Security Begins at the Home Router
insights.sei.cmu.edu
insights.sei.cmu.edu
The goal is to make firewalling and controlling network traffic really easy.
The UI should be so easy a parent could perform difficult tasks such as limiting an iot devices traffic to local net or maybe just one ip using just an app.
Or detecting unusual patterns of traffic from a device or IP addresses.
The apis exist I can't think of many barriers to entry.
Another is to limit a device to communicate to a specific country. Easy enough however a possible performance issue.
In a choice between mandating people rent their routers, or pushing vendors to offer patches, I wouldn't bet on ISPs picking the latter.
It's what I've done for years and it works fine. I have a Pi-hole off my ISP modem, and the Pi-hole does DHCP, DNS, VPN, and more for our network at the same time as doing it's normal filtering job.
I'd love a better device where my Pi-hole is though, which I can configure easier, set up for my friends and family then they can manage it themselves, etc. There's definitely a market for this at least from me!
Easy and secure are not always a good match though. Take UPnP for example. Disabled by default on my ER-L, it can be enabled, but its ultimately insecure. And ultimately, HTTP over SSL could download payloads.
It's impenetrable to anyone that doesn't want to invest months into the scene and develop expertise in it. Much like phones we really need a PC equivalent in this space.
That's describing pretty much all the alternative firmware distributions, except OpenWRT, which is actually well-organized and delivers real stable releases. If you're digging through forums to find forks and builds made by some anonymous individual, it's almost certainly because you got fooled into buying hardware that requires closed-source drivers. (Or else you bought something that is just too new and not yet supported by OpenWRT.)
Bingo, that seems to be about all that's available. I'm looking at off the shelf hardware I can purchase locally, hardware I know works with local ISP's, I have no idea if we use the same standards as America for this stuff, what connections and adapters I'll need, etc. Buying locally eliminates these variables.
If there's a happy path by all means share. I only looked into this stuff in the first place so I could get set up a home server and my current modem/router is woefully out of date and has a very suspect definition of DMZ.
Your ISP is irrelevant, unless you're shopping for an integrated modem+router. Rule number 1 is don't do that, and keep your modem separate and just a modem. Then your router only needs the universal standard Ethernet port as its WAN interface, and at worst you might have to configure PPPoE instead of just using DHCP to get your public IP.
I think I'm going to have to go down this path, I was just hoping to avoid it. It means having another device to configure, another set of blinking lights, another weird shaped plug to try and squeeze into the power board and learning whatever PPPoE is just to transform Ethernet packets into the ADSL equivalent.
It also possibly means a more complicated setup controlling outbound connections so that a compromised server cannot reach the modem.
But this would also involve the router manufacturer keeping it up-to-date as well.
Which gets me thinking... Does a SOHO (or any) device exist that effectively runs two firmware instances at once to allow minimal downtime as it switches over to new firmware? I imagine larger routers do, or at least, two identical physical routers accomplishes as much.
It should be possible to have some amount of regular updates, if not automatic.
My point was about availability of updates. Third partu firmwares seem to have a lot more updates than factory ones.
LEDE also merged back with OpenWRT so I hope that improves things.
Rather than poke holes, do you have any suggestions?
There are plenty of routers that have two OS partitions so that a new version can be installed without interrupting the currently-running version, but you still need a full reboot to switch to running the new OS.
Instead: stop making shit routers.
Router reboot is simply a network outage for 2-3 minutes and routers that can do auto-update also always support configuration it. E.g. Reboot at 3am in the night, only on Monday and only if there had been new firmware in the last week. I can assure you that it is neither disrupting nor noticeable at all. Router boots neither break work flows nor corrupt your data (in SOHO segment).
This would solve that while leaving it configurable for technical users.
Quite likely that google-wifi (chromeos) does, or at least is capabale of doing that given good enough hardware. All of google's products have moved to this sort of A/B layout.
There is no point in spending lots of time & effort trying to secure half-baked half-open devices that are not under my full control. I will do what I can [or what I'm allowed to do by the usually severely restricted configuration modem panel] but I know the game, there, is already lost. Moreover, the ISP can remotely administer the cable modem and flash anything to it.
A second perimeter that is based on infrastructure I fully configure/control/administer is where I still have a chance.
Together with the fact, that you are getting a single /64, it means that you cannot place another router behind their router.
(And for IPv4 part of the DS-Lite, no, they don't support PCP).
"START HERE" followed by steps. Communication and comprehension is always a key battle of onboarding.
For that reason alone it’s best to have your own equipment not tied to the ISP, IMO. The ISP can already see all of my plaintext traffic, DNS requests, and MITM all my sessions if they wish. I’d rather not give them full access to my private network on top of that.
They will also put it into bridge mode for you where none of that stuff applies.
I recommend to use a mnemonic password [1] and just print out the WiFi password (without using Google Cloud...) and use some adhesive tape to attach it on the bottom of the router. The downside is that someone who has physical access to the router can see the password within seconds. Someone's who's plumbing your drain or when you are on the toilet.
That they put it into bridge mode when you request is due to EU regulations where EU civilians have free choice of router.
Instead of a string of random letters and numbers, they should be a string of words.
It's frustrating to visit someone's home, and have to enter (on a phone keyboard, no less) some lengthy gibberish that they never bothered to change.
It is not like I am going to use it for my main email account.
I think this is one of the awesome things about Google Wifi (aka: OnHub). It's fully managed from a phone app (via "the cloud"), so you get the authentication tied to your gmail account. It's also based on ChromeOs (chromebook OS), and follows a similar auto-update that Chromebooks get. So you are always running the latest firmware.
(There are obviously downsides to Google Wifi, my primary issue being that it doesn't have many of the advanced features that something like UniFi has. But for most people, it works well.).
As an aside, you can read the Google WiFi privacy details here: https://support.google.com/wifi/answer/6246642?hl=en
Which isn't to say that home customers would have necessarily done better, but most people don't have random maintenance bring them down at random times.
https://www.theverge.com/2017/2/23/14722470/google-reset-onh...
I'm doing nothing illegal or unethical, nothing wrong. Nevertheless, I ran from Google asap due to that reason alone. Google represented a massive single point of failure to my digital life.
I now use separate products for just about everything I own. While it's not as convenient as Google, I feel far more secure.
Using Google with their famous lack of customer service to make purchases that I could conceivably need to put a chargeback on felt uncomfortably risky.
Tie my home internet connection to that? How do I know I won't get locked out of the cloud-integrated admin app? Why would I want it connected to anything Google?
The "one account everywhere" thing is convenient and great for their branding, but it's not great for my peace of mind.
What I’m more worried about is their “You violated the TOS. We can’t tell you how you violated the TOS. We can’t unban your account.” If you don’t know someone at Google, you’re out of luck.
https://blog.eero.com/mesh-trust-public-key-infrastructure-e...
Manual steps with the physical hardware, or even requiring a local wifi/ethernet connection, are always going to be more secure than an internet-accessible god mode.
Not that that has ever happened, of course.
Give me local ssh and WebUI. No cloud, no phone apps.
I found aggravating that:
- I need a smart phone and install an app to set up and configure the router.
- I also like the effort of simplifying the router configuration but I found it is lacking an "advanced mode"
- why if the Internet is down, the internal network does not work at all?
Microsoft with Windows 10 uses machine learning to figure out when its most convenient for the user to update (latest Insider build has this function). Either way, Windows has come a long way from 9x randomly crashing and every other piece of software requiring a reboot.
It's your network of course but it would be the first thing I'd turn off.
Have a DOCSIS3 / DOCSIS3.1 modem that is a dumb L2 bridge. TP-Link makes decent ones that are compatible with Comcast. You can find them and their reviews on Amazon.
Use something like a Ubiquiti ER-X (Edgerouter X) for your WAN-to-LAN interface and NAT. The Ubiquiti EdgeOS is developed by a team of people they hired away from vyattta when vyatta was sold to Brocade. It's a fork of Vyatta with a decent UI on top of it, and full SSH access. Which is of course based on Debian.
Have no wifi functions in your router!!!
And then something like a set of ubiquiti UAP-AC-LITE or UAP-AC-PRO access point(s), as needed. You can set up the ubiquiti unifi controller inside of a debian VM in virtualbox. The controller does not need to run persistently , just once to provision the APs, if you're doing basic WPA2-presharedkey authentication for your home. Bring up the VM again in the future on your laptop if you need to make changes.
This is a pretty low budget but highly effective solution ($65 cablemodem + $48 router + $78 wifi AP).
If you prefer Mikrotik to ubnt, there are a lot of small, similarly sized things you could replace the ER-X with that are in the $45 to $80 price range that will perform similarly.
Separating the ISP-controlled modem from the router is certainly good advice, but I can't see any strong reason to recommend separating the AP from the router. If you know your AP needs to be located far from the router in order to provide decent coverage, then it makes sense. Otherwise, there's no technological or economic justification for putting three exclamation marks on that point. You just make your setup a lot more complicated (a whole extra VM for the admin tools?!)
It's going to be me and my roommate only (with friends and family over) and I would like to get something secure and also reliable (and preferably on the cheaper side)
Any suggestions? I believe we have Cox if that is any factor....
Some time ago I decided to get a little more serious about security and put a mini-PC running pfsense between my home LAN and the Internet. Hopefully that is more secure though a similar search wouldn't prove that. Perusing some of the critical vulnerabilities at cvedetails.com seems to show that the only critical vulnerability for either of these is for versions of the software older than what I'm running. And I also see the flashing yellow "!" on the Asus management page that indicates an update is available.
That latter part is really a concern. I don't get a notification for an update unless I go look for it. Logging to either is not something I do every day.
The main security issue is that the vendors stop issuing security updates after they stop selling the router even though people are still using it, and the software that comes on it is usually crap to begin with. The solution to this is to get one you can install OpenWRT or Debian or whatever you prefer on it, do that as soon as you buy it and then it doesn't matter what the vendor does. But note that not all routers are supported by the software you want to use.
Also remember that a router is just a computer with multiple network ports on it. Adding another network port to your old laptop is a time-honored tradition. The hardware will be faster, the drivers are usually better, it has a built-in battery to survive power bumps, etc.
I wish there were $20-$30 PCI-E bridge cards of >2 1Gbit ethernet jacks but they don't exist.
Unless you actually need the ports to do some kind of network segmentation, one solution is to just plug the inside port into a five port switch (~$15). Which is how a lot of the consumer grade routers are implemented internally anyway.
You also can find quad port gigabit cards around those prices. Currently $22: https://www.amazon.com/HP-NC375T-Gigabit-Ethernet-539931-001...
There are scads of used quad port cards for even less on eBay.
Cost is not a primary concern, within reason. Wanting a consumer focused router is more about wanting to minimize set-up time and maintainence. Frankly, I’m not sure I have the time or trust myself to set up OpenWRT correctly/make sure it’s updating regularly/I’m installing the correct version etc.
As long as you're not going out of your way to install a nightly build of OpenWRT and you just stick with the stable releases, it's no more difficult than installing new firmware from the manufacturer and configuring it. The web interface for configuring OpenWRT is comparable to what most consumer routers provide, except that OpenWRT's UI is shared across all hardware platforms instead of being laden with vendor-specific branding and snake oil features.
These are trash too, full of closed code with backdoors. Buying small x86 mini PC and flashing it with OPNsense will take an hour. You get open source with GUI on FreeBSD, bulletproof.
Its documentation is however a bit lacking unfortunately.
Oh and it's openwrt under the hood, with lxc containers for things such as grafana.
You'll get a great interface, frequent firmware updates with new features and security fixes, and you'll have a good strong signal at your neighbour's house if you're going for a visit.
That's cheaper than most all-in-one routers, and while you won't get the best single-client bandwidth, you will get much better management/configuration options.
It really isn't. There are plenty of consumer router+AP combos in the $75-90 range that offer equal or better performance to the ER-X + UAP-AC-Lite combination.
I've been looking for an excuse to go down the Ubiquiti route, but I really can't find one.
I'm personally using a TP-Link Archer C2600 that was on sale for $70 from Newegg in January.
In the end mucking with open source firmware, while interesting, just wasn’t worth it. I found the ubiquiti solution stable and the UniFi management software (especially their iOS app) are excellent for my needs. Plus mounting my AP in the ceiling means I can cover the entire house from one AP and at the same time keep the rest of my networking equipment stored away in the basement.
However, no router in that price point gives you the ability to easily expand past one AP, RADIUS VLAN support, the Unifi web interface and so forth.
My last setup was an ASUS N66 dedicated as the router with an Archer C7 as the WAP. Good performance but the configurability and stability (even with ddwrt on the asus) doesn’t compare to the ubiquiti combo I run now.
You must be assuming that the user insists on sticking with broken vendor software, instead of switching to OpenWRT. The only software benefit that you don't get just as easily from OpenWRT is centralized management of multiple APs. Adding and configuring APs one at a time is very easy and since home networks never require more than 2-3 APs the lack of centralized management is not a significant issue. RADIUS and VLANs are fully supported by OpenWRT, and the web interface is fine except for the aforementioned limitation that you're only managing one AP at a time.
I suspect your stability issues with the ASUS router were a consequence of you using DD-WRT hobbled by proprietary WiFi drivers, instead of an OpenWRT-supported router. The DD-WRT "project" is a mess compared to OpenWRT, which actually puts out stable releases and operates more like a proper Linux distribution. Third-party firmware distributions aren't all the same.
I used Merlin ddwrt which was supposed to be dedicated to ASUS hardware. At some point fiddling with wrt takes more time than the nonexistent price difference with the ubiquiti equipment :)
I didn’t use the ASUS for WiFi, just routing. My instability had to do with ipv6 issues - it would stop broadcasting RAs if I remember correctly causing intermittent connectivity issues. I would have to cycle power every so often (month or so?)
No such issues with the edgerouter. I’m sure OpenWRT works great for folks, I just found it wasn’t the right fit for me.
Usually the ISP router just sucks at wifi, but I have seen ISP routers which have only 100mbit/s uplink ports when the internet connection is higher. In that case you'd want a custom router also. Or if they ship some router with some features you dislike that you can't disable (like public hotspots, unpatchable insecure config interfaces, etc.)
I just want to extend the range without monkeying with the existing router or running cables. Ideally configuring the slaves to use the existing SSID/WPS config if that's possible.
I don't care (much) about the impact to latency or throughput, it seems like there's excess capacity now.
EDIT: downvoters please join the discussion, seems like an innocuous question to me.
But now, the ISP provides a single device that is where they terminate the DOCSIS connection and originate the Wifi router. And casual investigation leads me to believe that I "can't" replace this device. I don't want/need a DMZ or my own public servers. Also, I have less patience for tracking down my own breakage these days. The ISP's device works and performs spectacularly. I know of no public vulnerabilities for the provided router.
So IMO no I don't "really want to get rid of any kind of ISP provided router and Wifi".
They usually didn't advertise that though.
Their cloud management stuff is solid(and free with spare PC!) which is great if you help your family set anything up.
Ars did a great deep-dive a whole back[1], it's a pretty good read.
[1] https://arstechnica.com/information-technology/2018/07/enter...
It's easy to set up and run multiple services (think XMPP, ssh, IP over DNS...).
My guess the if you get a wireless router, wifi signal strength is most important part, aside from that any mainstream router is probably OK.
That's because Ubiquiti Edgerouters and APs use the same processors and radios as consumer routers. If there's any truth to the memes about hardware quality, then the differences lie in things like the power supplies. Most of the perceived improvement in stability that Ubiquiti Edgerouters offer comes from having software that is actively maintained and not stuck on decade-old software branches. You can get all the same software benefits (more, really) by running OpenWRT on consumer hardware.
Cost | Purpose | What
$109 | Router | PCEngines apu2c2 http://pcengines.ch/apu2c2.htm
$10 | Router Case | http://pcengines.ch/case1d2blku.htm
$17 | Router Storage | http://pcengines.ch/msata16g.htm
$30 | Gigabit Switch | https://www.amazon.com/D-Link-Gigabit-Unmanaged-Desktop-DGS-108/dp/B000BCC0LO/
$80 | Wifi | Ubiquiti Unifi Lite https://www.amazon.com/Ubiquiti-Unifi-Ap-AC-Lite-UAPACLITEUS/dp/B015PR20GY/
With this setup, the router only does _routing_, so you also need a Wireless Access Point (WAP). Connect it like so: Modem->Router->Switch->WAP.Install pfSense on the router, configure the Unifi using Ubiquiti's Java app, and you're done. It's about $250 all together which _is_ more expensive than consumer routers, but IMHO it's worth the superior quality. The APU board is well-documented (PCEngines provides schematics!) and the firmware is based on Coreboot. The processor supports AES acceleration for faster encryption (great if you use VPNs!) PfSense is an enterprise-grade router/firewall with scads of graphs and features. And the Unifi has a great antenna with excellent range. Not to mention this setup leaves you with six spare ethernet ports on the switch.
Never had a better setup.
It blows any consumer router I've used out of the water in terms of stability, performance, flexibility, security, and user experience.
Getting emails for potential security issues, custom DNS domain for local network, fail2ban bruteforce prevention, QoS, alerting when WAN goes down, and so on, has all been a breeze to set up.
If you want to go deeper, get any cheap NUC or system with 2 NICs, install OpenBSD and configure it as a firewall / router.
I can't believe ASUS even considered this idea in this era of privacy concerns but I'm definitely going to research that before I buy another router.
It probably helps that it runs Debian stable, too, so security updates are frequent and regular.
I'm a PFsense user currently and am always looking for ways to tinkering with my networks.
They also have recently made it a PITA to use PFSense with IPTV, as UDP Multicast forwarding has been deprecated w/o warning. Like everything with PFSense, it just disappeared one update without so much as a warning :P
I have a friend who uses Debian as his core router, its not bad. I've gone to OpenWRT since its got the fit and finish, plus it will boot and be debugable no matter what happens.
You should be able to tune it from there to get a reboot under 30 seconds.
Ubiquiti did their own fork of vyatta for their edgeos offering, I believe.
But connection tracking tables for NAT may not. Plus the ISP might assign a new IP to your CPE on ppp auth.
Docsis gives the ISP the ability to control the router, but they are very bad at it and even if they aren't it's often the manufacturers who are the problem. So I always have bought my own cable modems instead of renting from the ISP. The last time I did this I went with a good Motorola, but come to find out arris has bought them out, I did some scans, notice it's vulnerable and needs and update, so I go to the arris website. Can't find the update anywhere. End up calling them and get told, even though I own the equipment, they only release updates to ISPs or "partners" and no I can't have it! Wtf!?
Docsis, even 3, is a shitty spec that needs to die.
So really the best thing you can do and what I suggest to people is to put the cable modem in bridge/passthrough mode after checking all settings, and then hit your own router.
Except most people, as the article states, just go get some crappy linksys (cisco owned), netgear, Asus, belkin, etc, which have their own set of problems. It's better with openwrt/ddwrt/tomato but there is a better way.
My favorite setup is thus:
ISP Router in passthrough
Ubiquiti edgerouter
Ubiquiti APs
Because you want internal network to keep working when you do server maintenance.