3 ms·
Hi folks, not much to see here. These routers are very well designed, receive regular firmware updates and are overall very solid. The only router that I haven
by aetherspawn 5y ago
Hi folks, not much to see here.
These routers are very well designed, receive regular firmware updates and are overall very solid. The only router that I haven't had to reboot since I've owned it (for nearly 18 months now). Had no random configuration resets, interface bugs, WiFi drop-outs, QoS issues ... just, solid.
So seeing that people have exposed it to the internet - sure, that's not recommended. But I don't think that it is something to be overly concerned about. It doesn't feel like your normal internet of crap router.
And as others have said, this is not the default setting, and you're actually warned when you try and enable external access. But for some, this is useful. Since this router supports a VPN server, external access could be the only way to troubleshoot it if you're not on-site.
- jfrunyon 5y agoOh, great! It's stable! That means it couldn't possibly have any 0days or weak passwords.
- aetherspawn 5y agoA security problem is a bug. If their track record is quality (i.e. no bugs), you can extrapolate that their process is pretty good at dealing with security problems as well. Until proven otherwise. Of course, nothing is unhackable. If a state actor wants to get inside your router, you'll lose no matter what. And you don't need to have https:// https:// exposed on WAN to get hacked in that way. The 0-day could just as easily be on the transceiver or on the WAN layer itself. The only way to protect yourself from a 0-day is to live in a tin foil bubble and simply never use a mobile phone or the internet.
- yipbub 5y ago> If their track record is quality. I really don't think that's the case for router manufacturers. > The only way to protect yourself from a 0-day is to live in a tin foil bubble and simply never use a mobile phone or the internet. Or have fewer attack surfaces. Like notoriously buggy routers.
- jfrunyon 5y ago> If their track record is quality (i.e. no bugs) They're a (consumer) router manufacturer. I don't care how good they are within that field, no, their track record is NOT quality. Worse yet, 90% of their code comes from the same vendors as every other router manufacturer. > you can extrapolate that their process is pretty good at dealing with security problems as well. That is a complete non sequitur; plenty of businesses have made useable, functional (widely-used!) software but had a head-in-the-sand approach to security. > Of course, nothing is unhackable. Exactly, which is why only things which must be exposed to the public should be exposed to the public. The rest of your argument is assuming the attack surface is the same whether remote management is on or off; or that the amount of attack surface doesn't matter. Either way is simply not correct. By the way, an issue in the "transceiver" would require physical proximity. I'm not sure what the "WAN layer" is, but if you mean like... the Ethernet port and interface, that would require physical access. If the remote management was off, you would likely be targeting nothing more than the units IP/TCP, UDP, whatever stack. With the remote management ON, you could target that, you could target the HTTP server, or you could target the admin panel running on it. Each of those are much more likely to have security holes for several reasons, but moreover there's simply no reason for them to be accessible publicly, while the routing and NAT functions are necessary to the purpose of the device.
- dole 5y ago"Regular firmware updates" Archer C7 v4's last firmware update, Dec 2019. Archer C7 v5's last firmware update, Jan 2021. Might be solid, but I guess "regular" is relative.