MikroTik routers are forwarding owners’ traffic to unknown attackers
blog.netlab.360.com
blog.netlab.360.com
Unfortunately NIH syndrome runs at an all time high at Mikrotik. Even the RouterOS webserver and SMB implementations were custom written, and both were later found to contain remotely exploitable bugs. I'm sure there are other holes lurking in their implementations of ipsec, openvpn, etc, so I no longer open up anything and rely on port forwarding to more secure and battle-tested services like OpenSSH / Wireguard for remote management.
Mikrotik boxes are really quirky. They basically have user-facing bugs, symptoms of which can have no explanation except for them fronting some massive clusterfuck on the inside. They used to do bizarre things with timestamps of freshly copied files, when the modified time would oscillate around some convergence point. Some wierd directory names (like .popup ?) were reserved for no apparent reason and an attempt to create them failed with "file not found". That sort of thing. And we even didn't own any of their devices, we were just in a splatter zone from our clients constantly walking into Mikrotik issues. It was few years ago though, so perhaps things have improved since then.
Unfortunately given their affordability and feature set, Mikrotik routers are often times administered by people who don't really have a solid grasp of networking. I've seen some downright awful advice posted on their user forums over the years, stuff that could easily cause connectivity issues under the right circumstances. Who knows how much of that gets copy/pasted into configs after a quick Google search.
Absolutely. I purchased an rb2011uiasrm when I got gig fiber at home. I enjoyed hardening the router and ran IPsec VPN for a bit but prefer using another box w/OpenVPN and HMAC auth. I just don't see no matter the promise of security a good reason for explicitly allowing remote access from internet to a core device, MikroTik or otherwise.
x86, can run OpenWRT.
Later today (if all goes well) I'll be adding wifi to it!
At one point I had an 802.11n card in my older ALIX2D router, but there were stability and performance issues so now I always use a separate access point, most recently a Unifi AC-PRO which has some quirks but works well in general.
I've been happy enough with the x86 routing strategy that when it came time to replace my older Cisco 100mbps switch, I decided to do that with x86 hardware as well. All of the smaller/cheaper gigabit switches either didn't support VLANs, made way too much heat, or had reliability issues, and the ones that were suitable were quite expensive and had reliability issues of their own.
So, I found a Supermicro Atom C2000 board (A1SRM-LN7F[1]) on sale for $90, which has 7 Intel NIC gigabit ports built-in and supports ECC ram. I put it in a Supermicro 1U[2] enclosure along with an Intel PCIe 4x gigabit NIC, for a total of 11 gigabit ports on the switch. I installed Debian on it and set up open-vswitch, which worked but was soon replaced by "vlan-aware" Linux bridging.
It's easily capable of switching gigabit traffic between multiple machines at the same time, ping shows an average latency of 0.310ms, has very low power usage and makes very little heat.
Note that those C2000 Atoms do have a "sudden death" hardware flaw, but Supermicro should have fixed it on more recent inventory, and they will send a "patched" board to replace any that are affected before they fail. The Atom C3000 doesn't have that issue, but I don't think Supermicro (or anyone, really) make any C3000 boards with that many built-in gigabit ports.
[1] http://www.supermicro.com/products/motherboard/Atom/X10/A1SR...
[2] http://www.supermicro.com/products/chassis/1U/510/SC510T-203...
Otherwise, get an edgerouter.
I retired them mostly because the Ubiquiti management is much easier and that hardware also affordable (though the software is not open, so not a fit for your use case).
(I'm not disputing your experience, but don't want other readers to conclude that 5GHz doesn't work on any of them.)
It's absolutely not all roses on the UBNT side of things. They are exhibiting some of classic signs of expanding too fast and stretching themselves a bit too thin. In particular their hardware lineup is starting to get overly broad and they aren't being aggressive about retiring older products and keeping the matrix simple, which of course in turn represents an increasing maintenance burden. And some of their hardware which was disruptively priced and fantastic value at launch is now getting very old in the tooth. The UniFi controller UI can be shallow for more then simple usage of things like DNS/DHCP/RADIUS, granted a lot of HN types may have their own separate appliances/servers for that. Their USG has always been a bit of an orphan and only recently has really started getting the serious attention it needs. They've got some features on high end hardware that while niche still haven't been fleshed out. Their EdgeRouter hardware is keeping up better though.
That said the update process has continued to be pleasant and solid, and their support even for old devices has been excellent. There are no required ties to any external services. The hardware itself has been very reliable, and even the RMA process for when something burned out on us was decent (2 minute wait to online chat on a Sunday morning and immediate RMA approval). They've been quite good on security updates for a number of the major issues that have come up over the last year, and have had no major snafus (that MikroTik one storing passwords as plain text was painful/disturbing to see). While enterprises will have more advanced needs for SoHo situations even if they're not open source I think UBNT is worth consideration, particularly for those wearing plenty of hats already who are ready to cut down on cognitive load a bit.
I've been running UniFi APs for years, but recently switched from my pfSense appliances to USG routers. I lost a lot of flexibility (especially for things like VPN configuration), but the simplicity and seamless management have been a huge time-saver.
I am puzzled by some of their new offerings—do they really expect any serious commercial customers to install lighting powered by PoE? Perhaps they're onto something innovative, but it seems like a distraction from their core business.
Yes, although I want to emphasize again that while they made a new hire specifically for the USG and it's seen dramatic improvements in the last year [1] it was still a kind of orphan child for a while and I still need to drop down to the shell sometimes for initial setup. Rock solid after that and simple and good integration with the overall site sure but it hasn't always been clear for someone starting from scratch how to get it up the first time in common SoHo situations. Also for those with gigabit links who want to run Suricata IDS/IPS (which requires turning off hardware offload), Ubiquiti just doesn't offer anything even remotely SoHo priced with the muscle for that right now. The low end USG "3P" (~$110) maxes out around 150 Mbps with IPS after the most recent update (an improvement from 85 Mbps before that) while the Pro (~$300) maxes out around 430-450. Only the XG can handle a gigabit or higher but that's $2500 and built with 8x 10G links, it's ludicrous overkill for those who don't want its other features and routing. Granted gigabit fiber links are far from the norm but they're gradually increasing and the HN crowd may be more likely to go for them then many, and the hardware in the USG 3P and USG Pro is just old now.
>I am puzzled by some of their new offerings—do they really expect any serious commercial customers to install lighting powered by PoE? Perhaps they're onto something innovative, but it seems like a distraction from their core business.
I definitely agree about distractions, though at the same time we should recognize that of course different divisions and people can be doing different things at the same time, development and engineering talent isn't necessarily fungible there. Still, they aren't a megacorp, overall resources and management bandwidth isn't unlimited either.
On the other hand at one point Ubiquiti had a real effort in the IOT space called MFi, but due to a lot of internal technical debt issues there (IIRC there) it essentially got canned, and they planned to eventually resurrect it on top of their more advanced foundations but haven't had the bandwidth. Maybe the lighting and their efforts to improve their security offerings are some first baby steps towards getting back into that? In fairness IOT has some of the same properties in terms of suckage that have made their networking efforts successful, and could also be a major market. Updates are often a pain or non-existent, the security story is awful, and much of it insists on using 3rd party cloud dependencies. There could be a real valuable hole there for Ubiquiti to fill were they to execute well enough, though I'd feel better about it if their core felt more tightly managed and foundations a bit steadier. We'll see I guess, and at least lighting should have been a pretty low R&D way experiment with it?
---
1: And for better or worse, the very fact of a piece of cheaper networking gear seeing years of support and improvements is depressingly unusual in the industry.
[1] DD-WRT struggled with 100Mbps to WAN - hardware NAT
Edit: actually, it is possible at least for some MT hardware : https://wiki.openwrt.org/toh/mikrotik/common
It can sustain 500mbit/s with no issue. As this is my internet connection speed, I don't know if it can go any higher.
My one complaint about this approach is that there are so many interactions happening at the software level that any time I set up a network stack, I always feel as though the whole thing is very fragile and only works because everything is precisely configured. Since I like to tinker, I want a system that feels more reliable, and so I go for the router-in-a-box approach of pfsense or opnsense. I wish it was easy to get a network configuration that "just works".
There are many brands and models that are compatible with OpenWRT. I have good experience with tp-link wr1043nd, wdr3600 but they are a bit old by now. I just ordered ZyXEL NBG6617 to test out.
(2) If you get the wrong router, just return it and get another.
(3) Buy a router at a brick and mortar store so you know what you're getting.
Take a look e.g. at OpenWrt's list of devices "Ideal for OpenWrt": https://openwrt.org/toh/views/toh_available_864
Consider TP-Link Archer C7, for instance. It is an older one, but has reasonably fast hardware, supports IEEE 802.11ac and is available on Amazon. New costs ~75 USD, a "certified refurbished" version costs ~50 USD.
I have performed some simple tests using `iperf` tool on Archer C7 with OpenWrt and it was able to sustain wired network speeds of around 750 Mb/s and wireless speeds (IEEE 802.11ac) of around 300 Mb/s (maybe even more, but I do not remember exactly).
If I am not mistaken FRITZ!OS is a Linux distribution.
The other option I've heard good things about are the PCEngines devices. They don't, as far as I'm aware, have hardware offload, so make sure their performance suits, but they use OSS U-Boot and you install the OS of your choice. It's one of the most open devices in a router form factor I've come across.
Depending on the number of ports you need, you could also use one of the Jetway devices. They make them with varying numbers of ports as SBCs in a case and you add RAM/M.2 SSD. I got a Celeron one with 2 ports and run it as a Suricata IPS. It performed just fine with my 100M pipe.
So speeds are kind a slow, around 50-90 megabits (i have gigabit fiber, that the er-x otherwise can fill out completely).
TP-Link, the former manufacturer of my choice, unfortunately has become a version roulette it seems.
If power consumption does not bother you, maybe banana pi? Or something atom based?
Another option would be your own hardware with pfsense (bsd) or ipfire(linux).
Even further would be your own hardware with linux and write your own nftables or bpf.
The best option in my opinion is something Intel based running a well known Linux distro with automated security updates that is fully in your control. Shorewall can do everything needed for a home router. This option is a lot more expensive though.
(Sadly my home internet connection is too slow to make hardware offloading on the edge router matter...)
Interesting, do you have any more about this?
Got an ER-PoE that intermittently loses packets and have never got to the bottom of why (I gave up and bought a non-Ubnt router, just haven’t got around to configuring it yet).
I was one of the people involved in some of the measurements on there.
I avoid ubnt networking gear in general after that experience (although ER-X seems good and I use one at home as a smart switch). Their specialty is in APs, which work really great.
[1] https://www.openbsd.org/octeon.html
[2] https://news.ycombinator.com/item?id=10079210
[3] https://an.undulating.space/post/180411-erl-openbsd-upgrade/
Unfortunately I was wrong and the post is just for cryptography acceleration. Will have to check the commits to see if any other work has been done.
They're basically the same hardware.
In any case, you can load it onto some fairly low cost hardware for your typical home user. It's fantastic.
I am not a huge fan of the Ubiquiti routers. They required loading a config onto them just to get DHCP enabled and NAT setup for a typical 1 WAN and 1 LAN environment. Why on earth they would ship without that config on them when 99.9999% of environments are like that is bewildering to me.
Don't know if it's changed since then but I haven't gone back to mess with them since.
As a Linux guy I have to admit PFSense and similar products (NAS4Free etc) interface is the best I have ever seen around wrt functionality and ease of use, sadly OpenWRT web interface simply doesn't stand a chance, and I'm not referring to aesthetics as I'm aware OpenWRT is aimed at hardware with orders of magnitude less resources, but pure functionality - in fact I have never been able to configure a small tp-link mr3020 router to use it as a WiFi bridge for my networked but not wireless printer. Yes it can be done and there is a HOWTO on that task, but it doesn't work and low level iptables scripts aren't exactly my strong point. It would be trivial doing that with PFSense, but sadly it cannot fit into that device. /Rant
For whatever braindead reason, they told me that they wouldn't give me an RMA because they don't "support" 3rd party SFP modules. They wouldn't loan me one to fix the problem, they wouldn't agree to reimburse me if it didn't fix the problem, nothing. Buy their module or deal with broken equipment.
I bought one of their SFP modules and to nobody's surprise the problem persisted. At the same time I bought a Mikrotik hAP and again to nobody's surprise, all the SFP modules that "failed" worked with zero problems.
At that point Ubiquiti finally granted me an RMA but at that point I went and got a refund instead.
After that support experience, I'll never buy Ubiquiti or recommend it again.
I'd much rather recommend PC-Engines: https://www.pcengines.ch/. They're x86 based so you can run whatever on them, cheap and have really good performance.
What’s your reason for suggesting friends buy a modem/router beyond the cost?
If you really need a small / low power usage appliance then some Ubiquiti devices run OpenBSD as I mentioned in another reply below.
Anecdotally OpenBSD also supports wireguard if that's a concern.
I would assume that they are easy to flash and high compatible.
[0] https://www.aliexpress.com/item/Wifi-Router-NEXX-WT3020H-300...
Specifically, the best deals can be had on the oldest model, the R6700v3, from an Amazon warehouse deal for $70. This is what I use, and it works without issue with dd-wrt. You'll need to flash it 3 times.
The best device is probably the R7800 model. It uses a very fast, non-Broadcom (OpenWRT-supported), modern chip. The only way this matters in practice is if (1) you have a gigabit Internet connection and (2) if you need QoS turned on for scoring an A+ in "bufferbloat" on speedtest.net--i.e., you play games.
If you don't use QoS, you will be able to serve 1 gigabit with dd-wrt's "Shortcut Forwarding Engine," which is an accelerated "in-Linux-kernel IP packet forwarding engine." If you don't have a gigabit connection, the typical Linux routing stuff that dd-wrt uses is fine.
With regards to model roulette, you can always buy it off eBay for the specific model. These routers are so common I see listing for them in Craigslist in the Bay Area right now.
I would argue the two main reasons to do this are for improved security/stability and QoS. If you're not interested in these features, buy something that Wirecutter recommends in your price range. But compared to $70, I believe a truly decent router can be had for $50 (the Archer series others have mentioned) that is also truly ancient.
The Apple Airport devices run ARM NetBSD and you can SSH into them. The last generation ran NetBSD 7 and executed binaries from NetBSD userspace when compiled statically.
OpenWRT does not ship closed-source Broadcom drivers, so it tends to have worse support across the board. I don't think their OSS-related reasons for doing so are material to you.
It's one of the only WiFi routers I've ever worked with that has a fallback flash mode in the bootloader, and the only one that I know you can buy today. This is invaluable when you're not sure if something you're doing could make it fail to boot, like installing an upgrade without knowing whether it uses the same partition layout as you had. When it does you can just try again. (I've needed this once already.)
If you're flashing your own images of OpenWRT, there are a few conveniences which are a bit more uncommon in the hardware which are useful if you ever need to debrick - eg easily openable case, UART header comes pre-installed (you don't need to solder your own), etc.
Using the hardware reset button doesn't fix things, so heads up for others in that situation. Use MikroTik's NetInstall to re-install RouterOS instead.
Lately I’ve been having IP & Internet issues like....
- match suddenly banned me as a subscriber to okcupid and match. They won’t tell me why either & ive been a subscriber on/off for years. Never or ever would I do anything inappropriate though my match.com account I feel was hacked. Yet they don’t want to listen :-(
- my 6 month old roku device suddenly would no longer find my router.
- yesterday just bought a new Roku & was unable to activate it after many attempts.
Anyone else having weird Internet/IP device issues too?
Mikrotik is Latvian, not Lithuanian.
/ip firewall filter
add action=accept chain=input connection-state=established
add action=accept chain=input connection-state=related
add action=accept chain=input dst-port=5000 protocol=udp
add action=accept chain=input dst-port=6000 protocol=udp
add action=accept chain=input dst-port=6001 protocol=udp
add action=accept chain=input protocol=icmp
add action=accept chain=input dst-port=22 protocol=tcp src-address-list=Mgmt
add action=accept chain=input dst-port=179 in-interface-list=LAN protocol=tcp
add action=drop chain=input in-interface=btopenreach
add action=drop chain=input
Clearly it's possible that an attacker could come in from the back door (desktop, XSS etc), I could lock down the BGP more, and tighen up Mgmt beyond it's current fairly wide subnets (a /16 owned by work and my wired range), but it becomes a hassle, which leads to more disabling of the "action=drop" while debugging. My backup script emails me when the configuration changesTo check if your proxy is enabled (probably shouldn't be)
/ip proxy print
enabled: noThe concept isn't hard -- block non-established incoming traffic from everywhere except where you want management to happen from. I have a few extra rules.
Generally if you leave yourself wide open don't expect to be immune from zero-days.
> What is disappointing for the attacker though, the mining code does not work in this way, because all the external web resources, including those from coinhive.com necessary for web mining, are blocked by the proxy ACLs set by attackers themselves.
Smart enough to breach Mikrotik routers. Dumb enough to fuck up linking in coinhive JS. That screams "script kiddie buying delivery method on an open market".
Also, how is coinhive still a thing?
It's too bad coinhive is so easy to abuse. I'd much rather live in a world where websites are financed with my electric bill rather than my data.
Which is to say that pretty much any form of cryptocurrency is likely to stay abuse-prone.
Practically speaking, the amount of electric bill you'd have to pay to make up the costs of what your currently pay for with data would almost certainly be shocking. I can't imagine that it costs anything like $5 to mine $5 worth of Monero on your average computer in the first world. And that would be just enough to pay for Gmail, never mind everything else!
The sheer, staggering inefficiency involved might help incentivize usage away from a proxy for micropayments and towards malware.
In general, I wouldn't mind that much if I had to pay some extra "Internet subscription" to cover publisher costs, if reasonable. I don't think electricity bill is the right place to include it in. And I definitely do not want this charge to be included by the means of cryptocurrencies - they're wasteful at their very core (as opposed to every other financial instrument in existence), and I don't want to support such ideas. Not to mention that, like 'Kalium observes, it would take extreme amounts of power use to "send" a publisher some reasonable amount of money.
* ASICs are roughly 100x more power-efficient at essentially any crypto mining algorithm
That's half of the problem.
The other half is that cryptocurrencies rely, in a structural way, on their generation to be difficult, so when enough ASICs get deployed, the currency ups its "difficulty factor", multiplying the amount of power you have to burn for the same reward.
Really, if I were a supervillain who wanted to accelerate energy crisis and climate change by exploiting human greed, cryptocurrencies is the scheme I would come up with.
If you can't understand the compound harm to the environment (for starters) of nations states existing and controlling currency, I feel bad for you. If you do understand it, you should know you're rightly fearful of this technology, because it's going to play a major factor in your future demise.
Show, don't tell. If you can't explain it adequately to an audience, then you don't know it well enough to to be stating it as fact.
Sure. Should we start with the estimated 262 million counts of democide committed last century?
http://www.hawaii.edu/powerkills/20TH.HTM
Or perhaps you're one of those people who thinks mass murder of humanity is a good thing because it reduces the human impact on the environment?
> If you can't explain it adequately to an audience, then you don't know it well enough to to be stating it as fact.
Absolutely untrue. That requires you to assume the audience is both intellectually capable of understanding a complex proposition, and that it hasn't been sufficiently biased against or indoctrinated against an opposing view. While I'm sure there is some correlation between familiarity with a given subject and one's ability to explain it, you would be making a gigantic leap in assuming this automatically means a given audience is going to adequately understand the argument.
That is also completely aside from the assumption that my comments were intended to make a compelling case on the matter outside of the person I was responding to. I'm not really convinced that wouldn't be a waste of time, but maybe I'll be surprised.
Being able to explain a complex topic simply is the point. Knowing how to distill the concept to essential points is useful, and if you can't identify the essential points, you probably don't really understand it.
> and that it hasn't been sufficiently biased against or indoctrinated against an opposing view.
> you would be making a gigantic leap in assuming this automatically means a given audience is going to adequately understand the argument.
I didn't say convince, I said explain. Indoctrination is irrelevant. Assume your audience is willing to hear you out, as otherwise all you are doing is yelling at people rather than conversing with people, and that's not acting in good faith.
> the assumption that my comments were intended to make a compelling case on the matter outside of the person I was responding to.
Yes, the assumption is that you are trying to contribute with your comments, and not just tell someone they are wrong without explanation, as the site guidelines specifically disallow that.
> Or perhaps you're one of those people who thinks mass murder of humanity is a good thing because it reduces the human impact on the environment?
You seem to be working under the assumption I disagree with you. I don't recall doing anything other than asking you to explain your reasoning. Do you consider that an aggressive argument against your point?
Edit: I'm sorry to see that you've done this repeatedly before. If you would please review https://news.ycombinator.com/newsguidelines.html and follow the rules when posting here in the future, we'd appreciate it.
I originally ignored the portion that mistakenly assumed I had a position against your point that aggressively insinuated I believed mass murder was acceptable. I revised my comment right after posting it to append a clarification on that.
> to engage in dishonest bickering
Please do not accuse me of being dishonest without being sure backing up your words with some sort of reasoning. I'm not being dishonest. I think you are not engaging usefully, and attempted to rectify that by asking for more information, and then to explain my reasoning when it was called into question, exactly as I suggested you do originally.
> filled with more assumptions as to my motivations
I'm not sure I assumed a single thing about you. I couched all my statements generically on purpose.
I think you are stuck in a context where you are interpreting me as attacking you. if you truly think I'm being dishonest or attacking you, don't reply. If you think I'm wrong, explain how I'm wrong. If you have problems explaining why I'm wrong, perhaps reexamine the assertion that I am. I'm fully willing to entertain that I'm wrong, and admit it. It wouldn't be the first time I've done so.
That genuinely interests me, which is why I've gotten into conversations on this topic a few times in the past. I understand that others may be uninterested in that or find it tedious, so I'll try to refrain in the future. My apologies.
I downvoted this, but now I'm gonna reply to explain why. This is a veiled insult against your audience, and as such it's both a fallacy and a bad-faith argument. The rest of the sentence, too. Let's not do "I'm smarter than you all and you're all biased" here, please. It just makes the forum a shade uglier.
> the compound harm to the environment (for starters) of nations states existing and controlling currency
Do you believe that nation states exist solely, or primarily, to control currency? Currency is the blood of the nation, yes, but nation states form organically, to further interests of groups of people. Whenever you have more than a dozen people in one place, you get hierarchical governance, and the more people you add, the more that hierarchy grows vertically to cope with the load. With millions of people, you arrive at some form of states; add couple wars into the mix, and you arrive at modern sovereign nation states.
Point being, if cryptocurrencies were to break states' control over money - and what I guess you hope for - destroy states entirely, after lots of blood unnecessarily shed, the states would be back in some form. It's doubtful though, that cryptocurrencies would survive the process. They need computing and Internet to work, and computers&Internet need stable global economy to exist. Break the economy, break the supply chains, and modern technology evaporates.
Along with 90% of urban population starving to death.
> you should know you're rightly fearful of this technology, because it's going to play a major factor in your future demise
Yes, I'm fearful, because this technology is tuned in with the markets just well enough that it may propagate, whether governments want it or not, and grow to the point of burning out most of our non-renewable energy sources, with little to show for it, before someone finally puts a stop to it.
--
I've painted a bleak worst-case scenario above, but I sincerely hope cryptocurrenicies as we know today will fizzle out and be remembered just as another scam, one with absurdly large ecological footprint. I'm not against distributed ledgers, distributed consensus, or even new designs for money. I'm just against stupidly inefficient solutions exacerbating the biggest problems humanity faces.
Not sure where you're getting that from. I do not want to "shut it down," quite the opposite.
> Do you believe that nation states exist solely, or primarily, to control currency?
No, but control of currency is a major factor in their sustained existence.
> Currency is the blood of the nation, yes, but nation states form organically, to further interests of groups of people. Whenever you have more than a dozen people in one place, you get hierarchical governance, and the more people you add, the more that hierarchy grows vertically to cope with the load.
Nation states are a symptom of obsolete social organization technology. They result in massive human suffering and hampering of technological growth. Their formation, whether "organically" or not, is irrelevant.
> With millions of people, you arrive at some form of states;
States neither require millions of people, nor are they a necessary result of millions of people existing.
> add couple wars into the mix, and you arrive at modern sovereign nation states.
Is this intended as an indictment?
> Point being, if cryptocurrencies were to break states' control over money - and what I guess you hope for
Yes.
> after lots of blood unnecessarily shed
"Unnecessarily" is a large assumption. And ideally it would happen with as little violence as possible, preferably none. When contrasted with the scale of the crimes of nation states, however, it seems difficult to make a case for their continued existence, even with massive short term casualty.
> the states would be back in some form.
What are you basing this assumption on? I think there is a strong case that social organizing technology is likely to result in nation states being made obsolete over time. The contradicting viewpoint is not substantiated by much, I suspect.
> It's doubtful though, that cryptocurrencies would survive the process. They need computing and Internet to work, and computers&Internet need stable global economy to exist. Break the economy, break the supply chains, and modern technology evaporates.
Computing and networking are not dependent on the existence of nation states. A stable global economy is especially not dependent on them -- in fact, nation states are quite probably the largest cause of global instability, economically and otherwise. Preferably, a transition away from nation states happens using technology itself. Cryptocurrency is likely to play a major role in this.
> Along with 90% of urban population starving to death.
A sudden overnight collapse of nation states might very well lead to large deaths, although probably not at this scale. This is not likely to happen, and certainly not likely to happen as a result of mass cryptocurrency adoption.
> Yes, I'm fearful, because this technology is tuned in with the markets just well enough that it may propagate
I'm glad you've admitted your remarks about cryptocurrency being wasteful and harmful to the environment are motivated by trying to suppress its existence.
> whether governments want it or not
As opposed to free people...
> and grow to the point of burning out most of our non-renewable energy sources
Ridiculous.
> with little to show for it, before someone finally puts a stop to it
Good luck.
> I've painted a bleak worst-case scenario above
You've spread fear-based propaganda based on an issue you clearly have made a lot of seemingly fear-based (as opposed to reasoned) assumptions about.
> I sincerely hope cryptocurrenicies as we know today will fizzle out and be remembered just as another scam
You fear the change that this technology brings, so you hope it is suppressed and remembered for being something you (possibly) understand it is not?
> I'm not against distributed ledgers, distributed consensus, or even new designs for money.
These are the potential benefits of cryptocurrency.
> I'm just against stupidly inefficient solutions exacerbating the biggest problems humanity faces.
Even a grossly less efficient method for mining cryptocurrency would be preferable to the problems caused by the continued existence of nation states, and probably by their control of currency alone, not even factoring in all of their other crimes.
The biggest problem humanity faces is the existence of nation states, and the resulting democide and destruction, as well as potential existential threats of nuclear annihilation or other destruction. In the pursuit of perpetuating themselves, nation states are also likely major limiting factors in technological advance, which is the single greatest factor in preventing human suffering.
You seem to be arguing that demand for renewable power will...make there be less renewable power available? Which is not really how economics works. Creating lots of power demand isn't going to make us like, run out of sunlight. It's going to raise the price of power. It's going to compensate people for building more capacity. It's going to do all the things that we want.
In fact, by providing a constant demand for excess power generation which is currently hard to store, crypto-currencies can substantially improve the economic profile of building out lots of capacity that otherwise wouldn't make economic sense.
90% of work, data copied on Internet have no value. Dunno why we need to pay for Clickbait article, or article without value or translated article (EN->FR)
I'd personally much rather live in a world where websites are financed up-front or not at all. It would disincentivize the low-effort creation of pointless or misleading material simply to direct time and attention to ads and miners.
https://blog.mikrotik.com/security/winbox-vulnerability.html
(referenced here : https://forum.mikrotik.com/viewtopic.php?f=21&t=137284&start...)
That strongly suggests password harvesting. Those ports/protocols often (not always) are used for unencrypted user/pass combinations. :(
/ip service disable winbox
Why would anyone want to use that? My theory is that it has something to do with how in many cases the MT sshd has to be told to figure out the terminal: $ ssh user+t@192.168.88.1
...and this information is really hard to find. If the terminal settings aren't right and you can't fix them, ssh is unusable and you're stuck with either winbox or webfig. Fortunately, if the ssh session is wrapped in a mosh session then mosh will handle MT's terminal settings.Since I do not use Windows, I had to emulate Winbox in Wine... pretty awful experience, but in the end it worked while everything else failed.
I would just prefer some sort of unix tool that ssh can use to connect to the equipment through layer 2.
i guess so...
https://blog.mikrotik.com/security/winbox-vulnerability.html