Question US investigating security risks relating to TP Link Routers

Page 2 - Seeking answers? Join the AnandTech community: where nearly half-a-million members share solutions and discuss the latest tech.

JackMDS

Elite Member
Super Moderator
Oct 25, 1999
29,524
413
126
@ RHoXS

Thanks for the good info.

I use some of Netgear hardware.

However, if Netgear is capable/willing to issue in the USA a statement that they brink the products to the US and Test them for security, then there is a point to it.

Otherwise, it is Items that are produced out of the USA and assuming that they are well safe is just words.


 
Reactions: Thibsie

Fallen Kell

Diamond Member
Oct 9, 1999
6,135
494
126
Keep an eye on the PoE Unifi items, they are not standardized, at least when I built my system, they used 24 and 48v PoE which caused the use of dongles for parts. Even though I have a PoE switch.
Just for clarification, you ran into the classic Passive PoE vs Active PoE (802.3af/at/bt). Passive PoE is usually only 24V (there are a few 48V examples) and the ports are not autosensing and have to manually turn on or off the PoE function. Active PoE (802.3af/at/bt) is autosensing and use a voltage range between 48-57V and will turn on the power if it senses the device it is connecting to requests the power.

There is also PoE+ (802.3at) and PoE++ (802.3bt) now in the mix as well. Mostly these just allow for higher power draw per port than the previous standards, but the voltage range they support also changes between them and thus are typically not interchangable. This is why I hate companies not using the actual standards in their documentation/marketing materials.


As for the thread's original purpose, the main reason they believe they are vulnerable is because they are so quickly abandoned with no firmware updates, leaving them open to attacks when a vulnerability is found in some of the underlying software that is in use on them. Running a third party firmware and keeping it updated will help mitigate that. There is the slim chance that there is some kind of backdoor as well built into the hardware, but I have not seen any announcements of those being found. The backdoor could be software or hardware based, so if it is software, again, running a third part firmware like DD-WRT or OpenWRT would remove that threat. Hardware based backdoors are a little tougher to resolve...
 
Last edited:
Reactions: Thibsie
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |