[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y ] [Search | Free Show | Home]

Router Security and Anonymity

This is a blue board which means that it's for everybody (Safe For Work content only). If you see any adult content, please report it.

Thread replies: 32
Thread images: 2

File: router.jpg (32KB, 640x360px) Image search: [Google]
router.jpg
32KB, 640x360px
What're technolo/g/y's thoughts on replacing your ISP's router with a router of your own choice for security and anonymity reasons?
>>
>>60009055
There's a good argument to be made that you should never use any ISP-provided equipment if you can help it. They only care about security to the extent needed to keep themselves out of the news. Firmware updates are an expense, they won't bother with them if they think they can get away with not doing so. And the thing they care about most is reducing costs from people who change something and then call customer service. Result being that ISP equipment is both insecure and inflexible.

Buy your own equipment. Preferably a standalone modem. If you can't, but your ISP's shitbox in bridge mode and plug it into a pfSense machine or something similar.
>>
>>60009132
What router/modem would you suggest?
>>
>>60009156
>modem
Depends. ISPs very much want you to rent your shit, but most should have a list of modems that will work with their service. (not every cable modem will work with every cable ISP, if I recall correctly) Cuntcast did, at least. Pick one on the list that seems to have good reviews, and be very firm with them that you don't want to rent their "home gateway" crap.

>router
Well pfSense runs on any old x86 machine that has at least two ethernet ports. That can be something you have lying around, that you put together from spare parts, or that you purpose-build. For home use it does not need to be very powerful. Anything from this millennium will work. If you're a do-it-yourselfer you can of course configure any Linux or BSD box as a router manually. That's quite a bit more difficult, but the Arch crowd likes it. pfSense has its own installer and web interface that makes this shit a lot easier.

pfSense supports some wireless cards, but it's a lot easier to pick a wireless router that you like and plug it into a pfSense interface. If you go that route, you should pick a router that works well with OpenWRT. Stock wi-fi router firmware is all shit, 100% of it. It's not as critical to replace it when its behind pfSense as it is when its directly between you and the internet, but its still a good idea.
>>
Oh yeah, also, note that none of this does anything for anonymity, only security. Your ISP still sees every packet you send and receive. They can still fuck with your DNS requests, if you use their DNS servers, and use that capability to block things they don't want you seeing, or log sites you visit.

If you want to put a stop to that then you need a VPN (Read thatoneprivacysite.net's VPN reviews, and Torrentfreak's VPN guide) and/or Tor, so that your ISP sees all your traffic as an opaque encrypted tunnel.
>>
>>60009240
>>60009271
Thank you very much, I've been saving up to renovate and replace my set-up, after the Vault 7 incident.
Goverments have literally become nothing more cartels backing pyramid schemes with enforces (law enforcement) and fixers (the military) to perform their violent extortions.
The old axiom:
>If you don't have anything to hide, why worry.
Is a lie, you should hide everything from a criminal organisation with global reach.
>>
Anything else enlightening?
>>
>>60009156
pc engines APU3 work well as routers. 10 watts, 3 gigabit Ethernet, 4 GB RAM, and about 160 USD total. They have good compatibility with Linux and pfsense. ok compatibility with OpenBSD, the only gripe I have about it is OpenBSD's shitty drivers don't do checksum offloading so the CPU runs more than it does with Linux (0% thanks to all the hardware acceleration).
>>
>>60010290
Perfect, this is exactly the type of concise information I was looking for, /g/ is really impressing me with their helpfulness.
Thank you, anon.
>>
Doesn't really matter. The next upstream device is theirs anyway.
>>
>>60009055
>security
You set the ISP modem to bridge only, and use your own router (pfSense or DD-WRT)

>anonymity
N/A
>>
>>60009271
Opendns
>>
>>60009240
>take a box with linux on it
>set up some ip table rules.
Why do you need a web interface?
Just ssh like a normal person.
>>
>>60010610
>Why do you need a web interface?
Because its easier. If OP is asking what he should use he probably isn't competent enough to roll his own.

And anyway pfSense lets you do that too. Tick a box in the interface to turn on the SSH server and you can log in and do whatever you like. It's just FreeBSD underneath, so you can play with the firewall, install other software, whatever.
>>
>>60010652
This.

But any guides on this: >>60010610?
>>
>>60010698
I'm guessing not.
>>
>>60011348
arch linux wiki router article
>>
>>60011385
Danke
>>
>>60009055
used to do tech support for Windstream and i would not trust the routers we send out. if they were non power users then they never disabled the remote support thing and we could go into almost anyones shit since our customers are all stupid hicks.
>>
>>60011451
Sounds comfy, thank you for the heads up.
>>
>>60009240
+1 for pf sense being master race

>>60011471
most of our DSL services allow customers to BYOModem but some of the fancier shit like vbonds and fiber required the use of windstream shit.

in a situation where you have you use a shit isp router you can always put your preffered router behind the isp one in a DMZ.
>>
>>60009055
I don't even care about the modem. All I need is a good router that will accept third party firmware. The features alone are enough to keep me there and the bonus of added security is nice.
>>
>>60011451
dumb company leaving remote support enabled then
>>
>>60009156
archer c5 or c7 with openwrt
>>
>>60011508
>>60011541
Thank you.

>>60011520
ISP is just dodgy and terrible.
>>
File: images(93).jpg (27KB, 531x428px) Image search: [Google]
images(93).jpg
27KB, 531x428px
Am I able to install custom firmware in my Telstra Max 1 gateway?
>>
Is there a toolkit for router software pentesting?
My ISP just updated the fw on my router, for the first time ever. Noticed the security got bumped up, but now I'm locked out of it.
>>
>>60012086
Bump for interest.
>>
>>60009271
How big you have to be (or how much money does it take) to be able to connect to the internet w/o ISP? Ie. make your own server and just omit the ISP.
>>
>>60014920
>Money!
>>
>>60010698
Check the arch wiki for firewall and router. Not the best, but everything is there. Most of it your Linux favour can be ignored. Allnof it if you are using netctl
>>
>>60015363
Danke, anon.
Thread posts: 32
Thread images: 2


[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y] [Search | Top | Home]

I'm aware that Imgur.com will stop allowing adult images since 15th of May. I'm taking actions to backup as much data as possible.
Read more on this topic here - https://archived.moe/talk/thread/1694/


If you need a post removed click on it's [Report] button and follow the instruction.
DMCA Content Takedown via dmca.com
All images are hosted on imgur.com.
If you like this website please support us by donating with Bitcoins at 16mKtbZiwW52BLkibtCr8jUg2KVUMTxVQ5
All trademarks and copyrights on this page are owned by their respective parties.
Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.
This is a 4chan archive - all of the content originated from that site.
This means that RandomArchive shows their content, archived.
If you need information for a Poster - contact them.