Securely downloading and installing Entware. Why not this?

Post new topic   Reply to topic    DD-WRT Forum Index -> General Questions
Author Message
atomicamp
DD-WRT User


Joined: 16 Apr 2018
Posts: 85
Location: Milwaukee, WI

PostPosted: Sat May 31, 2025 5:16    Post subject: Securely downloading and installing Entware. Why not this? Reply with quote
I noticed that in the DD-wrt entware installation guides, all of the links for downloading ddwrt are http, not https. This makes it seem like entware is very dangerous to download and install.

I found this guide to securely download and install entware (https://github.com/Lanchon/ddwrt-secure-entware), but am wondering if it is okay to use, and if so, why it hasn't been implemented in the entware ddwrt wiki or any other ddwrt entware guides?

Could someone please explain to me why this secure entware tutorial https://github.com/Lanchon/ddwrt-secure-entware is not published in the ddwrt entware wiki?

Thanks

_________________
DanRanRocks - Tech Tutorials by Dan Ran

https://github.com/danrancan
dan@danran.rockst
My Blog https://danran.rocks
Join me on key base! and Add me on Keybase

Current Linksys WRT3200acm Firmware "DD-WRT v3.0-r51140 std (12/31/22)
Sponsor
kernel-panic69
DD-WRT Guru


Joined: 08 May 2018
Posts: 16707
Location: Texas, USA

PostPosted: Sat May 31, 2025 5:40    Post subject: Reply with quote
Thanks for the links. I'm not going to explain why, because I didn't write that wiki. But I will add this to it at some point.
_________________
"Life is but a fleeting moment, a vapor that vanishes quickly; All is vanity"
Contribute To DD-WRT
Pogo - A minimal level of ability is expected and needed...
RSS feed for DD-WRT releases (2025)
RSS feed for DD-WRT releases (2024)
RSS feed for DD-WRT releases (2023)

----------------------
Linux User #377467 counter.li.org / linuxcounter.net
lexridge
DD-WRT Guru


Joined: 07 Jun 2006
Posts: 2152
Location: WV, USA

PostPosted: Sat May 31, 2025 5:51    Post subject: Re: Securely downloading and installing Entware. Why not thi Reply with quote
atomicamp wrote:
Could someone please explain to me why this secure entware tutorial https://github.com/Lanchon/ddwrt-secure-entware is not published in the ddwrt entware wiki?

Possibly because the wiki was written before Entware had https support and has not been updated?

_________________
- Linksys EA8500: I-Gateway, WAP/VAP 5ghz only. Features: VLANs, Samba, WG, Entware - r60xxx
- Linksys EA8500: 802.11s Secondary w/VLAN Trunk over 5ghz - r60xxx
- Linksys MX4300: 802.11s Primary w/VLAN Trunk over 5ghz. 2.4ghz WAP/VAP only - r60xxx
- Linksys MX4300: (WAP/VAP (7)) Multiple VLANs over single trunk port. Entware/Samba r60xxx
- Linksys MR7350: WDS Station for extended Ethernet r60xxx
- Linksys MR7500, MX8500: None in production. Just testing. r60xxx
- OSes: Fedora 40, 10 RPis (2,3,4,5), 23 ESP8266s: Straight from Amiga to Linux in '95, never having owned a Windows PC.
- Forum member #248
Alozaros
DD-WRT Guru


Joined: 16 Nov 2015
Posts: 7068
Location: UK, London, just across the river..

PostPosted: Sat May 31, 2025 6:39    Post subject: Reply with quote
I used that way and.....in a random amount of time and random devices (couse i ve few devices with Entware) updates stopped...and i ve found that the units with normal way of installing/updating...ware fine...so..i abandoned it... it was not linked to curl or anything missing from ddwrt, nor their https not working...just very very random.....you can always use https for the first deploy...but then, yep updates are always via http...and this is always questionable from the security perspective...well same even for https its not a rocket science Razz Razz Cool

in fact Lanchon way is mentioned here...but people are lazy to search, read, do their homework and ect...

https://github.com/Entware/Entware/wiki/Install-on-DD-WRT-firmware

sadly the Entware guys are so bad/inconsistent in updating their packages, as they said they are synchronized with OpenWRT... updates...but sometimes waiting is a too long... Cool

to compile and update on your own
https://github.com/Entware/Entware/wiki/Compile-packages-from-sources

but ive never made it trough Razz Razz

_________________
Atheros
TP-Link WR1043NDv2 -DD-WRT 62606 Gateway/DoT,Forced DNS,Ad-Block,Firewall,x4VLAN,VPN
TP-Link WR1043NDv2 -Gargoyle OS 1.15.x AP,DNS,QoS,Quotas
Qualcomm-Atheros
Netgear XR500 -DD-WRT 63257 GTW/SmDNS/DoT,AD-Blk,Forced DNS,AP&Net Isolation,x2VLAN,Vanilla
Netgear R7800 --DD-WRT 62606 Gateway/DNSCryptv2,AD-Block,Forced DNS,AP&Net Isolation,x3VLAN,Firewall,Vanilla,VPN cli
Netgear R9000 --DD-WRT 62606 Gateway/DoT,AD-Block,AP Isolation,Firewall,Forced DNS,x2VLAN,Vanilla
Dynalink DL-WRX36-DDWRT 62606
Broadcom
Netgear R7000 --DD-WRT 63257 GTW/DNScrypt-proxy2/AD-Block,IPset Firewall,Forced DNS,x4VLAN,VPN cli
NOT USING 5Ghz ANYWHERE
------------------------------------------------------
Stubby DNS over TLS I DNSCrypt v2 by mac913
mwchang
DD-WRT Guru


Joined: 26 Mar 2013
Posts: 1887
Location: Hung Hom, Hong Kong

PostPosted: Sat May 31, 2025 15:41    Post subject: Re: Securely downloading and installing Entware. Why not thi Reply with quote
atomicamp wrote:
I noticed that in the DD-wrt entware installation guides, all of the links for downloading ddwrt are http, not https. This makes it seem like entware is very dangerous to download and install.

The reason is very simple: the Wiki was writtten possibly decade(s) ago, when HTTPS was not yet mainstream due to hardware limitations!! Strong encryption needs good infrastructure! Did we talk about TPM 2.0 back then when Win 11 was not even born? Smile

Don't worry... some websites might auto-magically redirect HTTP to HTTPS. But things might change in the future when HTTPS became mandatory.

_________________
Router: Asus RT-N18U (rev. A1)

Drink, Blink, Stretch! Live long and prosper! May the Force and farces be with you!

Facebook: https://www.facebook.com/changmanwai
Website: https://sites.google.com/site/changmw
SETI@Home profile: http://setiathome.berkeley.edu/view_profile.php?userid=211832
GitHub: https://github.com/changmw/changmw
kernel-panic69
DD-WRT Guru


Joined: 08 May 2018
Posts: 16707
Location: Texas, USA

PostPosted: Sat May 31, 2025 15:45    Post subject: Reply with quote
Okay, I think I know why it wasn't added. The proof is on the forum (not to mention the previously mentioned "official" method link!). When someone is as technically-apt as the OP comes up with something, it may not be properly vetted or correct. Sorry, not sorry. Most tech-savvy people know you can never stop reading or researching and can pick up on clues as to why their key-based authentication ssh is broken that was directly in the information they posted.

Ultimately, all the information *IS* in the Wiki if you click the official Entware links. Still weighing in on catering to laziness.

_________________
"Life is but a fleeting moment, a vapor that vanishes quickly; All is vanity"
Contribute To DD-WRT
Pogo - A minimal level of ability is expected and needed...
RSS feed for DD-WRT releases (2025)
RSS feed for DD-WRT releases (2024)
RSS feed for DD-WRT releases (2023)

----------------------
Linux User #377467 counter.li.org / linuxcounter.net
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> General Questions All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum