17 pointsby albin0lobster2 hours ago2 comments
  • forestryan hour ago
    Its be nice to see some repercussions for selling backdoored devices. Yes, that includes Amazon corporate for listing it.
  • revolvingthrowan hour ago
    The AI-isms in this post are a bit much.

    Anyway. Routers are such juicy targets, especially since there's less eyes on them than on laptops/desktops, that it's hard to believe there are any which aren't backdoored, be it by China, US, US' middle eastern sidekick, whatever. My question would be: how limited are they to software, like in the article?

    You can flash with OpenWRT and Fritz, but to my knowledge it doesn't replace the boot parts. A suspicious bootloader in SPI flash probably isn't difficult to produce, even if it would likely be discovered... eventually. A separate modem / radio processor would be an even bigger nightmare, esp if it's an 5g router - you essentially add a second computer to your router, with its own components and network access, and I think you can't even play around LTE/5g networking as freely as with wifi without bending some laws.

    Theoretically you could watch the router from, well, outside the router. But as the article says, it can be difficult to say what's an actual connection and what's uploading your network's data to an uninvited third party. I'm also wholly ignorant what implications it has for things like Wireguard and Tailscale. I assume you're completely pwned if the Wireguard runs on the router, but I don't think it does anything if it runs on your laptop or whatever? Then again, there's a lot more devices in peoples' homes nowadays, and almost all the IoT has pretty much zero security.

    I suppose AI will help with some of those things. Tracking every connection made is very tedious for a human, but throw some compute at it and you'll get a much better insight, especially since you'll probably know what to expect out of your machines.

    I guess using a mini PC as a router-slash-proxmox-hub would be a safer choice? There's probably many fingers in this pie as well, but my gut feeling is that it's a lot safer than some cheapo box provided by your ISP at the cheapest price they could source them.