Anecdote: once I bought the cheapest router I could find online. The idea was to test connecting to a crap AP. Unfortunately the cheapest was a TP-Link and it worked absolutely perfectly, ruining my test plan.
Anecdote: once I bought the cheapest router I could find online. The idea was to test connecting to a crap AP. Unfortunately the cheapest was a TP-Link and it worked absolutely perfectly, ruining my test plan.
Another thing I've noticed is companies tend to still sell their models which are close to EOL on their website. Something needs to be done about that.
Selling models close to EOL or trying to hold hardware makers responsible for firmware security has been an issue for decades.
If this is actually the case then you should contact the FTC because Asus under an order to pay attention to security:
* https://www.ftc.gov/news-events/news/press-releases/2016/07/...
I have an Asus RT-AC68U that I bought ages ago that's still getting regular first-party firmware updates (plus the ones from Merlin). Currently using ISP-provided hardware, but given my past experience I'd definitely look at Asus as an option if I needed a new router.
As far as my TP-Link router, I think I remember it being stuck on a 2022/09 firmware until at least 2023/09, and I wound up flashing it with OpenWRT earlier this year.
* https://wikidevi.wi-cat.ru/ASUS_RT-AC1200_series
The V2 seems to be exactly the same except for some minor chip revisions (e.g., -DAN vs -AN), perhaps due to OEM part availability.
OpenWRT also supports (supported?) the V2:
Google and Amazon are full of spyware. I feel I have nowhere to run!
Another option is the recently released official OpenWRT One.
I do like that I can export my config as a script. Haven't had to reboot it yet, excluding firmware updates of course.
I switched to Ubiquiti EdgeRouters for a while but they went the way of the dodo too, so now I use a Protectcli box running Coreboot and OPNSense; it's essentially just a PC with nice Intel NICs that play nice for networking in a small fanless form-factor that you can install a routerOS on (pfSense, OPNSense etc) and always be up to date.
I own one dlink router I bought in 2014. Has been running since then. 0 updates.
What "update" should I give my router ?
Forgive my ignorance
Your D-Link router from 2014 likely stopped receiving updates within 2-4 years of its manufacture so updating now will still leave you quite outdated, if the manufacturer released any updates at all (and if they did, they may even have pulled them offline as we're now 10 years after the fact).
If you're concerned about the security, you can check if your router is supported by an open-source OS like OpenWRT and flash that over the factory software, or upgrade to a newer model (bearing in mind another consumer router will only get you a few short more years of updates).
If you're really cautious (like I am) you buy something that you can install a router OS on that you know will always be updated; pfSense, OPNSense, OpenWRT, Vy etc.
This link is from a quick query on dlink routers.
https://unit42.paloaltonetworks.com/6-new-d-link-vulnerabili...
Just like any other computer, it can be exploited if vulnerabilities are found and in 10 years it's likely some have been found.
Unfortunately, it's likely that dlink stopped providing updates for your product which leaves you with three options:
1. Ignore the problem
2. Install something like OpenWRT if your hardware is supported
3. Purchase new hardware
Old version works fine.
The FTC went after (Taiwan-based) Asus for security reasons:
> After a public comment period, the Federal Trade Commission has approved a final order resolving the Commission’s complaint against ASUSTeK Computer, Inc., charging that critical security flaws in its routers put the home networks of hundreds of thousands of consumers at risk.
* https://www.ftc.gov/news-events/news/press-releases/2016/07/...
So 'legitimate' security concerns have been a thing in the past.
Routers as the gateways into all sorts of networks, and they see/control all of the traffic in and out and often between devices on the network; they're a critical junction.
Some TP-Links are not great -- get a first gen C7, IIRC.
Two things can hold true at the same time. A US company selling US equipment and US software can have US law enforcement agents show up and point US guns at them for non-compliance.
But that in turns sets up a captive market where the US players in the market are more likely to perform collusion and raise prices.
Unless you are willing to re-flash their hardware with third-party firmware such as DD-WRT or OpenWRT, I would always encourage anyone to go with a company that keeps their firmware up to date, like Ubiquity.
It’s not their hardware. It’s their firmware which is the problem.
The nefarious, evil purpose of the cloud service is…just lock in. And being easy to configure.
From there, they can force ISPs to contact their clients to demand the issue be resolved. If the client does not respond to the ISP, the ISP is forced to suspend the connection until the client can demonstrate a fix has been implemented. In all cases, that vulnerability vanishing has the ISP updated so the client is no longer in danger of being pestered.
If the product is still being sold in stores, or is not very far past EoL, and there is no manufacturer patch available, those manufacturers must take their hardware back for a 100% MSRP refund, or provide an equivalent router without those exploits.
It’s only if the product has been no longer manufactured for a minimum set period of time - say, 7 years - that it is deemed “too far past EoL” for the responsibility for patching/replacing to fall on manufacturers, and responsibility finally falls to the consumer to replace/upgrade.
In all cases, a customer can “fix” their router with third-party firmware such as OpenWRT or DD-WRT, but this also requires laws to be written that forces manufacturers to not hardware-lock their routers, and force them to meet the minimum storage/driver-availability specs these third-party firmwares need.
So you have a router built with Chinese components (all of the ones anyone here can afford) with closed and "open" firmware built by them. I bought one of those GL.inet "open" routers and the WRT packages bricked it, so I have a choice of reverting or flashing from the factory (which appears to be a link to HK).
That's probably 99.99% of use cases. They're in your base and they always have been.
Say you know nothing about router firmware without saying you know nothing about router firmware.
OpenWRT and DD-WRT and other open-source third-party firmwares are THIRD PARTY firmwares. They have no connection with the manufacturer whatsoever.
> WikiDevi URL: https://wikidevi.wi-cat.ru/TP-LINK_Archer_C2_v3.x
Every one had a .ru domain. How do you know, exactly, who built it? GL.inet builds their own WRT package. It's a "feature".
Brand-new to the Internet, are ya?
Just because you cherry-pick Russian informational sites doesn’t mean that third-party firmwares have any connection to Russia whatsoever.
Third-party firmwares are open-source projects, worked on by tens of thousands of volunteers from around the planet, and frequently have ZERO CONNECTION to any one hardware manufacturer.
There are some collaboration efforts, when a particular manufacturer decides to adopt an open-source firmware as the exclusive firmware for their own hardware, but that simply means the hardware is fully unlocked for any third-party firmware that wants to be adapted for that hardware. These manufacturers just decided that they had no desire to f**k over the consumer by locking them into custom-made firmware.
For example, I believe Turris https://www.turris.com/ takes a stock, latest copy of OpenWRT and makes a few tweaks to extend its capabilities for additional, server-like features.
WiFi NIC firmware is a much smaller attack surface than the whole Linux OS.
Congrats, you have just identified DD-WRT and OpenWRT.
> The WiFi firmware is closed-source and comes from the silicon vendor rather than the router OEM: Qualcomm, Broadcom, or Mediatek, not TP-Link, ASUS, Netgear, etc.
Never heard of the term “driver”, have you? Look it up. It’s wild. Windows uses them, and so does Linux and other operating systems like DD-WRT and OpenWRT.
> Never heard of the term “driver”, have you? Look it up. It’s wild. Windows uses them, and so does Linux and other operating systems like DD-WRT and OpenWRT.
Please don't post with this kind of attitude, especially when you're so thoroughly wrong.
Look up the term "application processor"; I mentioned it previously but you must not have recognized that it was a concept you are unfamiliar with. This is the ARM (or formerly MIPS) processor that in a router will be running Linux, or on a phone would be running Android or iOS. The AP's CPU cores are not the only processor cores that will be found in the system. Separate from the AP and often at the far end of a PCIe link (and hopefully also an IOMMU) are the WiFi NICs, which have their own embedded processor cores. These embedded cores are not running Linux and instead are running proprietary firmware that is closely tied to the specific hardware. (In a phone, the cellular baseband will have its own processor core(s) running separate code from the AP's OS.)
Linux has its drivers for the WiFi NICs, and those drivers run on the AP cores. Typically, the first responsibility of the Linux driver is to retrieve the correct firmware from storage and transmit it over PCIe to the WiFi NIC so that the processor cores embedded in that NIC can boot up and start running that firmware on cores and a memory address space that is completely separate from what the Linux OS on the AP can directly interact with. The firmware must be uploaded to the NIC by the AP because the NIC typically doesn't have flash memory to store its own firmware, only volatile RAM, and because the firmware version usually must be precisely matched to the driver version running on the AP. This is in contrast to eg. SSDs, which store their own firmware (because they naturally have plenty of non-volatile storage) and expose standard interfaces for drivers to interact with rather than having tight version coupling.
Exactly what the firmware running on the WiFi NIC does will vary between devices. It can often be inferred by inspecting the Linux driver to see what it doesn't do on the AP. Common functionality handled by firmware running on the NIC includes selecting transmission rates and power levels, and handling frame aggregation.
You can readily inspect the filesystem of an OpenWRT image and you'll find the binary blobs that are the firmware which will be sent to the NICs as part of the Linux driver initializing. What you won't find is that binary blob code executing on the AP in any userspace process or kernel thread.
And if you're still arrogantly confused: the WiFi firmware is not the same thing as the Linux driver. In all WiFi hardware that uses firmware running on the NIC (which includes all WiFi hardware supporting anything newer than 802.11n), the WiFi NIC's firmware is closed-source. This is independent of whether or not the Linux driver is closed-source, because the Linux driver is a different piece of code running on a different processor.
All WiFi devices that have received the Free Software Foundation's "Respects your Freedom" certification are limited to 802.11n because those are the newest devices that don't run proprietary blobs on their own processor cores. OpenWRT has looser requirements and tolerates proprietary blobs as long as they don't need to run on the AP as part of the Linux system. The typical setup for an OpenWRT device is an open-source Linux driver communicating over PCIe with closed-source code running on the WiFi NIC.
The Candela Technologies page I linked to is an example of closed-source firmware to run on the WiFi NIC, paired with an open-source Linux driver to run on the AP. This is one of the few examples of the closed-source firmware not coming directly from the creator of the WiFi chip. Both the WiFi firmware and the Linux driver had to be modified in order to add the features Candela Technologies needed. They were able to acquire a license from Qualcomm to modify and redistribute the WiFi firmware, but not to open-source that firmware. The Linux driver was already open-source so no special license was required for that side of their feature enablement.
Eventually i got through to a human that said you can't run it without registering it. it did NOT say that on the box.
shit like this is what the ftc should crack down on
Ebay, aliexpress, reshipper, friend in europe...there is always a way
Routers are going to be a bit more expensive and a bit less reliable for a while. We'll live.