New FCC Rules May Prevent Installing OpenWRT on WiFi Routers?
cnx-software.com
cnx-software.com
This is a misunderstanding. The FCC has not tried to ban Wi-Fi device modding. What it might be requiring is locked-down radios. And only radios.
The phrasing of the recent guidance is unfortunately ambiguous, and calls out DD-WRT by name. But the original rules are clear [1], and staff guidance cannot trump Commission rules.
What's more, an attempt to ban third-party software would be inconsistent with the FCC's previous policy. The agency fined Verizon, for instance, when it tried to block third-party tethering apps [2].
[1] https://apps.fcc.gov/edocs_public/attachmatch/FCC-14-30A1.pd...
The software must prevent the user from operating the transmitter
with operating frequencies, output power, modulation types or
other radio frequency parameters outside those that were approved
for the device.
[2] https://www.fcc.gov/document/verizon-wireless-pay-125-millio... Manufacturers must implement security features in any digitally
modulated devices capable of operating in any of the U-NII bands, so
that third parties are not able to reprogram the device to operate
outside the parameters for which the device was certified. The
software must prevent the user from operating the transmitter with
operating frequencies, output power, modulation types or other radio
frequency parameters outside those that were approved for the device.
Manufacturers may use means including, but not limited to the use of
a private network that allows only authenticated users to download
software, electronic signatures in software or coding in hardware
that is decoded by software to verify that new software can be legally
loaded into a device to meet these requirements and must describe the
methods in their application for equipment authorization.For many devices, however, the practical result is likely to be the same as an outright prohibition on software modifications. Manufacturers of devices for which there is limited market demand for compatibility with third-party software have few incentives to incur the extra costs and certification risks of designs that provide for tamper resistance only where required, rather than for the software and firmware as a whole.
The situation in Verizon is distinguishable because the handsets involved were already designed to support third-party applications with limited privileges, and also because Verizon was a Block C licensee with network access obligations, not an equipment grantee.
So OF COURSE regulators should consider ways in which their reulations might cause unintended harm. This is a major reason why US Federal regulators almost all have mandatory public comment periods -- third parties might be able to point out some of these unintended consequences. Regulators might not always make the right decision, but they should at least be making informed decisions.
The attitude should be "We considered that possible outcome and the benefits outweigh the harms (or not)", rather than GP's "well that shitty outcome sucks, but guess what? Not my problem".
I honestly cannot believe the idea that regulators should be considering both positive intended and negative unintended consequences of regulations is controversial.
Look at item #2 under "Third-Party Access Control" which states a home router manufacturer must answer this question: "What prevents third parties from loading non-US versions of the software/firmware on the device? Describe in detail how the device is protected from “flashing” and the installation of third-party firmware such as DD-WRT."
What they're doing is requiring home router manufacturers to claim their device cannot be flashed to gain FCC approval. Theoretically, the FCC could penalize router manufacturers that allow their routers to be flashed. These manufacturers would then no longer be allowed to sell their devices in the USA.
I don't think it's particularly far fetched.
I'm unsurprised, but do you have a link for that? I'd like to read more about it.
So who pushed?
While I like DD-WRT, if you can flash DD-WRT you can flash anything, and arbitrary code breaks all possible chain-of-trust models.
The FCC has a long history of moving for more restricted hardware as a way of regulating the airwaves, one of its chief jobs. As a ham & commercial radio operator it drives me up the wall, but I understand why they do it.
No. The code I get on my router from the store is an arbitrary closed source buggy crap.
The code I load from debian, openwrt, etc. is far more trusted.
Obviously the FCC does not care about who you trust.
Your point is corporate code sucks.
Oh yeah, also. It's pretty settled case law that your first amendment rights do not apply to broadcast radio signals.
If I am not mistaken these are some of the "features" of DD!
Given the overcrowding of the 2.4GHz spectrum, I suspect that people were starting to use DD-WRT to run on Channel 14, which is a no-no in North America.
[1] http://www.geek.com/news/satellite-radio-worried-about-wi-fi...
I don't know of any WiFi chips that explicitly allow you to go below channel 1 (I know of a few that would let you go below if you twizzled the PLL directly, but generally that was very hackish) and they certainly never test there.
Whereas, nobody designs a WiFi chip that doesn't actually go to Channel 14.
No policies like this are made with the expectation they'll stop everyone. They just want to raise the barrier sufficiently.
Which doesn't help you all that much in replacing the firmware.
It's the bureaucratic equivalent of Apple's habit of inventing new proprietary Torx screws, which keep users out of their gadgets for the 2-3 weeks it takes the Chinese to come up with new screwdrivers.
> To whom is the UI accessible? (Professional installer, end user, other.)
What professional installer? Consumer routers are all set up so the user configures it. Making the distinction between the end user and the installer sounds like the way DOCSIS locks the firmware of cable modems so the network operator has complete control over it.
I also wonder if this is the part of the FCC's plan to put data in the white space of other bands. The argument has always been that it's too difficult to coordinate all the different radios to prevent one accidentally transmitting where it isn't supposed to. But sending out frequency maps is easier when you can limit the number of different radios to just a few authorized vendors.
We propose to modify the SDR-related requirements in Part 2 of our rules
based in part on the current Commission practices regarding software
configuration control. To minimize the potential for unauthorized
modification to the software that controls the RF parameters of the
device, we propose that grantees must implement well-defined measures to
ensure that certified equipment is not capable of operating with
RF-controlling software for which it has not been approved. [ . . . ]
We seek comment on these proposals.
-- http://transition.fcc.gov/Daily_Releases/Daily_Business/2015...Anyone interested should file public comments with the FCC in ET Docket No. 15-170 by August 16: http://apps.fcc.gov/ecfs/proceeding/view?name=15-170
It now says "Not Found"
How did you derive this date? It does not say it anywhere on that page.
The only thing I could find is that it says "Comment Date: (30 days after date of publication in the Federal Register)"
It seems like the date will be 30 days from tomorrow based on this: https://www.federalregister.gov/articles/2015/08/06/2015-184...
This goes far beyond the standard limitations of restrictions preventing people from innovating. It directly inhibits their ability to protect themselves or avoid conflicting interests between the manufacturer and the user (example: many wifi routers are now, without consent of the household, public access points). Especially if firmware is going to remain closed source (I see no reason why it wouldn't), this is troubling news.
Hi! I'm writing about the regulations described at https://apps.fcc.gov/oetcf/kdb/forms/FTSSearchResultPage.cfm...
I personally use OpenWrt on my home wireless router because it provides more capabilities than the firmware that came pre-installed. It also has a consistent interface, so I didn't have to re-learn how to configure my router when I upgraded. This gave me a lot more choice when upgrading—I didn't have to worry about staying with the same manufacturer to avoid loosing certain capabilities or having to learn a new interface. Also, OpenWrt, being open source, encounters far fewer vulnerabilities than manufacturer firmwares, and existing vulnerabilities are fixed quicker, meaning my home network stays more secure.
Not being able to install OpenWrt on newer devices will make setting up my home network far more frustrating the next time I upgrade my hardware. And on a broader scale, it'll stifle competition—upstart manufacturers will have trouble selling their solutions because businesses won't want to migrate to new software. If OpenWrt eventually becomes defunct because no new devices support it, then the situation will be even worse, because new manufactures won't have a reference point to base their firmwares off of. So these new regulations are actually very anti-competitive given the place open-source firmwares like OpenWrt play in the market.
Allowing end-users to install open-source firmwares is really important. Please reconsider your regulations against it.
The government lets me own a semi automatic rifle but I can't run non-standard firmware on my router because I might hurt someone.
Some HAMs use hacked routers to implement "broadband hamnet" (http://www.broadband-hamnet.org/) ... theoretically they could transmit from one of these routers at 1500W (in practice much less I presume, and the rules say you have to use the minimum power necessary) ... this regulation would effectively strip them of devices and force the use of devices blessed with a "SDR" label, if I understand it correctly. Facepalm for the masses.
And don't forget the billions of wifi devices already out there that aren't subject to this restriction...
I really don't know what or who they are trying to protect.
If we let this happen, they will continue to roll more and more things into their regulatory sphere. It's almost a law of nature. Eventually they will tell SDR owners that they need a 'license' (because bla bla safety).
The same "logic" will be applied to other gadgets. Open source cars, open baseband, and ultimately, open brain implants. Casualties in the war on general purpose computing.
The more "dangerous" WiFi modules are probably not router chips, since they are usually based on closed-source drivers/firmware, but rather ones like the ath9k ones.
Possibly the only good thing that this will accomplish is the emergence of open source hardware/software "routers".
Edit: And the possibility for purposeful maliciousness on the part of the baseband manuf. And after all, all a closed system like a baseband does is increase the cost of replacing it. It might be out of reach of you and me, but is it out of reach of everyone?
There's nothing odd about rejecting a compromise when there's no validity to the demands.
If we had made that assumption in the past, the clipper chip[1] would have been a "success". After all, the NSA doesn't care about software freedom either.
I don't think that is a good idea.
Right now, not all control is given to the WiFi firmware (where it exists), but I don't expect the situation with regards to WiFi firmware and open source will improve at all with the FCC adding more requirements.
You could have, for example, an OS that ships the source to its baseband firmware as part of it, where the baseband firmware has a deterministic build process that produces an object SHA-identical to the signed blob, assuming the signature is out-of-band.
With such a setup, you wouldn't be able to replace the firmware yourself on a production device... but you'd be able to modify the firmware source, submit a pull request, and determine that your change made it into the next version of the blob by doing the deterministic build yourself. Basically exactly the same idea as verifiable release binaries for things like Tor.
...oh wait, are you referring to the models that only sell in china? or did the models that pass FCC also did fail?
When routers are insecure and could be easily updated over the internet by a malicious entity, one could imagine a scenario where a state hacks a lot of routers and tries to cause as much interference as possible.
Don't try to enforce hardware behavior in software, especially if you're concerned with security. Instead, enforce limits on power and channels in the hardware itself.
Of course, the FCC won't do that because it will cost manufacturers money on region customization. And screwing big companies is harder than screwing consumers.
IMO FCC is the one abusing the spectrum by allowing it to be "owned" by private companies that "buy" huge swaths of the spectrum and never develop it, it just sits there unused for decades at a time.
Spectrum belongs to all persons, it should not be "owned" by a few huge companies
The limitation for local regulation can (and should) be done in the base band, many routers will have (or at least used to have) different base bands for North America, Europe, Asia and "Other World" regions.
The router OS it self knows only how to talk to the baseband but it doesn't handle the RF part on it's own it just own.
DD-WRT doesn't know what QAM is or what beamforming is it just knows how to trigger certain flags in you BBP to put it in a specific mode.
Seems to me that all that needs to be done to comply with this ruling is for router manufacturers to ensure that the baseband complies with US regulations and that you cannot unlock these features with software which should be easy enough to achieve by just having a dedicated version for the NA market if they don't have it already.
And it's not like it's new I've only seen a few routers that DD-WRT allows you to actually unlock channel 14 in 2.4ghz is only allowed in Japan, even if channel 14 appears in the selections in many cases it won't do anything and either the radio won't work at all or it will fallback to the default channel.
The GPL means that you have a license to do so from the person who owns the rights to the code, but that doesn't mean the government cannot prevent you from exercising that right.
IANAL, but I think it would be reasonably easy for them to get away with this on the grounds that they are "only" preventing activity that is already illegal. (Not to mention that many hardware manufacturers blatantly violate the GPL as it is already).
If you cannot comply with the terms of the GPL, you cannot distribute the GPL'd software at all. If the FCC prohibits you from distributing the tools and information necessary to build the source code as required by the GPL, then you have to stop using that software in your product. The FCC does not have the power to authorize copyright infringement like that.
However, Linus's interpretation of the GPLv2 in that video was only coincidentally in line with the FSF at the time. The goal of the FSF has always been to ensure user's freedoms above all else and I feel the GPLv3 better accomplishes that end than the GPLv2. From the perspective of the FSF, hardware manufacturers discovered a loophole in the GPL which allowed people to ship GPL code while denying users their freedoms.
I understand that for many developers there's a balance to be struck. Some developers don't care how their work is used and the MIT, BSD, or DWTFYW licenses are perfect choice for them, but some developers decide that they want to be sure that not only will they get source code back but also that their work wont be used to harm users and they're the perfect candidates for the GPLv3.
* Evil meaning
GPL v2 wouldn't be violated, per previous.
GPL v3 software isn't used in many places.
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.g...
The linux kernel is GPL v2 and that is the only part they'd really use.
It isn't Fort Knox, but look at how long it took to break the PS3 which utilised a system like this (years). While people may find other ways of gaining root and can subsequently disable this check, it would take third party firmware from "trivial to install" to "a damn pain in the ass."
Heck if they REALLY cared just enable things like SELinux and move a lot of root processes into other users.
While this is probably the most effective route to curb the behavior, it also seems like the most sleazy. If you didn't want DD-WRT allowing non-region channels, why didn't you go after them directly? Probably because the uproar would have been deafening. Instead you go after the router manufacturers because they're easier to control. If you can remove their product from the market, you can instantly curb the behavior.
There's no license to revoke, and I don't think we want to be in a world where the FCC can issue a civil forfeiture for simply publishing code to the web.
The router manufacturers are the FCC licensees, so going after them is the easiest route to compliance.
(The other option, going after users who are broadcasting on disallowed channels or above rated power levels, is practically untenable due to issues of scale.)
Maybe having such a free standing right would be good policy, but it's not current US law.
A couple more steps and Cory Doctorow will be found to be right.
I don't entirely get why people buy new hardware to flash with xx-WRT, although I do get the point for recycling some already purchased gear.
(And btw, Mikrotik's software is nothing special compared to OpenWRT. Hardware NAT support is about all you get last I checked, and it's not worth it.)
3 years ago I switched to TomatoUSB firmware, and since then I power cycled my router to get it to work again exactly ZERO times. It just works. I use default power and band, and I am not using any special features of the TomatoUSB, the only reason I run it is because it's rock solid, unlike EVERY stock OEM software I ever tried.
On a more interesting note, why are stock OEM firmwares so incredibly bad? I mean, there are open source alternatives they can use, or just write there own stuff that works. You would think that a large company like Linksys or Netgear would have at least one programer worth something working for them. No?
Doesn't locking down wifi radios basically outlaw software-defined radio (SDR)? How can SDR exist without infinite control over "modulation types"?
I'm not sure that it is possible to truly lock down a radio to a particular modulation type. Transmitters aren't magic. They cannot be DRMed. They don't even run software. Send them the voltage and they send the signal.
Basically it suggests a flashable device must be classified a "SDR", but FCC jurisdiction does not extend to independent software developers.
https://www.softwarefreedom.org/resources/2007/fcc-sdr-white...
I thought that the linux-wifi people had made some good efforts at regulatory compliance by signing the rules list. While this doesn't nearly make breaking the rules impossible, it makes it enough of a pain to do so that many people won't. The FCC could then go after bad actors who distribute modified blobs with one of those "Notice of Proposed Forfeiture: $25,000" actions the way they sometimes do with CB radio amplifier clowns, rude ham operators, and those pirate FM transmitter hoons who seem to be competing in a contest to demonstrate the worst engineering practices.
The one that talks about preventing loading third party firmware only applies to 5 GHz wifi routers, not 2.4 GHz wifi routers.
The one that applies to 2.4 GHz routers looks like it only requires that software (built in or downloaded) not be able to modify operation to operate beyond the equipment authorization.
Manufacturers of 2.4 GHz routers should be able to achieve that fairly straightforwardly without taking away the ability to run third party firmware.
Not that I approve this new rule - just saying that it's a natural extension of another existing rule.
1) for GSM (and all other 3GPP radio interfaces), regulatory control is completely on the network side. Network says when, where and at what power MS must/can transmit. And significantly deviating from network-dictated parameters does not get you anything worthwhile (except in situations that are totally outside of what normal consumer can reasonably do, like attaching 30dBi directional antenna to GSM phone).
[Edit: 802.11whatever STA radio is also somehow controlled by AP, but anybody can set-up their own AP without specific license and bandwidth allocation to do so]
2) Cellular phones are typically more strictly certified than WiFi devices.
The sad part is that most wifi cards won't even able to see anything on C14 none of my phones or laptops see the network on a router which is confirmed to have an open baseband.
But on most router's I've seen the baseband doesn't actually operate on C14 even if you set it up it just defaults back to it's default channel, 12 and 13 can usually be accessed these days on NA routers as well.
Basically every time you operate on a locked channel you are breaking the law, channel 14 in the US the only one which is flat out forbidden (most likely due to overlap with military communication), while 12 and 13 are restricted.
Would OpenWRT run on the Pi or on the CPU in the WiFi dongle?
Assuming the former, I don't see how there would be a problem here. It is the WiFi dongle that is the certified Part 15 device, and you would not be modifying that device. You would be using for exactly what it is designed and certified for: sticking it into a computer's USB port to provide WiFi access to that computer.