Open Source Firmware security

5 posts / 0 new
Last post
pastim
pastim's picture
Open Source Firmware security

There's quite a lot of talk about router security, and patches not being applied frequently enough by manafacturers such as Netgear..

So I am thinking of moving to the open source DD WRT Kong Mod firmware, partly for this reason, and partly to enable me to try a few t.hings that the stock firmware won't let me do easily (such as make an arp setting stick across reboots).

I have another stock router (from TalkTalk, not good, having firmware about 2 years old with no sign of an update) which I can use to rescue me if the change to my R6250 goes wrong, so the risk isn't too high for me.  I also have a copy of the stock Netgear firmware.

 

My question is whether the open source firmware obtained here is more likely to be kept reasonably up to date with security fixes, and is worth doing for that reason alone. 

Any views?

 
microchip
microchip's picture
Definitely

Definitely

open source firmware often updates individual compontents more often than stock vendor firmware. If you have telnet access to a NETGEAR router, you can sniff around and you'll see for yourself how old some of their used programs are. dnsmasq for example is one that hasn't been updated in many years by NETGEAR. It's not just NETGEAR but other vendors do it too. ASUS on the other hand seems to keep up with everything much more than the others so that's a +1 from me

That said, another plus for open source firmware is that it often provides far more capabilities than the stock one. I use Tomato for example as it allows me to do some things not possible on any vendor firmware, regardless of vendor. The same goes for DD-WRT/OpenWRT

In the case of Tomato, in the last version (v138) Shibby updated a lot of the components to their latest version. The same things happen with DD/OpenWRT.

pastim
pastim's picture
Thanks.  I'll think about it.

Thanks.  I'll think about it.

pastim
pastim's picture
Installed the firmware a

Installed the firmware a couple of weeks ago and am very happy with it.  Thanks.