4 ms·
I'd like explore making a small ecosystem of open security plugins built on top of OpenWrt. The goal is to make firewalling and controlling network traffic rea
by CommanderData 8y ago
I'd like explore making a small ecosystem of open security plugins built on top of OpenWrt.
The goal is to make firewalling and controlling network traffic really easy.
The UI should be so easy a parent could perform difficult tasks such as limiting an iot devices traffic to local net or maybe just one ip using just an app.
Or detecting unusual patterns of traffic from a device or IP addresses.
The apis exist I can't think of many barriers to entry.
- neospice 8y agoIt seems obvious that this should be developed, but to take it a step further it would be great if consumers could purchase something that gave them access to these plugins without needing to know how to setup OpenWRT. This will be challenging because most ISPs provide the router and firmware for the majority of their customers.
- CommanderData 8y agoI would personally love to see the same, and a way of unifying experiences across all open firmwares such as ddwrt. Another is to limit a device to communicate to a specific country. Easy enough however a possible performance issue.
- wtallis 8y agoISPs will have to start requiring the OEMs to offer some form of ongoing software maintenance, rather than just the rare bug fix on a distribution that otherwise dates to when the SoC inside first taped out. I can't imagine the OEMs or the SoC vendors being willing to do that kind of maintenance in-house, but the large ISPs certainly have enough leverage to require upstream support in OpenWRT.
- ethbro 8y agoHa. In a choice between mandating people rent their routers, or pushing vendors to offer patches, I wouldn't bet on ISPs picking the latter.
- ObsoleteNerd 8y agoWhere the ISP forces use of their modem (like mine does), you can still set it up as a gateway and make it a pure modem, using a second router for your local network. It's what I've done for years and it works fine. I have a Pi-hole off my ISP modem, and the Pi-hole does DHCP, DNS, VPN, and more for our network at the same time as doing it's normal filtering job. I'd love a better device where my Pi-hole is though, which I can configure easier, set up for my friends and family then they can manage it themselves, etc. There's definitely a market for this at least from me!
- corndoge 8y agoI think the problem is that it already is really easy. I feel like it'd be hard to simplify the interface of something like UniFi's AP series and still keep the number of knobs it gives you. And you almost certainly will never simplify it to the point that people will stop making youtube bandicam free edition tutorials on how to port forward your minecraft server.
- Fnoord 8y agoThe UniFi range is very easy. The Edge series (such as EdgeMAX) is slightly less easy, but also more powerful. Easy and secure are not always a good match though. Take UPnP for example. Disabled by default on my ER-L, it can be enabled, but its ultimately insecure. And ultimately, HTTP over SSL could download payloads.
- NickBusey 8y agoIt sure sounds like you are describing Turris OS. https://project.turris.cz/en/software https://project.turris.cz/en/software
- securityn0w 8y agoWhy did not they add the features to OpenWrt trying to make it better? Almost all the forks of OpenWrt die in months. Some lasted only few years. I am afraid that it is a wasted effort.
- bubblethink 8y agoI think mainline openwrt runs on turris hardware now. From what I remember, the main feature of their fork is/was snapshot management through btrfs. Updates are quite lacking in general on openwrt, so I think it's good that they are doing something about it. Ideally, I would like to run a full distro on routers, and manage it through standard distro tools, now that we have reasonably powerful hardware (like the Turris).
- iuguy 8y agoOpenWRT development was stale when Turris started. Don't forget the LEDE fork was born out of problems with OpenWRT development.
- deleted 8y ago[deleted]
- flukus 8y agoThe biggest barrier to entry I've found with this stuff is the hardware, I can't walk into a store and buy something with OpenWrt pre installed and for various reasons online isn't a a good option. I've looked at various possibilities and the whole scene is a mess similar to phone ROMs where you have to trawl through random forums, pull down random ROMs, trawl through more forums to find out why x doesn't work in $country with $ISP. It's impenetrable to anyone that doesn't want to invest months into the scene and develop expertise in it. Much like phones we really need a PC equivalent in this space.
- wtallis 8y ago> I've looked at various possibilities and the whole scene is a mess similar to phone ROMs where you have to trawl through random forums, pull down random ROMs, trawl through more forums to find out why x doesn't work in $country with $ISP. That's describing pretty much all the alternative firmware distributions, except OpenWRT, which is actually well-organized and delivers real stable releases. If you're digging through forums to find forks and builds made by some anonymous individual, it's almost certainly because you got fooled into buying hardware that requires closed-source drivers. (Or else you bought something that is just too new and not yet supported by OpenWRT.)
- flukus 8y ago> it's almost certainly because you got fooled into buying hardware that requires closed-source drivers. Bingo, that seems to be about all that's available. I'm looking at off the shelf hardware I can purchase locally, hardware I know works with local ISP's, I have no idea if we use the same standards as America for this stuff, what connections and adapters I'll need, etc. Buying locally eliminates these variables. If there's a happy path by all means share. I only looked into this stuff in the first place so I could get set up a home server and my current modem/router is woefully out of date and has a very suspect definition of DMZ.
- wtallis 8y ago> hardware I know works with local ISP's Your ISP is irrelevant, unless you're shopping for an integrated modem+router. Rule number 1 is don't do that, and keep your modem separate and just a modem. Then your router only needs the universal standard Ethernet port as its WAN interface, and at worst you might have to configure PPPoE instead of just using DHCP to get your public IP.
- EGreg 8y agoWe would like to build a captive portal using OpenWRT, to implement social networks running on a LAN. Anyone who is interested in this kind of stuff and has some experience, please contact me at greg+captive @ at @ qbix.com