Netgear Firmware Requires Online Registration
kb.netgear.com
kb.netgear.com
Reading up on it, this was achieved only after a community outcry because in the prior firmware versions the switch would have to connect to the Netgear Cloud on every bootup.
Needless to say I would not have bought the swiches if I had knew I needed to register them to Netgear Cloud to have access to the full functionality specified in the data sheet. If I had bought them as a consumer, not as a business, I would have returned them immediately.
Netgear are now on our purchasing blacklist.
⓪ - the switches are Netgear GS-108Tv3
I ended up going with Ubiquiti equipment for now, since it was available locally. Much more expensive and complicated but Linksys convinced me it was worth any cost to get the hell away from them. But I will definitely be looking into the Turris Omnia, pfSense devices, and maybe even reusing my current Ubiquiti AP with OpenWRT, next time I need to muck with networking.
I miss my Airport Extreme.
This is configuring the AP via CloudKey. Don’t know about other methods.
Sadly, even Ubiquiti gear has recently been criticised for doing the built-in phone home thing.
If you buy professional gear from an organisation that would think that was acceptable in the first place, you might want to re-evaluate your preferred suppliers anyway.
I ended up with a local-only tp-link JetStream.
The problem is: The old version (v2) is locally managed only, whereas the new version (v3) is with cloud management:
https://www.netgear.com/business/products/switches/smart/GS1...
https://www.netgear.com/business/products/switches/smart/GS1...
Maybe you looked into the datasheet of the old v2? And then got delivered the new v3?
We stumbled over the same problem a few month ago, after buying a bunch of these in the new version. I thought: Newer is better... But apparently not so with Netgear products. :-(
Very confusing, what Netgear does with their product naming!
We did not. We specifically chose the v3 version for its lower latency in switching packets and other features unrelated to cloud management.
Certainly would add to the old saying "every cloud has a silver lining".
Why would you not send them back as a business?
How generous, for a device that people buy (not rent) from them, and pay actual money for (not receive for free).
And apparently Netgear didn't even feel the need to bother including any contrived excuse as to why this is being introduced. What a time to be alive.
Buy router, plug it in, change password and rarely any setting required for average user.
Not worth the monthly fees and data collection on users (name, email, location, credit card,...)
Open source is the only equipment you can trust to not adopt this model as it’s much more profitable than shipping a box once every five years.
Is there additional telemetry that cannot be disabled?
If Ubiquiti staff has the non-existent procedures and corporate security for this to happen, they surely don't care about your privacy or security.
Not cool to do that :(.
You're right Ubiquiti did it though and I believe their devices are priced even higher. (Edit: note the post next to mine says you can opt out of this.)
I agree replacing the stock firmware with an open-source aftermarket one like OpenWRT is the way to go but there's still the moral dilemma of supporting such practices with your wallet.
I was also thinking if this could be an attempt to thwart the second-hand market for their devices? Is the binding to the online account permanent, or maybe it requires unbinding the previous account first?
I wouldn't mind going back to where I started and using Tomato again, so I was curious what major thing(s) they've done in the last 10 years and why you would chose Tomato over dd-wrt or openwrt.
As far as I know the choice is constrained by the SoC in the device you have (or are planning to get): generally, Tomato has better support for Broadcom devices, and OpenWRT works better on Atheros. DD-WRT should be more balanced in this aspect. (And predictably, open-source support for MediaTek devices is the most patchy.)
I haven't really used Tomato. Between DD-WRT and OpenWRT, the former is arguably easier to set up (through the GUI), while the latter can offer more functionality (with no hardcoded settings and a huge repository of installable packages). OpenWRT has higher memory and storage requirements though.
I get this with videoconferencing too (webex, teams), where the app starts downloading and the ability to do what you want (use the browser) is hidden or delayed until you've failed.
I wonder how many people installed the app thinking it was the only option now. I assume a lot of people. Or how to increase your install numbers with that one weird trick.
Very sneaky.
This is the dark side of the "update culture" --- forcing you to take all the things you don't want along with the bug fixes. Aided by dire security warnings of not updating, it's a perfect way to achieve control over your userbase.
If you can get the switch vendor to release a GPL archive (which is often a struggle in of itself) I have never seen them release the source code to manage the switch ASIC. That's always built as an out-of-tree module which is not released as part of the GPL archive.
Many switches are not even running Linux, it's quite typical to see eCos, VxWorks, or an RTOS (e.g. ThreadX) on a switch.
tl;dr - even if the switch runs Linux (many don't), it is very unlikely you will have the datasheet and/or reference implementation for managing the switch ASIC
Could you clarify what you're claiming here? The obvious interpretation seems far fetched.
It requires access to location, and phone settings or the app closes by design.
I don't think this stuff stops without legislation.
The app provides some benefits, but they're not required.
All those "* by using this free trial you agree to pay 19.99/month for at least 24 months" scams went away basically overnight.
The key to this is not to be afraid to aggressively add new dark patterns to the list of banned practices.
An alternative would be aggressively hitting scammers who clearly rely on people missing the fine print with criminal charges for fraud/extortion (when they try to collect on the non-contracts). No idea why that wasn't done - the legal system is usually a lot more resistant to the "well, TECHNICALLY" thing than engineers think.
Germany is really good about these rules. For example, a long list of practices, including mandatory arbitration, is explicitly forbidden (or forbidden in standard contracts) in § 308-309 BGB. § 312j BGB mandates clear disclosure that and what you're about to spend money on. The whole set of § 312-someletter is basically "we found another shitty practice and we're ending it now".
The US doesn't care at all, until it's huawei.
The downside of this is that you can' distinguish between apps that just want to use Bluetooth, and apps that are trying to get your device location through location services, and users are trained that "bluetooth app = location permission is legit".
Many people often think the house/life of a software developer is filled with "smart" things, and are astounded when they hear what I use. Maybe the younger ones are indeed surrounding themselves with this sort of predatory "smartness" and couldn't care less about the downsides, but not everyone in the industry thinks that way; sadly, I think those who don't want this crap are a dying breed.
It getting harder and harder to avoid this trash too. I fear it will be normal one day.
Yes. If not only because "cloud" services typically live for only a few years. Then the device is useless.
Tbh, there's nothing wrong with electronics, "smart" doesn't mean it needs an Internet connection.
Those are wear items, just like seals, and would definitely need to be replaced at regular intervals. Replacements are cheap and plentiful.
Tbh, there's nothing wrong with electronics, "smart" doesn't mean it needs an Internet connection
Electronics are more difficult to troubleshoot and specialised parts often become unavailable/rare quickly. I can do and have done component-level repair, but still prefer not to.
I enjoy the convenience of being able to control pretty much everything from bed, with just voice, but I can't get rid of the dystopian feeling that I'm just a "user" of it, but not in control of it.
My fridge just needs to keep my food cool. and I don't need to brew a cup of coffee from the bedroom.
Tech enthusiast: Everything in my house is smart.
Tech workers: The most smart device in my house is a printer and I keep a gun next to it in case it makes a weird noise.
> I don’t think this stuff stops without legislation
I agree, but sadly I expect it would quickly boil down to “click OK to waive all your rights, which you really want in order to make the device actually do what you bought it for”.
Imagine someone hacks their flimsy IoT service and manages to start those 3kW heater elements in hundreds of thousands of washing machines all at once, what that will do to the power grid.
https://git.openwrt.org/?p=openwrt/openwrt.git;a=commit;h=df...
These SoCs are used in a lot of consumer-level switches, so it's a target-rich environment! We're populating a wiki to keep track of it all, feel free to join in if you can help:
It's exactly why I'm leaning really heavily towards Mikrotik for all of my networking gear at home. These types of devices are user hostile, bad for the environment, and set a precedent for a type of world we shouldn't want to live in.
One thing I like about the SB8200 is that if I ever go back to running a "business" connection at home I can have a second IP assigned to the second WAN port it has.
I also plan on modifying the modem to fit into my network rack without a shelf like so: https://www.reddit.com/r/homelab/comments/ft579e/finally_got...
So the actual internal matter a little bit to me as well.
It's in my "never touch again for any reason" bucket now as a result.
So something dumb and performant is what I want. What I liked about the netgear modems is they do have models with a router built in without it being wifi which I would like to use as a failover. But I'll just keep my 2921 around as a failover if my new mikrotik router fails for some reason.
Arris (formerly Motorola) modems have a overheating reliability issue. Especially the Surfboard ones you like. SB6666
Go search online. You'll see.
I've had a number of them do this, and so I avoid their stuff.
But I do plan on modding mine so it's not something I specifically would run into.
" Jonathon Green, a British slang lexicographer who authored The Vulgar Tongue: Green's History of Slang, told me that his favorite rhyming slang word is "arris," which means ass, because it actually goes through more than one round of partially-dropped rhyming. "Arris," he said, is short for "Aristotle," which rhymes with "bottle," which itself is the first half of the phrase "bottles and glass," which rhymes with "ass." So in rhyming slang, "I'll put my foot up your arris" means "I'll put my foot up your ass" "
from https://www.vox.com/2015/2/16/8045999/cockney-rhyming-slang-...
Can't get the journalists nowadays.
Also I'm so sorry but "arse over ass" made me laugh and has kinda imprinted on me, so I'm gonna remember whenever I see "brigandish" in HN comments :-D
[0]: https://www.pcmag.com/news/razer-accidentally-exposed-custom...
I've used Logitech mice since forever, but their quality has taken a nose dive, so I bought a Razor Deathadder. Because everyone markets their products towards 13 year-olds, it's called "Deathadder" and it's stuffed full of RGB LEDs. To disable the LEDs, you must install the Synapse software which is Electron trash, because nobody writes real software any more. And you have to KEEP this software installed, to keep the LEDs off. If you uninstall it, the LEDs come right back on.
So I did what anyone would do: I took a screwdriver and a sidecutter, ripped out the leds and threw them in the trash.
This appears to be for one specific product, a "smart cloud switch" [0] (which comes with a "1-Year Insight Subscription").
I don't see anything to indicate that the product registration requirement applies to any of their other products.
I'd expect (I do not own one of these devices) that configuration without restriction can be done by uploading a modified config file.
Perhaps someone who owns a NETGEAR Smart Managed Pro Switch could chime in to confirm or refute that.
Never again.
I'm still on a now ancient TP-Link router, it works absolutely flawlessly with all the features one might need.
I know newer routers can be faster on stock firmware because of proprietary stuff, but fuck that, if I need Gigabit, I'll use wires. WiFi N speeds are good enough for me.
I assume I just got a dud, but what a dud. It was such a gradual downward slide into being unusable that it was beyond warranty when I finally figured out it was unsalvageable.
Why would I ever want to enable SMB 1.0 (security issues, deprecated) on my R8000. And even then, shares require admin credentials.
IMO this is refund material.
It's also the kind of thing EU regulators pick up on.
All is fine when you don't have internet access, but once you configured it, you'll find out that TP-Link lost access to the config-bound domain and now it's a website full of malware and the config keeps redirecting you there.
And they're still selling these (hopefully with updated firmware)
"Default IP route configuration disappears after reset"
Literally the device's bread and butter and it fails that. Not sure I care about its management interface after reading that.
No more Netgear device for me!
I think you could still make one that doesn’t have that problem, but the memory would limit doing much smart switch work. If any.
It's not immediately obvious what advantage you'd gain by doing that anyway, since you can just buy a white box switch and run your own software on it.
Yes, those are what you'd expect to find in the white box systems I mentioned, and most branded off-the-shelf switch products for that matter. But if that's what you need, I'm not sure what the advantage is to building your own hardware instead of buying one of the ready-made options. It seems like you'd need to have quite eccentric requirements before it was worth seriously considering designing and building a whole system of your own instead.
They have a range of personal/SOHO routers that all run officially-supported-by-manufacturer OpenWRT, and their own UI skin isn't bad (though easy to switch to LuCI if you want)
Reading through their support forums is what sold me on them - their firmware engineers actually pay attention to issues, engage in threads, and respond with patched firmwares.
Charmin declined to comment.
Are they still the laggard in this respect, or have they gotten better?
Netgear has been one of the main companies to go to if you care about using your hardware. They have had a spirited MyOpenRouter community[1] for their systems, with great firmwares & flexibile package-add-ons developed with assistance from their solid-gold readily-reproduceable GPL releases[2].
I just had a somewhat overlong thread about Broadcom chipset routers having headed towards being impervious & useless, resistant to any experimentation, & bereft of open source firmwares[3], & a general trend in wifi of routers getting less & less general purpose & user-centric hardware, under increasingly consumeristic teiring[3]. While hardware alternatives vanish. This news doesn't mean Netgear is going to go totally darkside & cut off the amazing innovation they've let grow under them, but it sure is frightening that it could be part of that wider scary course into darkness & ignorance that wifi seems to be heading down.
Own the means of production. Own the means of communication. Do not stop short, do not accept less.
[1] https://www.myopenrouter.com/forum
[2] https://kb.netgear.com/2649/NETGEAR-Open-Source-Code-for-Pro...
[3] https://news.ycombinator.com/item?id=24521265
Edit: hopefully much ado about nothing; seems this change only applies to their cloud ️ services
> It appears the registration is only required for "cloud" features managed through Netgear's subscription service.
> product registration is required to unlock full access to the local browser UI.
Emphasis mine.
You can use it like a phone at that point - you can send text messages and make calls, but I don't believe you can install any apps.
That said - you must go online - turn on cellular data or wifi before you can use the phone, it must be "activated". And apple phones home a lot.
I see this sort of claim often, but reliable information about the specifics is hard to come by. Can you share any?
It contacts a whole slew of apple and 3rd party sites. the main one is that it contacts *.ls.apple.com all the time (location services) even with location services turned off. lots of other apple sites. third party is akamai all the time, but also sites like phicdn.net and att.net (I have an at&t iphone). I do not have any at&t app installed.
on macos catalina, you can (currently still) run little snitch and all kinds of services start contacting apple. and new ones have shown up like touristd and rapportd. Every time you try to pull up a help page. Every account you configure, apple based or not. sigh.
I worked with software update mechanisms and they are an essential part of every IoT product. They are needed to supply the product with security updates and consumers should be trained to allow for automatic updates as maintaining 20 devices is not something your average user will do manually. Or at least to install updates when they come along.
This just fucks the consumer as it includes a massive inconvenience. What's going to happen? They won't install the update as they don't want shit forced down their throat. But the bad taste stays, and instead of installing a risky update on other devices or investing the time researching, the consumers will just keep them at the current software state.
Thanks Netgear for fucking a whole industry.
For a company on the other hand you might want to have secure systems not connected to the Internet at any time.
In my case, I perceived this as a signal that Microsoft was interested in monetizing my data when playing video games (e.g. schedule, hours spent, progression, overall cognitive capabilities, etc.) to third parties that will use this data without my informed consent (not to be confused with the consent given to Microsoft to "share with partners").
I still find this totally unacceptable today.
So, what is the problem? You got, what you payed for. ;-)
If you want to have a product with local management, then buy another one without "Insight" capabilities, e.g. one of the "Standalone Smart managed Pro" line:
https://www.netgear.com/business/products/switches/smart/sta...
https://kb.netgear.com/000061174/What-features-of-my-NETGEAR...
And here are the features of the cloud service:
There's no cloud features involved. You have to register online just to use all the features of the switch locally.
From what I'm reading, it seems like you're required to register some devices or their functionality will be reduced, and then if the device can also be managed through the cloud interface (regardless of whether you actually want to be managing it that way), it will count against the free device limit (as long as you register it under the same account).
However, it also looks like these products were advertised as such from the start. I previously thought that this was forced upon the users through a firmware update.
1. https://kb.netgear.com/000048452/What-devices-can-I-discover...
2. https://kb.netgear.com/000053256/What-Insight-subscription-p...
3. https://kb.netgear.com/000053255/What-countries-and-currenci...