Hacker News new | ask | show | jobs
by oprah2018 2934 days ago
Any suggestions for a good router that is immune from this nonsense?
5 comments

Buy a small cheap computer with two ethernet ports and run debian.
And most importantly: keep it updated.

About the only thing I would trust without updates is a bsd box. And even that, may eventually fall victim.

Ok, but what if you are very busy and you don't have time for that.
which BSD? And how is hardware support these days?
You could build your own with pfSense.
What if you are too busy for that?
As in another post, I’d suggest buying any router, taking it apart, identifying the flash chip, find the write-enable line in the data-sheet and MITM that line with a flip switch to block updates at all times.
That's actually a really good idea! I would love to see this built-in to future router models after something widespread like this. It's fairly reasonable to force users to be physically present to update. Plus, you could force them to flip the switch back by not working until the write-enable line is disconnected again.
It could have the unintended side effect of making people even less likely to upgrade firmware.
BIOS updates used to be like that. You would have to switch a jumper to do the update.

Then they got rid of that, even though most people that bothered with BIOS updates could be directed to switch a jumper around...

Ain't nobody got time for that.
An updated one, with sane defaults.