9 ms·
TP-Link firmware sends six DNS requests and one NTP query every 5 seconds
- xamlhacker 9y agoWell I run a TP-link repeater and now thinking of getting something better. Someone know any routers or repeaters with reputation for good firmware?
- ktta 9y agoWhy not use LEDE firmware? It's beats most consumer routers' firmware by a long shot. Search your router's model here - https://lede-project.org/toh/start https://lede-project.org/toh/start
- cbhl 9y agoIf you trust Google, consider buying into Google Wifi mesh routers. If not, consider eero.
- mtgx 9y agoAmplifi HD seems better in terms of range and signal strength.
- Thlom 9y agoThe Ubiquity Unifi stuff looks good and not very expensive.
- gh02t 9y agoSpeaking from experience, it is good. Takes a bit of networking know-how to set it up though, and you still need a router. Their consumer oriented stuff like the AmpliFi is quite excellent too and a bit friendlier. I use an Edgerouter Lite, a Mikrotik switch and UniFi APs for myself and was so pleased I bought the AmpliFi mesh for my parents.
- jagermo 9y agoI have a similar setup, without the switch and the Unifi APs are just excellent. Smooth setup, great range. So, if you can run a cable, I second Unifi. Op, if you can not run a cable, maybe look into a mesh network. Repeaters "loose" about half of the bandwidth anyway, a mesh might be good alternative. If you want to set up an open source enviroment, there is libremesh (http://libremesh.org http://libremesh.org). If you just want to buy something, there are products from Netgear (orbi), Linksys (Velo) or Ubiquiti (Amplifi). If you have a Fritz!Box-setup from AVM, you might be able to use their mesh features (site in German, because if you have a FritzBox, you probably speak German ;) https://avm.de/mesh/ https://avm.de/mesh/)
- danesparza 9y agoUbiquiti also has a line of Unifi mesh gear: https://unifi-mesh.ubnt.com/ https://unifi-mesh.ubnt.com/
- pm7 9y ago> Op, if you can not run a cable, maybe look into a mesh network. Repeaters "loose" about half of the bandwidth anyway, a mesh might be good alternative. Mesh network simplifies setting up many repeaters, but it "looses" bandwidth the same way (unless you connect it via cable/other frequency band) as repeaters.
- dawnerd 9y agoMy entire house uses them exclusively and they’re rock solid (as long as you have latest firmware, adopting old stock can be .... interesting). Also no need for the cloud controller as you can run t inside a docker and have a fully self hosted solution.
- baobrien 9y agoIf you don't want to pay $80 for the cloud key and don't want to run the controller on one of your machines, the unifi service can also be set up on a raspberry pi pretty easily.
- simooooo 9y agoIs the performance ok? I'd imagine it would be slow as heck
- baobrien 9y agoThe Unifi controller is a configuration front end for Unifi devices -- data on the network shouldn't be going through it. It might be a little slower to use, though I've never compared it with the cloud key, but for a home setup, that won't matter too much.
- danesparza 9y agoSpeaking from experience, Unifi is rock solid. I've got 2 Unifi access points and a gigabit PoE switch in my house. Troy Hunt also had a great article detailing his work with Unifi gear as well: https://www.troyhunt.com/ubiquiti-all-the-things-how-i-finally-fixed-my-dodgy-wifi/ https://www.troyhunt.com/ubiquiti-all-the-things-how-i-final...
- simooooo 9y agoJust priced a home network setup. Came to £600
- rebolek 9y agoTurris Omnia is nice router with auto update and strong focus on security. https://omnia.turris.cz/en/ https://omnia.turris.cz/en/
- Asooka 9y agoI've been very satisfied with my MikroTik router.
- alpb 9y agoMy most recent frustration with TP-LINK was they they DO NOT provide their firmware updates over HTTPS. They do not provide checksums for their firmware files either. (When I asked for these things, their support weren't helpful on Twitter.) So you're expected to download some unsigned binary over an untrusted connection and trust that with all your traffic. Definitely not buying TP-LINK next time. Good to know this there's a bandwidth problem like this!
- problems 9y agoWhat makes you think they're unsigned? Surely there's at least some basic checksumming if not cryptographic signatures inside of that blob? There's no reason to even bother with delivering it over https if you put a good signature on the blob itself.
- DSMan195276 9y agoI would assume it does not do those things, or else creating/flashing custom firmware like DD-WRT would presumably be impossible. They could be doing some verification in the firmware itself, but obviously that only saves you from bad downloads - anybody serving you up a malicious firmware can easily just serve one up without the verification checks inside.
- problems 9y agoThis is not the case anymore. https://github.com/xdarklight/mktplinkfw3/blob/master/README.md https://github.com/xdarklight/mktplinkfw3/blob/master/README... Their firmwares for newer devices do indeed include signature support. A malicious firmware on their server will fail the signature check and not be flashed. Signature checks occur only in the flasher, not in the bootloader, but that would require physical access to the device, at which point all bets are off anyways.
- snuxoll 9y agoTP-Link does a pretty good job on basic Layer 3 Lite switches and desktop wireless cards, but the junky software on their routers and repeaters is enough to make me not use them. Unfortunately they do the same thing worth firmware upgrades for their switches as well, no signatures, no hashes, no TLS.
- cthalupa 9y agoI use a TP-Link travel router while on the road to get access for all of my devices in hotels that have device caps, and for my Android TV devices which don't gracefully handle hotel login prompts. I have to say that the convenience, ease of use, and reliability of the product far outweighs any concerns I have over ~715MB over the course of a month. It boots quickly once plugged in, it reliably handles 4-5 devices utilizing it as a bridge for the hotel wifi, and I have never had it crash, give me any sort of wonky behavior, or anything of that nature.
- jsjohnst 9y ago> I have to say that the convenience, ease of use, and reliability of the product far outweighs any concerns I have over ~715MB over the course of a month. So your convenience trumps the impact you’re causing to global infrastructure? Yes, you’re just one among millions, but still a slippery slope.
- cthalupa 9y ago>So your convenience trumps the impact you’re causing to global infrastructure Honestly? Yes. Should I want TP-Link to fix it? Maybe. Should pressure be put on TP-Link to fix it? Yes. But not by consumers. It isn't the responsibility of a random consumer that has no idea what an NTP server even is to understand whether or not the TP-Link router is going the "right thing" for all sorts of use cases they've never even heard of it. From a consumer perspective, does TP-Link build a good product? Yes. And that's all consumers care about. The pragmatic reality of the situation is if this is an issue, the public service providers need to do something about it. You cannot expect consumers to worry about or even know about this sort of thing. They don't care. They'll never care. This blog post won't make these random consumers that see it as a highly rated product on e-commerce websites care. TP-Link won't care when the niche population of people that care about this don't buy their product because we're not the market. If the NTP pool cares about what TP-Link is doing, they should reach out to TP-Link about it, and if there's no co-operation, be public about it. Pissing into the wind on a random 3rd party blog about how consumers should switch because of something 99.9% of consumers don't care about isn't going to accomplish anything, whether we a conscientious net citizens should care or not.
- 0x0 9y agoReminds me about the D-Link vs phk NTP drama years ago https://slashdot.org/story/06/04/07/130209/d-link-firmware-abuses-open-ntp-servers https://slashdot.org/story/06/04/07/130209/d-link-firmware-a...
- edent 9y agoWow! 11 years ago Dlink were the ones abusing NTP https://m.slashdot.org/story/67096 https://m.slashdot.org/story/67096 Strange how these "mistakes" keep cropping up. Is it laziness, malice, or just ignorance?
- yeukhon 9y agoLaziness and ignorance (probably not even knowing what they were doing other than just using these ntp servers) at the beginning. I bet someone just “copied and pasted”.
- danesparza 9y agoPerhaps it's the same developers making the same stupid mistakes.
- ktta 9y agoPSA Anyone with commodity routers, repeaters, etc. please check out LEDE project https://lede-project.org https://lede-project.org. Check if your device has support here - https://lede-project.org/toh/start https://lede-project.org/toh/start LEDE firmware is amazing. You will be able to do a lot more with your router and they have quick security fixes. The recent krack vulnerability was fixed within 2 days after the announcement.
- skeleton 9y agoI'm interested in installing a different firmware on my home router, but there are many offerings. Is there any reason you recommend LEDE over the others? (e.g. Tomato)
- bubblethink 9y agoMaybe the name LEDE is not familiar to you, but LEDE is an openwrt fork, which is essentially going to get named to openwrt again through a merge since that's where most of the openwrt work is happening. From the various open or semi-open firmware, LEDE is the most active and open I think. Various other firmware will still be quite tied to vendor binary drivers.
- ktta 9y agoTomato, DD-WRT, etc. try to be extremely user friendly. Not that LEDE doesn't, but people who have some technical expertise tend to benefit a lot more from LEDE with all their packages. Especially if you can compile an image yourself (it is pretty easy on linux), then you can have all the features tailored to your preference.
- jlgaddis 9y agoOpenWRT/LEDE firmware is nice. I think I first used it with the (original) WRT54G. The future of the project is uncertain, however. They may or may not be around much longer.
- jml7c5 9y ago>The future of the project is uncertain, however. They may or may not be around much longer. Can you elaborate on this?
- kercker 9y agoUpdate: According to ktta (https://news.ycombinator.com/item?id=15912467 https://news.ycombinator.com/item?id=15912467), there is mistake in my calculation too. "138KB * 24 * 3600 / 5" should be 2.3287GB per day. And it's 2.3287GB * 30 per month. Update 2: "For comparison, a 5-minute check would be considered a pretty aggressive checking interval, and would only consume 1,37 MB per month. Instead, TP-Link goes through the same amount of data in just 82 minutes." This assertion from the article has multiple errors too. ----------------------------------------------------- The whole argument of the author is built on a flawed calculation by the author and the author exaggerated the number by a factor of 10. 715MB/month in the title and the article should be 71.5MB/month according to other information provided by the author. According to the author, "TP-Link product is using about 138 KB every 5 seconds — or 23,85 MBs per day — on timekeeping." 23,85 MBs per day is not right, because 138KB * 24*3600/5 is about 2.328 MBs not 23,85 MBs.
- ktta 9y agoAlso I think it is 138 B, not kilobytes since that would be 2.3GB/day. Whoops. Made it to the front page of HN with so many mistakes. EDIT: Since there seems to be interest in this let's do the test: 5 DNS requests + 1 NTP update according to the article (seems weird that it would resolve all the the NTP servers, but lets roll with it) DNS: dig <domain> (mean for request is 43.8 B and reply is 84.6 B) NTP: busybox_NTPD -n -q -p time.nist.gov --------------------- Egress: Single DNS request : 20 (IP) + 8 (UDP) + 44 (DNS) = 72 B NTP request (2 packets): 20 (IP) + 8 (UDP) + 48 (NTP client) = 76 B Total egress: 72x6 + 76x2 = 584 B ---------------------- Ingress: Single DNS reply: 20 (IP) + 8 (UDP) + 85 (DNS) = 113 B NTP reply (2 packets): 20 (IP) + 8 (UDP) + 48 (NTP server) = 76 B Total Ingress: 113x6 + 76x2 = 830 B ---------------------- The total bandwidth used according to my calc is 1414 B. So their number of 138 KB is actually 1.38 KB (which is 1380 B, and that's closer to my number. I rounded up if you look at my numbers) So their number of 715 MB is actually right. Just an error with 138 KB -> 1.38 KB
- deleted 9y ago[deleted]
- bravo22 9y ago
- void-star 9y agoStrongly suspect this device doesn't have a RTC...
- keypusher 9y agoSomewhat unrelated but if you are looking for a rock-solid router, check out Microtik. I've been through half a dozen routers over the years, with and without custom firmware, and having owned a Mikrotik Routerboard for the last year, it's the first one that just works 100% and never drops connections. Easy to set up if you know what you are doing and customizable if you want to dig in.
- Jaruzel 9y agoIf you can't get a Mikrotik, then a Draytek is normally a good bet also.
- garaetjjte 9y agoYeah, Mikrotik have great devices for reasonable prices, but it is irritating that you can't run own applications on it, there is no publicly available working kernel to run under MetaROUTER, and they want 45$ for GPLed sources https://mikrotik.com/downloadterms.html https://mikrotik.com/downloadterms.html
- frankzinger 9y agoCheck out http://demo.mt.lv/ http://demo.mt.lv/ and http://demo2.mt.lv/ http://demo2.mt.lv/ for a live demo of the OS (RouterOS) that comes with Mikrotik products.
- kuon 9y agoI discovered PC engines APU boards and now I do all my routers/network thingie with it and OpenBSD. I'm quite sure there are some nice GUI "ala pfSense" too, but I like my configuration files better.
- sschueller 9y agoI purchased cheap crap TP-Link access points and replaced the firmware on each one with open-wrt[1] and they all works extremely well for many years now. The Stock firmware is total junk and crashes all the time. [1] https://openwrt.org/ https://openwrt.org/
- herpderperator 9y agoDon't bother with repeaters. Get normal access points, and install several of them if you need to disperse the range around a large area/building/complex. If the SSID and security passphrases match, clients will roam seamlessly between the different APs. I suspect the reason people buy repeaters is that they don't realise that this is possible, or they don't want additional cabling. Repeaters add latency and I can't imagine any network engineer would ever recommend one.
- mseebach 9y ago> I suspect [...] they don't want additional cabling. You probably suspect correctly. Not having additional cabling is a pretty big selling point of wireless technology.
- tatersolid 9y agoEspecially as the majority of homes date back more than 25 years, and retrofitted cabling is very expensive. And if you rent rather than own, you likely can’t add cabling at all under the terms of your lease.
- forgottenpass 9y ago>And if you rent rather than own, you likely can’t add cabling at all under the terms of your lease. A POTS phonejack can use pair(s) in CAT 5 (or 5e, 6), and newish buildings often already run it to the wall jacks rather than CAT 3. Depending on access to the other end of the lines, and appetite for DIY upgrading a landlord's building, it's quite possible to temporarily swap the RJ11 hardware for some RJ45 and have a wired LAN ;)
- tatersolid 9y agoNo building or home 25 years old has even Cat-3 in the walls. It’s all “uncategorized” cheap ass aluminum or maybe copper unshielded twisted pair.
- 9y ago
- deleted 9y ago[deleted]
- easytiger 9y ago> To put this number in context: an always-on Windows device will use around 1,6 KB per month. Windows doesn't do time sync properly so that's hardly a relevant comparison
- Taniwha 9y agooh, f--k, every TP-link box on the planet is hitting nz.pool.ntp.org every 5 minutes? you guys know we only have a couple of cables connecting us to the rest of the world right? Please don't buy TP-link, you're DoSing an entire country
- chli 9y ago5 times a second !
- PhasmaFelis 9y agoOnce every 5 seconds.
- Jaruzel 9y agoSlightly tangential, but I've recently been writing a command line tool to talk to some TP-Link Smart Plugs, and discovered that they regularly talk to 'devs.tplinkcloud.com' even if you don't enable a TP-link Cloud account. More details here (not my site): https://www.softscheck.com/en/reverse-engineering-tp-link-hs110/ https://www.softscheck.com/en/reverse-engineering-tp-link-hs...
- Faaak 9y agoI changed the server url on mines to "localhost". I control the plugs via a script on a docker container (they pilot water pumps). It works well that way.
- unwind 9y agoOne silly thing that I hadn't thought of; the use of NTP for devices like this should mean that the NTP operators can gather pretty accurate statistics about each device's market share. I guess the same folks who design software that spams things like this don't bother working too much on making it hard to fingerprint their devices, either. On the other hand, I haven't looked at the NTP protocol recently. Perhaps this isn't even possible due to the protocol's simplicity?
- gcb0 9y agodns is a better target for this. Google even had rob pikes team do this sinkhole for them. which says its an expensive and worth goal and not some afterthought.
- mikerg87 9y agoHonest question. How would you begin discovering this kind of leakage? Do you need some sorry of tap that records protocols and Mac addresses? Do these firmware emplacements have this as a built in feature. With so many IOT devices being plugged in seems like this would be handy
- pixl97 9y agoLots of enterprise equipment have features where you can mirror traffic off an ethernet port and monitor it, but it is cheap and easy to do if you are poor too. Dig up a 100MB hub, not a switch, and then with another computer plugged into that hub run a program like Wireshark or tcpdump. This is one reason why I don't run all-in-one router/wireless combos. Most integrated (especially provided by ISP units) devices have no way to tell you what is being sent over the air and then to your ISP.
- dboreham 9y agoUse a decent router that allows packet sniffing. There are various low cost options. I use Mikrotik for example.
- chatmasta 9y agoEasiest way is to plug the router into an upstream router that you control and sniff the traffic there.
- d2wa 9y agoYou get a good non-consumer grade router with network sniffing, per-device bandwidth and connection history, and other nice features like that.
- phikai 9y agoI noticed it based on Pi-Hole [0] and seeing the excessive DNS Requests to those URLs... started googling and found this post which I thought summed it all up nicely. Looking at the author's post, it also appears they noticed it due to Pi-Hole as well. EDIT: It was a different post that someone had seen this via Pi-Hole. Not sure how the original author discovered it. [0] https://pi-hole.net/ https://pi-hole.net/
- colanderman 9y ago> an always-on Windows device will use around 1,6 KB per month How is this possible? Is the author ignoring Windows Update?
- djaychela 9y agoI'm thinking he's just referring to the traffic relevant to the TP-Link firmware - otherwise there's no way to make any relevant comparison.
- d2wa 9y agoIn equivalent NTP traffic.
- colanderman 9y agoWhy all the downvotes? Sorry I asked a clarifying question, geez.
- kees99 9y agofirmware sends six DNS requests and one NTP query every 5 seconds (...snip...) TP-Link has hardcoded the following non-configurable NTP servers and server pools in their firmware: (...snip...) au.pool.ntp.org, nz.pool.ntp.org Wait... so TP-Link is effectively DDoSing NTP pool? Also, as pointed out in another thread here, vendor using country prefix instead of applying for their own prefix is a violation of: http://www.pool.ntp.org/en/vendors.html http://www.pool.ntp.org/en/vendors.html ..which was put in place as a reaction to incidents just like this one: https://en.wikipedia.org/wiki/NTP_server_misuse_and_abuse#Notable_cases https://en.wikipedia.org/wiki/NTP_server_misuse_and_abuse#No...
- zaarn 9y agoA NTP request every couple seconds is similarly in violation of the vendor guidelines, once every 10 minutes or less often is stated.
- nacs 9y agoWould it be possible for the NTP server to detect what type of device/OS is sending the request and block it (ie: could au/nz.pool.ntp.org servers block all TP-Link requests to teach them a lesson)? If they can't do that maybe they can just detect IPs that are making requests every 5 seconds as the TP-Link products are doing and block those since they're in violation of the once-every-10-minutes-maximum rule for the NTP servers)?
- samstave 9y agoOut-of-the-loop: what products are using TP-Link? Aside: maybe there should be a governing body for comm protocol behavior? (Semi sarcastic)
- ganoushoreilly 9y agoTP-link is a manufacturer of multiple devices and an OEM for others. I would imagine, if consistent across firmwares, there are a lot of requests being made. https://en.wikipedia.org/wiki/TP-Link https://en.wikipedia.org/wiki/TP-Link
- deleted 9y ago[deleted]
- hammock 9y ago@dang why did you change the title to this (from the article's title)?
- LordKano 9y agoI know there's a joke to be made here. "TP" link firmware is peeing in the pool of ntp servers... I think I need more coffee first.
- ausjke 9y agoJust replace its firmware and load the router with LEDE/openwrt instead. LEDE is an Openwrt fork, and it might merge back to Openwrt sometime. LEDE is under active development and its newest release is 17.01.4 https://downloads.lede-project.org/releases/ https://downloads.lede-project.org/releases/
- NelsonMinar 9y agoThis kind of stupidity happens to NTP frequently. The ironic thing is NTP is so lightweight that sometimes it's better to just answer the query than try to block the traffic. The DNS traffic is more expensive than the time query! Note this was reported on the NTP Pool Discourse about 3 weeks ago: https://community.ntppool.org/t/software-and-devices-without-a-vendor-zone/28/26 https://community.ntppool.org/t/software-and-devices-without...
- tom_usher 9y agoI've been seeing an unusual amount of NTP requests in my PiHole logs but never got round to figuring out the cause - nice to have an explanation. Hope this is fixed in a firmware update, my repeater is quite a nice device otherwise.
- devy 9y agoTP-Link is a major networking equipment manufacturer globally and one of the largest in China, just behind Huawei. They are one of the few who design equipment firmware/software and hardware in-house[1] and certainly have resource (man+money) to get the network protocol implementation right (sometime they don't) for their products and I wonder if the author has proactively reach out to them so that they can fix it for all (rather than public shaming and/or product ban)? [1]: https://en.wikipedia.org/wiki/TP-Link https://en.wikipedia.org/wiki/TP-Link
- wnevets 9y agoslightly off topic, can anyone recommend a good router for home use? It seems like every major brand router is just awful.
- gergles 9y agoI find that my Synology router has been rock-solid and extremely performant. I have the RT2600ac and have been quite happy with it, and it has a nice web interface that you can configure automatic updates on, so it can even be distributed to people who aren't quite as network savvy.
- frankzinger 9y agoAs others have said, check out Mikrotik. I recently bought https://mikrotik.com/product/RB952Ui-5ac2nD-TC https://mikrotik.com/product/RB952Ui-5ac2nD-TC. It was much cheaper than my previous stock Netgear router but it's orders of magnitude better. This live demo of their web UI at http://demo.mt.lv/ http://demo.mt.lv/ and http://demo2.mt.lv/ http://demo2.mt.lv/ should give you a good idea of what you get.
- linsomniac 9y agoI ran a public NTP server for around a decade. I finally stopped, but these sorts of vendor abuse weren't the reason why. We started running them before the NTP pool (though we eventually did include our servers in the pool). The worst it got was a largish regional ISP had put our servers in their CPE, and one day they had an event where they rebooted all of their CPE at once. That caused a noticeable spike in our network traffic. The real DDoS that caused us to stop offering public DNS service was: misguided network admins. The week I had the second network admin calling me, asking why my network was attacking their network, and then started yelling at me over the phone and hung up in a huge huff. He had installed some sort of IDS and it was triggering on NTP traffic, and rather than investigate it he just called our emergency hotline and got me out of bed to deal with it. "Those packets you are receiving are in response to packets you are sending our NTP server asking for the time." was not the answer he was looking for I guess. :-( Honestly, I was already mad from being woken up (the emergency hotline says it is for service outages only), and that it was the second call that week on it. So I take some blame in the call not going well. But this dude never stopped yelling at me. The problem with running a public service is: The administration doesn't scale with the number of users.
- Forbo 9y agoNTP uses UDP, so he was probably the victim of a spoofed NTP request amplification attack. He probably didn't have clients that we're actually requesting the time, the requests were just spoofed to look like they came from his IP.
- ktta 9y agoI'm leaning towards incompetence - Hanlon's razor and all that.
- linsomniac 9y agoMy recollection was that the volume coming from this one site was tiny, not like a DDoS. I don't recall if he said as much or if I was reading between the lines, but it sounded like he had just set up some sort of IDS, and it reported this traffic as an attack, and he just took that at face value. We did have some UDP multiplication attacks at other times, mostly on our authoritative DNS servers. I don't recall that we ever had any against our NTP servers that I noticed. But we did block the broadcast address so the best multiplication vector was via DNS requests, IIRC the NTP responses were fairly short.
- AgentME 9y agoDidn't TP-Link backdoor one of their routers, additionally in a remotely-exploitable insecure way that they never patched?[0] Am I alone in that putting a company on my eternal shit-list? Looks like a good choice in retrospect if they're still coming up with things like this. [0] https://tech.slashdot.org/story/13/03/15/1234217/backdoor-found-in-tp-link-routers https://tech.slashdot.org/story/13/03/15/1234217/backdoor-fo...
- Sami_Lehtinen 9y agoAbout every 5 seconds Ubuntu is making DNS lookup for: daisy.ubuntu.com.
- d2wa 9y agoThis issue has been fixed by a new firmware release from TP-Link. The updated firmware changes the behavior to use ICMP pings on the local network rather than NTP+DNS requests out on the public internet. https://www.ctrl.blog/entry/ntplink-fixed https://www.ctrl.blog/entry/ntplink-fixed