• SaharaMaleikuhm@feddit.org
        link
        fedilink
        English
        arrow-up
        2
        ·
        4 months ago

        Companies should be forced to release all source code for products that are “EOL”. I will never change my mind on this.

      • Dran@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        4 months ago

        Because that bug was so egregious, it demonstrates a rare level of incompetence.

        • NaibofTabr@infosec.pub
          link
          fedilink
          English
          arrow-up
          2
          ·
          4 months ago

          that bug was so egregious, it demonstrates a rare level of incompetence

          I wish so much this was true, but it super isn’t. Some of the recent Cisco security flaws are just so brain-dead stupid you wonder if they have any internal quality control at all… and, well, there was the Crowdstrike thing…

          • Dran@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            edit-2
            4 months ago

            Idk, this was kind of a rare combination of “write secure function; proceed to ignore secure function and rawdog strings instead” + “it can be exploited by entering a string with a semicolon”. Neither of those are anything near as egregious as a use after free or buffer overflow. I get programming is hard but like, yikes. It should have been caught on both ends

      • tiredofsametab@fedia.io
        link
        fedilink
        arrow-up
        2
        ·
        4 months ago

        May 1st 2024 was a decade ago? (The article has a list and only two are old as you mention, though not quite a decade yet)

  • tal@lemmy.today
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    2
    ·
    edit-2
    4 months ago

    I mean, some of those EOLed nearly a decade ago.

    You can argue over what a reasonable EOL is, but all hardware is going to EOL at some point, and at that point, it isn’t going to keep getting updates.

    Throw enough money at a vendor, and I’m sure that you can get extended support contracts that will keep it going for however long people are willing to keep chucking money at a vendor – some businesses pay for support on truly ancient hardware – but this is a consumer broadband router. It’s unlikely to make a lot of sense to do so on this – the hardware isn’t worth much, nor is it going to be terribly expensive to replace, and especially if you’re using the wireless functionality, you probably want support for newer WiFi standards anyway that updated hardware will bring.

    I do think that there’s maybe a good argument that EOLing hardware should be handled in a better way. Like, maybe hardware should ship with an EOL sticker, so that someone can glance at hardware and see if it’s “expired”. Or maybe network hardware should have some sort of way of reporting EOL in response to a network query, so that someone can audit a network for EOLed hardware.

    But EOLing hardware is gonna happen.

    • shininghero@pawb.social
      link
      fedilink
      English
      arrow-up
      4
      ·
      4 months ago

      I think there should be a handoff procedure, or whatever you want to call it.

      As EOL approaches, work with whatever open router OS maker is available (currently OpenWRT) to make sure it’s supported, and configs migrate over nicely. Then drop one last update, designed to do a full OS replacement.

      Boom, handoff complete.

      • Brkdncr@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        ·
        4 months ago

        I’d support a regulation that defines either an expiration date or commitment to open source at the time the hardware is sold.

      • BearOfaTime@lemm.ee
        link
        fedilink
        English
        arrow-up
        2
        ·
        4 months ago

        Right?

        Something this old is going to be power inefficient compared to newer stuff, and simply not perform as well.

        I would know, I just booted up a 10 year old consumer router last night, because the current one died. It’ll be OK for a few days until I can get a replacement. Boy, is this thing slow.

        • metaStatic@kbin.earth
          link
          fedilink
          arrow-up
          0
          ·
          4 months ago

          I have a netgear router that isn’t even that old and it doesn’t have gigabit ports.

          even though I was able to throw openwrt on there to mess around with it’s still e-waste

          • WhyJiffie@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            1
            ·
            4 months ago

            e-waste? a lot of networks dont need anywhere near gigabit. Especially because at a lot of places around the world even the ISP can’t provide that bandwidth for internet, but this applies to internal networks too. in a lot of cases a 100 mbps capable managed switch (which a router can be, even if with limitations) is enough

    • arthurpizza@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      4 months ago

      I can still use a 2003 AMD Opteron with the newest builds of Linux. It’s an open standard. As long as the hardware still physically works. The only reason these pieces of hardware are EOL is because they chose to lock them down.

    • Rinox@feddit.it
      link
      fedilink
      English
      arrow-up
      1
      ·
      4 months ago

      EoL of anything should mean open source code. You don’t want to open source your code? Then you must keep servicing your products and must keep your servers up

      • uis@lemm.ee
        link
        fedilink
        English
        arrow-up
        1
        ·
        4 months ago

        EU is cooking something with EU Directive on Liability for Defective Products. I’ve read only part of it, but basically companies are liable for bugs in software unless they opensource it.

    • tabular@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      4 months ago

      When the users are in control of the software running on their devices then “EOL” is dependent the user community’s willingness to work on it themselves.

    • db2@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      4 months ago

      all hardware is going to EOL at some point, and at that point, it isn’t going to keep getting updates

      EOLing hardware should be handled in a better way

      Both of these are solved by one thing: open platforms. If I can flash OpenWRT on to an older router then it becomes useful again.

      • thejml@lemm.ee
        link
        fedilink
        English
        arrow-up
        1
        ·
        edit-2
        4 months ago

        Definitely don’t this in the past (Linksys WRT54G!) but let’s be honest, the kind of people running 10yo Dlink routers aren’t going to flash new firmware, let alone OpenWRT or even know to look for it. It would have to come that way from the factory. And even then I doubt most people even do regular updates, sadly.

        • Midnight Wolf@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          arrow-down
          1
          ·
          4 months ago

          Counter point: so it should automatically update every night when updates are available, and should have or migrate to an open standard at mfg EoL or from the factory.

          It’s still the mfg fault, full stop.

      • richmondez@lemdro.id
        link
        fedilink
        English
        arrow-up
        1
        ·
        4 months ago

        When we’re they last sold though, eol 8 years after last up for sale is fine, but if they were still on sale up to last month that is a different issue.

  • darkangelazuarl@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    ·
    4 months ago

    The DSR-150 is still being sold on Amazon under the D-Link store. Why the hell would you end of life something you still sell.

  • Stern@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    ·
    4 months ago

    Okay so the 2015 EOL ones, yeah I can understand telling the customer to update their shit. They shouldn’t have to support nearly 10 year out of date stuff.

    May 2024 EOL ones? Bruh. C’mon now.

    • snooggums@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      4 months ago

      I would love to know when they stopped selling it compared to the EOL. EOL should be at least 5 years past the last time the models were shipped out, maybe more. So if May 2024 was EOL I sure hope they weren’t selling them after 2018.

  • MehBlah@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    ·
    4 months ago

    a new non dlink router. Since the should be named f-link for a number of reasons.

  • sunbeam60@lemmy.one
    link
    fedilink
    English
    arrow-up
    2
    ·
    4 months ago

    I moved to an OPNsense router a couple of years ago and I’ve never looked back. Hell is shitty consumer routers.

      • sunbeam60@lemmy.one
        link
        fedilink
        English
        arrow-up
        1
        ·
        4 months ago

        Oh man, it’s a nightmare and I just happened to be lucky. I ended up buying one of those passively cooled router-esque N100 boxes out of China (AliExpress) and while it was a total punt it turned out to be a great experience, and their customer service was actually good too.

        Kingdel was the make/vendor and it’s been rock solid.

        • Tick Dracy@lemm.ee
          link
          fedilink
          English
          arrow-up
          1
          ·
          4 months ago

          I see. Currently I’m using an Asus one with Asus-WRT but I’m thinking of moving to an OPNSense one.

    • sugar_in_your_tea@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      1
      ·
      4 months ago

      Yup, my Mikrotik router is doing great years after I bought it, and I expect to keep getting updates into the future. I used to use a LinkSys router w/ DD-WRT and later OpenWRT, and I think those are still supported to this day.

  • skillissuer@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    2
    ·
    edit-2
    4 months ago

    but does it run openwrt?

    e: no it doesn’t, only one model had half-baked image made and available for download from some sketchy forum post made in 2014

  • andyortlieb@lemmy.sdf.org
    link
    fedilink
    English
    arrow-up
    2
    ·
    edit-2
    4 months ago

    Commodity hardware & open source software for the win.

    When my Western Digital NAS was never going to get critical security patches, I was so freaking glad to find out that they just used software raid… I threw the HDDs in a Debian server and never looked back.

    It’s certainly nice to have things that are turn-key, but if you can find your way around any OS, just avoid proprietary everything.

  • Sproutling@lemmy.ml
    link
    fedilink
    English
    arrow-up
    1
    ·
    4 months ago

    I hate to say it, but depending on manufacturers for this kind of stuff will always inevitably lead to these kinds of situations. This is why I always buy OpenWrt compatible routers and DIY my own NAS.

    Over the years, I’ve experienced:

    • Netgear refusing to patch bugs like their IPv6 firewall essentially letting all traffic through on the R7800
    • QNAP shipping NASes with Intel CPUs that had clock drift issues so bad they essentially bricked themselves. They then refused to provide any kind of support for them.

    After that I basically said, fuck it, I’ll DIY my own and have been much happier ever since. If you have the know-how and the time, DIY is the way to go for longevity.

  • reksas@sopuli.xyz
    link
    fedilink
    English
    arrow-up
    1
    ·
    4 months ago

    there should be list of companies that should be avoided and why, its impossible to keep track of everything like this

    • TriflingToad@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      1
      ·
      4 months ago

      An idea for an app I came up with for a class once was one that let you scan a barcode of a product in like Walmart and get what parent company owns it, like how Nestle doesn’t like to put their name on companies they bought (or not in big text anyways).
      So if you want to avoid Coca Cola you could scan it and see who it’s owned by and if that company matches one of the ones you have blacklisted

      Fun fact, ‘peace tea’ is owned by coca cola