Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Does that really say DD-WRT in particular is a threat? I take it simply as saying DD-WRT is the poster child.

While I like DD-WRT, if you can flash DD-WRT you can flash anything, and arbitrary code breaks all possible chain-of-trust models.

The FCC has a long history of moving for more restricted hardware as a way of regulating the airwaves, one of its chief jobs. As a ham & commercial radio operator it drives me up the wall, but I understand why they do it.



> arbitrary code breaks all possible chain-of-trust models

No. The code I get on my router from the store is an arbitrary closed source buggy crap.

The code I load from debian, openwrt, etc. is far more trusted.


His point was that individuals could compile their own malicious code in to DDWRT source then flash it to routers.

Your point is corporate code sucks.


I hate HN's tendency to be perfectly intelligent and rational most of the time, yet become infuriatingly obtuse and cultish any time we brush near ideology.

Obviously the FCC does not care about who you trust.


The code that ships in consumer routers is really awful security-wise compared to something like OpenWRT, though, and that's not ideology - it's the commercial reality of the consumer router market. Security costs money and it's not visible to the consumers buying the routers, so the manufacturers don't bother.


I trust GPL code only.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: