4 ms·
Don't rely on vendors to ship you secure fimware. Use something open source such as OpenWRT. It will make implementing the protections this blog mentions much e
by stonepresto 4y ago
Don't rely on vendors to ship you secure fimware. Use something open source such as OpenWRT. It will make implementing the protections this blog mentions much easier.
- throw0101a 4y agoI've found out-of-box Asus to be pretty good, and they sometimes even incorporate features from third-party firmware (see "first debuted"): * https://www.asuswrt-merlin.net/features https://www.asuswrt-merlin.net/features
- NGRhodes 4y agoMerlin firmware is special in a good way. Merlin has a good relationship with the Asus firmware dev team, he gets early access to official firmware, they sometimes ship him unreleased routers. He often finds and fixes bugs and creates/adds new features that Asus pickup. Also very careful to maintain full compatibility with the stock firmware, making it easy to switch between stock and merlin. He has also created an interface to allow 3rd party features to get their UI page. There is probably more, but it really is an excellent project.
- whateveracct 4y agoMerlin is why I got an Asus router when the time came to upgrade.
- Etheryte 4y agoI've had similar experiences. As time goes on I want to spend less and less time configuring things and more on things that actually matter. Asus' defaults are good and whenever I do need to reconfigure something it's always a breeze.
- teknico 4y agoAgreed. It’s also the easiest way to improve latency and fix bufferbloat. Unfortunately not all Merlin-supported routers support the CAKE algorithm. My choices are the RT-AC86U, and the RT-AX68U if you need Wifi 6 support. Don’t get the RT-AC88U though, it has no CAKE. (If you’re lucky enough to have a gigabit connection, you’ll need more expensive stuff.)
- amelius 4y agoI recently bought a TP-Link router. It comes with a note that says that it is based on GPL software. However, when I try to install OpenWRT firmware on it, it rejects the update (probably based on a missing crypto signature) ... They do provide access to the sources, but isn't this still a violation of GPL?
- phonepostingsux 4y agoMy understanding is that it would violate GPL-3 but not GPL-2 (search term "tivoization clause"). Notably, Linux itself is explicitly GPL-2. IANAL, nor am I an expert.