The firmware is the part you really have to worry about, though. But the proper solution is to simply never run the vendor's firmware on a consumer grade router, because none of them are any good at assembling and securing a Linux distribution.
The firmware is the part you really have to worry about, though. But the proper solution is to simply never run the vendor's firmware on a consumer grade router, because none of them are any good at assembling and securing a Linux distribution.
> > The majority of differences between routers is just firmware and packaging, the guts are all the same.
>
> The firmware is the part you really have to worry about, though
Professional quality routers often use ASICs to handle most of the processing, which is quite a bit faster, engineered to perform at specific workloads, and is more reliable. [1] Big iron gear are often specialized versions of blade servers. [2] And tons of software controls go into the CPU and software design to protect against firmware hacks, reverse-engineering, data exfiltration, counterfeit parts, insecure connections, license tampering, and hardening against internal compromise. [3] Aside from the CPUs and other guts inside the router, newer Cisco gear supports network adapters from Broadcom, Intel and QLogic.[1] https://blogs.cisco.com/wireless/not-all-802-11ac-aps-are-cr... [2] https://www.cisco.com/c/en/us/products/servers-unified-compu... [3] https://www.design-reuse.com/articles/20671/security-embedde...
[1] https://code.facebook.com/posts/843620439027582/facebook-ope... [2] https://github.com/facebook/fboss
The chassis may be open-source but the guts of that thing is a (high-end Broadcom chip, just like everyone else.
Much easier than flashing cell phone and the open source version normally has more features also.
I can imagine that you might have an unprivileged server presenting just the log-in page, then proxying to a privileged server that is started once the administrator is authenticated. But that doesn't get you much more security, and it probably does strain the resources of low-end routers. A small, auditable server may be better than a more complicated system, especially since it is trivial for more paranoid users to disable/uninstall the web server and just use SSH (which nobody seems to mind running as root).