11 ms·
The real lesson here: If you're successful, don't skimp on security/software! Also, don't abandon software/firmware security support for your products so quickl
by riskable 11mo ago
The real lesson here: If you're successful, don't skimp on security/software! Also, don't abandon software/firmware security support for your products so quickly.
If I was in charge over at TP-Link, getting news that tens of thousands of MY company's routers were compromised would have me furious! I'd be freaking out, making sure that we take immediate steps to improve software/firmware quality and to make sure we're in a constant state of trying to compromise our own hardware... To ensure no one else finds vulnerabilities before we do.
Instead, TP-Link seems to have just laughed and focused strictly on profit margins.
- stldev 11mo agoOr maybe, don't capture 50% market share in a country that's decided your country of origin is the threat of the decade.
- hekkle 11mo agoTP-Link's Headquarters are in California, they have a branch in Singapore and they manufacture in Vietnam, which of those were the threat exactly? This whole thing is reminiscent of the TikTok CEO Chew Shou Zi - "But, I'm Singaporean, Senator".
- sarchertech 11mo agoIt was a completely Chinese company until last year. Then it split in 2. The US headquartered half has 11,000 employees in mainland China and 500 in the US based on what I could find when I googled it. It’s solely owned by the founder of the original company and his wife who are Chinese citizens. I don’t know whether it’s worth banning them or not, but putting your hands up and saying “what Chinese company?” is just absurd.
- hekkle 11mo ago1. The company was founded Zhao Jianjun and Zhao Jiaxing who are brothers, I don't know where you got the husband/wife sole ownership from. 2. As you admitted, they have completely separated into 2 separate companies, claiming that it is still Chinese is akin to saying "tea is Chinese", that's completely absurd, yes, it was at some point in history, that point is not now.
- Dylan16807 11mo agoIt's hard to believe you're saying 2 in good faith. Companies don't change that fast, and you skipped the part where so many of the employees are still in China.
- hekkle 11mo agoIt took them 3 years to achieve this, so yes, they can change that fast... Did you not read the article? It's hard to take your comment in good faith if you didn't.
- Dylan16807 11mo agoThree years would be an impressive timescale to move a company from one country to another. Except they didn't do that. They moved the HQ. I'll accept for the purpose of this argument that they fully split the company into two separate companies. But both of those companies are still mostly Chinese, going by the numbers in this thread. > Did you not read the article? It's hard to take your comment in good faith if you didn't. This is a weak attempt at turnabout. The article doesn't present any evidence of separation or non-Chinese-ness, it just quotes the company (and even that quote admits a bunch of Chinese assets). But even if it did, it wouldn't be bad faith to skip reading it.
- hekkle 11mo ago> This is a weak attempt at turnabout. The article doesn't present any evidence of separation or non-Chinese-ness, it just quotes the company (and even that quote admits a bunch of Chinese assets). But even if it did, it wouldn't be bad faith to skip reading it. 1. Who else would document a company's restructure if not the company itself? 2. Yes, not reading an article and commenting on it is bad faith. > going by the numbers in this thread. 3. So you have no evidence of it not being as the company says, just the vibes of others on this thread, okay Senator.
- Dylan16807 11mo ago
- wdr1 11mo ago> TP-Link's Headquarters are in California, they have a branch in Singapore and they manufacture in Vietnam "TP-Link is a Chinese company that manufactures network equipment and smart home products. The company was established in 1996 in Shenzhen. TP-Link's main headquarters is located in Nanshan, Shenzhen; there is a smaller headquarters in Irvine, California" https://en.wikipedia.org/wiki/TP-Link https://en.wikipedia.org/wiki/TP-Link
- moi2388 11mo agoYou do realise all of Singapore is a front to export to China right?
- ksec 11mo agoJust because a company changed its headquarters to US all of a sudden they are a US company? Even if 99.9% of its decision, operation and R&D are still in elsewhere? That is like people saying Nothing is a UK company, when all I see is a Chinese company registered in UK.
- KAMSPioneer 11mo agoIt's like saying Apple Computers is an Irish company and not a US one because of where they file their corporate taxes.
- jmyeet 11mo agoYeah, that's not the lesson here at all. We're still in an era where you will suffer absolutely zero consequences for security lapses and breaches. Everything that is happening with this administration is simply because it suits American foreign policy or the interests of one of the oligarchs. I mean this with absolutely no hyperbole: the pretense of there being any rule of law for the ultra-wealthy is gone. The White House is openly selling pardons, which have the added effect of cancelling out debts to the US government. Tiktok getting banned? It had nothing to do with "national security". The government simply had less control over the content and the algorithm on Tiktok than they do on Meta and Google platforms. Reading through this article, you have Microsoft pointing the finger at TP-Link. That's... rich. Becvause Microsoft has historically been horrible for security. It would take further investigation but I really wonder if TP-Link isn't just a convenient scapegoat.
- Loughla 11mo agoI don't mean to be hateful with this, but what's the point of your post besides random conjecture and a sort of rant about something only vaguely related to the story?
- cyanydeez 11mo agoThat this is a political issue, not technical
- mindslight 11mo agoI see the comment as quite on point. There are many longstanding real problems that have been allowed to fester (in this case, embedded security). While these problems are now being talked about, there is still zero intention to actually address them. Rather they're merely being abused as talking points by fascists pretending that "something is being done" when really the "solutions" are merely the consolidation of autocratic control. Real reform here would be something like prohibiting tying software and hardware together as one product, source code escrow, etc. Things that actually create security and consumer choice, rather than merely one less vendor to pick from.
- parineum 11mo ago
- blitzar 11mo agoThe real lesson here: don't forget to bribe the president of the US.
- starttoaster 11mo agoI'm sure TP-Link could help fund a second ball room.
- 0xAFFFF 11mo agoThis was my first thought. Why TP-Link, why now? Looks like another extortion scheme from POTUS.
- harvey9 11mo agoUnfortunately people like you are hardly ever in charge of this kind of thing.
- bashtoni 11mo agoIf this was actually the lesson then they'd be banning Fortinet, but it seems these concerns about security don't apply to US listed companies.
- protocolture 11mo agoBold of you to assume those Fortinet vulns arent just exposed government backdoors.
- acdha 11mo agoThis is like seeing a food poisoning outbreak at a fast food restaurant and concluding that it must be CIA/FSB/Mossad bogeymen trying a bioweapon. These breaches are things like not validating authentication tokens (at all, not just correctly) and that would be a big drop in professionalism from what we’ve seen from nation-state level attacks: https://labs.watchtowr.com/get-fortirekt-i-am-the-super_admin-now-fortios-authentication-bypass-cve-2024-55591/ https://labs.watchtowr.com/get-fortirekt-i-am-the-super_admi...
- anonym29 11mo agoHanlon's razor, paradoxically, is the perfect cover for surreptitious malice. We've already got a perfectly reasonable razor telling people not to assume malice, after all. And to be clear, let's not forget that the US government did intentionally and secretly conduct surreptitious biological warfare tests against entire US cities that deliberately inflicted disease upon and killed American citizens. There was an entire formal program that spanned decades - https://en.wikipedia.org/wiki/United_States_biological_weapons_program https://en.wikipedia.org/wiki/United_States_biological_weapo... Of course, the US government doesn't have any secret programs anymore and never lies to us, so everyone can rest easy knowing nothing like this could ever happen again.
- duxup 11mo agoI think a lot of companies violate that lesson and continue to make money.
- itopaloglu83 11mo agoJust make them liable for the damages and then they will start caring. This might be one of the only cases where subscription model would work well to cover the maintenance cost.
- ryandrake 11mo agoYea, in the real world, the CEO gets news that tens of thousands of his company's routers were compromised, and calls up his General Counsel and asks "are we liable for damages?" And if the answer is NO, he goes back to enjoying the house party in his luxurious third home.
- itopaloglu83 11mo agoYeah, I know, at some point you cannot make them care for their customers wholeheartedly.
- eru 11mo agoIt depends on whether customers care.
- axiolite 11mo ago> This might be one of the only cases where subscription model would work well to cover the maintenance cost. 1) Company takes your subscription money. 2) Company finds a vulnerability that's difficult to fix. 3) Company announces your device is EOL and ends your subscription, taking your money for doing nothing, and not helping when you need it.
- worthless-trash 11mo agoYou have a bright future in product management.
- Intermernet 11mo agoOr medical insurance.
- PeaceTed 11mo agoUntil it hits their wallet, they will not do a thing. Now if they were more concerned about longer profits and how this could impact their image, maybe they would change but it is rare you see that nowadays.
- DANmode 11mo agoBut they got this far with $X in security spending, what’s the problem?
- mumber_typhoon 11mo agoPeople in the comments are defending TPLink for how 'solid' their products are. As someone who just switched to UniFi APs from a Deco Mesh (wired), I have to admit that the difference is deep dark hole and bright sunshine day. Maybe people are comparing to spectrum charter modem combos but I definitely don't see how a router that loses firmware updates in a year can be praised. And it needs reboots so frequently. The Deco has an option now to reboot 'everyday'. This sounds something maybe needed for rare cases where the ISP expects a reboot, but the fact that your routers have that as a feature to keep it stable is a big red flag. I was so used to this that when I started looking for this setting in UniFi OS I had forgotten the part 'networks are not supposed to be rebooted frequently!'.
- cryptoegorophy 11mo agoI couldn’t figure out what was wrong with my WiFi. Turns out all I had to do is power restart it. All my problems went away after setting up weekly reboots. It is stupid that it works and it is stupid that it is the only solution for stable WiFi. Shame on tplink
- mumber_typhoon 11mo agoits usually either low memory which basically crashes the devices or buggy software which works until you hit the bug at which point it requires a restart to get it working again. Most common is memory problems though because these devices have just enough memory to make it work.
- IgorPartola 11mo agoI have not used the Deco access points but the Omada ones have web rock solid for me for about 4.5 years now and I used UniFi before that with no real issues either.
- bayindirh 11mo agoThere are some misconceptions here. First, all of the TP-Link devices I use still have firmware updates regularly. I can't talk about Deco series, which I don't own. Second, mesh capabilities are not consistent across different brands, that's true. On the other hand, comparing TP-Link, which is a home/SOHO brand to UniFi, which is essentially a prosumer/enterprise offering is not fair. I have a small mesh (three devices) at one of the places I run these devices, and it hands-off nicely, extends coverage, and gives me the speeds written on the tin. Do I expect it to compare to a UniFi or Aruba mesh where the smallest element has more processing power than my router? Of course not. Do I expect it to run on a 300 sqm house with 10+ devices? Again, no. But as long as my network runs, I can access the devices with good connections and speeds they advertise, I'm golden. Lastly, "restart everyday at this time" setting is present since forever on many devices. The feature is to help home-downloaders / data hoarders to renew their IP periodically. Heck, even JDownloader has a feature to reset your modem remotely if your modem supports to renew IPs (since 2004?). Assumptions don't help here. I never had to automatically restart any of the routers/modems I used regardless of the manufacturer sans a couple Cisco/Linksys devices. E4200 which had two processors, one for the switch and one for the router. The router one stopped responding randomly to cut whole network off from internet, and my E900's processor crashed flooding whole home network with packets basically paralyzing it. Oh, that same E900 failed to negotiate with the on board RTL8139 Ethernet controller, so I had to buy another "Cisco/Linksys" RTL8139 card. TP-Links I had never done anything remote. They even have the best latencies and WAN recovery when things go south on ISP side. My TP-Link 802.11AX extender works flawlessly with my ISP supplied WiFi6 modem, and despite having no mesh communication going on, running on the same SSID and handing off pretty reliably.
- IgorPartola 11mo agoIt occurred to me recently while driving in a high traffic area that (a) this area is congested every single day at this time and (b) if I shipped a piece of software that literally crawled to a stop for a two hour period every morning and a two hour period every evening that I would be deeply ashamed of myself and my work and that if I ran a department that did that I would have no priorities other than fixing this bug until it was fixed. Yet we all know so many industries and products that just do not work like that and in fact the longer something is broken and it doesn’t seem to stop people from using it, the more it is accepted that it is ok for it to remain broken. I think that is somehow just a part of human psychology.
- close04 11mo agoI think this is you seeing the faults of other industries but being blind to yours. No single person created the traffic jam "bug", the "users" are the biggest part. In many industries "the fix" isn't a few lines of code that you can one-click push to all users. You can't fix that traffic jam in code or even in infrastructure, you need to change society itself on top of everything else. It may not even be a defect as much as a supply and demand issue where supply is very scarce and impossible to ramp up, while demand is super high and growing. Cloud providers run out of capacity in some regions, their developers should be ashamed? Software can be fixed quickly if broken. Capacity not so much. Software is also routinely launched broken, and subsequently stays in various degrees of broken or not usable enough throughout its lifecycle, with new and unpredictable issues replacing old ones. If too many people wanting to drive a car in the same place, at the same time despite the predictable outcome due to the limited capacity is purely a failure of the city, country, road builder, then isn't a user not being able or not knowing how to properly use the software the fault of the developer? Is demanding more from the software than it can deliver the fault of the developer? How much cumulated time does this cost, sometimes for absolutely no reason whatsoever than an arbitrary decision of the developer? You aren't "deeply ashamed" because you downplay the issues you (or your company) create as a developer and pretend they aren't problems for the users. A "part of human psychology" tells you 1000 smaller cuts are fine.
- IgorPartola 11mo ago
- hulitu 11mo ago> The real lesson here: If you're successful, don't skimp on security/software! cough Microsoft, Google, Apple cough
- deknos 11mo ago> The real lesson here: If you're successful, don't skimp on security/software! Also, don't abandon software/firmware security support for your products so quickly. Why? Microsoft and Cisco also skimp on security.
- NoGravitas 11mo agoThe real lesson is don't skimp on your political payoffs/tribute/bribes.
- swiftcoder 11mo ago> Instead, TP-Link seems to have just laughed and focused strictly on profit margins. Wait, what? TP-link provides security updates for about as long as their competitors - including providing security patches for devices that are officially out of their support window. For example, last year they provided a critical security patch for a number of out-of-support routers, including the 14-year-old TL-WR841ND [1]. [1]: https://www.tp-link.com/us/support/faq/4308/ https://www.tp-link.com/us/support/faq/4308/
- morshu9001 11mo agoI really miss AirPort, it was the only router/ap with totally solid and easy software. Took the consumer market years to catch up with its mesh features, and they're still annoying with online registration.
- notmyjob 11mo agoTP-link are definitely the worst of the worst. My cousin insisted they were fine as long as you kept the firmware updated, but then he lost all his bitcoins to hackers. TP-link, never again.
- fckgw 11mo agoI'm sorry but your cousin did not lose his bitcoin due to some TP-Link hackers.
- jrochkind1 11mo agoI'm not sure what news you are speaking of, can you link to specify?