You always kind of get what you pay for. If you pay an annual maintenance, then you can expect regular and secure updates, otherwise you are buying the product as is at time of purchase.
Then again, I buy stuff that can be flashed with OpenWRT ...
You always kind of get what you pay for. If you pay an annual maintenance, then you can expect regular and secure updates, otherwise you are buying the product as is at time of purchase.
Then again, I buy stuff that can be flashed with OpenWRT ...
This is a bit of a spurious comparison. Nobody is dying from an unpatched router. Why should a company be on the hook for a device, particularly if it's out of warranty? If you expect more than that, you need to be buying something with a contract stating you're going to get more than that.
Not just financial damage, the owners of defective routers can be targets of criminal lawsuits if their connections are used as proxies for attacks, death threats, bank fraud, etc.
That does have the potential to create some damage if anyone takes control of them. Maybe even kill some people, if say they DDoS the V2I network for self-driving cars in the future, or a hospital network over which remote surgeries are performed, etc.
I feel like this argument that "you get what you pay for" is pretty lazy. Usually, or ideally, consumer regulations are about setting standards and raising the bar.
So that means that if there were strong laws for stuff like this, then the minimum router price may become $70 instead of $50 - but everyone would be reasonably protected for the large majority a device's lifecycle (only a small portion of the customers should be affected by leftover bugs when support ends, like say <5%, as others will have moved on to new products by then).
I find it regrettable that the architecture commonly in use does not make a clear distinction between devices for convenience and for security.
It’d be crazy if in our homes the main entrance lock always came as an afterthought in the package of all the inside doors, and we didn’t have an obvious way to replace it separately on our own.
This case is more like a golf cart being sold as a car: it's technically usable for that, but lacking any sort of safety or weather protection.
There are arbitrary and discretionary licenses that have been created in response so prior issues.
Licensing/certification regimes allow for almost any expansion of the role of government to those licensed, including capital requirements to resolve an issue.
So first you would need a license, determine the scope of the license, who needs it, and the consequences of operating without one.
Good luck
This is false equivalence. A car is not $/£/E/50 piece of hardware.
You know, like tons of other safety-relevant products. Anything you plug into the wall, or put gas in, or has enough torque to hurt someone ends up going through safety checks.... except software.
Let's unpack this:
You get what you pay for... yet you also say that OpenWRT solves this problem and is available free of charge.
If you pay for a support contract, you get support right up to the point where the company decides to stop that support. If you have a contract worded the right way, you might be able to take the company to court over it, but if the company's willing to settle, you end up with some go-away money and an insecure router nobody's supporting. Does the money pay for next week's massive outage due to someone taking over your routers?
Finally, the product as it was at time of purchase was a product fit to be sold, without major defects. In other industries, that's a standard companies are held to: If a ball joint goes out completely after 10,000 miles, Ford's kinda on the hook for that, neh? They can't say that you have the car you purchased because the car you purchased was driveable and not sitting on the side of the road.
And we already have a system put in place to assess. It's called CVEs. If you exist, you should be on the hook to fix.
It's called 'Being Responsible'. And corporations have a strong tendency to not want to be. That's why we need the 'stick'.
Often times when defective products are sold there is some responsibility for some time to correct or notify people. Cars, child seats, and many other things fall into that.
The defective devices that get updates or notifications are often safety related. Yet, safety and security are not talked about much with regard to technology. Maybe it's time to start doing that.
https://battlepenguin.com/tech/using-the-banana-pi-bpi-r1-as...
but then I learned the hardware itself could fail into an insecure state, and there was no way to deal with it in software:
https://battlepenguin.com/tech/banana-pi-bpi-r1-fails-into-a...
I'd expect cheap mass-produced routers to be around $15 - $25, like an immersion blender.. I don't quite understand why cheap ones are still $40-$60.
An edgerouter X is $50 for instance, but doesn't have wifi and lacks serious routing features. It is considered a very low end router compared to more expensive stuff from Juniper or Cisco. (even an entry grade router/firewall like an SRX300 will run you back atleast 4x the price of the edgerouter.)
One thing these $50 routers lack besides proper software is stability. Most consumer networking equipment has an abysmal track record in terms of reliability.