Dump these small-biz routers, says Cisco, we won't patch their flawed VPN
theregister.com
theregister.com
That's not true at all. Divulging data without offering license terms does nothing to hurt your ability to enforce intellectual property rights. The people using that data just do so knowing they're technically breaking the law. Patents are not trademarks.
And in a way, the patent system is exactly about "opening up" technology. After all the idea of a patent is "you tell everyone how to build it, in return nobody is allowed to use that knowledge commercially for X years unless you allow it. This aligns great with "give us the tools to modify the software of hardware you find commercially unattractive".
I've read a lot of modern patents, and not one of them was written to convey useful information. They're all dense legal writing, and as vague as the author can get away with.
Most medium/big companies have patent attorneys whose entire job is writing patents. They don't care about the patents having any useful details to make it a useful reference. Usually the attorneys aren't subject experts on the patent topic, and couldn't make it accurate even if they tried.
Modern patents are a game where you file a whole bunch and then wait for somebody to step on one by accident with a parallel invention. Then you sue them unless they have enough patents to also sue you.
Patents don't promote innovation at all, at least not any more. If anything, they're a tax on our industry and they stifle small players - exactly the sort of person who they're supposed to help.
For patents to be useful they need to be writing in the language of experts in the field -not lawyers. And the law needs to make it best for my employer to make me search for and read potentially relevant patents before doing anything. That is infringing after making an effort to avoid a patent (that the courts decide is not enough effort) is better than infringing without knowing.
https://www.cisco.com/c/en/us/support/switches/catalyst-6500...
If you mean the time between the first day of manufacturing and the end of software patching, it will be higher, but it’s definitely not 25, years. The 6503 (not the 6503-E) went end of hw support in 2012 [1], patching must have stopped a couple of years prior to this, but it’s so old I can’t find the EoL notice for this…
Finally if you mean “time between first day of manufacturing and end of patching”, then the the RV110W has at least 7 years. I can find article listing it in 2011 already [2], end of patching was 2018 [3].
I completely agree on the idea of pushing for open sourcing hardware and firmware when a device becomes end of support, but we also need to get the facts straight.
Headlines like “cisco won’t patch legacy VPN routers” are simply disingenuous and pure clickbait. But they do make me smile =) so it’s not all bad.
[0] https://www.cisco.com/c/en/us/products/collateral/switches/c...
[1] https://www.curvature.com/resources/tech-guides/cisco-6500-e...
[2] https://www.cnet.com/videos/cisco-rv110w-wireless-n-vpn-fire...
[3] https://www.cisco.com/c/en/us/products/collateral/routers/sm...
This seems to be more and more prevalent even in other areas like washing machines, microwaves and even cars. I don't get old parts. Even the service technicians throw up their hands and say "Just buy a newer model".
And when it’s $300-400 for a computer board, you might as well get a whole new machine.
The only way I’ve found to counteract that is to look for commercial or commercial-based units that share parts for years or more. But this can be harder for some classes of equipment ( commercial ovens are NOT at all like residential - they’re usually not insulated) but it can be a start.
But that's nobodies fault, as long as companies are required to release any protocols or specs for interop. You can't sensibly force companies to turn back the clock forever or stay in a business they don't want to be in. You can sensibly force companies to fully describe the products that they sell unless they are willing to continue to maintain them.
If they're required to release the specs of parts that they won't replace, Chinese factories would flood ebay with any of them that they think they can move 50K units of.
I agree that their support is the best of the smartphone vendors, but I would also welcome legislation that opens up hardware for arbitrary software at EOL.
When Apple decides it's done updating the 6S, I should be able to run Android or Linux on it. But they've locked down the hardware so it can only run iOS.
You are literally paying them for being closed source.
Stop rewarding these corporations for screwing you over and they will cease to screw you over. Either they will change their ways or go out of business if enough people feel the way you do. And, regardless, you would have solved these sorts of problems for yourself long before that happens.
It's been a very long time since Cisco was the only game in town for enterprise networking. Companies like Broadcom have released powerful ASICs that allows practically anybody to build a high performance routers and switches.
hyperscalers got into building their own switches a decade ago. whitelabel silicon and software _IS_ available, but the entrenchement is still huge as noone ever got fired for buying cisco.
EOLing a laptop that's hauled around is one thing, or a server with a CPU that's configured to run at the limit of what its cooling system supports. But routers are little boxes that run at very conservative clock speeds and a correspondingly high MTBF, are never moved, never reconfigured, never given new software to run, and to which its users hardly ever pay attention. Five years is unreasonably short for that kind of device.
Incidentally, my own upstream uses a twelve-year-old router. I know where it is but I'm not sure that cupboard has been opened this year.
a five-year lifetime is is business decision balancing customer expectations and maintenance cost (including keeps a hardware stock of these routers in each continent, sometime even in country for specific countries, keep development alive, etc.).
You may say they underestimate the willingness of their customer to buy a new router after 5 years, but they definitely know that a huge proportion of their customers are running woefully out-of-date and unsupported hardware/software.
Same for all on-prem vendors and a major reason why moving customers to cloud is so appealing for so many vendors.
If you buy one of the popular firewalls, you need a subscription for it to actually work. Once it's expired, you lost your web filtering and IPS and whatever 'modules' you've subscribed to using.
A 3 year subscription is often as much as the hardware.
It's kind of a waste, it'd be nice if there was a OpenWRT style firmware you could load on all the old Fortinet, Watchguard, Sophos, etc firewalls out there.
One big company rolls out an anti-consumer, anti-ownership, anti-freedom policy. People get annoyed and some small subset of customers leave, while the rest maybe grumble but stay. Then the next-biggest companies see that the big player is still doing fine with their anti-consumer policy, so they get a little greedy and start doing it too. Then all of a sudden it's a new industry standard, and consumers who value their own freedom find themselves rapidly running out of alternatives.
Maybe if outcry gets really bad, the big corp need to roll back the decision, and either wait for a different opportunity, or let another corporation take the lead, or change the type of policy to be more subtle.
My personal system for evaluating a conspiracy theory is: 1) how big is the payoff? 2) how hard is it to execute? 3) how hard is it to keep secret? 4) how many people need to be involved?
This scenario passes all 4 criteria with flying colors. 1) The payoff is absolutely enormous. 2) It would be relatively easy for the same people who would be most strongly motivated to do this. 3) It should be easy set up a communication system that maintains almost total plausible deniability against collusion, because it actually only requires minimal knowledge of and cooperation between participants and their plans. Just a few meetings among subgroups of participants, and more head nods than spoken words. During the process, active communication can be reduced to basically zero. 4) Very few. Most corporate decision makers at most companies wouldn't have to know, they'll be able to see where things are headed and follow along. In general, the only holdouts will be HN poster types with small businesses that serve only tiny fractions of the market.
So that any user could install anything they wanted and use it as they wish. Including replace components with similars and/or make modifications.
Beyond that, as an example, open apis (for drivers re:hardwwre) are not the same as giving full chip scematics.
But! If the, for example, SoC stopped updating binary blobs, and things stopped working with newer kernels, as an example, then they'd have to 100% open up and provide sources.
People get all rah-rah about the environment, but I throw away pounds and pounds of highly polluting electronics, just so someone can sell me another.
This model need to stop.
I think this is reasonable.
It's unreasonable to expect companies to support old products indefinitely, otherwise they would collapse under the weight of the legacy.
It's also unreasonable to leave customers that bought something, however old, with nothing to fix it themselves.
Ideally also the companies would have to release all this at least a year before EOL for people to be able to get acquainted with the codebase.
"Oh, that's not what you meant ? Well, the others are cheaper so byebye anyway"
For anything smaller that doesn't need that, I don't see the point in buying (new) Cisco hardware.
This is what all the vendors say about their stuff.
Current favourites are tplink-archer-c7, edgerouter-x, asus rt-ac85p ... all of these retail for about $60 and are more then capable enough to route a gigabit at linerate and do stuff like wireguard.
My current favorite small business router is the pcengines apu2 family. I run openbsd on them. but really it could be anything. great little boxes.
I hate on Meraki so much because it's the epitome of something that doesn't need to be a paid subscription except for juicing customers (the hardware is great). Ubiquiti does cloud-managed the right way; you can self host and the hardware isn't bricked if you let maintenance lapse.
At a previous company, we used in the office as the center of the LAN a switch (Cisco Catalyst 3548 XL) which was already past EOL. In fact, it was so long past EOL that the switch model which replaced that model was also already past EOL. And yet, it worked perfectly (other than a couple of failed ports), and we probably used less than a tenth of its capabilities. I wouldn't be surprised if that same switch is still working today; the main reason to replace it would be that it only has Fast Ethernet (100baseTX), instead of the current mainstream default of Gigabit Ethernet (1000baseT).
Cisco branded, but appears not what an network engineer might consider as such; these are Linux-based routers. Cisco routers and switches are based on their proprietary chipset and proprietary IOS/IOS-XR/IOS-XE/NX-OS operating system. Without it, I would rather pick ASUS or anyone else.
Imagine you have to throw out your car after 5 years because the manufacturer stopped updating the software. We are getting there.
5 years is not nice. A large, established company like Cisco, selling devices in an established and very slowly evolving market like routers to companies, should be offering much longer support periods.
Apple supports iPhones for 7 years which I still think is not enough. I think routers for small businesses should be supported for at least double that.
There is physically nothing wrong with these routers. They are perfectly capable doing their job from every possible angle. This is just generating garbage so that Cisco can sell more new hardware that is performing basically the same job.
That's 7 years from launch, not 7 years from end of sale.
Not defending Cisco here, but looking up the RV110W I can find documents for it dating back to 2011, so that's 11 years of support.
For the RV130 I can find an administrators guide that was revised in Aug 2014, so at least 8 years there. probably more given that it's a revision.
Using your argument, you could stop all support right after the devices stopped being sold.
So it was being sold for 15 years and the software has been in support for 15 years and it is old so we stop selling it and supporting it at the same time.
Now hope you are not the person who bought it on the last day...
However, this isn't killing the entire router. Just the VPN functionality. If you don't use that, there's no need to get rid of the router. Just make sure the VPN is disabled, as per the article.
If you do use the VPN, then you should either replace the router or implement the VPN differently. Second-hand, that router is still good for anyone that doesn't need a VPN.
When tech is moving fast, I can understand a short warranty, but I don't think routers are in that category. (Wifi routers are, but I've yet to have a Wifi router that could handle my residential usage of it anyhow. They always end up having problems. I've moved to having an access point separately from a router so at least it doesn't kill the whole network when it gets stupid.)
One of the main reasons to buy these SMB routers over consumer grade devices is usable VPN support. A lot of those small companies use their routers only for Internet access in their offices plus router-based VPN for remote employee, support or admin access to intranet. In a lot of cases it is essentially the reason to choose these devices over anything else.
After all, it's not exactly environmentally friendly for working hardware to get ditched just because of some software turns it useless.
The EOL sucks, but that's what people kinda signed up for with Cisco.
Don't know for how long these routers have been around, but for one of them I found a overview document dated 2011.
Should be same for devices. If not, they should at least carry a "best before date" like food, so you know at time of purchase how long you can expect to get updates.
EOL isn't real, it's made up. Broken or not powerful enough anymore is real. The town crier could decide to blow a trumpet and proclaim "EOL" a week after the last one is sold.
If i had an old product, there's also some point where i'd say "I wont be updating this anymore", as to phase it out. Expecting something to receive active support forever is unreasonable.
> there's also some point where I'd say "I wont be updating this anymore", as to phase it out.
You don't get to phase out my stuff. If you're not going to update it anymore, you've broken our support relationship, so you should also be breaking the hardware and software locks that prevent me from getting support from another source.
But then small businesses like to cheap out and gamble on a device that has a short time of support left and complain when it ends.
This is not a surprise, except if you chose to put on a blindfold yourself. And if you think EOL of 5 years is too short, don’t buy a device with an advertised EOL of 5 years.