4 ms·
I really wish there was an open source equivalent that’s user friendly. I run OPNSense but the learning curve is steep and I wouldn’t recommend it to family bec
by syntaxing 3y ago
I really wish there was an open source equivalent that’s user friendly. I run OPNSense but the learning curve is steep and I wouldn’t recommend it to family because of it. I’ve been debating Firewalla but this same issue can happen since the control panel is cloud based.
- Arnavion 3y agoWell, since we're talking about delays in security responses, OPNsense is in the same boat. https://news.ycombinator.com/item?id=34839161 https://news.ycombinator.com/item?id=34839161
- ojfkwai 3y agoI have a lot of complaints about OpnSense. But how exactly is that a similar security response? That wasn’t a security incident for OpnSense. It was a CVE for an optional package most users probably don’t have installed. Sounds like not-an-emergency to me. That user is completely unreasonable. Opnsense should refund their money (if any lol) and tell them to pop off.
- Arnavion 3y ago>That wasn’t a security incident for OpnSense. It was a CVE for an optional package most users probably don’t have installed. First of all, the point is that the OS didn't release CVE fixes for the packages in its repositories even though it had already committed those fixes to version control. Notice that my comment specifically talks about "delay in security response", not that it was an "emergency". >That user is completely unreasonable. Opnsense should refund their money (if any lol) Second, I recommend reading the comment you respond to carefully before you rush to make an account to respond to it. "That user" is me. The GH thread has a clear comment from me that I did not pay them any money and do not have any expectation of support. Third, notice that the point of the GH thread was me asking what their policy of releasing CVE fixes was. You seem to think I was some Karen complaining that they hadn't released the fix. All I asked was a confirmation that they're aware that they're shipping a package with a CVE, that they've already fixed the package but just not published it, and what their policy is for releasing fixes in general. They could've responded with something like "We're aware of the CVE but we don't plan to release the fix in 23.1. Our policy is to only release bugfixes for non-critical packages in the next stable release, and we consider os-haproxy to be a non-critical package." Instead they got weirdly defensive about it, tried to lecture me about how OS releases generally work, called me "rude" (ironic), and locked the issue. The ultimate point is that OPNsense delays security fixes. Maybe you think it's okay because you think some OS packages are critical and this one wasn't. Maybe you think if an OS can't articulate its security fixes release policy without getting combative, then it's hard to take its security seriously. The decision is yours.
- Althuns 3y agoThe maintainers of OpnSense are able to make their own determination about the severity of the issue and the method of the fix. They gently reminded the user of their process. Ubiquiti, as a provider of a paid security product, has a much larger, immediate, and different responsibility to fix the issue and communicate clearly with their clients. I think that everyone is entitled their own intentions, but they are also responsible to communicate those intentions effectively. If the intention was to not be "some Karen complaining" it wasn't clearly communicated that way.
- lolfamdum 3y ago[flagged]
- smittywerben 3y agoYeah he installed a webserver on his router and walks up to the BSD port maintainer and complains about security LOL, he even archived it.
- radicality 3y agoIf it was open source, would you recommend Unifi to your family? I feel like family will either be technical enough to understand OPNSense, or not technical at all at which point even Unifi is not something they'll manage themselves. I actually run OPNSense for myself at home, but for my parents I deployed full Unifi. This way if there's any problem, I can remotely look at the network in the cloud console and try and see what's wrong.
- kube-system 3y ago> I feel like family will either be technical enough to understand OPNSense, or not technical at all at which point even Unifi is not something they'll manage themselves. Agreed. Major ISPs in the US (and I presume many other places) offer routers that work well enough to satisfy the requirements of any non-technical household and often come with provisioning/troubleshooting features that enable the ISP to provide technical support if necessary. In the old days, ISP-provided devices often lagged behind other consumer or prosumer network offerings, and it made sense to swap them out... but that's not really the case today. Today, swapping out the ISPs router is probably going to make a non-technical user's life harder, unless they have someone technical to manage it for them.
- olyjohn 3y agoISP gear is still trash. It's just better for the user, because the ISP won't bitch and moan and tell you your hardware is unsupported.
- kube-system 3y ago"Trash" is subjective. Satisfaction happens when a product or service meets the user's requirements. A new Cisco catalyst setup may be technologically superior to my mother's ISP provided router, but it might not make it easier for her to play Candy Crush on her iPhone if she forgets the wifi password.
- olyjohn 3y ago
- bityard 3y agoI'm pretty bad at coming up with business ideas, but one that I think would work, if I ever got the time to do it, is a user-friendly x86 router firmware centered around the idea of making it as easy as possible to set up and control your network and its devices. On my home network, what I really want is the ability to define one or more networks (VLANs, if you will) and then place devices in those networks. When you click on a device, you are then able to do things like give it a static IP, look at the traffic it's generating, shape its traffic, disallow traffic from/to certain ports, kick it off the network at certain times of day, allow it access to the local network but not the Internet, change its DNS resolvers, etc. In order to do these things on most routers, if they offer the ability at all, you need to jump around to different places in the UI and manage each service as its own thing. OPNSense is great (and it's what I currently use) but it's UI is really just multiple little windows into the various sub-services that the firmware provides. Separate page for all the firewall rules, another for all the DHCP leases, etc. It works, but it's kind of frustrating to use, especially when you're not digging around in it every day. The business model would be: everything open source, but three "tiers" of releases: 1) free "beta" releases featuring new and lightly-tested features for the adventurous. 2) "stable" releases via subscription (paying customers have access to the source code and build tools) 3) "freeloader" releases, the same as "stable" but with a 6-9 month delay. Devil is in the details of course, but if I had any entrepreneurial bent at all, I think it would be a big improvement over the current state of things.
- worksonmine 3y agoDo you know about OpenWRT and the others? If yes what are they lacking?
- bityard 3y agoI know about OpenWRT and used it for years on various cheap MIPS routers. But back then, the UI did not come with the firmware, you had to install it separately. And it was _very_ basic and there was lots that you still had to do on the command line to get anything done. Correct me if I'm wrong, but that still looks to be largely true. Except that there are multiple to choose from: https://openwrt.org/docs/guide-user/luci/webinterface.overview https://openwrt.org/docs/guide-user/luci/webinterface.overvi... I had a look at a few, and they all seem to be "managing the router"-centric, not "managing your network"-centric.