Posted June 3 on YouTube:
Drop down to the 1st (pinned) comment, which is by the creator, and from that:
"The lede I probably buried: I looked into Netgear’s claim that TP-Link routers are a great place for criminals to hide, and yes, the TP-Link BE800 audit gives plenty of reasons to be concerned. Context is important to me, so this video is about context of the testing that led here.
Awkward: the Netgear RS700S preliminary audit does not look better. It may be worse.
So the answer is not “TP-Link bad, Netgear good.” The answer is that consumer routers have a software lifecycle problem. These boxes keep working for years after the kernel, services, cloud agents, VPN stacks, and bundled userland have aged into a security swamp. Netgear knows something is up; they took down all their GPL sources to make auditing harder. Bold strategy, Cotton!
A router is not a toaster. It is DNS, DHCP, firewall, NAT, sometimes VPN, sometimes storage, sometimes cloud management, and increasingly part of your online identity footprint. Treating firmware updates like occasional PR events instead of a long-term maintenance promise is how we got here."
--------
I chose to add that to this thread because over time I've noticed (at least elsewhere) some people seem to think TP-Link's product line is particularly vulnerable to potential foreign 'bad actor' exploitation. If that's someone's concern, better dig a little deeper.
If the FCC or some other entity wanted to improve the security awareness in the U.S. consumer router market, it'd be nice if there was a single site that listed the various brands and models, whether they are actively getting firmware updates or not, vulnerabilities known for that specific model and an overall 'grade' kept current over time as to how secure it's judged to be now.
I'm curious - is there some point beyond which old hardware is too outdated to make secure in modern networking? Just how long is updating firmware feasible before?
Revisiting the original question, I think the premise was that the ban would exclude so much foreign competition that Apple, having great wealth and technical expertise and thus the leverage to enter the U.S. router market in compliance with the ban fast enough to take advantage, could do so and theoretically turn a profit.
I don't think it's going to happen. Apple keeps a narrower product portfolio to focus on than Microsoft, for example, a '
we do fewer things but better' mindset. I don't see it as potentially lucrative enough; we're not talking smart phones or iPods, etc. And enough exclusions have been issued (e.g.: Eero, Netgear) to keep competition in play, plus routers for many people are 'set it up once and forget it' and interfaces good enough I don't seen an opportunity for Apple's famed user interface and ecosystem integration advantages to turn the tide. Plus it's a long lifecycle product.
I'd be interested to see what Apple could do!