4 ms·
Another option is to build your own. You could buy a small ARM board like a NanoPi R6S (<$100) with 2.5GbE ports and run pfSense on it.
by profquail 3y ago
Another option is to build your own. You could buy a small ARM board like a NanoPi R6S (<$100) with 2.5GbE ports and run pfSense on it.
- demandingturtle 3y agoyou mean buy it from China? Guangzhou,GuangDong China. That's great advice.
- colordrops 3y agoOr better yet OPNSense.
- wannacboatmovie 3y agoThe NanoPi is of Chinese origin, all the way down to the silicon, how do you know the bootloader or the CPU isn't compromised? If someone told you a cup may contain poison, would your first reaction be to drink it just to be sure?
- maven29 3y agoWe have photographic evidence of the NSA intercepting Cisco routers. I'm not sure the country of origin matters if you have a red spot painted on your back. https://arstechnica.com/tech-policy/2014/05/photos-of-an-nsa-upgrade-factory-show-cisco-router-getting-implant/ https://arstechnica.com/tech-policy/2014/05/photos-of-an-nsa...
- wannacboatmovie 3y agoWhat's being proposed here - as an alternative solution to mass-produced Chinese equipment of unknown trustworthiness - is to purchase different mass-produced Chinese equipment of unknown trustworthiness. Your example of highly-targeted physical interception by state-level actors is irrelevant here.
- maven29 3y agoYou are really bringing your own OS here. The nanopi can run mainline linux and u-boot[0]. If you suspect an Intel ME-style component with ring -3 access, it should show up in the initialization sequence - there are no blobs here. Features like these are not cheap to implement, especially when Chinese vendors are so keen on cutting costs. Essentially, this means that there is zero risk, unless you are a target, at which point any unintentional hardware bug caused by the aforementioned corner-cutting will become a concern. [0] https://linux-sunxi.org/Linux_mainlining_effort https://linux-sunxi.org/Linux_mainlining_effort https://linux-sunxi.org/U-Boot https://linux-sunxi.org/U-Boot https://linux-sunxi.org/H3 https://linux-sunxi.org/H3
- chatmasta 3y agoHow do you guarantee there isn't some logic flashed onto the chip that overrides the bootloader sequence? btw, I asked about this 5 months ago [0] and got some interesting replies. I ended up purchasing a PCEngines board (just before they went out of business) [0] https://news.ycombinator.com/item?id=35568984 https://news.ycombinator.com/item?id=35568984
- heavyset_go 3y agoFrom what I've seen, networking peripherals you can attach to a Pi via USB, or whatever, can't really compete with networking peripherals in routers that are integrated on SoCs/SoMs.
- rjsw 3y agoThe suggested NanoPi R6S has two 2.5G ports connected to PCIe and one 1G port built in to the SoC, it doesn't use USB for networking.
- heavyset_go 3y agoI figure people are using them for router things, like using it as a wireless AP and switch, and the hardware available for those use cases usually fall short of what's available on router SoCs.