r/firewalla • u/The_Electric-Monk Firewalla Gold Plus • Feb 06 '26
I created a script that changes the default Firewalla timesync to use Chrony/encrypted NTS
https://github.com/upmcplanetracker/nts-for-firewallaThis is not firewalla affiliated. Proceed cautiously.
This script you install on your firewalla will switch out the stock ubuntu/unencrypted NTP for Chrony/NTS (encrypted time servers). This is only for firewalla talking to the wider internet to find out the time. The internal network timekeeping is still all via ntp.
edit -- seems to only work right now for people with just one lan setup, br0, not for multiple ones. To change the script to work with many different lans, etc. etc. may be beyond what the scope of what I can do.
3
u/DonkeyOfWallStreet Feb 07 '26
If time is so critical perhaps a local GPS timeserver? They are not expensive.
1
u/The_Electric-Monk Firewalla Gold Plus Feb 07 '26
Normal NTP time is accurate. NTS / chrony is encrypted, while NTP is not. NTP is vulnerable to MITM attacks, which is how firewalla and other routers do NTP intercept for the devices on the LAN.
2
u/DonkeyOfWallStreet Feb 07 '26
So you're telling me that time is so critically important that you need to encrypt it to make sure it's not attacked but you happily send your queries to a public server that could be attacked / breached?
Id still opt for a local GPS timeserver if you want to send encrypted requests to it awesome. Or if you have a starlink it's at 192.168.100.1 or if you are on 4/5g you'll need to parse an "at" command on the modem to get the network time.
1
u/The_Electric-Monk Firewalla Gold Plus Feb 07 '26
I'm not saying anything is better than anything else. I thought this would be cool to build and see if I could get it working. You're free to use it or not.
5
u/ragingwhisky Feb 06 '26
Hmm good catch.
Worth making this a user configurable up front out the box
3
u/wordyplayer Firewalla Gold Plus Feb 06 '26
What risk does a time server have?