• BassTurd@lemmy.world
    link
    fedilink
    English
    arrow-up
    6
    arrow-down
    2
    ·
    1 day ago

    TP-Link has a bad history of significant security vulnerabilities that have to either be gross negligence or intentional backdoors. Consumer router firmware is notoriously neglected in the grand scheme of tech, but TP-Link is exceptionally bad. Your average and even most above average techies probably have no idea unless they follow security releases or live in the security world. I personally wouldn’t know much if anything about them if not for some YT content I watch about software and security. I don’t love blanket blocking of stuff, but this one I feel is necessary to help protect an ignorant population.

    I 100% agree with the sentiment that Trump is way more dangerous, because he is, but the two issues can be addressed (or not unfortunately) at the same time. If our reps won’t stop Trump, and not going to be upset over he small wins that we do get.

    • Machinist@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      1 day ago

      So, say I have a POE outdoor router that is TP-link. It is wired to my main router and is the network for outdoor cameras. How bad an idea is this?

      • BassTurd@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 day ago

        If you’re just running it in AP mode and extending from your base router you will be better off than if it’s your WAN device. I don’t know enough about these exploits to know how they are executed, so I can’t give you a solid answer, but I think it’s best to err on the side of caution when it comes to your data security.

        If you’re fairly tech savvy and willing to put in a little effort, you can flash the firmware on the TP-Link with something open source like openWRT and that would eliminate any exploits directly caused by their coding. I haven’t done this in years, but I’m sure there are plenty of guides to walk you through this. It would require resetting up your network, but you’d need to do that if you replaced anyway.

        Personally, I would replace the device with something higher quality. I don’t have recommendations for you, but I’m sure there are some resources you can find with security minded device recommendations. For “pro-sumer” grade stuff, where it’s better than your off the shelf options but not enterprise grade, I’ve heard Unify is a good option, but it’s complicated and expensive.

    • Telorand@reddthat.com
      link
      fedilink
      English
      arrow-up
      4
      ·
      1 day ago

      Do you have any links to the alleged bad history? I couldn’t find anything, partly because the recent political theatre makes it hard to be informed.

      • BassTurd@lemmy.world
        link
        fedilink
        English
        arrow-up
        7
        ·
        1 day ago

        Here is the main video I watched that breaks down a recent ish CVE and at the end he gives some thoughts on TP-Link, D-link, and another and just his professional security opinion on them.

        It is only one source, but I think it’s a strong one.