Announcing the OpenWrt/LEDE merge
forum.lede-project.org
forum.lede-project.org
The table of hardware[1] on the LEDE site has a ton of info but filtering through 100s of devices manually doesn't seem very doable. Would love if someone would just suggest one or two devices, preferably something they've use themselves. All I really care about are Gigabit LAN and the latest Wi-Fi (5Ghz N?) so no USB storage, NFS, etc.
If faster USB is needed, the recommendation is the Linksys WRT series of routers (new ones). Avoid the WRT1900ACv1 (keep rebooting, watchdog driver bug i think). WiFi is pretty stable now. One really nice benefit of these routers is that most of the drivers have been upstreamed in the kernel and thus get love from the kernel community (enhancements and bug fixes). Not so with the other popular routers.
VPN needed?
- yes: WRT1200AC (OpenVPN: 50 Mbit/s, WireGuard: 100+ Mbit/s)
- no: continue (OpenVPN: 12 Mbit/s, WireGuard: 24 Mbit/s)
Gigabit needed?
- yes: Archer C7
- no: TL-WR841N
I currently use OpenVPN in bridge mode between all my OpenWRT routers.
Also, stickers: https://lists.zx2c4.com/pipermail/wireguard/2017-May/001338....
I particularly like the QoS features of LEDE.
Also, great news on the merge, hoping the documentation will get unified at some point as well.
Back on topic, what hardware are people with these sort of speeds running? It seems most consumer routers usually top out around 500mbit for NATing. I’m currnetly using a Mikrotik Hex with RouterOS, but prefer OpenWRT/LEDE.
However, most home level routers usually rely on (proprietary) hardware traffic offload which is why the code doesn't float back upstream.
I will not buy a router if I can't flash OpenWRT on it. It's a requirement for me now.
If it has wireless then you enter a minefield of regulatory and approvals pain. I suspect that under the current fcc rules you can't sell hardware that isn't locked to its firmware (because if you did users would be able to freeband).
There already exist some products that pretty much meet the requirement so the niche for pure play OSS is even smaller than you might imagine. e.g. Mikrotik sells a huge line of products running Linux under the hood. If you are familiar with kernel networking you can easily work with their CLI and UI. Very low cost. Does everything Linux does and is fcc approved.
One you get beyond super-low cost (e.g. into 10G NICs and wire-speed 1G routing) customers expect stuff to work, and with an OSS kernel plonked onto someone else's hardware it probably won't 100% work. This again constrains the niche within which pure OSS is viable.
You absolutely can and most companies do not lock their firmware. There are companies that commercially sell routers with DD-WRT and other OSS firmwares by default, like Buffalo. http://www.buffalotech.com/news/dd-wrt-nxt-routers
End users are expected to adhere to FCC rules even if they have the technical ability to violate them.
The FCC rules changed ~two years ago, you aren't allowed to sell devices capable of violating FCC rules. The original rule just banned third party firmware, but after some outrage it was changed so that the easiest way to comply was blocking third party firmware. They clearly wanted to ban them altogether, wouldn't be surprised if they were working on it right now
Yes, under the revised rules [1] manufacturers are required to ensure certain changes can't be made, such as disabling DFS and using non-standard channels. And as I said, the FCC explicitly does not ban third party firmware. The biggest reason is that it's cheaper to make adjustments to the radio chips to prevent certain changes than it is to swear to the FCC no one can hack in new firmware.
And as I stated and you quoted, users are still required to follow FCC rules. You can't hook up an external signal amp to boost transmit power past legal levels, use unapproved channels, etc, even if they find bypasses for the protections required by the FCC. You can't use a signal booster for a TV antenna that causes interference. You can't boost power on your CB radio. Etc.
[1] https://apps.fcc.gov/kdb/GetAttachment.html?id=zXtrctoj6zH7o...
Their original proposal for the revised rules specifically banned third party firmware, mentioning DD-WRT by name, and the revised version decided not to ban it.
The rule also doesn't hold the company liable if someone manages to hack a third party firmware onto the device. Before selling it,you need an approved application showing either a chip unable to break the rules, or a way of preventing unauthorized code from running on the device. If the FCC approves the application and you've implemented it, you aren't at fault if a workaround is discovered. This makes locking the firmware a cheaper than producing two models or selling a limited model elsewhere.
To me, it seems like they wanted a hard ban on the firmwares, settled for a soft ban, and will likely revisit the issue when there's some political capital justifying a hard ban.
I've got pretty entry level ambitions: I plan to created a utility that allow the user to configure a list of scheduled SSID names for automated SSID changes. I use to do a lot of tech support for the bar & restaurant scene, and always wanted to schedule the public WiFi SSID to change daily and broadcast marketing info. (Think restaurant daily specials, retail store popup/promo coupon codes, estimated wait times, deal of the day, etc.)
Or, is anyone aware of this feature existing in a commercially available device&firmware?
Is your wish to have help in the specifics of packing existing software for OpenWrt/LEDE, or in developing your specific utility?
If you're interested in a guide to building/packaging software for OpenWrt/LEDE, there are already detailed guides describing how to create packages for the OpenWrt/LEDE build system. [1] [2]
> and always wanted to schedule the public WiFi SSID to change daily and broadcast marketing info. (Think restaurant daily specials, retail store popup/promo coupon codes, estimated wait times, deal of the day, etc.)
As a user/customer, that sounds very annoying. Why not have a captive portal on the network instead of abusing the SSID for advertising?
Something like pfSense can easily be configured with a captive portal where you could do this advertising while having a button for users to gain access to the internet. [3]
[1] https://watchmysys.com/blog/2015/10/build-package-your-softw...
>As a user/customer, that sounds very annoying. Why not have a captive portal...
To me, as a user/customer, captive portals are very annoying
>...instead of abusing the SSID for advertising? I have a propensity toward repurposing systems for different functionality (abusing things) ;-)
It looks like 3, using pfSense, may make using captive portals less terrible so I'll look into it.
Thanks for the suggestions!
I actually like this idea, though I would suggest you broadcast two SSIDs, with one staying the same always (so returning customers could connect to it automatically).
e.g.
Never been to Starbucks on a Sunday? You'll have to read (or ignore) the SSID marketing info to connect but after that you're good.
WTF, why diddn'I auto-connect to the Wi-Fi, I come here every Monday? Oh, looks like they have a new special
Why not just keep the SSID the same (more convenient for customers -- "returning" devices would auto-connect) and instead set up a captive portal that redirects to a custom web page that includes all that info?
I have come across many hotels/restaurants/whatever to tell you that this is cancer. I don't even try to use any public wlan anymore. In my own country I have cell coverage, abroad free roaming (at least in Europe).
Fortunately for users, Yelp aquired TurnStyle so it's only uphill from here! /s
I heartily approve.
For home, I've got an APU2c4 (http://pcengines.ch/apu2b4.htm), running LEDE. It pushes something near a gigabit pretty easily (and has a the bufferbloat patches!), and I've got the time needed to administer it when necessary.
For my folks, I grabbed an Ubiquiti Unifi Security Gateway (https://www.ubnt.com/unifi-routing/usg/) and a separate Ubiquiti AP AC Lite. I fired up a controller in the cloud, and now I can manage it remotely if there's ever a problem. It's pretty awesome :).
The Unifi Security Gateway looked interesting until I googled a bit, no IPv6 support in 2018 at £100? That's insane. I mean, apparently you can do it manually, but bleh.
Besides the router issue, I've become very apprehensive at installing the latest UniFi AP firmware releases because I've experienced one revision absolutely tank WiFi performance (which took me a while to figure out the culprit thanks to the controller auto upgrading firmware) and another make APs periodically crash/bounce like every 20 mins.
So yeah in my experience after using Ubiquiti products for a few years, they are way overhyped. I guess people are willing to overlook a lot if you have a nice sleek industrial design.
I also see you're in NZ. Did you get it from Nicegear?
And yeah, I grabbed it from nicegear; they're good people :). They also sell AU/NZ power adapters that fit.
I used to run OpenWrt on my router ... years ago, and I remember that router had 16 MiB RAM, and a 125 MHz MIPS CPU. If you set up such a machine, say, as an OpenVPN server, this would seriously limit the amount of data I could push through the VPN connection. (Not really, because my Internet connection is not very fast, but that is beside the point.)
Even a Raspberry Pi is far more powerful than the typical OpenWrt router (at least the ones I have handled).
At work, we set up a wifi network using OpenWrt routers, using separate wifi networks as well as different VLANs for employees and guests. To get a vendor-supported solution that can do this, you have to have spend a lot of money.[1]
So in my experience, OpenWrt is a lot better than what most commodity routers/wifi-access points offer. With the exception, maybe, of the Fritz!Box family.
[1] Okay, it depends on your definition of "a lot". In our case, the requirement was to make it as cheap as possible, because strictly speaking we had no budget at all for the wifi.
That was the case back then, but newer routers have to be a lot beefier just to handle the throughput of faster net connections.
I've got a WRT1900ACS running OpenWRT/LEDE at home. 1.6GHz dual core and 512MB of RAM, and it's not really even top of the line by today's standards.
But my point was that you can run OpenWrt on very small devices[1], but not pfSense. It is true, of course, that today's bandwidth requires more powerful devices.
[1] A friend of mine works in embedded systems, and to him 16 MiB of RAM would be ginormous.
And strangely enough, my Wemos are also having trouble today, and Belkin (wemo) is blaming the issue[2] on security patches regarding the Intel meltdown bug. Everything is interconnected these days...
[2] http://community.wemo.com/t5/News-and-Announcements/Intermit...
If you want more features than you could possibly want or use, LEDE/OpenWrt.
With some routers (Broadcom and Qualcomm mainly), stock firmware tends to perform better since no cooperation with the kernel or LEDE/OpenWrt.
For security reasons, you'll want to use LEDE/OpenWrt. KRACK fixes got pushed pretty fast (same day) for example.
One of the benefits of the stock firmware is taking advantage of hardware accelerated NAT and Wifi encryption (WPA) but when I installed LEDE a few months ago on the old Netgear WNR3500L it did give me the option to install a Wifi server that does use hardware acceleration so I can still get that nice high performance.
Note that all of those routers listed above are generally well supported by custom firmware because that's how I made my buying decision. My current main router (Asus AC66U) I left it with stock firmware as it has all the features I want and it's still getting updates often enough.
https://hn.algolia.com/?utm_source=opensearch&utm_medium=sea...
I am assuming projects like this exist already - focused on the dad segment, but if not it's on my 2018 list. Anyone know of any?
Cut your kids a break. If you are going to monitor their usage, at the very least tell them about it first.
I get the urge - when your kids are very young you have to protect them and do everything for them. At some point you have to accept they are people, however young and inexperienced, and you have to teach them to look after themselves, not invade their privacy.
Or maybe I've misunderstood you and you meant older as in, they are 6 or something. Even then, I'd argue that you should be up-front about the fact you monitor it. Hiding it is just going to feel like entrapment.
but my main point still stands - we live in a surveillance society that works against us, so i want to use it to start working for us. and that to my mind means starting with metrics.
will it help to know daddy spends x hours a day on HN? will it be harder to complain about my kids watching cartoons if i spend 12 hours a day on netflix?
In my experience, ignorance is responsible for a lot more harm than "seeing too much". Going off hear-say, or just remaining ignorant is not a good thing. Having some room for privacy is important for development as people and for learning.
Yes, there is room for insight and lessons from data, but without an opt-out switch, it'll also be something that limits them. It's not just porn, there is a lot of stuff I'd want to learn about that I wouldn't want my family to know I'm learning about, if I was a child all over again.
I was fortunate in that I got to look up that stuff without fear of being discovered, and otherwise I know I'd have gone around believing playground rumours and the like.
It's easy to say "but I want them to be able to talk to me about that stuff" - it's easy to say that, but it's harder for it to be true, especially from the point of view of your child. You can't pre-empt every fear, question and insecurity, and some things will just always be embarrassing enough they'll stay ignorant rather than ask you.
I had a friend who didn't know basic (important) things about her own anatomy that caused health issues during university just because she was too embarrassed to ask her (non-judgemental, lovely) parents about it as a child. She didn't have a computer in her home then, but I'm sure if she had, knowing she couldn't have privacy would have stopped her as well.
It's not the worst thing in the world or anything, but I think many parents don't start giving their children privacy early enough. I get it's scary and hard to judge when it's perfect, but I think it's important.
On a side note, I just watched the ultimate "turned up to 11" version of this in Black Mirror S04E02 - ArkAngel, where a parent gets a monitoring device implanted in their child after a scare with them getting lost. Good series about the potential dangers of tech as it evolves, if you haven't already seen it.
Actually this idea is far lower down my priority tree than say working out how to monitor how much TV we watch, how much time on social media (or HN) - and then to compare to things we would prefer to do like walking the dog or playing board games.
Just inventorying our lives will be a huge step towards getting conscious control over the mass distraction world we live in.
Further ranting:
No one thinks having a comprehensive view on my monetary spend is a bad idea - websites, apps and even EU directives are trying to help. but there is nought for my time spend - apart from stupid things like please enter how much time you just spent on an activity.
So as a starting list i want
- To know what the TV was showing when.
- What netflix was showing on what device
- what youtube was showing
- for my phone - what podcasts, what youtube etc,
- same for social media (HN counts for me)
- The Nintendo Switch kinda sorta gets it - there is a parent app that lets one set time limits on daily usage. but hahahahha it assumes you only have one child (per switch)
- then use my GPS tag to show where was I and can I correspond that with an activity - gym, commute, walking across fields
- I am fairly sure there is value in Alexa / similar voice monitoring working out what is happening in the house (it takes you on average 34 minutes from the first "get dressed for school" till the door finally bangs)
Don't get me started on MOOPs
And none of which has an API i know about. All because they don't want me to stop watching.
Oh dear...I really wish your kids have the best parents in the world. I really do, my parents probably believed that too, but unfortunately they were not - surprise!
But I'm really happy that I was born at least two decades too early for that shit. I hope kids can still outsmart their parents today. If not, we've lost.
The internet is full of crazy awful stuff, and yeah sure I get that at some point you have to let them be independent and trust them, but we don't know how old his kids are, at younger ages there is certainly some protection required. And as they grow up and learn you can gradually give then more trust and freedom.
As much as I’d like to tinker myself, the little I’ve seen of the Circle app looks like a really slick way to monitor and manage usage in a low maintenance and least-intrusive manner.
Does anyone know of a concise guide to configuring your router for this type of use? I tried going off of what's available on the LEDE site but couldn't get it to work for whatever reason.
https://lede-project.org/toh/start?dataflt%5BModel*%7E%5D=r6...