13 ms·
US could ban TP-Link routers over hacking fears: report
- misiek08 2y ago[flagged]
- tharmas 2y agoThe US Authorities remember when they did it to fax machines in Eastern Europe.
- oefrha 2y agoNSA has been “SIGINT-enabling” router chips for a long time according to Snowden documents. Discussed last year: https://news.ycombinator.com/item?id=37570407 https://news.ycombinator.com/item?id=37570407 There’s also that famous photo of NSA “upgrading” Cisco routers, of course. https://arstechnica.com/tech-policy/2014/05/photos-of-an-nsa-upgrade-factory-show-cisco-router-getting-implant/ https://arstechnica.com/tech-policy/2014/05/photos-of-an-nsa...
- tastyfreeze 2y agoExactly. Remembering that our own NSA has intentionally compromised devices makes all of the "ban China" calls sound like jealousy.
- oefrha 2y agoMore like “we know we’re doing this, so they’re likely doing it as well”. Makes sense.
- kittikitti 2y ago[flagged]
- tacticalturtle 2y agoThe NY Post is just reposting original reporting by the Wall Street Journal: https://www.wsj.com/politics/national-security/us-ban-china-router-tp-link-systems-7d7507e6?st=pbz4uG&reflink=article_copyURL_share https://www.wsj.com/politics/national-security/us-ban-china-...
- jaimsam 2y ago[flagged]
- NDizzle 2y agoIs the content in these articles incorrect?
- bediger4000 2y agoWho can tell? The WSJ article doesn't even say whether TP-Link hardware or software is the problem, which would seem to me to be extraordinarily important in reporting on this issue.
- tacticalturtle 2y agoTo be a little more charitable, I don’t think the average non-technical newspaper reader knows or cares about the difference. Most non-tech people I know treat a router as a black box system - you plug it in, and then when you have issues, you turn it on and off again. If it keeps happening you get a new one. The word firmware will draw blank stares.
- pessimizer 2y agoSome people read things as a source of information, others read them as a source of opinion. For the former, this link is fine because they don't care what the NY Post wants them to think. For people who prefer to receive their opinion along with their information, they should maybe consult a more personalized outlet, or their pastor.
- dole 2y agoThose running TP-Link gear might want to check whether theirs supports OpenWRT or another firmware option.
- throwway120385 2y agoThat doesn't help people running TP-Link infrastructure like Omada switches and Omada WAPs with an Omada controller behind a separate firewall/router.
- fidotron 2y agoAPs are going to be the great new app platform, but also a very clear security problem. They have now grown so much spare capacity they can host a lot of extra interesting services. The noises from China suggest some people in companies like Xiaomi worked this out a while ago. Fundamentally we need to move to a home networking model that involves isolating all clients completely (especially cameras and smart TVs), and using AP hosted services to mediate interaction between them and the Internet at large. This will involve needing to trust the AP, but will have the advantage of being able to deploy slightly less trustworthy devices at the very edge.
- toomuchtodo 2y agoCan you ensure this level of assurance without requiring an independent review of router firmware? If it is managing security boundaries, how do you know if you trust it? And how do you ensure that trust is maintained over device lifetime as firmware updates are shipped? Hard problem to solve by building and maintaining long run "people, process, tech" systems.
- fidotron 2y agoThat's kind of my point - it's inevitable that we will end up having to take the security of the AP enormously more seriously than we have. The AP will end up needing cellphone style updates and chain of trust integrity checks for the firmware. The reason this is inevitable is the alternative hasn't worked. Cloud based IoT has been a disaster in both the atrocious edge device security and cloud service bait and switch burning customer confidence in the whole concept. Most people are not going to deploy dedicated servers in their house, but an AP absolutely. The HomeAssistant and Frigate ecosystems demonstrate the demand for functionality is there, but they are very much enthusiast type tools.
- toomuchtodo 2y agoStrongly agree, I just don't see evidence there is any appetite for spending the resources needed to accomplish this. I would very much like there to be, but, you know. No one likes to spend until the place is already on fire. If this is the fire ("never let a crisis go to waste"), we should try to spend what's required to do what is needed. (a component of my work is software supply chain security)
- bloomingkales 2y agoI have one, should be worried?
- amelius 2y agoThis is a real pity since TP-link makes reliable gear with a very good price/performance ratio (Linux user).
- alephnerd 2y agoConversely, I find Ubiquiti to provide a better product
- y-c-o-m-b 2y agoI've found the opposite. The TP-link router I had was frustratingly unreliable, even when setup to reboot every night. Their firmware updates were slow to arrive. I tossed both the router and the TP-link PoE devices I had into the dumpster. My dad bought some TP-link devices and also complained about reliability issues. We've both vowed not to buy that junk again. Switched to ASUS a couple of years ago running ASUSwrt-merlin and haven't looked back.
- wtallis 2y agoIt seems a little unfair (and wasteful) that you didn't consider simply using decent third-party software on the TP-Link hardware you already owned, but rather bought new hardware and then started using third-party software. ASUS consumer networking hardware is no higher quality than TP-Link consumer networking hardware, and neither of them (nor anyone else operating in the consumer networking hardware market) provides high-quality software out of the box.
- deleted 2y ago[deleted]
- imp0cat 2y agoThis is not my experience, but I use the AX73, which is not a completely bottom-of-the-barrel model.
- JaggedJax 2y agoI have to agree here. I've had multiple TP-Link routers and all of them had regular random dropouts that would require reboots. They may work if you have 5 devices connected, but they are simply unreliable with even a moderate amount of devices and traffic. TP-Link is on my list of, "Not worth it at any price."
- nottorp 2y agoThere's that nagging feeling that they're not concerned about security but banning anything that works well, is inexpensive and isn't made by an US company... Anecdote: once I bought the cheapest router I could find online. The idea was to test connecting to a crap AP. Unfortunately the cheapest was a TP-Link and it worked absolutely perfectly, ruining my test plan.
- tiahura 2y agoThat doesn’t seem likely. Are there really US companies clamoring to make 0 margin disposable electronics?
- bluGill 2y agoThe margin is not 0. there is a lot of $$$ in low margin disposable products (think toilet paper). However it takes great management to make money building such things and few companies are that good.
- rekabis 2y agoTheir firmware is absolutely riddled with flaws and exploitable vulnerabilities. Unless you are willing to re-flash their hardware with third-party firmware such as DD-WRT or OpenWRT, I would always encourage anyone to go with a company that keeps their firmware up to date, like Ubiquity. It’s not their hardware. It’s their firmware which is the problem.
- nottorp 2y agoUbiquity has already attempted to make their customers dependent on the "cloud" once. I believe there was some pushback and they just made it annoying to not use their online services, but I'd still like to know what they need my personal data for...
- buildbot 2y agoAccording to their privacy policy, they don’t collect or sell anything (besides the standard we run a website stuff). The nefarious, evil purpose of the cloud service is…just lock in. And being easy to configure.
- amelius 2y agoCan we start banning hardware companies __after__ we have banned the selling of user data to the highest bidder (which might as well be Chinese companies)?
- ToucanLoucan 2y agoFuck no. There is NO effort at all here to go after surveillance capitalism, I don't give a shit what their press releases say about "protecting American's privacy." It's straight horseshit. The biggest offenders to American's privacy are squarely in Silicon Valley, and the only companies that ever end up in the Government's crosshairs are the big scary Chinese ones that are gonna use their algorithms to turn you into a communist or whatever the fuck. And FWIW to anyone in power who happens to read this, I was plenty radicalized by my own experiences and those of my friends under capitalism. China didn't do shit.
- pixl97 2y agoThis is a pretty poor take. Whoever is getting the information is going to use it for their benefit. The Chinese government is a scary government, this does not take away from or add to the US government being a scary government.
- ToucanLoucan 2y agoYou're correct, and banning TikTok and/or TP-Link is not going to stem the flow of user data to the companies who sell it, not even a little bit. Hence my comment: this is not about protecting anyone's privacy, it's about keeping American tech companies on top.
- iszomer 2y agoI wouldn't be surprised if some (American) corporate lobbying was performed for this to be pushed through this way but given the numerous stories of how the CCP have practically _bullied_ their way into our markets with cheap(er) goods and/or services through state-sponsored subsidies, I would imagine that this is becoming the global response to a long-winded draw-down on the lessons of repercussions and self-reliance.
- 2OEH8eoCRo0 2y agoI chucked my only piece of TP-Link equipment a few months ago out of caution.
- pjmlp 2y agoYet another step for nationalists to start pushing for internal technologies across the globe. Slowly I am feeling back into world geopolitics of my childhood.
- neilv 2y agoI'm currently upgrading my home network, trying various options, and one of the headaches is provenance of the equipment. By provenance, I mean where it's designed, where it's manufactured, who has brand oversight of it, who controls the firmware, who runs the IoT phoning-home servers, etc. (I don't have high security requirements for home, but I pay attention to such things out of curiosity.)
- alias_neo 2y agoThe closest I've been able to get is to buy a Protectli box, replace the AMI with Coreboot that you can compile yourself, and install OPN/PFSense. It's still Chinese hardware, but it's warrantied by Protectcli and you have control over the bits you can change. My first move out of the consumer "junk" was Ubiquiti EdgeRouters but their software quality declined a few years back, and my models got no more updates, then my main router died. My overkill i3 6-port Protectcli box has been running great ever since; first with pfSense now OPNSense; I'll only replace it when it dies or I want 10GbE routing.
- dvdbloc 2y agoWhat solution do you use for wireless access points? That’s generally my problem, you can find plenty of solid hardware to run pfSense on but as soon as you look at access points everything seems to be proprietary something or from questionable sources.
- alias_neo 2y agoI currently use a bunch of Unifi APs, not got full-house coverage yet, but I have key areas and run their management software on a Raspberry Pi. They've mostly been solid, and aren't too expensive. I did replace the one in the hall (on the ceiling) outside my living room recently though, upgrading it from an AP-AC-Pro to an U6-Pro and the range is significantly worse on the same WiFi spec, making the living room TV basically unusable for streaming, despite being flawless on the older AP. I'm going to try the newer U7 Pros and if that doesn't work out, I'll start looking at alternatives, but I suspect anything acceptable will be more expensive. I run ethernet almost everywhere so WiFi is just for our mobiles/laptops/tablets/IoT, but the TV in the living room currently has no easy way to get cables to so that AP is critical.
- bilal4hmed 2y agoSo what are my options here now? I run an omada system - do I move over to ubiquiti or DIY with opnsense ? if firmware is the issue then an entirely open system is what makes sense here.
- ulfw 2y agoThings get dumber by the day. I'm very happy with my TP-Link Deco mesh router. The US outsourced absolutely everything to China and is now banning it up down and centre. Shizophrenic much?
- pixl97 2y agoNo, we just had the capital class sell us out for money, and now that the world is beating the war drums again we realize how much of a fuckup it was.
- whimsicalism 2y agothen tax them, don’t go crazy over some foreign policy paranoia - and it is paranoia.
- salawat 2y agoIt isn't paranoia to recognize ongoing saber rattling.
- HankB99 2y agoI upgraded to Deco mesh (2 nodes) about a year ago. They perform well, but the settings have been dumbed down quite a bit. I'm using them as APs and have a small box running pfSense connected to my cable modem. The Deco AP should be unreachable from the Internet but still have full access to the Internet. In theory no black hat should be able to access them from the Internet but they could call out and ask for commands if they are so programmed.
- ksec 2y agoI will take this opportunity to ask if anyone want Apple to make AirPort Extreme again?
- acuozzo 2y agoI do.
- tgeorge 2y agoI wonder what happens to their Kasa brand of smart devices then. I have bunch of wall switches and smart power plugs with them.
- ljoshua 2y agoI have two Kasa light strips (KL400) and anecdotally I’ve noticed that its performance degrades every other day or so to the point where it stops responding to change commands. The fix? Blocking all inbound and outbound WAN (internet) traffic to it. Now works flawlessly, just like you think a light strip would. I only ever want to issue commands locally anyway, and why it should be talking to the broader internet in that case is beyond me.
- eqvinox 2y agoTo be fair, TP-Link routers without OpenWRT installed should be banned, considering their vulnerability history... But they are nice and cheap OpenWRT platforms. Ban the software instead? ;D
- myself248 2y agoExactly this. I don't want my source of hardware to dry up, but I'd love if ISPs wouldn't allow the stock firmware to connect to their networks. I bought a pair of TP-Link units specifically because OpenWRT ran well on them. If I had to get something more expensive, I might not decide to keep a cold spare.
- iszomer 2y agoWhat can be said for those whom throw the "you bought it, you own it" over "nah, you're really just renting it afterall" arguments?
- m000 2y agoYes, but if they did that, they would have to enforce the same rule on routers of US companies. So the net advantage for the US companies would be zero (which I believe is the point - the "hacking fears" is just a smokescreen).
- dokyun 2y agoGod forbid any of that corrosive communist ``free software'' touch our pure American companies.
- Havoc 2y agoI'm sure you'll be able to still get older gen openwrt compatible stuff. The newer generations of TP links are a different beast entirely. Doubt you can even set it up local only let alone openwrt it
- emchammer 2y agoI'm wondering if this suspicion should apply to TP-Link wifi range extenders as well as they should be just layer 2 devices. I tried installing OpenWRT on my TP-Link extender, everything was supposed to be compatible, but it did not work.
- whimsicalism 2y agowhat i would give to live in a rational well-run country, rather than one governed by populism, paranoia, and jingoism
- pixl97 2y agoTell me when you find that planet. Nationstates have nation state interest and politics has not changed in thousands of years.
- whimsicalism 2y agoI have a nation state interest in getting wealthy and trading our comparative advantage. Not paranoid delusions and one-sided brinksmanship. China can produce things cheaper than we can. “Industrial policy” to make a wealthy nation like the US a competitive low-cost manufacturing hub are delusional. Let us focus on what we are good at and other countries focus on what they are good at. Realpolitik is making our country wealthier and rationally approaching emerging risks, not banning cheap cars and solar panels because other countries are too good at making them. Let alone engaging in trade wars with our allies and banning acquisitions from Japan.
- sbfeibish 2y agoWe have to have a dependable supply chain. We found out during Covid we couldn't obtain the goods we needed. It doesn't matter how cheap goods are if they can't be purchased. China is a predatory, mercantilist economy. That cares more about providing its citizens with jobs than profit. They can ship goods under cost and drive competitors out of business. When it comes to cars I'll bet our tariffs haven't been anything like for example European tariffs on US cars. It's not a fair game with China. They'll supply us with hardware for our grid, but won't use our hardware in their grid. China blocks our internet.
- shadowerm 2y agoTo believe this is paranoid is rather delusional really. You should try reading less political bullshit that is rotting your brain.
- showerst 2y agoWhat's everyone's recommended replacement brand for home users? Mikrotik?
- lotsofpulp 2y agoI’d go with Aruba instant on. https://www.arubainstanton.com/ https://www.arubainstanton.com/
- j_h_o 2y agoI'd strongly consider Ruckus R710 off-lease from eBay, running Unleashed firmware.
- daft_pink 2y agoUgh, I use TP-Link Omada and I really don’t want to rip out everything to switch it to Unifi.
- sharpshadow 2y ago“investigators believe that TP-Link routinely fails to address vulnerabilities in its products that are shipped to customers who use the routers for both home and business purposes” good luck finding someone which is able to adress this issue and can deliver the same amount of devices in the price range. Sounds like they want to apply pressure to TP-Link so they start to fix more and faster.
- eduction 2y agoWirecutters top two router recommendations are both TP-Link. Near the top of the review they praise "Hitting the sweet spot between price and performance" but then bury the disclosure that you have to pay extra for security, including "most protection." "TP-Link also offers a $5-per-month or $36-per-year plan for Security+ network protection and IoT security. If you don’t pay, you still get some basic functionality such as the ability to block websites and to manually toggle internet access on your kids’ devices, but advanced settings, automatic timed internet control, most protection, and reporting are disabled after the one-month free trial. That said, the Archer AX3000 Pro will continue to provide solid Wi-Fi connectivity even if you don’t sign up for the added plans." This report is a great example of why it's a bad deal to trade away security for a lower price. Wirecutter should have been leading the way in pointing this out, instead of just steering people to the cheapest fast thing, YOLO style (anyone can make that kind of recommendation). https://www.nytimes.com/wirecutter/reviews/best-wi-fi-router/ https://www.nytimes.com/wirecutter/reviews/best-wi-fi-router...
- impish9208 2y agoDupe: https://news.ycombinator.com/item?id=42449503 https://news.ycombinator.com/item?id=42449503
- zenethian 2y agoWhat is a good recommendation for replacing a TP-Link Omada AP? I have the Wifi6 AP and it performs great. But if I do need to replace it with something more secure, what are my choices? I know Ubiquity is a choice, but the reason I chose Omada over Ubiquity is that I can host the Omada controller locally and not be forced to use a cloud product.
- ElectRabbit 2y agoYou can host a Unifi controller yourself. No cloud needed.
- gtvwill 2y agoThis in itself is a nightmare. I recently hacked for a client their Unifi controller db on a network. It had been setup 5 years ago and the company that did the setup didn't hand over any admin passwords. 5 companies and 4 years of problems later they almost turned their accommodation business into a wifi free off grid experience because they couldn't get the system working correctly without admin access. Nightmare stuff. Any system so heavily reliant on a single point of failure with such difficulty to replace is a no go for me. Never in half a decade have I seen such a problem whilst rolling out mikrotik hardware.
- EvanAnderson 2y ago> ... It had been setup 5 years ago and the company that did the setup didn't hand over any admin passwords. ... > Any system so heavily reliant on a single point of failure with such difficulty to replace is a no go for me. Not to shill for Ubiquiti here, but none of that sounds like a problem with UniFi or the idea of centrally-managed APs. UniFi APs don't stop working if the UniFi server fails. You can't make configuration changes, but you can SSH into the AP, reset it, and associate it with another UniFi server.
- gtvwill 2y agoOh don't get me wrong. UniFi and central management can be great if your on actively managed IT infrastructure. That is to say, you pay someone a monthly fee to keep your stuff configured, monitored and working. But where I live, most of these installs are at rural businesses or properties where IT only gets called when things go wrong. These are exactly the wrong place to put managed infrastructure. It can be years between problems and rarely are the same techs even in the area when the next call comes around. Which is exactly why I was able to crack the DB in the first place, it was an out of date V6 install of the controller using a unsecured mongodb. Took me about 20 minutes of googling to find out how to do it when I used the right key words/after I'd figured out what was wrong (someone plugged in a router with DHCP enabled upstream of all the p2p wifi nodes but downstream from the unifi security gateway, the router got flagged as trying to provide/hijack dhcp and unifi blocked that port it seems, killing all the p2p wifi with it, honestly not a bad response from unifi hardware but a nightmare for your joe blog tech who doesnt really have much experience with network problem solving). I advocate certain clients towards centrally managed systems, but for most of these clients who aren't interested in a regular checkup or business agreement with an IT provider I generally put them on un-managed setups with at least 2x USB devices with copies of config on-site and a printout of what the setup and network layout is. This is in-case I'm not here the next time they need work done or in case I do come back and don't want to spend a day deciphering their setup again. All cloud services are disable, no external log-in from outside of the site allowed. I leave the main modem/ISP connected router ideally up to the ISP they are getting internet services from and build everything downstream from that. Auto-update set to on. I've got multiple p2p and p2mp wireless networks at properties all around the region that haven't had a tech on-site for 4+ years and they won't until something breaks or the protocol their operating on gets too slow for user requirements which I would expect is another 4+ years at least because mikrotik wifi is rock solid when its setup manually and correctly. Security is less of a worry. I mean honestly if your willing to drive out to the middle of nowhere to war-drive and crack the passwords and get into their network...hell you probably deserve to get some internet and check ya emails for the effort you've put in. They'll probably see your vehicle while your doing it and invite you in for a cuppa and give you the password anyways.
- blackeyeblitzar 2y agoIt might be the right move. I’ve noticed a lot of oddities with my top of the line TP Link Mesh routers. Limited ability to configure it compared to past routers (not many advanced settings). Forced use of a very sanitized app instead of a browser based panel. Forced updates with no ability to use the admin panel without accepting the update. And so on. It works and is high quality in a way, but I also don’t trust it. Unfortunately a lot of these issues aren’t visible until after you buy it.
- buffington 2y agoAre those Omada based routers? For the price, I've been very impressed with the Omada based APs from TP-Link. All of my equipment is configurable through a web based interface that's served by a Windows app (or through an available hardware controller).
- tyjen 2y agoWait until Congress figures out about all the new "free" games pouring out of China, each requiring kernel level anti-cheat software to operate in the background.
- deleted 2y ago[deleted]
- m3kw9 2y agoHow hard is it to place transistor level string detection that activates an encrypted program within the asic
- Havoc 2y agoThe concept of string doesn't exist at "transitor level"
- nashashmi 2y agoWe are on a slippery slope of banning everyone: TikTok; Kaspersky, ... TP-Link. Huawei was not banned, they were bullied out of the US market, and had restricted access to US technologies.
- _bin_ 2y agoslippery slope? i think curtailing china's access to US networks and data, as well as crippling her tech sector, is a great goal. this is one step along the path, not another foot downhill.
- nashashmi 2y agoIm all for crippling tech advancements in other countries. It’s wrong when we do it by bullying and abusing our powers. Instead we should have the foresight to attract their best talent. This we don’t do as much like we used to before the Bush years.
- _bin_ 2y agoi don't think it's wrong. you can't fight a bad-faith actor with good-faith actions. china has built an entire nation off lying, cheating, and stealing. we shouldn't be bound to respond by only being nice. attracting her best talent works better when the CPC doesn't hold families hostage. because of that, we are unable to trust most chinese nationals.
- ryanalam 2y agoAn alternative to NY Post, which I don’t find very credible: https://arstechnica.com/tech-policy/2024/12/report-us-considers-banning-tp-link-routers-over-security-flaws-ties-to-china/ https://arstechnica.com/tech-policy/2024/12/report-us-consid...
- phendrenad2 2y agoDo TP-Link routers really have more security holes than, say, ASUS (designed in Taiwan) or Mikrotik (designed in Latvia)?
- orbital-decay 2y agoI think it's painfully obvious it's not about software security concerns at all, since most non-enthusiast home routers are pretty janky, not just TP-link ones.
- harry8 2y agoSo who knows much about banana pi and using that to build a router. What firmware? Are there better hardware options? Anything user-friendly enough to compare with consumer grade uis for routers? Anything else that should be being asked in this space? https://www.banana-pi.org/ https://www.banana-pi.org/
- bdcravens 2y agoIs it possible to run BPi on any hardware? If TP-Link is banned, I'd think that many other Chinese-based manufacturers may also be on the chopping block.
- harry8 2y agoBanana Pi /is/ hardware. OpwnWRT is one distro that runs on it, apparently. Seems you know even less than I do about it. https://www.banana-pi.org/en/product-news/557.html https://www.banana-pi.org/en/product-news/557.html
- bdcravens 2y agoThen wouldn't it potentially be as risky as TP-Link, being a Chinese company?
- harry8 2y agoshow me consumer router hardware not made in china.
- bdcravens 2y agoEero is made in Vietnam, but for purposes of Congressional bans, I assume the point is to ban products from companies based in China, even if they are still manufactured there. (In which case Linksys for example would be safe)
- 2y ago
- onewheeltom 2y agoProbably compromised from the factory
- wrs 2y ago"...routinely fails to address vulnerabilities in its products... When cybersecurity experts point out the flaws...the company declines to engage with them..." I feel like this used to apply to most mass-market home routers. Have things improved recently such that TP-Link is an outlier?
- vkaku 2y agoI haven't found a competitively priced US made product in the segments where TP-Link seems to do extremely well. For home office switches, if we required PoE 1G + 10G ports - the nearest option sold by US companies is 2x the price of TP-Link. There are no competitively priced options (10-20% additional cost) available for these segments. Ditto for gateways. In the higher end, the campus switches offered by the competition is not even priced at < 10x the TP-Link switch prices. Which means the immediate cost of using TP-Link right now and replacing it with a much better TP-Link 2-3 years down the lane would justify buying TP-Link only. At this point, the expensive gear from competition feels like an over-engineering + cash grab to an end user. Shouldn't more competition be about lowering prices and increasing choices? Where are the choices? Is there even an effort being made to help the end users of these budget segments?
- GSh080 2y agoI think this is quite ridiculous. If they collect data, it will be a huge amount. Additionally, most traffic is already encrypted, so they would just get garbage.
- tomaskafka 2y agoApparently one of the dangers is the routers serving a Chinese botnet attacking western infrastructure from US-base IP addresses. https://9to5mac.com/2024/12/18/most-popular-home-internet-routers-in-us-may-be-banned-as-national-security-risk/ https://9to5mac.com/2024/12/18/most-popular-home-internet-ro...