<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <p>Fellow developers-</p>
    <p>I wanted to follow up on this topic, as it pertains to anyone
      considering using OpenWRT/LEDE on Ubiquiti wireless gear (I can't
      speak to the EdgeRouter, etc. devices).</p>
    <p>I have been speaking with one of the executives at Ubiquiti, and
      he disclosed that they have been feeling pressured by the FCC to
      deal with the perceived issue of firmware being able to alter the
      RF characteristics of the hardware, particularly in the 5 GHz.
      band. He pointed to this note from the FCC as evidence: <a
href="https://assets.documentcloud.org/documents/2339685/fcc-software-security-requirements.pdf">https://assets.documentcloud.org/documents/2339685/fcc-software-security-requirements.pdf</a></p>
    <p>This is an interesting document - I really don't understand what
      legal standing it has - wasn't this the proposal that set us all
      to the web last year to try to make the FCC be sensible? In its
      First Review and Order of July 13 (<a
        class="moz-txt-link-freetext"
        href="https://apps.fcc.gov/edocs_public/attachmatch/FCC-17-93A1.pdf">https://apps.fcc.gov/edocs_public/attachmatch/FCC-17-93A1.pdf</a>)
      the FCC specifically mention in the footnotes that they are NOT
      addressing "...provisions to prevent the unauthorized modification
      of the software and firmware that ensure that and RF device
      complies with FCC rules that prevent harmful interference..."</p>
    <p>So it appears, at this point, that the FCC's position is that the
      replacement of firmware on devices is perfectly legal, but, to
      have a U-NII (5 GHz) device authorized in the U.S., it must have
      its firmware locked so it cannot be modified.<br>
    </p>
    <p>Whatever the legality is, the folks at Ubiquiti have made the
      decision to lock the bootloader on all their models so that
      firmware that is not specifically "signed" by Ubiquiti cannot be
      flashed on to their products. Models with locked bootloaders are
      just being introduced now - my last batch of Loco M2 units (note
      that these are 2.4 GHz. radios) were very odd: on units running
      AirOS 5.6.12 (as they shipped) I could load LEDE via the Web UI,
      but I could not load it using tftp. I updated some units to AirOS
      6.0.6 and could not load LEDE at all via any method. Even
      connecting to the serial port did not help - the console stops
      when the firmware starts booting.</p>
    <p>The bottom line is this: effective in the very near future, we
      will not be able to load OpenWRT/LEDE on to Ubiquiti wireless
      gear, unless I'm missing something here.</p>
    <p>And we should expect every vendor to follow suit.</p>
    <p>This represents an interesting problem for getting commercial
      vendors to adopt and support OpenWRT/LEDE - if Ubiquiti is
      interpreting the FCC's notes correctly, any company that wants to
      use OpenWRT/LEDE will have to sign the images so they cannot be
      modified. This seems to contradict the real value of OpenWRT/LEDE
      - and how would that even work with opkg, etc?).</p>
    <p>I wanted to report what I have found to this group and see if
      anyone has any brilliant ideas. I haven't any at the moment.<br>
    </p>
    <p>Thanks,</p>
    <p>Bill<br>
    </p>
    <p><br>
    </p>
    <br>
    <div class="moz-cite-prefix">On 08/14/2017 10:46 AM, Adrian Draus
      wrote:<br>
    </div>
    <blockquote type="cite"
      cite="mid:topic%2F5760%2F23771@forum.lede-project.org">
      <div>
        <table style="margin-bottom:25px;" border="0" cellspacing="0"
          cellpadding="0">
          <tbody>
            <tr>
              <td>
                <table border="0" cellspacing="0" cellpadding="0">
                  <tbody>
                    <tr>
                      <td style="vertical-align:top;width:55px;"> <img
src="http://forum.lede-project.org/letter_avatar/r43k3n/45/5_e919f74e387e99c6ab048078e2669f9f.png"
                          title="r43k3n" moz-do-not-send="true"
                          height="45" width="45"> </td>
                      <td> <a
                          href="http://forum.lede-project.org/users/r43k3n"
                          target="_blank" style="text-decoration: none;
                          font-weight: bold; color: #006699;;
                          font-size:13px;font-family:'lucida
grande',tahoma,verdana,arial,sans-serif;color:#3b5998;text-decoration:none;font-weight:bold"
                          moz-do-not-send="true">r43k3n</a> <a
                          href="http://forum.lede-project.org/users/r43k3n"
                          target="_blank" style="text-decoration: none;
                          font-weight: bold; color: #006699;;
                          font-size:13px;font-family:'lucida
grande',tahoma,verdana,arial,sans-serif;text-decoration:none;margin-left:7px;color:
                          #3b5998;font-weight:normal;"
                          moz-do-not-send="true">Adrian Draus</a> <br>
                        <span
style="text-align:right;color:#999999;padding-right:5px;font-family:'lucida
grande',tahoma,verdana,arial,sans-serif;font-size:11px">August 14</span>
                      </td>
                    </tr>
                  </tbody>
                </table>
              </td>
            </tr>
            <tr>
              <td style="padding-top:5px;" colspan="2">
                <p style="margin-top:0; border: 0;">Ubiquiti still
                  refuses to release images for complete system recovery
                  for EdgeRouter devices. So when your EdgeOS firmware
                  gets corrupted beyond repair and your out of warranty
                  then the only course of action is to install LEDE. No
                  official restoration procedure for EdgeOS is
                  available.</p>
                <p style="margin-top:0; border: 0;">That is not
                  understandable for me since most TP-Link devices and
                  Netgear units too have a way to restore the entire
                  firmware using TFTP.</p>
              </td>
            </tr>
          </tbody>
        </table>
        <div style="color:#666;">
          <hr style="background-color: #ddd; height: 1px; border: 1px;;
            background-color: #ddd; height: 1px; border: 1px;">
          <p><a
              href="http://forum.lede-project.org/t/new-ubiquiti-loco-m2-xw/5760/5"
              style="text-decoration: none; font-weight: bold; color:
              #006699;; background-color: #006699; color:#ffffff;
              border-top: 4px solid #006699; border-right: 6px solid
              #006699; border-bottom: 4px solid #006699; border-left:
              6px solid #006699; display: inline-block;"
              moz-do-not-send="true">Visit Topic</a> or reply to this
            email to respond.</p>
        </div>
        <hr style="background-color: #ddd; height: 1px; border: 1px;;
          background-color: #ddd; height: 1px; border: 1px;">
        <h4 style="color: #222;; font-size: 17px; color: #444;
          margin-bottom:10px;">In Reply To</h4>
        <table style="margin-bottom:25px;" border="0" cellspacing="0"
          cellpadding="0">
          <tbody>
            <tr>
              <td>
                <table border="0" cellspacing="0" cellpadding="0">
                  <tbody>
                    <tr>
                      <td style="vertical-align:top;width:55px;"> <img
src="http://forum.lede-project.org/user_avatar/forum.lede-project.org/bmoffitt/45/161_1.png"
                          title="bmoffitt" moz-do-not-send="true"
                          height="45" width="45"> </td>
                      <td> <a
                          href="http://forum.lede-project.org/users/bmoffitt"
                          target="_blank" style="text-decoration: none;
                          font-weight: bold; color: #006699;;
                          font-size:13px;font-family:'lucida
grande',tahoma,verdana,arial,sans-serif;color:#3b5998;text-decoration:none;font-weight:bold"
                          moz-do-not-send="true">bmoffitt</a> <a
                          href="http://forum.lede-project.org/users/bmoffitt"
                          target="_blank" style="text-decoration: none;
                          font-weight: bold; color: #006699;;
                          font-size:13px;font-family:'lucida
grande',tahoma,verdana,arial,sans-serif;text-decoration:none;margin-left:7px;color:
                          #3b5998;font-weight:normal;"
                          moz-do-not-send="true">Bill Moffitt</a> <br>
                        <span
style="text-align:right;color:#999999;padding-right:5px;font-family:'lucida
grande',tahoma,verdana,arial,sans-serif;font-size:11px">August 14</span>
                      </td>
                    </tr>
                  </tbody>
                </table>
              </td>
            </tr>
            <tr>
              <td style="padding-top:5px;" colspan="2">Yes, they are not
                being very friendly towards us...</td>
            </tr>
          </tbody>
        </table>
        <div style="color:#666;">
          <hr style="background-color: #ddd; height: 1px; border: 1px;;
            background-color: #ddd; height: 1px; border: 1px;">
          <p><a
              href="http://forum.lede-project.org/t/new-ubiquiti-loco-m2-xw/5760/5"
              style="text-decoration: none; font-weight: bold; color:
              #006699;; color:#666;" moz-do-not-send="true">Visit Topic</a>
            or reply to this email to respond.</p>
        </div>
        <div style="color:#666;">
          <p>To unsubscribe from these emails, <a
href="http://forum.lede-project.org/email/unsubscribe/d77905e615393f4ac90fda533896470e252bc1a7f50554875dac5763ab8e4293"
              style="text-decoration: none; font-weight: bold; color:
              #006699;; color:#666;" moz-do-not-send="true">click here</a>.</p>
        </div>
      </div>
      <div itemscope="" itemtype="http://schema.org/EmailMessage"
        style="display:none">
        <div itemprop="action" itemscope=""
          itemtype="http://schema.org/ViewAction">
          <link itemprop="url"
            href="http://forum.lede-project.org/t/new-ubiquiti-loco-m2-xw/5760/5">
          <meta itemprop="name" content="Read full topic">
        </div>
      </div>
    </blockquote>
    <br>
  </body>
</html>