10 ms·
Newer TP-Link Routers send large volumes of requests to Avira servers
- danpalmer 5y agoI remember reading in the UK government's security assessment of Huawei that one of the issues is not necessarily data being sent to bad places or backdoors in the software, it's that the engineering processes behind these devices/software are completely unable to protect against any sort of supply chain attacks. The sorts of things they highlighted were: no version control, no code review, production builds happening on arbitrary machines, no automated testing, poor access control on code, no audit trail on code changes, the list goes on, and that's just for the software side. The conclusion was that Huawei were about a decade away from being able to even claim they had no backdoors. And that's a major telecoms hardware provider, trying to sell into governments and major infrastructure projects. I'm not in the least bit surprised that TP-Link are doing this, and also not at all surprised that when questioned on it they are (so far) unable to actually describe why it's happening or really seem to know anything about it. I think this sort of product is built in a very different environment to what most HN users would expect.
- legalcorrection 5y agoAlso a perfect environment to slip in back doors that look like mistakes.
- danpalmer 5y agoExactly, that was their point. I suspect there are a lot of software supply chains that are actually compromised, because it's just too easy when this is the standard of software engineering. It's easy to forget that git for example is not just a big "undo" button, it's a cryptographically secure audit log of all changes made, that allows you to know exactly what software you're actually shipping.
- bostik 5y ago> cryptographically secure audit log of all changes made, that allows you to know exactly what software you're actually shipping. To be pedantic: not quite. Git is certainly a cryptographically secure audit log[ß] but it only tells you what the source code was that went _into_ the build at the time of checkout. You can subvert the process through malice (eg. Solar Winds), through incompetence (eg. off-tree "magic" patching as a build step), or through sheer negligence. Reproducible and auditable builds are a much harder problem than source code provenance. ß: from my previous job: once auditors understood what git is, they loved it. They, by their profession, love immutability. Failing that, they consider tamper-evidence a really good second-best.
- danpalmer 5y agoOf course, I was simplifying this somewhat to make a point. I think git can be a significant part of the solution, but there's a lot more that goes into it.
- bell-cot 5y agoWith enough mistakes, why would anyone bother to install a back door? That costs money, and reduces deniability.
- Dah00n 5y agoYes, it has happened multiple times at Cisco.
- geokon 5y agoA perfect situation for Hanlon's razor... Is this stuff not par for the course? Everything hardware/embedded in my experience is like a decade or two behind the current norms for c/c++ programming. What I never understood from that audit, was this code quality unusual? I didn't get the sense they audit European and American companies - so sure they looked at the source and said "lol your code sucks" but there was no baseline for comparison But it sounds like you know the situation better - maybe you have better context. I've been curious to know from someone more familiar with the subject
- danpalmer 5y ago> A perfect situation for Hanlon's razor... I'm not at all suggesting that Huawei (or TP-Link, or anyone else) are actively attempting to subvert security systems or intentionally adding backdoors. In that sense it's probably right to conclude this is ignorance. The problem is that an attacker, especially those with the backing of a nation state, can trivially attack those insecure supply chains and install backdoors or data exfiltration. As for whether others are as bad, I think the sort of audit that was done on Huawei is done for other companies attempting to sell into that level. These audits are not really about looking at the code – sometimes they do, but you're never going to get a useful security audit of 10s-100s of millions of lines of code. They're more about the security posture of these companies, and in that way, Huawei failed. I do expect that Cisco, HP, other network hardware vendors are better at this. Do they still have crap code? Sure. Do they still have security vulnerabilities? Of course. Could a nation state still get a backdoor in? Probably. But would it be significantly harder to do, easier to detect, and easier to resolve? Yes, and that makes them better suited to critical infrastructure.
- geokon 5y ago"But would it be significantly harder to do, easier to detect, and easier to resolve? Yes, and that makes them better suited to critical infrastructure. " But like what is that conclusion based on? I'm not saying you're wrong - just curious why you hold HP and Cisco in high esteem. At least in terms of engineering talent I'd expect them to be much worse. Huawei is prolly the Google of China paying huge salaries and getting the county's top engineers (along with Alibaba). When I lived in Santa Barbara Cisco didn't have a good rep and they didn't pay well. A typical bureaucratic officespaceesque soul sucker. I don't know about HP but I don't get the sense it's a presitgious place to work either. Again, these are very shaky ill informed judgments on my part I admit :) hence why I'm curious if you're talking from a position of knowledge on the subject
- servytor 5y agoThe UK has been indecisive about trusting Huawei [0 (sorry for the Daily Mail link),1,2,3]; I don't know why and find it very interesting. I am used to reading about nation states having an unwavering opinion, not flipping back and forth (unless because of political lines). They claim that their hand has been forced by the USA [4]. [0] https://www.dailymail.co.uk/news/article-7935905/MI5-MI6-GCHQ-tell-Boris-Johnson-defy-Americas-pleas-pull-plug-tech-deal.html https://www.dailymail.co.uk/news/article-7935905/MI5-MI6-GCH... [1] https://www.cnbc.com/2019/10/09/former-uk-spymaster-john-sawers-plays-down-huawei-security-fears.html https://www.cnbc.com/2019/10/09/former-uk-spymaster-john-saw... [2] https://www.reuters.com/article/us-britain-huawei-tech-five-eyes/uk-spy-chief-says-no-threat-to-five-eyes-alliance-over-huawei-idUSKBN23B2T3 https://www.reuters.com/article/us-britain-huawei-tech-five-... [3] https://www.ft.com/content/90c07bbe-38ce-11e9-b856-5404d3811663 https://www.ft.com/content/90c07bbe-38ce-11e9-b856-5404d3811... [4] https://www.euractiv.com/section/politics/short_news/uk-banned-huawei-because-us-told-us-to-former-minister/ https://www.euractiv.com/section/politics/short_news/uk-bann...
- danpalmer 5y agoYeah the actual position of the government is all over the place and it's all tied up in the politics of US/China relations. I think the findings in the report are still a concrete assessment of Huawei's abilities that we can draw conclusions from about their product security.
- blibble 5y agovince cable is not part of the government and has no more information on the situation than you or I the government was resistant to the US' position until the CCP's crackdown on hong kong, at which point they reversed their position
- deleted 5y ago[deleted]
- user3939382 5y agoI had/have a Gemini (Android) from Planet Computers. I disabled wifi and forced its network connections through an ethernet adapter that I connected to a mirror port->wireshark and through a proxy after putting in my own root certificates. My goal was to silence its network activity when I wasn't using it. One by one I removed APKs and blackholed IPs and domains, starting with everything from Google. I was disturbed to discover that, even having nothing installed and everything ripped out that I could, once every week or two while sitting untouched it would phone home to an IP address in China that I failed to connect to any software on the phone and whose IP WHOIS made no sense. I asked Planet Computers about it and they had no idea.
- landemva 5y agoWould like to see this writeup somewhere, both for the results and for the methodology.
- _wldu 5y agoI find it hard to believe that Huawei does not use version control. No company is perfect, but surely software developers (at a multinational company) with advanced degrees in CS and ECE are using version control.
- matheusmoreira 5y agoSo how do we get routers that support open source firmware? It seems these things are getting more difficult to find.
- aaronmdjones 5y agoThe WRT1200AC family (WRT3200ACM etc) support it out of the box as a first-class feature. https://www.linksys.com/nz/wireless-routers/wrt-wireless-routers/linksys-wrt1200ac-ac1200-dual-band-wifi-router/p/p-wrt1200ac/ https://www.linksys.com/nz/wireless-routers/wrt-wireless-rou...
- haukem 5y agoThe WRT1200AC family is not well supported. The Ethernet part should work fine, but the Wifi is unsupported since some years now, see here the repository: https://github.com/kaloz/mwlwifi https://github.com/kaloz/mwlwifi The vendors are not interested in this hardware any more, but they have very good marketing and sales. Linksys and Marvell also did not really support the OpenWrt community, they just had good marketing. If your WRT1200AC device does not work well with OpenWrt do not complain to OpenWrt, but complain to the Linksys support. The WRT1200AC family for example does not support WPA3, because the closed source Wifi firmware does not support it. The 15 years old WRT54G supports WPA3, it is just very slow. ;-) Currently I would suggest the Linksys E8450 / Belkin RT3200 (same hardware) or some other device using the current Mediatek platform with MT7622 + MT7915 + MT7531. (2 X Cortex-A53, Wifi 6) All chips are supported in recent upstream Linux kernel, including Wifi. The Mediatek router team is currently doing pretty good upstream open source work for their chips.
- aaronmdjones 5y agoNeat! Looks like that just became my new front-runner. I'm still happy with OpenWRT on my WNDR3800 for now either way.
- filomeno 5y agoOne alternative could be, instead of buying a router, getting a single board computer designed to run whichever routing software you like. Banana pi is an example that comes to my mind. You'd need to get a case, and it won't be as neat as a commercial router.
- squarefoot 5y agoThe software answer would be easy: use OpenWRT or any other *BSD based alternative, but what about the hardware? A quick search for WAN interfaces for PCs returned nothing.
- peppermint_tea 5y agoconfigure the box your ISP gives you in bridge mode. I do this and use apu2d4 as hardware
- ianai 5y agoQotom and protectli make some cool options. I’ve used both with *nix.
- kemotep 5y agoI would agree that it can be difficult to find quality hardware that supports the open source software stack. For example, what wireless access points are compatible with an openbsd router/firewall? I’ll admit that my initial searches were short but only finding results about wireless chipsets to use in the router were frustrating (I guess if I wanted to build my own access points that information would be valuable).
- detaro 5y agoWhat does it even mean for an access point to be "compatible" with a specific OS on the router?
- kemotep 5y agoLike the ability for the ap to understand how the vlans the router setup work. I’m still quite the network novice but it seems like if I wanted a bsd firewall -> managed switch -> wireless ap I would need to confirm some level of interoperability for decent performance?
- detaro 5y agoThat kind of interoperability has nothing to do with the OSes though if you straight-up configure things. VLANs are VLANs, regardless if it's Linux, Windows, BSD, Cisco, ... on the other end of the cable. (And if you expect some kind of automatic configuration sync etc the answer is in reverse "doesn't work unless you buy everything from one vendor", for that part there is little standardization)
- frogger8 5y agoFrom the comments Nothing in your analysis shows this. Moreover unless you explicitly deployed a root certificate on your clients (or if an app on the client did it), the router can't decode TLS traffic (deep inspection) without you getting certificate warnings on the client. In that case, the only thing the router can see is the dns request, the IP and the TLS SNI. In short your title is misleading. permalinkembedsavereportreply [–]ArmoredCavalry[S] 11 points 14 hours ago* I agree they couldn't be inspecting the contents of your traffic over TLS, but they could easily view destinations. I also agree, there's nothing in my analysis that proves that all the requests are related to network traffic. However, if you look at the wording of the reply (directly from TP-Link) to XDA in their review, I don't see how it could be interpreted any other way? Regardless, I probably should have made my title "appears that it may send traffic related data". I'll be happy if that isn't the case, but the lack of clear explanation from TP-Link when I've contacted support leads me to assume the worst permalinkembedsaveparentreportreply [–]2fast2fourier 4 points 12 hours ago I think it's best not to write something that damaging without proof, especially when most people only read titles. Saying they're sending metadata and violating your privacy is all you'd need to hear.
- jjav 5y agoThere is really no excuse for any network equipment to be sending anything at all to external parties, unless you've specifically subscribed to some service where it becomes necessary. Which the OP said they don't. Let's be careful to not normalize this type of data exfiltration from equipment that's supposed to be yours.
- tinus_hn 5y agoThis case is not that, but for instance update services and time servers are defensible reasons to connect to external parties.
- zinekeller 5y ago... and I don't get your point in this useless pedantry? Sure that the data in of itself is not sent, but you seemed to imply that DNS queries don't reveal anything. In practice, you can build a good enough picture to decode what's their interests, what type of places they visit etc., which is worrying of itself. It's like saying to not worry because they didn't know you ordered a Big Mac while the fact that you went to McDonald's is being known is already creepy to a lot of people.
- maxloh 5y agoTP Link is a Chinese company. I won't trust them personally. In China's current political status, it is impossible for Chinese companies to reject the autocratic government's requests for surveillance. You may endup in jail or even get killed.
- ttybird2 5y agohttps://arstechnica.com/tech-policy/2014/05/photos-of-an-nsa-upgrade-factory-show-cisco-router-getting-implant/ https://arstechnica.com/tech-policy/2014/05/photos-of-an-nsa...
- naoqj 5y agoI mean, I get it, but Avira is a German company.
- lotsofpulp 5y agoAvira’s bosses get their marching orders from NortonLifelock bosses, which seems to have pretty American leadership: https://www.nortonlifelock.com/us/en/corporate-profile/management-team/board-of-directors/ https://www.nortonlifelock.com/us/en/corporate-profile/manag...
- Lifelarper 5y agoSo hypothetically as a western activist at risk of govt coercion you'd trust Cisco more? Statistically, you very likely own a Chinese manufactured router while using it to tell others here not to do the same.
- irutirw222 5y agoThis is a good point. Probably most people are not aware of the country of origin of most of the tech products (resp forna given product, how many important, modular subparts come from Chinese companies). It would be highly interesting if there would be a website where you could type in the name of a product (e.g. sime Cisco) router and it would give you a detailed decomposition of where and by whom is parts where made. Something like (highly simplified) : - CPU design: Company X - CPU manufacturing: Company - RAM design and manufacturing: Company Z - Overall remaining logic: Cisco
- ajot 5y agoThat's before installing OpenWRT! This kind of shenanigans make (once again) the case for 3rd party post market FLOSS firmware to be installed on every device I own. Sure, I spend some extra time researching which router/AP/phone/ereader/smart appliance will be compatible with OpenWRT/LineageOS/KOReader/Tasmota/ESPHome/etc., but I feel more confortable this way. I have more trust in a bunch of people doing this for owning their devices than some corporation whose goals clearly don't align with mine.
- mise_en_place 5y agoYou could also buy an SBC with a few network ports and use that as your router.
- mananaysiempre 5y agoIME small ARM SBCs generally have a miserably slow bus arrangement for this sort of thing (and no hardware switch chip, of course). People have had some success with routers built on x86 mini-PCs[1], but these lean towards the “flexible and performant” side, not the cheap side. [1] https://arstechnica.com/gadgets/2016/04/the-ars-guide-to-building-a-linux-router-from-scratch/ https://arstechnica.com/gadgets/2016/04/the-ars-guide-to-bui...
- nerdponx 5y agoI was just wondering about this the other day. Are there still no options other than to buy/build a grossly overpowered x86 machine?
- zinekeller 5y agoBefore you say anything about this feature (which is apparently called HomeCare, https://www.tp-link.com/homecare/ https://www.tp-link.com/homecare/), you should probably know that Asus also has a AiProtection feature powered by Trend Micro (https://www.asus.com/content/aiprotection/ https://www.asus.com/content/aiprotection/) and D-Link having McAfee Secure Home Platform built-in (https://www.dlink.com/en/latest-news/d-link-introduces-new-exo-router-series-with-mcafee-protection https://www.dlink.com/en/latest-news/d-link-introduces-new-e...). Definitely not vindicating TP-Link here (especially the alleged continuous querying despite the feature being off), just noting that this is not exclusive to TP-Link.
- sloshnmosh 5y agoI came here to say the same. I even purchased a LAN throwing star to look to see if my Asus router was sending anything to TrendMicro but never did get around to it. But I will now for sure.
- webmobdev 5y agoDamn. Seems like they have all "discovered" a new revenue model - harvest and sell user data to third-parties / data brokers.
- jnwatson 5y agoThese are all premium features you have to sign up for.
- zinekeller 5y agoSo why is the first line of their marketing material says "lifetime subscription for the life of the device" and not for a monthly fee? Also, I have an Asus Router with AiProtect and it didn't upsell me, and definitely no monthly dues (I'm not shocked if the data collected is resold however though).
- Pxtl 5y agoYes but the feature is optional, and tells you how it works if you turn it on. And realistically, most of the extended features on consumer routers are ineffective at best and network-destroying in typical cases. For example, I've never used a router ever turning on QOS did anything but trash network performance. I use and recommend Asus routers because in spite of them being shitpiles when you turn on anything but the basic functionality, the industry standard is that low that consistently good basic functionality is a stand out success. The router industry makes printer companies look like Apple.
- richardfey 5y agoGDPR fine & class-action lawsuit in 3...2...1
- Kiro 5y agoReadable link on mobile: https://www.reddit.com/r/hardware/comments/tbthjj/psa_newer_tplink_routers_send_all_your_web/ https://www.reddit.com/r/hardware/comments/tbthjj/psa_newer_...
- 29083011397778 5y agoShould be [0] for mobile [0] https://i.reddit.com/r/hardware/comments/tbthjj/psa_newer_tplink_routers_send_all_your_web/ https://i.reddit.com/r/hardware/comments/tbthjj/psa_newer_tp...
- Kiro 5y agoI personally prefer the regular mobile view.
- sebow 5y agoTP-Link became a big no-go for me as soon as ax came out and I saw that they required account registration[0] for managing a personal, local router. Probably has to do with the fact that they're not western-owned and are 'legally required' to have such a system in order to be covered from 'borrowing' your data. I expect other vendors(Huawei,etc) to do the same, and it's insane that people don't revolt against such practices, especially considering we still have such vendors being installed by default in people's homes by the ISPs.And whilst a router is replaceable by the end user, something like an ONT is harder to find in most places, and the ISP doesn't usually give config details for an ONT. [0] Edit: An online account for the mobile application, not the web interface of the router itself.
- YaBomm 5y ago
- WJW 5y agoALL routers send my web traffic to 3rd party server I would hope. I don't have a router to access all the websites on my home network after all. Joking ofc, this is pretty bad. Terrible coding in the best case, outright spying in the worst. Neither instills a lot of confidence in TP-link.
- sabujp 5y agoI setup cloudflare zero trust and started pointing my AC4000 to it, let's see what happens.
- sabujp 5y agoi've had it on for 2 days now, no requests to avira, i have homeguard completely turned off.
- microtonal 5y agoThis is why for home and small office use, I usually get AVM Fritz [1] network devices. They have been around for since forever, provide regular updates for their devices and over a long period. Their web interface allows for a lot of fine-grained configuration and their devices have been rock solid for me. They are a German company and as far as I know software development is also done in Germany, so I expect that they operate within the relatively strict privacy regulations of the EU. [1] https://en.avm.de https://en.avm.de
- q3k 5y ago- 8< - I was wrong - 8< -
- ChuckNorris89 5y agoWould you mind to provide a source for this claim please.
- deleted 5y ago[deleted]
- mhitza 5y agoIf you want to see TP-Link routers track record, and if you have an existing TP-Link router, check the updates page on their support website. Same kinds of vulnerabilities are fixed often across devices, as if not learning from their mistakes. When it comes to budget routers I still turn to TP-Links when I can easily find a decent model on the market that is supported by openwrt.
- ytch 5y agoI was annoyed by the Deco APP too. It provides remote management, which I believe that all data is forwarded through TP-Link's server. My solution is running those devices as a Wi-Fi to LAN bridge, also setup my own NAT gateway (by bare-metal Linux, Openwrt... etc). Then blocking there devices from accessing Internet at gateway. If I have more IoT devices at home, I will apply such policy to all of them.
- deleted 5y ago[deleted]
- lazyeye 5y agoSenior people at tp-link should go to jail for this.
- jmillikin 5y agoThis was alarming since I use a TP-Link router, so I tried figuring out to what extent it's able to inspect and record regular (encrypted) traffic. My TP-Link Archer AX50, running software version "1.0.11 Build 20210730 rel.54485(4A50)" is doing at least some sort of DPI on outgoing connections. I found a page in its settings (Advanced -> Security -> Antivirus -> History) that contains a log of connections I've made to "suspicious" domains, which include quite a few that I would consider innocuous. After clearing that log, I loaded a few domains I'd seen in it, and verified that new entries were created. Wireshark shows that no DNS requests were made, and the DNS-over-HTTP used by Chrome didn't leak that traffic. I believe the router must be inspecting TLS headers for the ServerName field. Didn't try to verify whether that data is being sent to a third party, but given that this thing is collecting data that it has no business looking at, it wouldn't surprise me if it's shipping it somewhere. edit: the URL I tested with is <https://api.mangadex.org/docs.html https://api.mangadex.org/docs.html>.
- t0mas88 5y agoIt could be doing reverse lookup on the IP you connected to? That's what a lot of network monitoring tools do.
- jmillikin 5y agoThat's not as common any more, due to the broad adoption of TLS-capable CDNs (Cloudflare, Fastly, etc) over the past ~10 years. In this case the site I tested with had a few different subdomains backed by the same IP, which I verified from a remote VPS. Using `curl` locally, with the `--resolve` flag to bypass DNS resolution, caused the router's log to contain entries for the specific subdomains requested.
- jnwatson 5y agoLooking at DNS traffic isn't generally considered DPI.
- verisimi 5y agopwned
- jamal-kumar 5y agoHasn't avira been just generally for a lack of better words completely fucking awful over the past year or two? The last I remember hearing about them was installing crypto miners along with their AV, which I can only imagine being bottom quality at this rate of insanely bad behaviour...
- vehemenz 5y agoAnecdotally, I've seen that TP-Link routers are ubiquitous in Chinese households. I don't draw any conclusions from that, but I did stop buying TP-Link devices. It would be nice if the US took import controls as seriously as export controls.
- Ourgon 5y agoI never rued the day when I switched off the last "appliance" router after switching to a virtual router - OpenWRT running in a container on a Proxmox-managed host. I use a number of repurposed "appliance" routers (also running OpenWRT) as access points, some of them connected to additional "dumb" PoE-switches for IP-camera's. Those camera's run over their own VLAN and never get to touch the 'net, the same goes for "IoT" things (heat pump, PV-inverter etc). Xi and friends will be disappointed, even if they built backdoors in their equipment these only lead to a dead-end street.