# Freedombox's Ethernet card resistant to soft-bricking?

**URL:** https://discuss.freedombox.org/t/freedomboxs-ethernet-card-resistant-to-soft-bricking/382
**Category:** Support
**Created:** [September 15, 2019, 1:59pm UTC](https://discuss.freedombox.org/t/freedomboxs-ethernet-card-resistant-to-soft-bricking/382 "2019-09-15T13:59:11Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![tebin](https://discuss.freedombox.org/letter_avatar_proxy/v4/letter/t/b3f665/32.png) [@tebin](https://discuss.freedombox.org/u/tebin)
#### Post date: [September 15, 2019, 1:59pm UTC](https://discuss.freedombox.org/t/freedomboxs-ethernet-card-resistant-to-soft-bricking/382/1 "2019-09-15T13:59:12Z")

</div>

It’s theoretical, I’m looking to istall/get Freedombox (on BeagleBone or some Olimex board, or maybe Freedombox Pioneer, IOW preferably fully free hardware).

The case is theoretical, because hard data would deanonymize me, but ethercards/routers get soft-bricked, I had a few cases myself.

What protection there is against soft-bricking? I wouldn’t mind going through very careful and lengthy preparation once I build/buy my Freedombox.

I can tell for one thing that good iptables/nftables is way safer than without (see e.g. [https://trac.torproject.org/projects/tor/wiki/doc/BlockingNonTorTraffic](https://trac.torproject.org/projects/tor/wiki/doc/BlockingNonTorTraffic) ).

But there is also the hardware level… How safe will it be at that level?

But if the router is say only [http://192.168.x.x](http://192.168.x.x) (no https), and the provider is less than friendly, to put it very mildly, what protection there is for the ethernet card of the Freedombox --say in Freedombox Pioneer, i.e. Olimex Lime2 board-- against soft-bricking…

Bottom line: can I install/buy a Freedombox and not get soft-bricked pretty soon, in case of, as put (too) mildly above, adverse conditions?

Thanks in advance!

---

<div class="post-metadata">

### Author: ![Sunil](https://discuss.freedombox.org/user_avatar/discuss.freedombox.org/sunil/32/8_2.png) [@Sunil](https://discuss.freedombox.org/u/Sunil)
#### Post date: [September 17, 2019, 8:47pm UTC](https://discuss.freedombox.org/t/freedomboxs-ethernet-card-resistant-to-soft-bricking/382/2 "2019-09-17T20:47:36Z")

</div>

The Olimex’s Lime2 is powered by Allwinner A20 chipset. As far as I know, there is only small piece of software in the Chip known as BROM which is read-only. The Ethernet MAC address are write-once fuses. Rest of the software including the firmware (u-boot) resides on the SD card. If the software gets corrupted or turns malicious, all you need to do is get a new SD card. That way, the hardware is unbrickable.

Or perhaps you are referring to firmware within the Ethernet hardware of A20 chip that I know nothing of.

As for incoming traffic, we have firewalld installed and managed automatically by FreedomBox. It uses nftables as backend.

---

<div class="post-metadata">

### Author: ![tebin](https://discuss.freedombox.org/letter_avatar_proxy/v4/letter/t/b3f665/32.png) [@tebin](https://discuss.freedombox.org/u/tebin)
#### Post date: [September 26, 2019, 9:44am UTC](https://discuss.freedombox.org/t/freedomboxs-ethernet-card-resistant-to-soft-bricking/382/3 "2019-09-26T09:44:18Z")

</div>

> [@Sunil](#):
>
> Or perhaps you are referring to firmware within the Ethernet hardware of A20 chip that I know nothing of.

I do. It’s a complex issue where spears break… However, I hope it could be repairable, by refleshing the firmware, should it happen, and I do count on help on this forum, should it happen, because I very much like the whole concept and implementation of Freedombox, and I will get it…  
Thanks for your reply!

---

<div class="post-metadata">

### Author: ![Sunil](https://discuss.freedombox.org/user_avatar/discuss.freedombox.org/sunil/32/8_2.png) [@Sunil](https://discuss.freedombox.org/u/Sunil)
#### Post date: [September 26, 2019, 6:43pm UTC](https://discuss.freedombox.org/t/freedomboxs-ethernet-card-resistant-to-soft-bricking/382/4 "2019-09-26T18:43:35Z")

</div>

It might be worth trying to ask this question to Olimex on their [forum](https://www.olimex.com/forum/). They might known if Ethernet firmware on the A20 chip is modifiable and if bricked, who to reflash it.
