Lemmy
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Kid@sh.itjust.worksM to Cybersecurity@sh.itjust.worksEnglish · 2 months ago

US congressional panel urges Americans to ditch China-made routers

www.reuters.com

external-link
message-square
15
fedilink
29
external-link

US congressional panel urges Americans to ditch China-made routers

www.reuters.com

Kid@sh.itjust.worksM to Cybersecurity@sh.itjust.worksEnglish · 2 months ago
message-square
15
fedilink
reuters.com
www.reuters.com
external-link
alert-triangle
You must log in or register to comment.
  • remotelove@lemmy.ca
    link
    fedilink
    English
    arrow-up
    28
    ·
    2 months ago

    So… All of them?

    • sugar_in_your_tea@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      8
      ·
      2 months ago

      Does it count as “China made” if the firmware is FOSS and I load it myself? NICs and boards are pretty much all made in China, but how far does this go?

      • remotelove@lemmy.ca
        link
        fedilink
        English
        arrow-up
        10
        ·
        2 months ago

        It depends on how bad China wants your porn. There could be secondary MCUs that are designed to completely bypass the original firmware. (Think Intel ME)

        That is not very practical for consumer grade gear, but still possible.

        • Ajen@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          5
          ·
          edit-2
          2 months ago

          Wifi chips have their own firmware that could have a backdoor. If it’s connected to the CPU over PCI-E or another interface that supports DMA then it’s also able to inject code into the main system even if it’s running FOSS firmware.

          • remotelove@lemmy.ca
            link
            fedilink
            English
            arrow-up
            3
            ·
            2 months ago

            It seems that a few router types have WiFi + SoC setups now. (Like ones using the IPQ4019, for example.)

            While that doesn’t significantly reduce the risk of something nasty, it would limit places for nasty code to hide. Well, “hide” in the traditional sense, like on another chip entirely.

            However, I haven’t really looked into any drivers to see how these SoC’s are segmented to see if its really any different than the old MCU + WiFi chipset setups.

        • admin@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          5
          ·
          2 months ago

          This reminded me of a real life story, from the tip or my tongue so details might be inaccurate, but I remember hearing that a/the main MINIX maintainer, all of the sudden, started getting bug reports or some type of feedback from somebody, that ended up being an Intel employee looking to use MINIX for either ME or AMT.

          In short, these hardware devices are 100% capable of having their own independent OS, processes with kernel and all, totally obscured from the end user.

        • sugar_in_your_tea@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          4
          ·
          2 months ago

          Hmm, it’s pretty spicy porn.

      • earphone843@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        6
        ·
        2 months ago

        Yes, it counts. Hardware backdoors are absolutely a thing.

  • piccolo@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    27
    arrow-down
    1
    ·
    edit-2
    2 months ago

    And replace them with american spyware? Nice try NSA

    • sugar_in_your_tea@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 months ago

      Mine’s European, but actually Chinese.

  • _haha_oh_wow_@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    9
    ·
    edit-2
    2 months ago

    Best I can do is flash custom firmware.

    Edit: See this helpful comment below if you’re interested! https://sh.itjust.works/post/33900457/17108468

    • sunzu2@thebrainbin.org
      link
      fedilink
      arrow-up
      7
      arrow-down
      2
      ·
      2 months ago

      This is what every normie should be doing.

      Bought a router but it wanted me to get an account with a “proper” email address.

      Lol wtf good thing Foss chads were already cooking haha

    • technocrit@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      3
      ·
      2 months ago

      For anybody else considering…

      • https://www.makeuseof.com/tag/top-6-alternative-firmwares-router/
      • https://en.wikipedia.org/wiki/List_of_router_firmware_projects
  • onlinepersona@programming.dev
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    1
    ·
    2 months ago

    EU commission should be urging Europeans to ditch US products and services 🤷

    Anti Commercial-AI license

  • GrumpyDuckling@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    1
    ·
    2 months ago

    Openwrt

    Opnsense

    Pfsense

Cybersecurity@sh.itjust.works

cybersecurity@sh.itjust.works

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !cybersecurity@sh.itjust.works

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

  • Be respectful. Everyone should feel welcome here.
  • No bigotry - including racism, sexism, ableism, homophobia, transphobia, or xenophobia.
  • No Ads / Spamming.
  • No pornography.

Community Rules

  • Idk, keep it semi-professional?
  • Nothing illegal. We’re all ethical here.
  • Rules will be added/redefined as necessary.

If you ask someone to hack your “friends” socials you’re just going to get banned so don’t do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 281 users / day
  • 716 users / week
  • 1.59K users / month
  • 3.57K users / 6 months
  • 1 local subscriber
  • 7.16K subscribers
  • 832 Posts
  • 1.3K Comments
  • Modlog
  • mods:
  • Kid@sh.itjust.works
  • Lanky_Pomegranate530@midwest.social
  • BE: 0.19.8
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org