New ASUS router firmware now requires a user to be 16y or older and will restrict features and even security upgrades if you opt out
ASUS rolled out an update to its firmware (3.0.0.6.102_34791) that now requires users to be over the age of 16 and to send a slew of metrics and data back to ASUS. If you do not agree or do not check the box to verify you are 16y or older, you cannot use the router. At this time, I’m not sure if ASUS has meant to disable the router for anyone under 16 or if it’s a bug.
You can opt out at any time but lose access to a slew of features:
Please note that users are required to agree to share their information before using DDNS, Remote Connection
(ASUS Router APP, Lyra APP. AiCloud, AiDisk), AiProtection, Traffic analyzer, Apps analyzer, Adaptive QoS, Game Boost and Web history. At any time, users can search the contents of the terms at this page or stop sharing their information with other parties by choosing Withdraw.
Moreover, ASUS disables automatic firmware updates and worse, all security upgrades unless you opt into the data sharing. Security upgrades perform the following:
Security upgrade incorporates security measures that continuously update its security file and scans to protect against malware, malicious scripts, and emerging threats in order to secure the router and ensure system stability. Some upgrades addressing important security issues or meeting legal/regulatory requirements will still be downloaded and installed automatically, even if "Security Upgrade" is turned off.
Sadly, many ASUS routers use Broadcom chipsets, which has major compatibility issues with openwrt. Notably, Broadcom has refused to allow open source drivers, and OpenWRT only uses open source. So installing any kind of OpenWRT on a Broadcom router will effectively cripple it, because even basic functions like WiFi will be unavailable due to the lack of drivers.
That sucks too because you miss out security fixes. I would rather run a secure and up to date firmware that leaks data to ASUS than one with known security exploits. If those were my only options.
I'd rather update it as well. But the routers are behind my ISP router and aren't externally accessible. The attack surface is smaller in that regard. I'm not happy with the thought of an unpatched router. Maybe I can hold out long enough for merlin to support my routers.
I dont think the latest few updates I did mentioned any security updates. Only bugfixes.
I'll tackle the problem when it presents itself I guess.