• @[email protected]
    link
    fedilink
    English
    1229 days ago

    And that’s why you should run your own router. Preferably using open firmware/OS like ddwrt or pfSense/opnSense.

    • robotica
      link
      fedilink
      English
      229 days ago

      I’m curious, does running open source software somehow exempt you from getting malware?

      • @[email protected]
        link
        fedilink
        English
        1329 days ago

        Not necessarily, but the odds of getting popped by a heretofore undisclosed backdoor that your ISP didn’t think would be a big deal are eliminated entirely, and you can also do a lot more interesting things with your home infrastructure, if that’s your thing.

        • @[email protected]
          link
          fedilink
          English
          929 days ago

          You also get regular updates with open source firmware. Many of the ISP provided routers will never see an update.

        • Max-P
          link
          fedilink
          English
          429 days ago

          It also doesn’t ship with ISP backdoors or ISP remote management crap that can be a big attack vector. Just about every ISP router I’ve looked at has some hardcoded super admin password or secret unauthenticated paths to access hidden settings.

          Custom firmware ships with plain web UI and/or SSH only from the LAN side (or even specific VLAN), so right off the start there isn’t a whole lot of potentially exploitable surface. And the community actually cares.

        • robotica
          link
          fedilink
          English
          1
          edit-2
          29 days ago

          Is the recent XZ backdoor (and something that had to do with SSH too) anything to worry about in terms of the probability of there being a backdoor even in open source router software?

          Not trying to dissuade anyone here, I love open source software, I’m just wondering how much effort is reasonable to be put into securing your local network (i.e. buying your own router, also installing open source software, or writing your own router software if you don’t trust existing solutions) given that not everyone is tech savvy and you get diminishing returns for every additional security measure. And when is the usual point at which you would say “okay, this is secure enough”?

          My router is not from an ISP, but it does get frequent firmware updates and I don’t use any cloud management features, only local configuration.

          • @[email protected]
            link
            fedilink
            English
            128 days ago

            I mean, the ISP-provided boxes don’t give you a way to upgrade past that faster than you would on an open distribution. The latter had fixes out within a week, or just weren’t affected. And it’s also way easier to check the deps on open firmware/OSes.