Another successful OpenBSD setup

I’ve been buying these little boxes from AliExpress for years to use as firewalls and routers. My oldest one is almost 9 years old now! OpenBSD installs just fine. Just a BIOS tweak to always boot up after power is restored.

@selfhosted #selfhosting #selfhosted #openbsd #runbsd

You are viewing a single thread.
View all comments
16 points

Do any of those cheap Chinese computers ever get any firmware or bios updates?

permalink
report
reply
32 points

No and they don’t provide the source either. Makes you wonder what’s running in there.

permalink
report
parent
reply
22 points

While i agree, no one provides full source blobs for firmware and bios that i am aware of. Please correct me if I am wrong, however.

permalink
report
parent
reply
3 points
14 points

I’d be surprised if it wasn’t just based off the UEFI sdk examples containing 30+ CVEs over the last couple of years. If anything, it won’t get patched for logofail and all the others UEFI exploits we’ll definitely see in the coming years.

permalink
report
parent
reply
7 points
*

I was wondering… that tp-link probably negates anything remotely resembling security on its own. But yeah, you can update some of these noname boxes easily, others, not so much.

I have dealt with (in a professional capacity) Chinese manufacturers that are under the impression they do not have to provide a working build tree for the kernel, let alone firmware, so its a gamble if you’re not talking to a major Chinese name brand. Mind you, I was ordering hundreds of those boxes, so there was some leverage.

permalink
report
parent
reply
15 points
*

That TP-link is a dumb switch. Unless you’re telling me that someone is going to find an opening in the firmware and hack their way into the ARP table or something (in which case the threat model here just became state actors and I don’t think the OP is safe with this equipment), I don’t think it affects much, if anything.

Now, if I’m mistaken and that is actually a managed switch; god help them with network security.

permalink
report
parent
reply
8 points
*

It is a managed switch. What’s wrong with TP-Link managed switches?

I have a basic Netgear managed switch for VLANs.

permalink
report
parent
reply
6 points

They do make managed switches, but just to be completely clear, my comment was mostly hyperbole. I just found the general combination of security - mindedness and cheap Chinese hardware curious / amusing.

permalink
report
parent
reply
7 points

None that I know of :(
But @benjja tells me that on some of these you can install coreboot: https://ohnepunktundkomma.org/@benjja/111991771619601081

Something I’m keen to look into.

@cmnybo @selfhosted

permalink
report
parent
reply
3 points

@otl @cmnybo @selfhosted

Protectli ported coreboot for their hardware, and with a little research you can find this hardware on aliexpress, of course under a different name.

permalink
report
parent
reply
3 points

Does any board ever get firmware updates? I don’t understand your logic.

permalink
report
parent
reply

Selfhosted

!selfhosted@lemmy.world

Create post

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don’t control.

Rules:

  1. Be civil: we’re here to support and learn from one another. Insults won’t be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it’s not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don’t duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

Community stats

  • 5K

    Monthly active users

  • 3.6K

    Posts

  • 81K

    Comments