frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Drilling Down on Uncle Sam's Proposed TP-Link Ban

https://krebsonsecurity.com/2025/11/drilling-down-on-uncle-sams-proposed-tp-link-ban/
60•todsacerdoti•2h ago

Comments

ddtaylor•2h ago
> The company says it researches, designs, develops and manufactures everything except its chipsets in-house.

So, the plastic bits?

hdgvhicv•2h ago
Presumably the software, the boards, connectors, antenna design, etc.
tliltocatl•1h ago
> connectors, antenna design

And also passives like SMD resistors. They are also refining copper and iron from raw ore. /s

thfuran•1h ago
They actually make their own iron in the heart of a dying star.
R_D_Olivaw•37m ago
They actually manufacture a synthetic star from which they gather their elements.
seizethecheese•1h ago
As a hardware founder, low quality plastic is not rocket science. On trips to China I’ve heard similar things about other companies, specifically that Foxconn makes everything it uses, including things like coolant or plastic for prototype production.
MomsAVoxell•1h ago
Does anyone know what their chips are doing? Do you, really?

Until we have desk side silicon fabrication/placement, with accompanying tunnelling microscope features, we simply cannot trust our silicon in any way other than through utterly peaceful means, which is to say, through systems of human trustworthiness.

Technology never allows us humans to advance sufficiently well to do without it .. unless it is evenly distributed.

Right now we are all at the mercy of the masters of silicon. This is no joke!

BobbyTables2•1h ago
Even with desk-side silicon fabrication, one would have to hope the hardware/software with the design tools wasn’t already backdoor-ed…
Meneth•1h ago
Reflections on trusting trust...
matheusmoreira•6m ago
Absolutely. We'll never be 100% free until we can fabricate computers at home, just like we can write our own software at home.
vjvjvjvjghv•2h ago
If only there were US manufacturers that could produce things at a decent price and didn't actively hate their customers.
hdgvhicv•2h ago
I’m sure there’s some way to inject advertising - otherwise it’s just leaving money on the table.
ZeroConcerns•2h ago
I'm old enough to remember most cable modems and set-top boxes being manufactured in the US.

They were... not great...

system2•1h ago
There is, but corporate greed doesn't allow it.
silisili•1h ago
Eero used to be pretty close. Years ago, I used to stalk the subreddit despite never owning an Eero just because the (US based) devs would often drop knowledge bombs. AFAIK they wrote the entire software stack in house.

I have no idea if that's still the case, especially post AMZ, but worth looking into if so.

medoc•1h ago
The fact that TP-Link products are vastly better and cheaper than all their numerous competitors is indeed a bit strange. You have to either think that all the people at Linksys, Netgear, D-link, etc. are incompetents or that something a bit out of the ordinary is going on at TP-Link...
ZeroConcerns•2h ago
I don't have any particular opinion on TP-Link (never used their products), but the idea that a low-cost vendor targeting home and SMB users is somehow a state-level agent trying to compromise those users... needs evidence.

I mean, in the case of actors like Huawei, you can at least credibly make the argument that the continued access of their support staff to internal provider networks is a significant risk, but that vector is entirely absent here.

Sure, embedded firmware has been, is, and will continue to be a tire fire prone to embarrassing compromises, but containing those is mostly about notification and containment by government agencies (which the current US administration is doing their utmost best to kneecap) and/or large ISPs (which in the US have traditionally never cared).

Forcing "foreign" products off the market in favor of "domestic" replacements with the exact same, if not worse, flaws won't fix a thing, unless you put some pretty significant controls into place that nobody is willing to enforce or even outline.

thfuran•1h ago
But it does provide ample opportunity to profit personally, and that’s much more of a priority for the current federal administration than fixing anything.
riskable•1h ago
The real lesson here: If you're successful, don't skimp on security/software! Also, don't abandon software/firmware security support for your products so quickly.

If I was in charge over at TP-Link, getting news that tens of thousands of MY company's routers were compromised would have me furious! I'd be freaking out, making sure that we take immediate steps to improve software/firmware quality and to make sure we're in a constant state of trying to compromise our own hardware... To ensure no one else finds vulnerabilities before we do.

Instead, TP-Link seems to have just laughed and focused strictly on profit margins.

stldev•45m ago
Or maybe, don't capture 50% market share in a country that's decided your country of origin is the threat of the decade.
WheatMillington•1h ago
So much freedom in America lately. TP-Link, DJI, BYD, must be great to never have these options.
avalys•1h ago
Can a civilian buy an AR-15 in China?
TheBicPen•1h ago
No. But which nation claims to be all about freedom, and which is known for restricting individual liberties for (whatever the people in charge consider to be) the greater good?
philipallstar•44m ago
It's really silly to judge nations on their claims rather than their outcomes.
dc96•1h ago
You're comparing apples to oranges here. The USA is supposed to be capitalistic, free market, yada yada. China doesn't make that claim.

The main point the comment you replied to is trying to make is that the US doesn't put their money where their mouth is.

maxglute•52m ago
PRC restricts guns ownership, but to make your example less stupid, PRC shooting ranges has access to western pattern arms vs US where civies has more freedom to own guns but you know... not sanctioned Chinese origin guns. So even on muh 2nd amendment grounds, PRC within their right to play with guns (again not own), still less protectionist than US. Which mirrors how you know, almost every major US tech brands operated in PRC with reasonable controls/oversight but not vice versa.
kotaKat•1h ago
I'm so glad there's other American drone manufacturers that cater to the consumer market, like Skydi-oh right, they stopped making consumer drones after the successes in forcing DJI out of the market.
rasz•49m ago
and their mil drones are subpar

https://en.defence-ua.com/news/which_western_drones_have_sho...

https://www.defensenews.com/global/europe/2025/11/07/of-fibe...

>drones from the American company Skydio proved ineffective in Ukraine [notably, a Skydio drone was used by the U.S. Army to drop a combat grenade for the first time], as they were unreliable in front-line interference conditions.

>The problems with Skydio drones in Ukraine were reported last year, and the manufacturer acknowledged the poor quality of its products.

>According to Alex, a key issue with today's low-quality products is the "information gap among many European and American manufacturers about current battlefield conditions and the timing of when they receive this information."

Surprisingly

>Some of the most effective ones have included the German-made Vector drones and Polish-made FlyEye drones.

deadlydose•1h ago
I just bought a new DJI drone and I have a cheap TP-Link WAP in my home office. Worry about your own freedom, kid, and not mine.
fujigawa•53m ago
You're from NZ, which perpetuated one of the most brutal COVID lockdowns, including allowing police to enter homes without a warrant to enforce quarantine and restrictions.

The US routinely bans unsafe products. Far east garbage riddled with security holes are unsafe products.

cflewis•1h ago
I've been really happy with the TP-Link smart plugs. I keep upgrading them as The Latest Standard That's Definitely The Real One This Time Trust Us Bro comes out, and the Matter ones are excellent. Getting an instant response from them is really nice. I see no reason to buy others.

I would buy only Hue but that's because I have more money than sense, and they don't actually make smart plugs last time I looked, they make plugs but label them all as lights in the app, which is more annoying than it sounds.

The real problem to solve ditching TP-Link _routers_ is that all routers are uniformly fucking awful, and all you are doing is choosing your particular poison. This is especially true after Apple exited the game so long ago. I use Google Wifi because it mostly works most of the time, but that's not glowing praise. But the world has become trained that rebooting a router once a week and praying that it works when it comes back is a perfectly normal state of affairs and we couldn't possibly do this any better.

iamacyborg•54m ago
Eve smart plugs are solid and don’t have any unnecessary cloud stuff.
add-sub-mul-div•50m ago
I have some TP-Link smart plugs and was happy with them for a long time because their app could be used without an account. Then I recently got the new version of the app and it forces an account, there's no more guest mode. I'm done with TP-Link now.
microtonal•46m ago
I would buy only Hue but that's because I have more money than sense, and they don't actually make smart plugs last time I looked,

Ikea makes Zigbee smart plugs with power monitoring (Inspelning) that are ~10 Euro here (probably $10 in the US). Also Zigbee does not have all the security issues, since it is purely local and will talk with whatever hub/bridge you choose, e.g. Homey, Hubitat, or if you want to go free software Home Assistant or zigbee2mqtt.

It's somewhat insane to me that people use WiFi plugs for actuating things that actuate real-life electrical devices. Even more from companies that have a bad security reputation. Zigbee or Z-Wave all the way or possibly Matter over Thread, but the only Matter device that I had (an upgraded Eve Energy plug) has been a pain.

The real problem to solve ditching TP-Link _routers_ is that all routers are uniformly fucking awful, and all you are doing is choosing your particular poison. This is especially true after Apple exited the game so long ago.

I switched to Unifi gear (Cloud Gateway Max, two of their U7 access points, and a bunch of their managed switches) and they are a dream to set up. Making VLANs, associating VLANs with SSIDs, etc. is so easy. I had a TP Link managed switch and the interface was a huge pile of crap and I saved it several times after misconfiguration by virtue of it having a serial console. I only used it for two months or so because it was so frustrating.

bethekidyouwant•1h ago
I don’t get the end game here D-link isn’t any better. Are we heading for isp enforced hardware in our homes?
imagetic•57m ago
God help us.
chatmasta•1h ago
TP-Link makes really solid products, and if you don’t want to use their firmware then almost all of them can easily flash OpenWRT. In fact most of their routers are built from OpenWRT anyway.

I installed their mesh Wi-Fi system for my parents recently and was really impressed how seamless the process was. It did involve making a cloud account which I wasn’t thrilled about, however.

forinti•49m ago
TP-Link let me down twice.

I bought a cellphone from them many years ago and they never really supported it and I couldn't even buy a replacement battery.

Recently I bought a router with the firm intent of installing OpenWRT, but I received a newer revision that had a different CPU, less RAM, and less flash memory.

These events left a bad impression, but they do make affordable stuff with reasonable quality.

mbreese•20m ago
> Recently I bought a router with the firm intent of installing OpenWRT, but I received a newer revision that had a different CPU, less RAM, and less flash memory.

This also happened many years ago with Linksys (prior to Cisco). It’s not that uncommon for manufacturers to release new revisions of hardware without necessarily making it clear to the purchaser. If their purpose is to deliver a router and they can shave a few cents off the BOM with less RAM, but it still works with their software, why would they care. And once new revisions have been released into the supply chain, it can be hard to know exactly what version you are buying.

In the Linksys case, IIRC they eventually re-released the first revision WRT54G as the WRT54GL (for Linux), so that people who wanted different firmware could get the exact hardware they wanted.

imagetic•1h ago
I have TP-Link Deco's for our WiFi, sitting behind a Firewalla Gold. This has been by far the nicest, simplest at home setup I've ever deployed. Do I love that I chose TP-Link? No. But price to purpose it was the best product available to me at the time.

If TP-Link gets banned, my concern is what that means for the massive market share in the US. Warranty? Software updates? Or maybe that action is what turns them into an agent of the state. Or do you horde all the hardware until its valuable like DJI parts are today?

ComplexSystems•55m ago
I don't get what to make of this. Is it all just security theater? The idea of having consumer networking hardware that isn't riddled with security vulnerabilities seems to be a ship that sailed long ago. I doubt this move will prevent major nation states from hacking into whatever they want.
abridgett•53m ago
I'll just leave this little NSA intercepting Cisco products reminder here: https://arstechnica.com/tech-policy/2014/05/photos-of-an-nsa...
misiek08•33m ago
But Sir! We are talking here between USA <eagle sound> versus rest of the world that’s unsafe and all the time attacking USA people privacy. Cisco is India based, not American!

disclaimer: not connected in any way with Cisco, just disappointed business customer.

SilverElfin•40m ago
I don’t like that TP Link routers regularly force you to accept new terms of service within their app. If you don’t, then you can’t access much of their configuration options. Basically you get locked out of your own device. I feel like these dark patterns should be illegal.
nickpsecurity•27m ago
"TP-Link Systems told The Post it has sole ownership of some engineering, design and manufacturing capabilities in China that were once part of China-based TP-Link Technologies, and that it operates them without Chinese government supervision."

Is that even possible? Or do you always have to be on good terms with the Chinese government to own engineering, design, and manufacturing capabilities in China?

Marble Fountain

https://willmorrison.net/posts/marble-fountain/
255•chris_overseas•4h ago•32 comments

Montana Becomes First State to Enshrine 'Right to Compute' into Law

https://montananewsroom.com/montana-becomes-first-state-to-enshrine-right-to-compute-into-law/
231•bilsbie•7h ago•112 comments

The Manuscripts of Edsger W. Dijkstra

https://www.cs.utexas.edu/~EWD/
141•nathan-barry•5h ago•52 comments

Protect Your Consciousness from AI

https://jordangoodman.bearblog.dev/protect-your-consciousness-from-ai/
37•zekrom•1h ago•7 comments

The Principles of Diffusion Models

https://arxiv.org/abs/2510.21890
81•Anon84•4h ago•4 comments

Building a 2.5kWh battery from disposable vapes to power my workshop [video]

https://www.youtube.com/watch?v=dy-wFixuRVU
29•rsanek•6d ago•13 comments

Bumble Berry Pi – A Cheap DIY Raspberry Pi Handheld Cyberdeck

https://github.com/samcervantes/bumble-berry-pi
62•MakerSam•4h ago•10 comments

Drilling Down on Uncle Sam's Proposed TP-Link Ban

https://krebsonsecurity.com/2025/11/drilling-down-on-uncle-sams-proposed-tp-link-ban/
61•todsacerdoti•2h ago•46 comments

Reviving Classic Unix Games: A 20-Year Journey Through Software Archaeology

https://vejeta.com/reviving-classic-unix-games-a-20-year-journey-through-software-archaeology/
111•mwheeler•8h ago•40 comments

CHIP8 – writing emulator, assembler, example game and VHDL hardware impl

http://blog.dominikrudnik.pl/chip8-emulator-assembler-game-vhdl
26•qikcik•6d ago•0 comments

AI isn't replacing jobs. AI spending is

https://www.fastcompany.com/91435192/chatgpt-llm-openai-jobs-amazon
438•felineflock•5h ago•288 comments

The Sega Master System

https://bumbershootsoft.wordpress.com/2025/11/08/the-sega-master-system/
11•ibobev•1h ago•1 comments

Zensical – A modern static site generator built by the Material for MkDocs team

https://squidfunk.github.io/mkdocs-material/blog/2025/11/05/zensical/
87•japhyr•8h ago•31 comments

Visualize FastAPI endpoints with FastAPI-Voyager

https://www.newsyeah.fun/voyager/
96•tank-34•8h ago•12 comments

Using bubblewrap to add sandboxing to NetBSD

https://blog.netbsd.org/tnf/entry/gsoc2025_bubblewrap_sandboxing
63•jaypatelani•7h ago•19 comments

Startups are pushing the boundaries of reproductive genetics

https://www.wsj.com/tech/biotech/genetically-engineered-babies-tech-billionaires-6779efc8
41•nradov•6h ago•60 comments

When Your Hash Becomes a String: Hunting Ruby's Million-to-One Memory Bug

https://mensfeld.pl/2025/11/ruby-ffi-gc-bug-hash-becomes-string/
60•phmx•5d ago•18 comments

The overengineered solution to my pigeon problem (2022)

https://maxnagy.com/posts/pigeons/
60•cyb0rg0•6d ago•44 comments

Solving Every Sudoku Puzzle (2006)

https://norvig.com/sudoku.html
4•djoldman•5d ago•0 comments

Email verification protocol

https://github.com/WICG/email-verification-protocol
106•sgoto•1w ago•72 comments

Samsung Family Hub for 2025 Update Elevates the Smart Home Ecosystem

https://news.samsung.com/us/samsung-family-hub-2025-update-elevates-smart-home-ecosystem/
278•janandonly•5h ago•267 comments

I Am Mark Zuckerberg

https://iammarkzuckerberg.com/
1016•jb1991•14h ago•362 comments

Ironclad – formally verified, real-time capable, Unix-like OS kernel

https://ironclad-os.org/
336•vitalnodo•21h ago•99 comments

Python Software Foundation gets a donor surge after rejecting federal grant

https://thenewstack.io/psf-gets-a-donor-surge-after-rejecting-anti-dei-federal-grant/
60•MilnerRoute•3h ago•21 comments

William Gass and John Gardner: A Debate on Fiction (1979)

https://medium.com/the-william-h-gass-interviews/william-h-gass-interviewed-by-thomas-leclair-wit...
6•ofalkaed•6d ago•0 comments

Largest cargo sailboat completes first Atlantic crossing

https://www.marineinsight.com/shipping-news/worlds-largest-cargo-sailboat-completes-historic-firs...
361•defrost•1d ago•242 comments

American Heart Association says melatonin may be linked to serious heart risks

https://www.sciencedaily.com/releases/2025/11/251104012959.htm
38•pogue•3h ago•24 comments

Reverse engineering Codex CLI to get GPT-5-Codex-Mini to draw me a pelican

https://simonwillison.net/2025/Nov/9/gpt-5-codex-mini/
137•simonw•16h ago•66 comments

Ask HN: How do you get over the fear of sharing code?

30•sodokuwizard•3h ago•53 comments

Ask HN: How would you set up a child’s first Linux computer?

152•evolve2k•9h ago•195 comments