HI version is available. Content is displayed in original English for accuracy.
Advertisement
Advertisement
⚡ Community Insights
Discussion Sentiment
86% Positive
Analyzed from 718 words in the discussion.
Trending Topics
#router#security#devices#isp#consumer#nextdns#software#probably#wifi#again

Discussion (3 Comments)Read Original on HackerNews
Anyway. Routers are such juicy targets, especially since there's less eyes on them than on laptops/desktops, that it's hard to believe there are any which aren't backdoored, be it by China, US, US' middle eastern sidekick, whatever. My question would be: how limited are they to software, like in the article?
You can flash with OpenWRT and Fritz, but to my knowledge it doesn't replace the boot parts. A suspicious bootloader in SPI flash probably isn't difficult to produce, even if it would likely be discovered... eventually. A separate modem / radio processor would be an even bigger nightmare, esp if it's an 5g router - you essentially add a second computer to your router, with its own components and network access, and I think you can't even play around LTE/5g networking as freely as with wifi without bending some laws.
Theoretically you could watch the router from, well, outside the router. But as the article says, it can be difficult to say what's an actual connection and what's uploading your network's data to an uninvited third party. I'm also wholly ignorant what implications it has for things like Wireguard and Tailscale. I assume you're completely pwned if the Wireguard runs on the router, but I don't think it does anything if it runs on your laptop or whatever? Then again, there's a lot more devices in peoples' homes nowadays, and almost all the IoT has pretty much zero security.
I suppose AI will help with some of those things. Tracking every connection made is very tedious for a human, but throw some compute at it and you'll get a much better insight, especially since you'll probably know what to expect out of your machines.
I guess using a mini PC as a router-slash-proxmox-hub would be a safer choice? There's probably many fingers in this pie as well, but my gut feeling is that it's a lot safer than some cheapo box provided by your ISP at the cheapest price they could source them.
About two years ago, I signed up for NextDNS, which is a fantastic managed 3rd-party DNS service. NextDNS is capable of "PiHole" style ad blocking, as well as filtering adult content and basic security hygiene. They do have a functional free tier to try it out. As a bonus, you also get excellent logging capability, and these logs are stored on NextDNS's servers.
So, at the time, I had a consumer-grade router, and a few devices on the home LAN, and they were all configured to query NextDNS directly. And this was working so smoothly. Well, one night I went to see a horror film with friends, and when I arrived home, I found very disturbing entries in the logs. The DNS logs were clogged with cryptic, inexplicable entries that pointed to only one conclusion: my router was compromised, and had joined some kind of botnet.
I checked my Windows machine, and my smartphone, and other devices, which were all clean, and the router was the only pwned device. I identified 1 or 2 CVEs which may have allowed unauthorized entry to the router's admin interface. I yanked it out of the network and took a Dremel to its innards. I also discovered that my obsolete router's installation of OpenWRT was compromised. Dremel time again.
After several rounds, around and around with my ISP about their duties and ability to provide reliable WiFi service, I again purchased a consumer-grade WiFi router, this time from Netgear. Now in 2026, there is no "antimalware software" for consumer routers. These router admin interfaces have no visibility for the admin to see running tasks or processes, or determine whether there is malware payload installed or running, or listening on external ports. No way to tell. There is indeed "security software" sold, even by annual subscription, but this software simply does some lame port scans of your LAN. That's right, it's scanning all devices except for itself and expects to point fingers at your other hardware for security issues! That is deflecting blame.
Sadly, having discontinued my NextDNS subscription and therefore the logging facility, I again have no visibility into my WiFi router (nor the ISP router running in Bridge Mode now.) I would not know if they are compromised, but they probably are. Yours are, too. It is nearly certain that most people, having a residential IP with good reputation, has a residential proxy Trojan running on it currently, and is a member of at least one DDoS botnet, and you have absolutely no way of telling. Your ISP does not care; your ISP will not scan or detect it proactively, and if they receive any complaints, they would not tell you so.
It is very sad, in 2026, that a supposedly "loyal" company as Netgear should have such atrocious security. No visibility, no detection, no logging, just finger-pointing. They should all be ashamed of themselves. ISPs should have some mechanism to seek out botnet members, residential proxy providers, and shut down those malicious, wasteful, fraudulent connections, and restore some sanity to metropolitan networks and backbones.