8 ms·
Newer TP-Link Routers send large volumes of requests to Avira servers
- matheusmoreira 5y agoSo how do we get routers that support open source firmware? It seems these things are getting more difficult to find.
- aaronmdjones 5y agoThe WRT1200AC family (WRT3200ACM etc) support it out of the box as a first-class feature. https://www.linksys.com/nz/wireless-routers/wrt-wireless-routers/linksys-wrt1200ac-ac1200-dual-band-wifi-router/p/p-wrt1200ac/ https://www.linksys.com/nz/wireless-routers/wrt-wireless-rou...
- haukem 5y agoThe WRT1200AC family is not well supported. The Ethernet part should work fine, but the Wifi is unsupported since some years now, see here the repository: https://github.com/kaloz/mwlwifi https://github.com/kaloz/mwlwifi The vendors are not interested in this hardware any more, but they have very good marketing and sales. Linksys and Marvell also did not really support the OpenWrt community, they just had good marketing. If your WRT1200AC device does not work well with OpenWrt do not complain to OpenWrt, but complain to the Linksys support. The WRT1200AC family for example does not support WPA3, because the closed source Wifi firmware does not support it. The 15 years old WRT54G supports WPA3, it is just very slow. ;-) Currently I would suggest the Linksys E8450 / Belkin RT3200 (same hardware) or some other device using the current Mediatek platform with MT7622 + MT7915 + MT7531. (2 X Cortex-A53, Wifi 6) All chips are supported in recent upstream Linux kernel, including Wifi. The Mediatek router team is currently doing pretty good upstream open source work for their chips.
- aaronmdjones 5y agoNeat! Looks like that just became my new front-runner. I'm still happy with OpenWRT on my WNDR3800 for now either way.
- filomeno 5y agoOne alternative could be, instead of buying a router, getting a single board computer designed to run whichever routing software you like. Banana pi is an example that comes to my mind. You'd need to get a case, and it won't be as neat as a commercial router.
- matheusmoreira 5y agoI would love to replace these "routers" with a normal computer. The thing is these computers would need special ports for either phone lines or fiber optic connections, as well as built-in modems. I've never seen a computer with this sort of hardware built into it. Even on dedicated network cards I only ever see ethernet ports, nothing compatible with whatever it is my ISP is using (SFP?). Decades ago in the dial up days I used to be able to buy modems separately but not anymore, and I'm not even sure what sort of hardware components are needed for a fiber connection...
- Lascaille 5y agoIf you're on DSL, the DLink DM200 has an integrated adsl/vdsl modem that's supported by OpenWRT, and the platform is quite powerful. You'll need a second device for wifi though but that suits my use case. If you want a dedicated OpenWRT device Mikrotik would be my suggestion.
- mypalmike 5y agoMy ISP gives me a box that terminates the fiber and has ethernet on the other side. They also rent and sell routers that are configured to handle the pppoe and vlan settings needed for the WAN interface to this box. Plenty of routers can do this, and a dedicated Linux box like you are proposing should work, or you can throw a cheap managed switch in between if not. The hardest part is knowing what settings are needed (e.g. I had to call my ISP to ask for the pppoe password). DSL standalone termination is still widely available, as are standalone DOCSIS cable modems.
- deleted 5y ago[deleted]
- cassianoleal 5y agoThe Turris routers are quite good these days. I own an Omnia and despite it having been a bit rough a few years ago, it's now nearly flawless. The MOX is modular and could be more interesting for your use-case but it can also get pretty expensive. https://www.turris.com/ https://www.turris.com/
- inglor_cz 5y agoAh, a Czech product. I know some engineers from Turris. Very proud of them. This is how a good router should look like.
- ajot 5y agoYou have some makers like Turris and GL.iNet that ship their devices with some customised flavor of OpenWRT. I just wander through OpenWRT's table of hardware, looking what devices fulfill my needs and are available in my country. In the forums [0](Discourse alert) you have many threads with suggestions, too! [0] https://forum.openwrt.org/c/hardware-questions-and-recommendations/13 https://forum.openwrt.org/c/hardware-questions-and-recommend...
- Gigachad 5y agoIt’s a lost cause. The router should be treated as hostile and shouldn’t be allowed to know anything if possible. DNS over HTTPS and that SNI encryption stuff should be used.
- quotha 5y agoHow do you plan on blocking ad servers with DoH?
- Gigachad 5y agoWith ublock origin. DNS level ad blocking is rubbish and mostly circumvented by providers now.
- sloshnmosh 5y agoI heard that ads were able to circumvent DNS by using canonical names. But uBlock origin and PiHole both do CNAME inspection to block this. Is there other ways that ads are circumventing DNS ad-blockers such as PiHole?
- Gigachad 5y agoI have found that rather than finding a way to sneak ads in, most non browser apps will just detect that the ads are missing and throw up an error refusing to display the content.
- somat 5y agoMy go to home router is the pcengines apu2. I run openbsd on them(not for security but because I really enjoy using openbsd), But just about any os will work well. They have opensource firmware. https://pcengines.github.io/ https://pcengines.github.io/ Full disclosure, I have never built the firmware but I take great comfort that it is developed in an open source manner, and that I could build it if I wanted to.
- squarefoot 5y agoThe software answer would be easy: use OpenWRT or any other *BSD based alternative, but what about the hardware? A quick search for WAN interfaces for PCs returned nothing.
- implements 5y agoYou can get a minimalist ADSL modem such as: https://www.draytek.co.uk/products/business/vigor-130 https://www.draytek.co.uk/products/business/vigor-130 “The DrayTek Vigor 130 is a VDSL2 and ADSL modem with an Ethernet connection; it is not a router but a true ADSL/VDSL Ethernet Modem (bridge).”
- ianai 5y agoQotom and protectli make some cool options. I’ve used both with *nix.
- kemotep 5y agoI would agree that it can be difficult to find quality hardware that supports the open source software stack. For example, what wireless access points are compatible with an openbsd router/firewall? I’ll admit that my initial searches were short but only finding results about wireless chipsets to use in the router were frustrating (I guess if I wanted to build my own access points that information would be valuable).
- detaro 5y agoWhat does it even mean for an access point to be "compatible" with a specific OS on the router?
- kemotep 5y agoLike the ability for the ap to understand how the vlans the router setup work. I’m still quite the network novice but it seems like if I wanted a bsd firewall -> managed switch -> wireless ap I would need to confirm some level of interoperability for decent performance?
- maxloh 5y agoTP Link is a Chinese company. I won't trust them personally. In China's current political status, it is impossible for Chinese companies to reject the autocratic government's requests for surveillance. You may endup in jail or even get killed.
- naoqj 5y agoI mean, I get it, but Avira is a German company.
- lotsofpulp 5y agoAvira’s bosses get their marching orders from NortonLifelock bosses, which seems to have pretty American leadership: https://www.nortonlifelock.com/us/en/corporate-profile/management-team/board-of-directors/ https://www.nortonlifelock.com/us/en/corporate-profile/manag...
- Lifelarper 5y agoSo hypothetically as a western activist at risk of govt coercion you'd trust Cisco more? Statistically, you very likely own a Chinese manufactured router while using it to tell others here not to do the same.
- irutirw222 5y agoThis is a good point. Probably most people are not aware of the country of origin of most of the tech products (resp forna given product, how many important, modular subparts come from Chinese companies). It would be highly interesting if there would be a website where you could type in the name of a product (e.g. sime Cisco) router and it would give you a detailed decomposition of where and by whom is parts where made. Something like (highly simplified) : - CPU design: Company X - CPU manufacturing: Company - RAM design and manufacturing: Company Z - Overall remaining logic: Cisco
- x13 5y agoMany US companies publish lists of suppliers. These examples do not show individual components, but may shine some light on things: https://www.apple.com/supplier-responsibility/pdf/Apple-Supplier-List.pdf https://www.apple.com/supplier-responsibility/pdf/Apple-Supp... https://www.cisco.com/c/dam/en_us/about/supply-chain/cisco-supplier-list.pdf https://www.cisco.com/c/dam/en_us/about/supply-chain/cisco-s...
- richardfey 5y agoGDPR fine & class-action lawsuit in 3...2...1
- danpalmer 5y agoI remember reading in the UK government's security assessment of Huawei that one of the issues is not necessarily data being sent to bad places or backdoors in the software, it's that the engineering processes behind these devices/software are completely unable to protect against any sort of supply chain attacks. The sorts of things they highlighted were: no version control, no code review, production builds happening on arbitrary machines, no automated testing, poor access control on code, no audit trail on code changes, the list goes on, and that's just for the software side. The conclusion was that Huawei were about a decade away from being able to even claim they had no backdoors. And that's a major telecoms hardware provider, trying to sell into governments and major infrastructure projects. I'm not in the least bit surprised that TP-Link are doing this, and also not at all surprised that when questioned on it they are (so far) unable to actually describe why it's happening or really seem to know anything about it. I think this sort of product is built in a very different environment to what most HN users would expect.
- _wldu 5y agoI find it hard to believe that Huawei does not use version control. No company is perfect, but surely software developers (at a multinational company) with advanced degrees in CS and ECE are using version control.
- legalcorrection 5y agoAlso a perfect environment to slip in back doors that look like mistakes.
- Dah00n 5y agoYes, it has happened multiple times at Cisco.
- danpalmer 5y agoExactly, that was their point. I suspect there are a lot of software supply chains that are actually compromised, because it's just too easy when this is the standard of software engineering. It's easy to forget that git for example is not just a big "undo" button, it's a cryptographically secure audit log of all changes made, that allows you to know exactly what software you're actually shipping.
- ajot 5y agoThat's before installing OpenWRT! This kind of shenanigans make (once again) the case for 3rd party post market FLOSS firmware to be installed on every device I own. Sure, I spend some extra time researching which router/AP/phone/ereader/smart appliance will be compatible with OpenWRT/LineageOS/KOReader/Tasmota/ESPHome/etc., but I feel more confortable this way. I have more trust in a bunch of people doing this for owning their devices than some corporation whose goals clearly don't align with mine.
- mise_en_place 5y agoYou could also buy an SBC with a few network ports and use that as your router.
- mananaysiempre 5y agoIME small ARM SBCs generally have a miserably slow bus arrangement for this sort of thing (and no hardware switch chip, of course). People have had some success with routers built on x86 mini-PCs[1], but these lean towards the “flexible and performant” side, not the cheap side. [1] https://arstechnica.com/gadgets/2016/04/the-ars-guide-to-building-a-linux-router-from-scratch/ https://arstechnica.com/gadgets/2016/04/the-ars-guide-to-bui...
- nerdponx 5y agoI was just wondering about this the other day. Are there still no options other than to buy/build a grossly overpowered x86 machine?
- frogger8 5y agoFrom the comments Nothing in your analysis shows this. Moreover unless you explicitly deployed a root certificate on your clients (or if an app on the client did it), the router can't decode TLS traffic (deep inspection) without you getting certificate warnings on the client. In that case, the only thing the router can see is the dns request, the IP and the TLS SNI. In short your title is misleading. permalinkembedsavereportreply [–]ArmoredCavalry[S] 11 points 14 hours ago* I agree they couldn't be inspecting the contents of your traffic over TLS, but they could easily view destinations. I also agree, there's nothing in my analysis that proves that all the requests are related to network traffic. However, if you look at the wording of the reply (directly from TP-Link) to XDA in their review, I don't see how it could be interpreted any other way? Regardless, I probably should have made my title "appears that it may send traffic related data". I'll be happy if that isn't the case, but the lack of clear explanation from TP-Link when I've contacted support leads me to assume the worst permalinkembedsaveparentreportreply [–]2fast2fourier 4 points 12 hours ago I think it's best not to write something that damaging without proof, especially when most people only read titles. Saying they're sending metadata and violating your privacy is all you'd need to hear.
- jjav 5y agoThere is really no excuse for any network equipment to be sending anything at all to external parties, unless you've specifically subscribed to some service where it becomes necessary. Which the OP said they don't. Let's be careful to not normalize this type of data exfiltration from equipment that's supposed to be yours.
- tinus_hn 5y agoThis case is not that, but for instance update services and time servers are defensible reasons to connect to external parties.
- zinekeller 5y ago... and I don't get your point in this useless pedantry? Sure that the data in of itself is not sent, but you seemed to imply that DNS queries don't reveal anything. In practice, you can build a good enough picture to decode what's their interests, what type of places they visit etc., which is worrying of itself. It's like saying to not worry because they didn't know you ordered a Big Mac while the fact that you went to McDonald's is being known is already creepy to a lot of people.
- zinekeller 5y agoBefore you say anything about this feature (which is apparently called HomeCare, https://www.tp-link.com/homecare/ https://www.tp-link.com/homecare/), you should probably know that Asus also has a AiProtection feature powered by Trend Micro (https://www.asus.com/content/aiprotection/ https://www.asus.com/content/aiprotection/) and D-Link having McAfee Secure Home Platform built-in (https://www.dlink.com/en/latest-news/d-link-introduces-new-exo-router-series-with-mcafee-protection https://www.dlink.com/en/latest-news/d-link-introduces-new-e...). Definitely not vindicating TP-Link here (especially the alleged continuous querying despite the feature being off), just noting that this is not exclusive to TP-Link.
- sloshnmosh 5y agoI came here to say the same. I even purchased a LAN throwing star to look to see if my Asus router was sending anything to TrendMicro but never did get around to it. But I will now for sure.
- webmobdev 5y agoDamn. Seems like they have all "discovered" a new revenue model - harvest and sell user data to third-parties / data brokers.
- jnwatson 5y agoThese are all premium features you have to sign up for.
- zinekeller 5y agoSo why is the first line of their marketing material says "lifetime subscription for the life of the device" and not for a monthly fee? Also, I have an Asus Router with AiProtect and it didn't upsell me, and definitely no monthly dues (I'm not shocked if the data collected is resold however though).
- Pxtl 5y agoYes but the feature is optional, and tells you how it works if you turn it on. And realistically, most of the extended features on consumer routers are ineffective at best and network-destroying in typical cases. For example, I've never used a router ever turning on QOS did anything but trash network performance. I use and recommend Asus routers because in spite of them being shitpiles when you turn on anything but the basic functionality, the industry standard is that low that consistently good basic functionality is a stand out success. The router industry makes printer companies look like Apple.
- Kiro 5y agoReadable link on mobile: https://www.reddit.com/r/hardware/comments/tbthjj/psa_newer_tplink_routers_send_all_your_web/ https://www.reddit.com/r/hardware/comments/tbthjj/psa_newer_...
- 29083011397778 5y agoShould be [0] for mobile [0] https://i.reddit.com/r/hardware/comments/tbthjj/psa_newer_tplink_routers_send_all_your_web/ https://i.reddit.com/r/hardware/comments/tbthjj/psa_newer_tp...
- Kiro 5y agoI personally prefer the regular mobile view.
- sebow 5y agoTP-Link became a big no-go for me as soon as ax came out and I saw that they required account registration[0] for managing a personal, local router. Probably has to do with the fact that they're not western-owned and are 'legally required' to have such a system in order to be covered from 'borrowing' your data. I expect other vendors(Huawei,etc) to do the same, and it's insane that people don't revolt against such practices, especially considering we still have such vendors being installed by default in people's homes by the ISPs.And whilst a router is replaceable by the end user, something like an ONT is harder to find in most places, and the ISP doesn't usually give config details for an ONT. [0] Edit: An online account for the mobile application, not the web interface of the router itself.
- YaBomm 5y ago
- WJW 5y agoALL routers send my web traffic to 3rd party server I would hope. I don't have a router to access all the websites on my home network after all. Joking ofc, this is pretty bad. Terrible coding in the best case, outright spying in the worst. Neither instills a lot of confidence in TP-link.
- sabujp 5y agoI setup cloudflare zero trust and started pointing my AC4000 to it, let's see what happens.
- sabujp 5y agoi've had it on for 2 days now, no requests to avira, i have homeguard completely turned off.
- microtonal 5y agoThis is why for home and small office use, I usually get AVM Fritz [1] network devices. They have been around for since forever, provide regular updates for their devices and over a long period. Their web interface allows for a lot of fine-grained configuration and their devices have been rock solid for me. They are a German company and as far as I know software development is also done in Germany, so I expect that they operate within the relatively strict privacy regulations of the EU. [1] https://en.avm.de https://en.avm.de
- q3k 5y ago- 8< - I was wrong - 8< -
- ChuckNorris89 5y agoWould you mind to provide a source for this claim please.
- deleted 5y ago[deleted]
- mhitza 5y agoIf you want to see TP-Link routers track record, and if you have an existing TP-Link router, check the updates page on their support website. Same kinds of vulnerabilities are fixed often across devices, as if not learning from their mistakes. When it comes to budget routers I still turn to TP-Links when I can easily find a decent model on the market that is supported by openwrt.
- ytch 5y agoI was annoyed by the Deco APP too. It provides remote management, which I believe that all data is forwarded through TP-Link's server. My solution is running those devices as a Wi-Fi to LAN bridge, also setup my own NAT gateway (by bare-metal Linux, Openwrt... etc). Then blocking there devices from accessing Internet at gateway. If I have more IoT devices at home, I will apply such policy to all of them.
- deleted 5y ago[deleted]
- lazyeye 5y agoSenior people at tp-link should go to jail for this.
- jmillikin 5y agoThis was alarming since I use a TP-Link router, so I tried figuring out to what extent it's able to inspect and record regular (encrypted) traffic. My TP-Link Archer AX50, running software version "1.0.11 Build 20210730 rel.54485(4A50)" is doing at least some sort of DPI on outgoing connections. I found a page in its settings (Advanced -> Security -> Antivirus -> History) that contains a log of connections I've made to "suspicious" domains, which include quite a few that I would consider innocuous. After clearing that log, I loaded a few domains I'd seen in it, and verified that new entries were created. Wireshark shows that no DNS requests were made, and the DNS-over-HTTP used by Chrome didn't leak that traffic. I believe the router must be inspecting TLS headers for the ServerName field. Didn't try to verify whether that data is being sent to a third party, but given that this thing is collecting data that it has no business looking at, it wouldn't surprise me if it's shipping it somewhere. edit: the URL I tested with is <https://api.mangadex.org/docs.html https://api.mangadex.org/docs.html>.
- t0mas88 5y agoIt could be doing reverse lookup on the IP you connected to? That's what a lot of network monitoring tools do.
- jmillikin 5y agoThat's not as common any more, due to the broad adoption of TLS-capable CDNs (Cloudflare, Fastly, etc) over the past ~10 years. In this case the site I tested with had a few different subdomains backed by the same IP, which I verified from a remote VPS. Using `curl` locally, with the `--resolve` flag to bypass DNS resolution, caused the router's log to contain entries for the specific subdomains requested.
- jnwatson 5y agoLooking at DNS traffic isn't generally considered DPI.
- verisimi 5y agopwned
- jamal-kumar 5y agoHasn't avira been just generally for a lack of better words completely fucking awful over the past year or two? The last I remember hearing about them was installing crypto miners along with their AV, which I can only imagine being bottom quality at this rate of insanely bad behaviour...
- vehemenz 5y agoAnecdotally, I've seen that TP-Link routers are ubiquitous in Chinese households. I don't draw any conclusions from that, but I did stop buying TP-Link devices. It would be nice if the US took import controls as seriously as export controls.
- Ourgon 5y agoI never rued the day when I switched off the last "appliance" router after switching to a virtual router - OpenWRT running in a container on a Proxmox-managed host. I use a number of repurposed "appliance" routers (also running OpenWRT) as access points, some of them connected to additional "dumb" PoE-switches for IP-camera's. Those camera's run over their own VLAN and never get to touch the 'net, the same goes for "IoT" things (heat pump, PV-inverter etc). Xi and friends will be disappointed, even if they built backdoors in their equipment these only lead to a dead-end street.