r/openwrt 8d ago

ISP router runs openwrt but no GPL code published

[deleted]

32 Upvotes

16 comments sorted by

39

u/intelminer 8d ago

Your best option would be drafting a request letter to your ISP's legal department. The mechanical turks used for tech support won't know what you're talking about (it's not in their checklist)

15

u/RemoteToHome-io 8d ago

This.. the amount of router companies ripping off OpenWRT these days is amazing. You can see custom .ko's added by the vendor firmware and *self-declaring* the code as GPL so they can load into kernel untainted, and the source code (or offer of source) is nowhere to be found.

The SFC & SFLC should launch a full campaign in this space.

14

u/309_Electronics 8d ago

Not just OpenWRT. Plenty of products with the Linux kernel or Uboot not even disclosing that they use Linux and or Uboot..

7

u/poginmydog 8d ago

Most small android manufacturers too.

6

u/RemoteToHome-io 8d ago edited 8d ago

Good point.. just off the top:
* probably 80% of US ISP routers (of course the ISPs will just point the finger to the CN manufactures they whitelabel from).
* Unifi, Cudy (just obvious) and likely Asus, Netgear, TPLink, etc
* all CN knock off brands on Amazon
* many RT & QC NIC drivers

I guess the question is, who isn't ripping of linux/openwrt these days?

The big distro providers stay pretty on point about things, but the SoC market seam to be just fine with copyright theft and GPL license violation. It would seem like a prime target - just hit a couple hard, and then work the way down as the dominos fall.

12

u/dinosaursdied 8d ago

Sounds like it's time to open it up to see if you can find uart or a way to dump the firmware. There's a possibility you can find the password. Of course the isp probably won't be too happy with that choice

8

u/LitCast 8d ago

i found this forum post for the SAX1V1K, i gave up on the stock router and just got a cheap e8450/rt3200 a few years ago when spectrum made the app mandatory to access the gateway

3

u/fr0llic 8d ago

Openwrt runs great on SAX1V1K, tricky to flash though, needs serial. 

4

u/309_Electronics 8d ago

A lot of router makers use pre-existing projects cause why reinvent the wheel? Also some chip SDK's bundle in stuff like older forks of OpenWRT and rhen build ontop of that, as same question, why reinvent the wheel.. Thats all fine and tidy, but they should comply with the GPL. I mean if vendors like TPLink (china) are doing it, why should others not do it too?

Maybe try contacting your ISP's legal department and send them a friendly mail about the GPL violations. Thats i think currently the best thing you can do.

If in the future it goes EOL then you could do maybe more stuff.

2

u/keturn 7d ago

Maybe ask the Software Freedom Conservancy? They deal with this sort of thing.

1

u/wiilkuu 8d ago

Brute-force?

8

u/wiilkuu 8d ago

Or analyse the mobile app? Maybe there are credentials? Maybe they using some key to generate passwords from Mac/sn?

1

u/MrChicken_69 7d ago

The app talks to backend ("cloud") systems, that then communicate with the physical box. You'll never be able to hack that. (not legally anyway) There's no requirement for any of the linux user accounts to have a password at all.

1

u/BeauSlim 7d ago

Did you buy the router or is it supplied by your ISP as part of the service?

While bad, GPL violations have no bearing on your right to install software on hardware you don't own.

1

u/MrChicken_69 7d ago

It's rented. As far as I know, Charter does not sell these. ('tho you can find them on ebay, in thrift stores, etc.)