Ask Slashdot: How Can You Avoid Routers With Locked Firmware?
thejynxed writes:
Awhile ago the FCC in the USA implemented a rule that required manufacturers to restrict end-users from tampering with the radio outputs on wi-fi routers. It was predicted that manufacturers would take the lazy way out by locking down the firmware/bootloaders of the routers entirely instead of partitioning off access to the radio transmit power and channel ranges. This has apparently proven to be the case, as even now routers that were previously marketed as "Open Source Ready" or "DD-WRT Compatible" are coming with locked firmware.
In my case, having noticed this trend, I purchased three routers from Belkin, Buffalo, and Netgear in Canada, the UK, and Germany respectively, instead of the USA, and the results: All three routers had locked firmware/bootloaders, with no downgrade rights and no way to install Tomato, DD-WRT, OpenWRT, etc. It seems the FCC rule is an example of the wide-reaching effect of US law on the products sold in other nations, etc. So, does anyone know a good source of unlocked routers or other technical information on how to bypass this ridiculous outcome of FCC over-reach and manufacturer laziness?
The FCC later specified that they were not trying to block Open Source firmware modifications -- so leave your best suggestions in the comments. How can you avoid routers with locked firmware?
In my case, having noticed this trend, I purchased three routers from Belkin, Buffalo, and Netgear in Canada, the UK, and Germany respectively, instead of the USA, and the results: All three routers had locked firmware/bootloaders, with no downgrade rights and no way to install Tomato, DD-WRT, OpenWRT, etc. It seems the FCC rule is an example of the wide-reaching effect of US law on the products sold in other nations, etc. So, does anyone know a good source of unlocked routers or other technical information on how to bypass this ridiculous outcome of FCC over-reach and manufacturer laziness?
The FCC later specified that they were not trying to block Open Source firmware modifications -- so leave your best suggestions in the comments. How can you avoid routers with locked firmware?
It's a fantastic router platform, supports oodles of hardware, and can run on cheap machines. For instance: Start here use a 5600 series Xeon and the smallest amount of RAM and HDD you can get, and you've got a killer router capable of handling much greater than gigabit traffic. If you need Wireless as well, you can either add a low-profile 802.11 card, or buy a cheap home "router" and run it in Access Point only mode, which will put it behind your firewall (and thus safe from internet-based hack attacks), rather than it being your firewall and vulnerable.
http://elinux.org/RPI-Wireless...
Pretty much only way to be sure.
Beyond that, you go with the same approach as when getting a PC to use with Linux - try to verify each individual component and whether it works or not.
PLENTY of "make your own" options out there these days... Easy options even. Newegg has an ITX mainboard with a built in AES-NI CPU for Hardware accelerated encryption, for 56$... Add a dell Broadcom SFF 4 Port Gig NIC and some RAM, and whola! Whatever router config you need is just a download away!
https://omnia.turris.cz/
Specs: 1.6 GHz dual-core ARM, 2 GB DDR3, 8 GB flash, 5 Gbit LAN, 1 Gbit WAN, 2 USB 3.0, 2 Mini PCI Express, 1 mSATA / mini PCI Express, 3x3 MIMO 802.11ac, 2x2 MIMO 802.11b/g/n
I use it together with two hard drives attached via SATA.
It ships with a custom version of OpenWRT but you can also install other stuff on it like Debian:
https://wiki.debian.org/Instal...
Or openSUSE:
https://en.opensuse.org/HCL:Tu...
Personally, I find that going with a dedicated router and dedicated access point(s) makes for a more flexible solution anyway. Better placement options, easier to upgrade the wireless, etc. I use Ubiquiti gear, which gives me Vyatta on the routing/firewall and a solid (locked down) access point.
Curious to try out the little pfsense appliances, but they are a bit more pricey.
The FCC later specified that they were not trying to block Open Source firmware modifications
they were told IN NO UNCERTAIN TERMS that this is exactly what would happen - that manufacturers would take the "lazy" way out. unfortunately, a number of prominent "open source" activists completely and utterly failed to comprehend that this would happen, and ENDORSED the FCC's proposal.
there are some very specific companies that sell RYF-Endorsed products (answering the OP's question: google "RYF Certified router" or other such keyword combinations), and these companies are near-completely screwed. if they are not careful they have to sell ILLEGAL products in order to satisfy the RYF-Endorsement Criteria! however it turns out that there's a small workaround: what they can do is put an UNPUBLISHED hidden link into the web interface in order for users to carry out quotes unauthorised quotes firmware updates.
basically as a world-wide community we f******d up. the opportunity to stop the FCC from being a Corporate lap-dog was when the "Save WIFI" campaign was underway. it was a complex situation understood by very few people: we should have listened to the people who properly understood it, and supported them. we didn't do that... and now we suffer the consequences, as indicated by the OP.
Blame the idiots hacking their firmware and using their routers irresponsibly (illegally).
First you have to understand why the FCC made the request to router manufacturers. Shortly after the FCC opened up the 5 GHz band for unlicensed use, terminal doppler weather radar was invented in response to several airliner crashes due to adverse weather conditions. Unfortunately, it relies on frequencies smack dab in the middle of the open 5 GHz band, so the FCC took the unusual step of revising their rules which opened up those frequencies
That's why most 5 GHz devices only support channels 36-48 and 149-165. The intermediate channels were reclassified as DFS - dynamic frequency selection. Open devices could use them, but if they detected weather radar in use they had to switch to a different channel. A few devices actually do this and check to see if weather radar is in use. Most manufacturers just took the easy way out and blocked out channels 50-144 entirely in the firmware.
DD-WRT supports DFS - it will change frequencies if it detects weather radar in use (at least it does on my hacked TP-Link). If you install third party firmware and use the 5 GHz band, do the responsible thing and enable this functionality if you're going to enable channels 50-144. Unfortunately, some idiots didn't do this, which caused the FCC to grow concerned about the impact of third party firmware on the effectiveness of TDWR. That's why the FCC made the request to router manufacturers. Not because they hated third party firmware, but out of concern for the safety of the flying public.
This is why we can't have nice things - a few idiots ruin it for everyone else. I had lots of fun with lawn darts as a kid, but we always treated the target area as if it were a shooting range. Here's an example of what happens to TDWR when an idiot blasts their router in the TDWR frequencies. The unauthorized broadcast shows up as a wedge-shaped area spanning a few degrees and extending to the edge of the radar image, completely obscuring any weather in the wedge.
And buying the router in Canada or Europe won't make any difference because those countries have the exact same restrictions on those TDWR frequencies. The only reason they're not being as aggressive as the FCC is because TDWR so far is mostly used at U.S. airports. Eventually most airports in the developed world are going to upgrade to it (or at least airports which frequently encounter bad weather). So the regulatory agencies in Canada, the EU, and most of the rest of the developed world are all going to be on the same page as the FCC once TDWR is rolled out in those countries.
Some routers aren't "locked" particularly well, for example I have a WR841N v11 here which had supposedly FCC locked firmware, but it was relatively simple to install open firmware on it using the TFTP firmware recovery procedure
Many Americans replied to their consultation on network neutrality. They ignored all comments that didn't suit them. The only thing you can do is vote out the republicans. Most likely you will need to vote out the democrats after that too.
I'd be happy if we could just stop Americans from pronouncing it "rawter". They need to learn the difference between "rout" and "route".
First off, the FCC is underfunded and cannot enforce it's own rules. This is one of those cases where lack of funding leads to inept regulation. The FCC cannot set a rule and simply enforce the rule. They have to set a rule that is enforced in a defacto manner without them spending any money.
So by regulating what manufacturers can and cannot do- they get the "appearance" of responsible regulation. With the added side effect of stifling innovation, modification, or customization (within the law) of the equipment.
You can try to explain this to people.. but since the principles involved are nuanced and technical most eyes glaze over. But the short form is this: if you lock down the hardware you stifle innovation.
Another primary example of the FCC failing for lack of funding is the regulation of radio bandwidth which citizens have access to. That would be the CB, GMRS, FRS, MURS, or Amateur Radio services. The FCC either farms out the enforcement (Amateur Radio is farmed out to the ARRL) or simply makes no enforcement action at all. The result being that the radio spectrum has become a cesspool of "pirate radio", free-banders (Illegal unlicensed operators), or licensed operators who break all the rules.
There are illegal operators across all the bands in the spectrum that are known by the FCC, the general public who use the spectrum, local law enforcement, and the defense community. But they are rarely enforced against.
They are not enforced against because the FCC has no budget for enforcement. They rarely enforce interference with government services first, commercial services second, and do nothing at all anywhere else. Very occasionally there is Amateur enforcement.
This means as a citizen FCC enforcement will come through any tangential avenue that has no cost to the FCC.
Another consultant who stuck it out.
"We are the Priests, of the Temples of Syrinx..."
There's no particular reason to play politics on this.
When you get FCC certification, you are certifying to the government that your product meets their requirements for EM emissions and reception (intentional or otherwise). This isn't new, it's been around since before, I would guess, everyone reading this was born. By allowing customers to go monkey with those settings you can no longer give any such certification. It makes some sense for the FCC to stop this, and honestly I wondered how long before they did since most people doing this are dramatically boosting the transmission levels on their routers.
Now it may be that you think that the burden is on the government to find and stop people who are breaking the rules individually, rather than putting the burden on manufacturers, and I agree with the point in principle, but in practice the entire point of the FCC is to ensure the airwaves are shared and we don't end up with broadcast power wars. I do not know of many people who after making changes to their radio settings, also go put their router in a testing chamber and ensure that it is still compliant, not only at 5GHz (for example), but that harmonics are not leaking out at other frequencies that they did not intend (in some cases also due to lazy electronics design). Those labs cost some bucks, so unless you happen to have access to one, and your boss happens to look the other way when you use it for personal use rather than billing a customer, its hard to do. Hunting down each and every person who is breaking the rules is very expensive, and I think we can all agree we don't want to pay more in taxes for this. Therefore putting the burden on mfg's is a cheap solution that solves their problem. I'm not sure why we would want to fight the FCC on this.
The fact that manufacturers are ALSO locking out the non-radio facing firmware is an entirely different issue that the FCC is not responsible for. That part needs to be fought, but hopefully some manufacturer will see some money in doing it right. Shipping WiFi firmware is so universally awful that almost anything else is better.
I believe the point is in huge issues that effect the whole country in which we can get public awarness campaigns backed by reddit, google, and several main stream TV personalities like John Oliver backing the public and helping them navigate through the intentionally obtuse comments section of their page, things are still not looking so positive in this direction. Issues like custom router firmware... in which well, maybe .001% of the population is even aware that such is even possible, and only a very small subset of that group has motivation to even consider using it when it is freely available, so then factor in it is likely a subset of that which might even care to fight for it. It's not even bringing a knife to a gunfight, more like bringing a foam finger to a nuclear war.
most people doing this are dramatically boosting the transmission levels on their routers.
General rule of thumb: if you can't get a good signal at 15dBm on 2.4 and 18dBm on 5GHZ, do not try to go higher. Install more APs closer to your clients. Otherwise you are just damaging the spectrum. The higher levels are really meant for when you have real antennas on both ends, like a WDS. You can't make cheap client antennas better by shouting at them. Also, you should have a compelling reason to deploy 5GHz outdoors, even using factory firmware... you are a lot less likely to do something destructive fumbling around with the 2.4GHz band outdoors. Partly because it is already ruined, and partly because it doesn't have to worry about radar.
Many settings that are not strictly RF-related are bunched in with the RF settings, and can use some tuning, and are not settable from factory firmware -- which you should never run anyway because it is full of junk plug-and-play services and will stop receiving security updates long before you are done using the AP.
Vendors have no incentive to separate out these settings in hardware, nor support them in software, nor continue to support an AP after it is out of warranty, as then they are just decreasing demand for their latest models.
Most people who install Open Source firmware are after features not related to RF, few people feel any need to install custom firmware on the WiFi card (more on some models than on others) and what special WiFi card settings they are looking to alter are things like beacon formats and timing, noise floor detection, etc.
Refusal to publish solid specs from which open source drivers can be written probably account for the majority of issues where RF parameters are set up wrong.
Especially, vendors shipping product whose EEPROM settings are wrong and then kludging things back together in their binary-only drivers, rather than reprogramming the EEPROM on upgrade, might be the number one cause.
Someone had to do it.
and the Internet, which he helped make public - and never said he 'invented', folks
And he never said 'helped make public' either. I don't know where you got that. The exact quote was, " I took the initiative in creating the Internet." He tried to make it sound like he was more important to the development of the internet than he really was.
Overturning that boneheaded decision was prominent in the Democratic platform - a point Bernie Sanders, if not all of his supporters
Bernie wasn't a Democrat. He ran as a Democrat, which the DNC hated him for, and they did everything they could to throw a wrench into his campaign.
And that guy, whatshisname?, Al Gore... He got net neutrality (and the Internet, which he helped make public - and never said he 'invented', folks). But yes, he's a bit of a stick in the mud politically, so we got W instead.
Gore was yet another example of how shitty the DNC is at getting elected. They keep backing candidates with zero charisma (or actually negative charisma, in the case of Hillary), and then wondering why they lose. It happens over and over and over: Hillary, Kerry, Gore, Dukakis, Mondale... and when they picked someone with real charisma (Bill Clinton), they won. You'd think they would have figured out this simple formula (charisma = win) after all these decades, but apparently not, and most obviously in this most-recent election where the Dem candidate lost to the biggest joke of a candidate ever on the GOP side. And worse, they *still* haven't really figured it out and won't admit it, and instead blame "the Russians", Comey, etc.