Another successful OpenBSD setup

I’ve been buying these little boxes from AliExpress for years to use as firewalls and routers. My oldest one is almost 9 years old now! OpenBSD installs just fine. Just a BIOS tweak to always boot up after power is restored.

@selfhosted #selfhosting #selfhosted #openbsd #runbsd

    • const_void@lemmy.ml
      link
      fedilink
      English
      arrow-up
      16
      arrow-down
      1
      ·
      7 months ago

      No and they don’t provide the source either. Makes you wonder what’s running in there.

      • Spaz@lemmy.world
        link
        fedilink
        English
        arrow-up
        6
        arrow-down
        2
        ·
        7 months ago

        While i agree, no one provides full source blobs for firmware and bios that i am aware of. Please correct me if I am wrong, however.

    • Bitflip@lemmy.ml
      link
      fedilink
      English
      arrow-up
      10
      ·
      7 months ago

      I’d be surprised if it wasn’t just based off the UEFI sdk examples containing 30+ CVEs over the last couple of years. If anything, it won’t get patched for logofail and all the others UEFI exploits we’ll definitely see in the coming years.

    • scrion@lemmy.world
      link
      fedilink
      English
      arrow-up
      7
      ·
      edit-2
      7 months ago

      I was wondering… that tp-link probably negates anything remotely resembling security on its own. But yeah, you can update some of these noname boxes easily, others, not so much.

      I have dealt with (in a professional capacity) Chinese manufacturers that are under the impression they do not have to provide a working build tree for the kernel, let alone firmware, so its a gamble if you’re not talking to a major Chinese name brand. Mind you, I was ordering hundreds of those boxes, so there was some leverage.

      • MigratingtoLemmy@lemmy.world
        link
        fedilink
        English
        arrow-up
        9
        arrow-down
        1
        ·
        edit-2
        7 months ago

        That TP-link is a dumb switch. Unless you’re telling me that someone is going to find an opening in the firmware and hack their way into the ARP table or something (in which case the threat model here just became state actors and I don’t think the OP is safe with this equipment), I don’t think it affects much, if anything.

        Now, if I’m mistaken and that is actually a managed switch; god help them with network security.

        • scrion@lemmy.world
          link
          fedilink
          English
          arrow-up
          5
          ·
          7 months ago

          They do make managed switches, but just to be completely clear, my comment was mostly hyperbole. I just found the general combination of security - mindedness and cheap Chinese hardware curious / amusing.

        • Link@rentadrunk.org
          link
          fedilink
          English
          arrow-up
          5
          arrow-down
          1
          ·
          edit-2
          7 months ago

          It is a managed switch. What’s wrong with TP-Link managed switches?

          I have a basic Netgear managed switch for VLANs.

  • Da_Boom@iusearchlinux.fyi
    link
    fedilink
    English
    arrow-up
    9
    ·
    7 months ago

    I recognise that internet router on the right. That looks like the “smart router” Telstra gives their customers - we have one we used to use back when we had Telstra cable. It’s currently playing the duty of an Ethernet switch for dad’s office.

    • Daughter3546@lemmy.world
      link
      fedilink
      English
      arrow-up
      8
      ·
      7 months ago

      There are a few 5x 2.5g N100 for $120-130 USD range on AliExpress. I grabbed one a while back for my own network.

  • wernsting@lemm.ee
    link
    fedilink
    English
    arrow-up
    5
    ·
    7 months ago

    What bios tweak do you apply? That’s the one thing I still need to do.

    These things are awesome!