These articles indicate that many of our routers are unknownst to us infected with dangerous software, and there may not be any easy solution.
Should we be doing something about this?
Bob W8ERD
https://www.schneier.com/blog/archives/2018/06/router_vulnerab.html
https://blog.talosintelligence.com/2018/05/VPNFilter.html
Should we be doing something about this?
Bob W8ERD
https://www.schneier.com/blog/archives/2018/06/router_vulnerab.html
https://blog.talosintelligence.com/2018/05/VPNFilter.html
Our nightly builds are as current as we can make them with the latest security fixes on the linux platform we are building upon. It's probably more the concern that the stream of changes we receive hasn't been vetted enough. There will be a steady stream of these security fixes, could be 100s in a given month. By keeping our releases close behind this stream from the linux community, we keep on top of the security risks.
But security goes beyond the mesh nodes. Each local mesh island should be talking about and concerned members attach laptops and other devices that are also current with OS patches and Antivirus updates. Proper device hygiene should be on each group's checklist. It's a matter of time before someone unknowingly connects an infected device and propagates to other devices on the network. All devices should be connected to the internet monthly to receive OS updates and virus definition updates.
Joe AE6XE