6 ms·
Interestingly I was all for this until one day when I wasn't able to log into my Router's page. The router used a self signed SHA1 certificate and Chrome outrig
by nivla 11y ago
Interestingly I was all for this until one day when I wasn't able to log into my Router's page. The router used a self signed SHA1 certificate and Chrome outright refused to render it. Gladly the router was open to dd-wrt and I was able to replace the certificate manually. However I wonder how many other devices are there which people can't update that may be affected because of this.
- dredmorbius 11y agoI'm in precisely the same boat, with a Linksys WRT54g router. Linksys have no firmware update for this device. Looks like dd-wrt (or another alternative) is the way to fly.
- justinsaccount 11y agoYou've been running an obsolete firmware on an obsolete device for what I imagine is years. A wrt54g doesn't have gigabit ethernet, doesn't support 802.11N or AC.. The last one I used topped out at 50mbit on a single connection. Those things were good for a while, but unless the rest of your hardware is from 2008, you probably owe it to yourself to upgrade.
- dredmorbius 11y agoFunny thing is: the device is sufficient for the use. It's attached to a DSL connection that's far slower than it, and largely ties together a small number of client systems which communicate exclusively with the Internet gateway (no local traffic). Oh, and the folks who own the system itself would have absolutely no idea of what any of the items in your second sentence mean, or what they'd matter to them (if the features mattered at all to them, which they in fact don't). There's no GigE on the property. If they had a Web-only system they'd probably be ahead of the game (less shit to go wrong), and wireless bands supported work fine with devices connecting to it. Point is, there's a piece of perfectly _suitable_ and _usable_ hardware that's running just fine at the job for which it was originally intended, but the manufacturer's abandoned it. Something I strongly suspect we'll be seeing rather more of in the coming age of the Internet of Broken Things That Spy on You. But, say you've sold me: what's a decent replacement. And a Free-Software based ROM to put on it (I'd like to put extensive blocklisting on the gateway device itself).
- justinsaccount 11y ago> Point is, there's a piece of perfectly _suitable_ and _usable_ hardware that's running just fine at the job for which it was originally intended, but the manufacturer's abandoned it. Fortunately most[1] wrt54g devices are re-flashable, so if the slow lan speeds and poor wifi support are not a problem, you can get another few years out of it. > But, say you've sold me: what's a decent replacement. And a Free-Software based ROM to put on it (I'd like to put extensive blocklisting on the gateway device itself). At home I use a pair of an edge router lite and a random TP link AC router in AP mode (basically, DHCP server disabled). You can't really buy a decent AC access point, it's much more cost effective to buy a router and put it in AP mode. A Unifi UAP‑AC might be nice, but it's 3x the cost the tp-link was. I haven't bothered re-flashing the TP-link, but I made sure I could when I bought it. The edge router lite will probably end up running something like openbsd or pfsense in a few years. [1] a few ran vxworks with flash too small to support linux
- dredmorbius 11y agoThanks.
- pyre 11y ago> A wrt54g doesn't have gigabit ethernet You say this like GigE is required in every situation that might need a router. It really comes across like "that guy" who talks down at the (e.g.) Prius owner because they aren't driving a turbo-charged V8 (as if every person driving a car should be required to have one).
- gist 11y ago"Interestingly I was all for this until one day when I wasn't able to log into my Router's page. The router used a self signed SHA1 certificate and Chrome outright refused to render it. Gladly the router was open to dd-wrt" Couldn't you just have logged in with another browser or an older browser?
- nivla 11y agoI did but since Chrome is my main browser it was much easier to change the Cert once than to switch browsers everytime.
- mikeash 11y agoThat would be really annoying if you didn't have anything else installed and you needed to access the router to fix your connection.
- pyre 11y agoYour router is broken. Your router supplies your Internet connection. "Just hop on ye olde Internet and get an older browser." (Also, how exactly does this work if you are not one of the tech literate?)
- gist 11y agoWell you've got a good point actually however the parents statement (that I was replying to) does say this which requires a bit more tech literacy, eh: "Gladly the router was open to dd-wrt" On a fun note not sure if you remember the old "Get Netscape Now!" icons that were at the bottom of nearly every 90's webpage which, to your point, was as if someone visited your site and would actually pause to download and install a new browser (over dialup no less) if it didn't render correctly. [1] [1] http://sillydog.org/netscape/now.html http://sillydog.org/netscape/now.html
- johnmaguire2013 11y agoIs this a recent router? If it's 5+ years old, I think this might be one of those situations where it's time to decide to just upgrade our devices and be done with it.
- nivla 11y agoIts not a new router - Buffalo AirStation HighPower N600. However I guess I am one of those people who gets irky to replace something that is not exactly broken. Maybe once the AC specs starts showing up in the gadgets I use, I might.
- paulddraper 11y ago5 years, really? How often do I have to replace stuff that I own? My car is 25 years old (gasp) and reliable, though not designed for current emissions standards, my laptop is 8 years old and works great, though it can only run so many app-that-is-browser programs, my phone is 4 years old and works, and my router is 5 years old and still kicking, and my table saw is 10 years old and works great. I'd like to not have to replace my biggest, most expensive tools in my life every couple years, just because someone else has and thinks I should too.
- kijin 11y agoIt's not "just because someone else has and thinks I should too". Your 25-year-old car probably emits a lot more harmful substances into the air than recent cars do, so someone could argue that you are actually harming others by continuing to drive it. Similarly, one could argue that your use of computing devices that only support outdated cryptography is harmful to other people, because it makes it difficult for everyone else to upgrade to more secure algorithms. You might not be directly forcing anyone else to make any particular choice, but your choice contributes to the perpetuation of an insecure ecosystem, just like your car contributes to air pollution in your neighborhood.
- paulddraper 11y agoYour point about the car is correct, though I believe the argument on crypto is weak. I just would like to figure out how to use something for its actual lifetime. c'est la vie
- magicalist 11y ago"I was all for forcing others to upgrade their technology stack until it was inconvenient for me" Yes it is a chicken and the egg problem (and, I guess, evolutionary offshoots with no genetic future...), and this is exactly the kind of thing that is inconvenient about it. The decision was that it was worth the pain to be rid of SHA1 once and for all (just look at all the CA objections in the various threads about this to see the very strong objections to sunsetting SHA1 in the next year instead of five+ years from now).