/Articles/722135/
http://lists.infradead.org/pipermail/lede-adm/2017-November/...
http://lists.infradead.org/pipermail/lede-dev/2017-December/...
LEDE has, in general, active, managed, and unified development. You'd have to hunt down a specific Tomato/DD version that works for you. Sometimes the latest version of DD/Tomato works, sometimes it doesn't. LEDE? Just download the latest stable release, done.
When buying hardware, look at the LEDE hardware support list. Recently I have bought a TL-WDR4300 (get right version) and a Buffalo Airstation N600 router. LEDE runs good on these and the router has enough flash and RAM. Running hardware vendor firmware is not good, IMHO.
Software!
So you're expected to download some unsigned binary over an untrusted connection and trust that with all your traffic.
Definitely not buying TP-LINK next time. Good to know this there's a bandwidth problem like this!
https://github.com/xdarklight/mktplinkfw3/blob/master/README...
Their firmwares for newer devices do indeed include signature support. A malicious firmware on their server will fail the signature check and not be flashed. Signature checks occur only in the flasher, not in the bootloader, but that would require physical access to the device, at which point all bets are off anyways.
Often acceleration modules on Broadcom, Qualcomm, Mediatek etc are proprietary and without acceleration in OpenWrt/Lede the router is going to be dog slow.
The wifi modules are also proprietary and need be well supported by Openwrt/Lede or you will see throughput drops.
Of late it's just best to use what's in the router and not bother. And we move to faster connections on consumer routers with slow main SOCs the proprietary accelerators will become even more important.
[1]: http://www.etsi.org/technologies-clusters/technologies/regul...
Depends on what your priorities are - high performance or high security.
TP-Link plastic routers have nice cheap hardware and they make it really easy for you to flash it with LEDE/OpenWRT.
Maybe what I wanted to express was more like this: TP-Link has a sloppy attitude towards the security of their stock firmware. It might work, but it is full of security holes. HTTPS and checksums/signatures wouldn't change that.
Maybe they could do everything right with their firmware and provide top notch security and updates. But then their firmware would be a factor for market differentiation and at that point they would be incentivized to put effective code signing schemes in place. Other market players do that. Look at AVM Fritz Box products - nice hardware, security updates for many years and the result is: they are known GPL offenders and have strong code signing in place.
Instead TP-Link delivers you crap firmware on nice and cheap hardware and they don't care what you run on it.
"138KB * 24 * 3600 / 5" should be 2.3287GB per day. And it's 2.3287GB * 30 per month.
Update 2: "For comparison, a 5-minute check would be considered a pretty aggressive checking interval, and would only consume 1,37 MB per month. Instead, TP-Link goes through the same amount of data in just 82 minutes."
This assertion from the article has multiple errors too.
-----------------------------------------------------
The whole argument of the author is built on a flawed calculation by the author and the author exaggerated the number by a factor of 10.
715MB/month in the title and the article should be 71.5MB/month according to other information provided by the author.
According to the author, "TP-Link product is using about 138 KB every 5 seconds — or 23,85 MBs per day — on timekeeping."
23,85 MBs per day is not right, because 138KB * 24*3600/5 is about 2.328 MBs not 23,85 MBs.
Whoops. Made it to the front page of HN with so many mistakes.
EDIT:
Since there seems to be interest in this let's do the test:
5 DNS requests + 1 NTP update according to the article (seems weird that it would resolve all the the NTP servers, but lets roll with it)
DNS: dig <domain> (mean for request is 43.8 B and reply is 84.6 B)
NTP: busybox_NTPD -n -q -p time.nist.gov
---------------------
Egress:
Single DNS request : 20 (IP) + 8 (UDP) + 44 (DNS) = 72 B
NTP request (2 packets): 20 (IP) + 8 (UDP) + 48 (NTP client) = 76 B
Total egress: 72x6 + 76x2 = 584 B
----------------------
Ingress:
Single DNS reply: 20 (IP) + 8 (UDP) + 85 (DNS) = 113 B
NTP reply (2 packets): 20 (IP) + 8 (UDP) + 48 (NTP server) = 76 B
Total Ingress: 113x6 + 76x2 = 830 B
----------------------
The total bandwidth used according to my calc is 1414 B. So their number of 138 KB is actually 1.38 KB (which is 1380 B, and that's closer to my number. I rounded up if you look at my numbers)
So their number of 715 MB is actually right. Just an error with 138 KB -> 1.38 KB
I'm going to go on a limb and say his 138KB is more like 1.38KB which would bring us closer to his 0.71 GB/month
(6 * (75 + 125)) + (90 + 90) == 1380
There's 86,400 seconds/day and an average of 276 bytes/second (1380/5), so per day this is: 276 * 86400 == 23,846,400 -or- 1380 * (86400/5) == 23,846,400
Monthly: 23,846,400 * 30 == 715,392,000
Or, "a total of 715,4 MB per month", as the article states.Looking at DNS requests to those domains, I'm averaging about 30 bytes for the request and 70 bytes for the response.
Significantly larger and more complicated DNS requests returning a ton of DNSSEC records are coming around 4KB with eight separate UDP packets required for the response.
There is no way that 6 DNS queries for simple records and 1 NTP query comes in at 138 KB.
Edit: A dig on the 6 domains listed + a NTP query to one of them, for me, is sitting at less than 1KB total. Where are these numbers coming from?
Take a look at the response sizes in this CloudFlare post - https://blog.cloudflare.com/a-deep-dive-into-dns-packet-size... - they are talking about how they get DNSSEC responses under the 512 byte limit. The "unoptimized" ones are 4KB in response size. Even assuming that these domains turned on an unoptimized DNSSEC setup, that's still 24KB for those and less than 1KB for the NTP portion. The 138KB seems to be completely fabricated.
Edit2: Assuming the author meant 138 bytes as ktta pointed out, 86,400/5 = 17,280 sets of requests per day. That's 2,384,640 bytes, or ~2.3 megabytes a day. On a 31 day month, we're at ~71 megabytes. 1/10th of the amount the author is claiming.
Edit3: Though, 138 bytes seems low to me for 6 DNS queries and 1 NTP. Going by the numbers I get from a dig to the addresses it's closer to 600 bytes, which puts it at around ~309 megabytes per month. Without seeing what types of queries the repeaters are making it's hard for me to have any idea what the real numbers are, but it doesn't seem like the article's numbers add up regardless.
There's no way you could fit six DNS queries and a couple of NTP queries into 138 bytes.
As pointed out by jlgaddis, based on the numbers in the article given for the size of DNS & NTP requests and responses, seems like the author meant 1380 bytes.
That gets you about 715 MB (or about 682 MiB).
My DNS numbers are all basically half his - all of my requests are sub 40 bytes, responses are all sub 80, some are sub 60. My NTP query and response packets are pretty close, though - sitting around 80 bytes for request and response.
See my edit - https://news.ycombinator.com/item?id=15912467
dig/ntpq on osx.
Repeaters add latency and I can't imagine any network engineer would ever recommend one.
I've found the most 'reliable' arrangement is to not only have the same SSID and passphrase, but to have them all on the same frequency and if you can, make them all from the same vendor.
Also, if you are going to re-purpose an old router as an access point, make sure you turn everything off on it except the access point service. It mustn't hand out IP addresses or offer any DNS resolution. You want your devices IP to be provided by the main router regardless of which AP you connect to. It sounds obvious, but this the main stumbling block people encounter when trying to do this.
You probably suspect correctly. Not having additional cabling is a pretty big selling point of wireless technology.
And if you rent rather than own, you likely can’t add cabling at all under the terms of your lease.
A POTS phonejack can use pair(s) in CAT 5 (or 5e, 6), and newish buildings often already run it to the wall jacks rather than CAT 3. Depending on access to the other end of the lines, and appetite for DIY upgrading a landlord's building, it's quite possible to temporarily swap the RJ11 hardware for some RJ45 and have a wired LAN ;)
I knew I could do it the proper way, but there would have been a lot of work involved, with very little payoff.
Or better yet, buy a bunch of Ubiqity UniFi's, which were specifically made for this purpose and should provide the most seamless and efficient way to blanket your house in Wifi (provided you already have cabling to the access points). They are not cheap, but also not extremely expensive compared to a decent router either.
Warning: do not follow this advice; Ubuiqiti products are like potato chips in that you can never eat just one.
Oh I'll get the AC PRO access point, you think. Five minutes later you've set it via quick QR code scan and the UniFi app. That was painless! No wonder people recommend these things.
Oh wait I need to make some more device tweaks but UniFi won't do it.. better get the cloud key thingy that manages the device. I'll have one of those.
A couple of months go by and you discover your Google Home device or NEST doesn't work with beam steering. Wait, you can manage the advanced AC PRO settings using their own software? Fine I'll build a small PC to run that since if you're going to do it may as well see the stats all the time.
Hmm... KRACK/sploit-du-jour is out, maybe I'll just get a new Edgerouter since it's already fixed there. Oh wait, there's a fringy area in my house I'll bet another AC PRO or maybe an AirMax repeater would be just the thing.
Oh dear, I seem to be running out of ports, better go ahead and get a nice POE switch since that'll declutter things a bit. Etc.
- UniFi brand works well for setup, but the cloud controller is necessary for command/control management outside of iOS/Android app.
- EdgeRouter is not a UniFi product and does not act as a cloud controller.
- EdgeRouter X does not deliver 48V PoE; upgrade was needed to power the AC-PRO.
- EdgeRouter UI is horrid and it’s much easier to manage over SSH.
- Cloud Controller is easy to setup, but doesn’t work with all product lines.
tl;dr The hardware is really good, but software is lacking, especially because not all hardware is UniFi compatible.
https://fedoraproject.org/wiki/Architectures/ARM/Raspberry_P...
I use an Atom based PC stick that I had lying around to run the controller (on Windows) and it works great.
I will say that the features in the controller software rivals serious commercial offerings that I've used (Cisco, Meraki, Aerohive).
I'd say none of this matters if you just want to have a few access points around the house for a WiFi network that currently runs on a single standalone router. Nobody said configuring the UniFi's is easy or convenient, but the premise is that you only do it once, using whatever computer you have that you can install the cloud controller on. You don't absolutely need to buy anything besides the AP's, it's only for convenience if your network changes a lot.
Disclaimer: I have a unifi and edge router and it's a great combo
If you want a DHCP server in your Wi-Fi "box", you likely want it to do NAT and DNS as well, and that is a "wireless router".
Consumer grade gear is made to be easy and "just work".
Basically, is it a hardware or software problem?
The restaurant I was 'stealing' wifi from (not to mention my landlord) probably would've had a problem with me running a hundred meters or so of ethernet cable so a $60 repeater + aluminium can parabolic dish and Bob's your uncle. Worked for around two years until the interference from my neighbors' wifi made to signal too dodgy and (I think) they got wise and changed the password.
Why is that?
To cross the phases, the signal has to go to the power pole where the phases originate. X10 has a repeater you can install and sometimes people just install a passive one (a capacitor if I recall.)
In a smaller house, signalling to the panel and back out to circuits on the same leg is more likely to work than crossing the phases.
A downside of powerline ethernet devices is they use your house wiring as a hub-style network. While I think some support a form of MIMO, the more devices you have the worse performance will be. The TP-Links I have sport QoS, but I've not messed with it.
Oh well, I'll probably have to get an ubiqity or something.
Keep in mind that these TP-Links are consumer grade hardware, and that they make sense for some use cases. Not every consumer can or wants to run wire for another AP, regardless of what a network expert would say.
I use an RE450 at my dad's house (which happens to be next to mine) so when I'm there I can access the Internet. My parents don't have any computers, smartphones or tablets and don't use the Internet. The RE450 does the job -- very well I might add -- and was cheaper and easier than drilling holes in masonry to run a network wire between the houses.
The NTP and DNS requests are concerning, but they don't materially impact my bandwidth cap on the plan I'm on.
We started running them before the NTP pool (though we eventually did include our servers in the pool). The worst it got was a largish regional ISP had put our servers in their CPE, and one day they had an event where they rebooted all of their CPE at once. That caused a noticeable spike in our network traffic.
The real DDoS that caused us to stop offering public DNS service was: misguided network admins. The week I had the second network admin calling me, asking why my network was attacking their network, and then started yelling at me over the phone and hung up in a huge huff. He had installed some sort of IDS and it was triggering on NTP traffic, and rather than investigate it he just called our emergency hotline and got me out of bed to deal with it.
"Those packets you are receiving are in response to packets you are sending our NTP server asking for the time." was not the answer he was looking for I guess. :-( Honestly, I was already mad from being woken up (the emergency hotline says it is for service outages only), and that it was the second call that week on it. So I take some blame in the call not going well. But this dude never stopped yelling at me.
The problem with running a public service is: The administration doesn't scale with the number of users.
We did have some UDP multiplication attacks at other times, mostly on our authoritative DNS servers. I don't recall that we ever had any against our NTP servers that I noticed. But we did block the broadcast address so the best multiplication vector was via DNS requests, IIRC the NTP responses were fairly short.
Note this was reported on the NTP Pool Discourse about 3 weeks ago: https://community.ntppool.org/t/software-and-devices-without...
I guess the same folks who design software that spams things like this don't bother working too much on making it hard to fingerprint their devices, either. On the other hand, I haven't looked at the NTP protocol recently. Perhaps this isn't even possible due to the protocol's simplicity?
More details here (not my site): https://www.softscheck.com/en/reverse-engineering-tp-link-hs...
Please don't buy TP-link, you're DoSing an entire country
Strange how these "mistakes" keep cropping up. Is it laziness, malice, or just ignorance?
This is one reason why I don't run all-in-one router/wireless combos. Most integrated (especially provided by ISP units) devices have no way to tell you what is being sent over the air and then to your ISP.
EDIT: It was a different post that someone had seen this via Pi-Hole. Not sure how the original author discovered it.
[0] https://tech.slashdot.org/story/13/03/15/1234217/backdoor-fo...
Windows doesn't do time sync properly so that's hardly a relevant comparison
If not, consider eero.
I use an Edgerouter Lite, a Mikrotik switch and UniFi APs for myself and was so pleased I bought the AmpliFi mesh for my parents.
So, if you can run a cable, I second Unifi.
Op, if you can not run a cable, maybe look into a mesh network. Repeaters "loose" about half of the bandwidth anyway, a mesh might be good alternative.
If you want to set up an open source enviroment, there is libremesh (http://libremesh.org).
If you just want to buy something, there are products from Netgear (orbi), Linksys (Velo) or Ubiquiti (Amplifi). If you have a Fritz!Box-setup from AVM, you might be able to use their mesh features (site in German, because if you have a FritzBox, you probably speak German ;) https://avm.de/mesh/)
Mesh network simplifies setting up many repeaters, but it "looses" bandwidth the same way (unless you connect it via cable/other frequency band) as repeaters.
Also no need for the cloud controller as you can run t inside a docker and have a fully self hosted solution.
Troy Hunt also had a great article detailing his work with Unifi gear as well: https://www.troyhunt.com/ubiquiti-all-the-things-how-i-final...
LEDE is an Openwrt fork, and it might merge back to Openwrt sometime.
LEDE is under active development and its newest release is 17.01.4 https://downloads.lede-project.org/releases/
Hope this is fixed in a firmware update, my repeater is quite a nice device otherwise.
I recently bought https://mikrotik.com/product/RB952Ui-5ac2nD-TC. It was much cheaper than my previous stock Netgear router but it's orders of magnitude better.
This live demo of their web UI at http://demo.mt.lv/ and http://demo2.mt.lv/ should give you a good idea of what you get.
"TP" link firmware is peeing in the pool of ntp servers...
I think I need more coffee first.
How is this possible? Is the author ignoring Windows Update?
I have to say that the convenience, ease of use, and reliability of the product far outweighs any concerns I have over ~715MB over the course of a month. It boots quickly once plugged in, it reliably handles 4-5 devices utilizing it as a bridge for the hotel wifi, and I have never had it crash, give me any sort of wonky behavior, or anything of that nature.
So your convenience trumps the impact you’re causing to global infrastructure? Yes, you’re just one among millions, but still a slippery slope.
Honestly? Yes.
Should I want TP-Link to fix it? Maybe. Should pressure be put on TP-Link to fix it? Yes.
But not by consumers. It isn't the responsibility of a random consumer that has no idea what an NTP server even is to understand whether or not the TP-Link router is going the "right thing" for all sorts of use cases they've never even heard of it.
From a consumer perspective, does TP-Link build a good product? Yes. And that's all consumers care about.
The pragmatic reality of the situation is if this is an issue, the public service providers need to do something about it.
You cannot expect consumers to worry about or even know about this sort of thing. They don't care. They'll never care. This blog post won't make these random consumers that see it as a highly rated product on e-commerce websites care. TP-Link won't care when the niche population of people that care about this don't buy their product because we're not the market.
If the NTP pool cares about what TP-Link is doing, they should reach out to TP-Link about it, and if there's no co-operation, be public about it.
Pissing into the wind on a random 3rd party blog about how consumers should switch because of something 99.9% of consumers don't care about isn't going to accomplish anything, whether we a conscientious net citizens should care or not.
Your attitude kind of reminds of the people that toss their cigarettes out their car window. When confronted they'll say something like "But my car doesn't have an ashtray, this is easier" or "But I don't want used cigarette butts in my car" or "What am I hurting? It's only one cigarette, and there are volunteers that clean up my cigarette butts from the roadside" or "If it was really a problem, they'd enforce it better, I've never been given a ticket for it"
Notably, they are ignoring the ones that make it possible for NTP to be aware of the problem in the first place. Right now, TP-link's traffic probably just looks like millions of unrelated devices misconfigured. NTP wants vendors like this to make requests to a particular subdomain so they can identify problematic vendors in the first place.
> The firmware of some TP-Link repeaters — but not routers — including all 2017 models ... --TFA
This appears to be entirely a supposition that the NTP pool cares that TP-Link is doing this, without any evidence from the actual people in charge of it are concerned. As best I can tell, this blog is not run by Ask Bjørn Hansen and neither he nor the ISC have voiced any concerns here.
* https://community.ntppool.org/t/software-and-devices-without...
He's not the reason.
As TFA points out, it's TP-Link repeaters and explicitly "not routers" that are affected.
Looks like LEDE might support them, though when I purchased it, it did not. I might check that out.