Building a freedom-friendly WiFi pocket-router (2020)
kulesz.me
kulesz.me
I find the benefit of a router with you when traveling are;
- More secure (you can set it up the way you want).
- Your device(s) do not need to be configured to work and sync.
- Better wi-fi coverage.
PS. I have no relationship with GL•iNet. They just seem to be the most ideal from all the reviews I have stumbled on so far.
Don't get the Mango (GL-MT300N-V2), it is cute but woefully underpowered for anything but the most light throughput.
(also no relation, just a satisfied customer)
I used to carry around a Huawei 4G router, but it required its own wall wart and couldn't bridge to another wifi. So if the 4G coverage was crap, we had to use public hotel wifis, meaning I had to configure 6-10 devices to use the crappy portaled network.
With the Beryl AX I get:
- Wifi-bridging. The Beryl has its own network, our devices connect to it and I can wrangle it to any public network
- Ad-blocking, global DNS via nextdns, Mullvad VPN, Tailscale, all built in and work with just one click.
- Internet failover if I have multiple active connections (wifi + 4g for example
- Standard USB power input
What I lost was the 4G connectivity, BUT it has an USB port and I use an old Android phone with a data plan on it. Used the developer menu to make it always default to tethering when an USB cable is connected and it's pretty much fire and forget.(It's also on sale for around 100€ for Black Friday, well worth it)
Very flexible, i.e. wifi interface and two wired interfaces, and can mix and match roles however you like (e.g. wired uplink & downlink, wifi up/wired down, wired up/wifi down etc), combined with the ability to terminate a VPN on the device.
(Possibly my most silly use was to provide a network connection via a phone wifi hotspot to a wired network appliance).
And size-wise it's about half the size of a cigarette packet. (Yeah - that feels like quite an odd size comparison...)
I'm asking this because the smaller models from them are limited to 32MB flash and 128/256MB RAM, which is way too less for typical AdGuard Home usage.
Personally I'm using some older Linksys WRT 1900AC/3200ACM models for my malware homelab and for the 1900AC the AdGuard daemon is constantly OOM once a few blocklists are selected.
Does anybody maybe know whether there's a fork that uses less memory and skips all the statistics and stuff that you won't need?
If you represent LPM tries as JSON and order them by alphabet, you'll get even benefits of gzip on HDD to save lots of space. Just a suggestion and how I would implement it with an eBPF module, not meant as a critic.
I've used their other products (convexa) and was pretty happy about it.
The creta travel router offer power over ethernet too.
On the topic of GL.iNet. I have had a good experience with their customer support as we tried to work out some issues likely related to hardware. They were patient and allowed me to swap between routers until we got it to work. Oddly the final solution was to put an unmanaged switch so that we had two switches separated by about 30 metres of Cat 6A Ethernet cable, rather than plugging it straight into the router. According to the specification, this should not be an issue from what I can tell. Still, given how helpful and patient their support were, the whole experience still leaves me as a happy customer - despite the obvious hack.
It has replaced the modem/router that my ISP gave me. I still use this modem/router with the Gl-inet which is set up in bridge mode.
It's stable. No WiFi flake outs. The only time I have had to reset it is when I have updated the firmware.
Eventually I plan to switch to a pfsense based router and use the Gl-inet as a wifi access point when at home and a router when I am abroad. This way all my WiFi devices will work seamlessly.
2. Connect to the Wi-Fi, but run your own DHCP in the router to distribute your IPs to your devices.
References;
- https://www.monoprice.com/product?p_id=44504
- https://store.ui.com/us/en/pro/category/accessories-cables-d...
Otherwise you can usually set up a router to bridge one WiFi network to another. Sometimes the captive portal screen just works on your computer that you're connecting to your own router. Other times you can sign in while connected to the hotel WiFi, and then clone your machine's MAC address so the network thinks the router has already signed in.
My favorite hack is bridging a congested hotel 2.4GHz network to my own personal 5.8GHz network, which benefits everyone if you are a family about to light up 5-10 more devices.
The WiFi-to-WiFi bridge isn't always very efficient, especially if the router has to multiplex the two connections using a single antenna, but speed isn't always the top concern.
I do the same thing. It's failed only once: the /24 address space in my "internal" network was the same as the /24 used by the hotel's network and I didn't think to chrck. I brought down the hotel's router.
Depending on if the NAT configuration in the router is fully correct, it should even fully work if both are the same.
I wish we had open source modern lte hardware, but it's not just that we haven't got any open source stuff. There is barely any commercial stuff either. Qualcomm seems the only company I'm able to find that makes lte cat 20 hardware, let alone cat 24. I wonder why. Wouldn't open source hardware projects like limesdr have the resources necessary to deliver it? (there is an fpga on board).
Likewise with WiFi 6 and 7. But here were talking about high frequencies so I can understand a lack of open hardware.
Because Qualcomm is the main supplier of modems for nearly all devices in US, and nearly all flagship devices and LTE-routers globally.
It's nearly impossible to compete with Qualcomm on pure modem-chipset pricing, because:
1) The sheer volume of chipsets they produce
2) The fact that their modem firmware of those few-dollar component is largely validated (and paid for) by Smartphone device manufacturers and carriers when they launch their 800+ USD Premium Smartphones with the same modem.
3) Qualcomm's iron grip of patents and manufacturer contracting practice
Few have tried over the years, including juggernauts like Huawei, Samsung, LG. All failed.
Add on top Apple.
The only ones who did succeed are Mediatek with their bottom-of-the-barrel stuff... wonder how that is possible.
I'm not aware of Mediatek competing with LTE modems for routers, not even low-tier. I'm aware they are trying again now with 5G, but also here I'm not seeing big tractions for commercial products...
Could you name an example device or chipset of a Mediatek-based LTE-router?
[0] https://teltonika-networks.com/de/products/routers/rut951/
[1] https://www.mediatek.com/products/tablets/mt8735d
[2] https://benchmarks.ul.com/hardware/tablet/Lenovo+Tab+7+Essen...
- The second example MT8735D is a tablet SoC (not just a modem but also a CPU, GPU, Audio DSP, Camera ISP etc in one package)
[1] https://www.mediatek.com/products/home-networking/mt7628k-n-...
Open source baseband firmware and hardware projects exist but, even if a LTE baseband firmware and hardware were to be developed, you wouldn't be able to use it outside of a Faraday cage unless you spend lots of money getting it certified.
Unlike WiFi, LTE allows quite high latencies, so the host computer can do all computations, no real need for FPGA code.
For WiFi you have OpenWiFi: https://github.com/open-sdr/openwifi It currently has 11ac support and WiFi6E is in development. Operation on 2.4GHz can be a bit confusing due to lack of 11b support but on 5 or 6GHz it 'just works' (though note lack of DFS support).
Just some napkin math, Apple had 232M iPhone sales in 2022. If Apple paid USD 8 (low end estimate) per iPhone sold, that would be USD 1.8B just for 2022. If I were Apple, I'd gladly spend USD 2B a year if that meant I would not have to pay Qualcomm USD 1.8B
My guess is this work is actually difficult especially given all the patents/royalty traps you'd have to avoid and not something people have not simply gotten around to doing.
We don't need that; if our data is encrypted the modem hardware sees only noise passing through. Yes, it can know who we are speaking with or which address we're connecting to, but that information would be already known by the carriers anyway and shared with whoever has the power to tell them to. All we need is Free and Open Source Software and Hardware outside of the modem, so that our data can't be intercepted before it is being encrypted or after it is being decrypted - think about a malicious app intercepting where you tap the screen so that it can read all your passwords even before they're fed into some app or a browser code. Now think what would happen if this malicious code was built into the screen driver itself, or the storage driver for data that comes encrypted but is being decrypted to be read and stored by the user. We badly need open source everywhere, but asking for it in radio hardware is a lost cause; carriers will never open up their devices, and for a very good reason.
The company noticed that 1) folks were upgrading storage, and 2) hackers were adding pins so they could connect to the serial port. They then modified their production to include both of those hacks. They called it the "6416".
I've gone on to buy many of the GL.iNet devices. I take a Brume with me on travel. Their built-in software (OpenWRT with a custom WebGUI) is so handy that, despite knowing they have anti-features built in, I just use it as-is. I normally use it's 802.11ac radio to connect to the hotel, and copper Ethernet to my machine. But with dual antennas, you can also connect wirelessly without going half-duplex.
That DIY 6416? I use it as my home WAP, configured as a bridge to my central switch. It's been running 24/7 since 2015 or so.
GL.iNet also make an open-source hardware design. So if you're uber-paranoid, you can build your own.
Can you elaborate on that? I am on version 4 and don't see anything hostile. And there is always luci if you need something more advanced.
Not that I'm not a big fan. These things are exactly what I need for travel. And my company sends me places with iffy Internet connectivity, so I have found it incredibly useful to have a tiny device which can set WAN to be wireless, wired, or cell-modem. I used to wipe it and reload with OpenWRT.
When you find a company who sees what users are doing (like populating the serial port), and that company changes their device to do that by default, you've got someone who actually cares about customers.
The problem, really, is China. Just like Russia, China has laws requiring full cooperation with the MSS by all electronics manufacturers. So I just assume breach, meaning my devices are either back-doored at the factory, or are sigint-ready just by pushing out a new system image. If they have your device ID and external IP address, they can probably target specific people who are high-value.
Just to be fair, the NSA has been caught fiddling with crypto to make it "sigint ready". Snowden showed photos of NSA re-boxing Cisco gear (where do you suppose they got that Cisco-branded anti-tamper tape?) Everyone spies; it's just a fact of life.
I also hear about travel usecases for these, even for devices with wireless which I don't understand.
Some cite security, which I don't understand. Which device's security depends on the network to provide security? Are they weak on 4G?
Some cite avoiding captive portals. Are they that annoying that it's worth maintaining and carrying a travel router?
I trust this is just my lack of imagination. Please enlighten. :)
For those traveling with multiple devices, it's faster to connect one router to a transient network, than to connect N devices.
A travel router can VPN back to home network, e.g. via Tailscale, https://www.gl-inet.com/products/gl-mt3000/
But 300Mbps max throughput (2.4GHz, a/b/g/n) on a single antenna (meaning it's actually something like 150mbps down maximum) is frustrating. The 16mb storage also leaves barely any space on the router.
All I want is something that can boot on a minimum draw of 5A/1V -- and appropriately throttles performance down in that environment -- but can take something up to like 5A/3V and appropriately increases performance.
I like it, but I wonder if I want to carry it when I go carry-on only in Europe. I guess most people will trade some privacy and inconvience for weight- and cost-savings.
If you have a non-artificially-limited android phone (i.e. rooted), you can just open a hotspot with everything going thru your wireguard vpn back to home.
If you have stock android or IOS, then the real owners of your device won't allow you do this, since they get location data from your network on all those devices.
They also have a tiny, less powerful unit (mAP) that may fit with some travel use cases.
Mikrotik's product names are sufficient to uniquely identify them and easily searchable. This differs from many hardware vendors, so your question was reasonable, despite already having what you asked for from the prior poster.
The article says that there was already an item that could fit the bill (one of the ThinkPenguin mini-routers) but was out of stock. Sounds like a supply chain problem to me.
>and this board doesn't look like any Raspberry Pi anyway, so it's not a knockoff.
This is false, all SBCs are RasPi knockoffs. /s