TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Newer TP-Link Routers send large volumes of requests to Avira servers

345 pointsby decryptabout 3 years ago

21 comments

frogger8about 3 years ago
From the comments<p>Nothing in your analysis shows this. Moreover unless you explicitly deployed a root certificate on your clients (or if an app on the client did it), the router can&#x27;t decode TLS traffic (deep inspection) without you getting certificate warnings on the client. In that case, the only thing the router can see is the dns request, the IP and the TLS SNI. In short your title is misleading.<p>permalinkembedsavereportreply [–]ArmoredCavalry[S] 11 points 14 hours ago*<p>I agree they couldn&#x27;t be inspecting the contents of your traffic over TLS, but they could easily view destinations. I also agree, there&#x27;s nothing in my analysis that proves that all the requests are related to network traffic. However, if you look at the wording of the reply (directly from TP-Link) to XDA in their review, I don&#x27;t see how it could be interpreted any other way? Regardless, I probably should have made my title &quot;appears that it may send traffic related data&quot;. I&#x27;ll be happy if that isn&#x27;t the case, but the lack of clear explanation from TP-Link when I&#x27;ve contacted support leads me to assume the worst<p>permalinkembedsaveparentreportreply [–]2fast2fourier 4 points 12 hours ago I think it&#x27;s best not to write something that damaging without proof, especially when most people only read titles. Saying they&#x27;re sending metadata and violating your privacy is all you&#x27;d need to hear.
评论 #30651040 未加载
评论 #30653903 未加载
danpalmerabout 3 years ago
I remember reading in the UK government&#x27;s security assessment of Huawei that one of the issues is not necessarily data being sent to bad places or backdoors in the software, it&#x27;s that the engineering processes behind these devices&#x2F;software are completely unable to protect against any sort of supply chain attacks.<p>The sorts of things they highlighted were: no version control, no code review, production builds happening on arbitrary machines, no automated testing, poor access control on code, no audit trail on code changes, the list goes on, and that&#x27;s just for the software side. The conclusion was that Huawei were about a decade away from being able to even claim they had no backdoors. And that&#x27;s a major telecoms hardware provider, trying to sell into governments and major infrastructure projects.<p>I&#x27;m not in the least bit surprised that TP-Link are doing this, and also not at all surprised that when questioned on it they are (so far) unable to actually describe why it&#x27;s happening or really seem to know anything about it.<p>I think this sort of product is built in a very different environment to what most HN users would expect.
评论 #30651512 未加载
评论 #30651147 未加载
评论 #30651006 未加载
评论 #30650902 未加载
评论 #30651604 未加载
评论 #30651412 未加载
danieldkabout 3 years ago
This is why for home and small office use, I usually get AVM Fritz [1] network devices. They have been around for since forever, provide regular updates for their devices and over a long period. Their web interface allows for a lot of fine-grained configuration and their devices have been rock solid for me. They are a German company and as far as I know software development is also done in Germany, so I expect that they operate within the relatively strict privacy regulations of the EU.<p>[1] <a href="https:&#x2F;&#x2F;en.avm.de" rel="nofollow">https:&#x2F;&#x2F;en.avm.de</a>
评论 #30651095 未加载
ajotabout 3 years ago
That&#x27;s before installing OpenWRT!<p>This kind of shenanigans make (once again) the case for 3rd party post market FLOSS firmware to be installed on every device I own. Sure, I spend some extra time researching which router&#x2F;AP&#x2F;phone&#x2F;ereader&#x2F;smart appliance will be compatible with OpenWRT&#x2F;LineageOS&#x2F;KOReader&#x2F;Tasmota&#x2F;ESPHome&#x2F;etc., but I feel more confortable this way. I have more trust in a bunch of people doing this for owning their devices than some corporation whose goals clearly don&#x27;t align with mine.
评论 #30651166 未加载
评论 #30650890 未加载
zinekellerabout 3 years ago
Before you say anything about this feature (which is apparently called HomeCare, <a href="https:&#x2F;&#x2F;www.tp-link.com&#x2F;homecare&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.tp-link.com&#x2F;homecare&#x2F;</a>), you should probably know that Asus also has a AiProtection feature powered by Trend Micro (<a href="https:&#x2F;&#x2F;www.asus.com&#x2F;content&#x2F;aiprotection&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.asus.com&#x2F;content&#x2F;aiprotection&#x2F;</a>) and D-Link having McAfee Secure Home Platform built-in (<a href="https:&#x2F;&#x2F;www.dlink.com&#x2F;en&#x2F;latest-news&#x2F;d-link-introduces-new-exo-router-series-with-mcafee-protection" rel="nofollow">https:&#x2F;&#x2F;www.dlink.com&#x2F;en&#x2F;latest-news&#x2F;d-link-introduces-new-e...</a>). Definitely not vindicating TP-Link here (especially the alleged continuous querying despite the feature being off), just noting that this is not exclusive to TP-Link.
评论 #30651287 未加载
评论 #30651387 未加载
评论 #30651279 未加载
matheusmoreiraabout 3 years ago
So how do we get routers that support open source firmware? It seems these things are getting more difficult to find.
评论 #30650901 未加载
评论 #30650852 未加载
评论 #30650884 未加载
评论 #30650955 未加载
评论 #30652929 未加载
评论 #30650897 未加载
评论 #30650880 未加载
sebowabout 3 years ago
TP-Link became a big no-go for me as soon as ax came out and I saw that they required account registration[0] for managing a personal, local router. Probably has to do with the fact that they&#x27;re not western-owned and are &#x27;legally required&#x27; to have such a system in order to be covered from &#x27;borrowing&#x27; your data. I expect other vendors(Huawei,etc) to do the same, and it&#x27;s insane that people don&#x27;t revolt against such practices, especially considering we still have such vendors being installed by default in people&#x27;s homes by the ISPs.And whilst a router is replaceable by the end user, something like an ONT is harder to find in most places, and the ISP doesn&#x27;t usually give config details for an ONT.<p>[0] Edit: An online account for the mobile application, not the web interface of the router itself.
评论 #30651275 未加载
jmillikinabout 3 years ago
This was alarming since I use a TP-Link router, so I tried figuring out to what extent it&#x27;s able to inspect and record regular (encrypted) traffic.<p>My TP-Link Archer AX50, running software version &quot;1.0.11 Build 20210730 rel.54485(4A50)&quot; is doing at least some sort of DPI on outgoing connections. I found a page in its settings (Advanced -&gt; Security -&gt; Antivirus -&gt; History) that contains a log of connections I&#x27;ve made to &quot;suspicious&quot; domains, which include quite a few that I would consider innocuous.<p>After clearing that log, I loaded a few domains I&#x27;d seen in it, and verified that new entries were created. Wireshark shows that no DNS requests were made, and the DNS-over-HTTP used by Chrome didn&#x27;t leak that traffic. I believe the router must be inspecting TLS headers for the ServerName field.<p>Didn&#x27;t try to verify whether that data is being sent to a third party, but given that this thing is collecting data that it has no business looking at, it wouldn&#x27;t surprise me if it&#x27;s shipping it somewhere.<p>edit: the URL I tested with is &lt;<a href="https:&#x2F;&#x2F;api.mangadex.org&#x2F;docs.html" rel="nofollow">https:&#x2F;&#x2F;api.mangadex.org&#x2F;docs.html</a>&gt;.
评论 #30651390 未加载
评论 #30653881 未加载
WJWabout 3 years ago
ALL routers send my web traffic to 3rd party server I would hope. I don&#x27;t have a router to access all the websites on my home network after all.<p>Joking ofc, this is pretty bad. Terrible coding in the best case, outright spying in the worst. Neither instills a lot of confidence in TP-link.
squarefootabout 3 years ago
The software answer would be easy: use OpenWRT or any other *BSD based alternative, but what about the hardware? A quick search for WAN interfaces for PCs returned nothing.
评论 #30651131 未加载
评论 #30651008 未加载
评论 #30650877 未加载
评论 #30650872 未加载
评论 #30650991 未加载
评论 #30651052 未加载
评论 #30650861 未加载
Ourgonabout 3 years ago
I never rued the day when I switched off the last &quot;appliance&quot; router after switching to a virtual router - OpenWRT running in a container on a Proxmox-managed host. I use a number of repurposed &quot;appliance&quot; routers (also running OpenWRT) as access points, some of them connected to additional &quot;dumb&quot; PoE-switches for IP-camera&#x27;s. Those camera&#x27;s run over their own VLAN and never get to touch the &#x27;net, the same goes for &quot;IoT&quot; things (heat pump, PV-inverter etc). Xi and friends will be disappointed, even if they built backdoors in their equipment these only lead to a dead-end street.
ytchabout 3 years ago
I was annoyed by the Deco APP too. It provides remote management, which I believe that all data is forwarded through TP-Link&#x27;s server.<p>My solution is running those devices as a Wi-Fi to LAN bridge, also setup my own NAT gateway (by bare-metal Linux, Openwrt... etc). Then blocking there devices from accessing Internet at gateway.<p>If I have more IoT devices at home, I will apply such policy to all of them.
jamal-kumarabout 3 years ago
Hasn&#x27;t avira been just generally for a lack of better words completely fucking awful over the past year or two? The last I remember hearing about them was installing crypto miners along with their AV, which I can only imagine being bottom quality at this rate of insanely bad behaviour...
Kiroabout 3 years ago
Readable link on mobile: <a href="https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;hardware&#x2F;comments&#x2F;tbthjj&#x2F;psa_newer_tplink_routers_send_all_your_web&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;hardware&#x2F;comments&#x2F;tbthjj&#x2F;psa_newer_...</a>
评论 #30651344 未加载
sabujpabout 3 years ago
I setup cloudflare zero trust and started pointing my AC4000 to it, let&#x27;s see what happens.
评论 #30662769 未加载
mhitzaabout 3 years ago
If you want to see TP-Link routers track record, and if you have an existing TP-Link router, check the updates page on their support website. Same kinds of vulnerabilities are fixed often across devices, as if not learning from their mistakes.<p>When it comes to budget routers I still turn to TP-Links when I can easily find a decent model on the market that is supported by openwrt.
lazyeyeabout 3 years ago
Senior people at tp-link should go to jail for this.
richardfeyabout 3 years ago
GDPR fine &amp; class-action lawsuit in 3...2...1
verisimiabout 3 years ago
pwned
maxlohabout 3 years ago
TP Link is a Chinese company. I won&#x27;t trust them personally.<p>In China&#x27;s current political status, it is impossible for Chinese companies to reject the autocratic government&#x27;s requests for surveillance. You may endup in jail or even get killed.
评论 #30651167 未加载
评论 #30650959 未加载
评论 #30650940 未加载
评论 #30651076 未加载
vehemenzabout 3 years ago
Anecdotally, I&#x27;ve seen that TP-Link routers are ubiquitous in Chinese households. I don&#x27;t draw any conclusions from that, but I did stop buying TP-Link devices.<p>It would be nice if the US took import controls as seriously as export controls.