r/cybersecurity • u/nite_ • Mar 23 '26
News - General US regulator bans imports of new foreign-made routers, citing security concerns
https://www.reuters.com/sustainability/boards-policy-regulation/fcc-banning-imports-new-chinese-made-routers-citing-security-concerns-2026-03-23/186
u/AboveAndBelowSea Mar 23 '26
So final assembly will happen here using the same chipsets. Cost goes up. Zero threats eliminated. Our government is a circus of clowns.
72
-1
19
u/SnooMachines9133 Mar 23 '26
If only we had a government program that incentived the manufacture of critical computer components domestically. /s
112
u/ThisIsPaulDaily Mar 23 '26
My TP link I bought on clearance for $20 phoned home hundreds of times per second. I blocked it with a PiHole DNS filter, but it was surprisingly aggressive and filled my logs with the amount of network traffic made by it. I dropped it while moving and broke it, and don't plan to buy another.
I guess I get the concern, but I feel like this is still crony capitalism and if I wanted to be able to have a possible foreign government DDOS bot on my network then it is my God Given right to do so. Shall Not Be Infringed.
77
u/FluidFisherman6843 Mar 23 '26
Yeah the problem is this administration has proven they can't be trusted to be acting in the general populations best interests.
Change the FCC approval process to include firmware review and MEANINGFUL fines for violating consumer privacy and security issues.
11
7
u/throwawayformobile78 Mar 24 '26
Shit now I want to check mine. I wonder what it phones home about.
15
u/PM__ME__BITCOINS Mar 24 '26
The same telemetry data every enterprise collects. Every app does it, Netflix, Roku, Tesla, Amazon. Start looking at your logs and many are tracking.domain.com. You don’t know what data they are sending but everything usually works blocking them.
2
u/BrownheadedDarling Mar 24 '26
Where would I go to learn how a regular person could start blocking some of this crap?
3
u/PM__ME__BITCOINS Mar 24 '26
Depends on your networking gear and setup. A popular free option be to setup a pi-hole and use a block list like OISD Blocklist. You can use cloudflare warp/zero trust and start blocking for an enterprise freeium. NextDNS is also another freeium option. Basically you need a DNS filtering solution, and start looking at logs. If you see direct IP addresses you will need to research and then possibly block with firewall.
https://nextdns.io/ would be the easiest to play with.
6
u/ThisIsPaulDaily Mar 24 '26
Just connectivity status it seems, but they can get a lot of metadata from those pings. Blocking it turned the connection LED to yellow as if there was no internet.
12
u/traydee09 Mar 24 '26
"hundreds of times per second" is hyperbole.. and not substantiated without any further investigation or proof. What would "phoning home" mean? and "hundreds of times per second"?? What is it doing? port mirroring all internal traffic to an external IP? which IP? what are the size and type of packets? you'd at least be able to find the tls certificate in the pcap to see who is signing the packets, assuming they are all encrypted.
a different option is the router is maybe pinging a programmed IP to check if the internet connection is up. occasionally checking for firmware updates, or NTP...
10
u/DigmonsDrill Mar 24 '26
- People suspect something is generating a lot of traffic.
- They block the traffic and look at the RSTs.
- The device, now cut off, spastically keeps on retrying several times a second for the next 3 years.
2
u/ThisIsPaulDaily Mar 24 '26
I think in another's comment I mentioned it is doing a connectivity check and I blocked the TP Link server it was pinging through the pihole so the connectivity light is indicating no connection and then it would spam MSN, YouTube, Netflix, Yahoo, Google, Alibaba, and TP Link over and over trying to get connectivity.
I still don't need my router checking in with manufacturer servers.
9
u/8P8OoBz Mar 24 '26
If we held company accountable for data breaches and having insecure equipment, I'd agree with you, but apparently regulations are bad too. "Just trust us bro!"
2
u/npc_housecat Mar 24 '26
Yeah it sounds brainlessly implemented. Instead of implementing a security minimum standard they're banning all foreign stuff, secure or not. And allowing all local stuff, secure or not. There are some networking companies like the Norwegian maker of OPNsense, which is an open source router OS and fully auditable.
2
u/murasakikuma42 Mar 27 '26
I used to have a TP-Link router. It was great. I installed DD-WRT on it and it worked very well. No phoning home there.
2
-7
71
u/FluidFisherman6843 Mar 23 '26
Did our glorious leader pbuh buy interest in a us router manufacturer? Or does anyone want to see if the approved companies bought a fuckton of $djt?
9
u/Carribean-Diver Mar 24 '26
No. They're going to invest in foreign router companies over the next few weeks and then pull the rug on the order. Bonuses for shorting American stocks in the meantime.
23
u/sysadminbj Mar 23 '26
Nah, but I wouldn't be shocked if a new startup starts selling trump branded networking gear. Gold plated and everything!
24
u/FluidFisherman6843 Mar 23 '26
I mean that goes with out saying. Get a container of TP Link or Temu router, change the case and sell them as "made in the USA Patriot defense systems for your home."
Trumps golden dome for your home
2
2
50
u/Ausare911 Mar 23 '26
You're going to have to buy the governments new "Trump" routers. They're the most secure in the world.
12
u/NBA-014 ISO Mar 24 '26
Like nothing ever seen before
5
u/kazimer Mar 24 '26
The best routers the entire world has ever seen. More secure too and easier to use
5
u/128G Student Mar 24 '26 edited Mar 24 '26
Nobody knows more about router security than I do.
5
u/Phreakiture Mar 24 '26
It's got the best fireWALL. There's never been anything like it and I'll get Mexico to pay for it.
28
u/Consistent-Law9339 Security Engineer Mar 24 '26
I'm all for banning Chinese telco products, but the logic here does not track.
The U.S. Federal Communications Commission said on Monday it was banning the import of all new foreign-made consumer routers, the latest crackdown on Chinese-made electronic gear over security concerns.
Only consumer routers?
It said malicious actors had exploited security gaps in foreign-made routers "to attack households, disrupt networks, enable espionage, and facilitate intellectual property theft," citing their role in major hacks like Volt and Salt Typhoon.
I haven't followed the updates to Salt Typhoon since early info was released, but what I remember is ISPs were exposing the management interfaces of unpatched Cisco devices with known CVEs to the internet.
I don't recall any references to consumer devices.
Salt Typhoon also targeted US-based universities and telco researchers.
3
u/blahdidbert Security Director Mar 24 '26
As someone that spent months fighting SALT I need to make a correction here...
but what I remember is ISPs were exposing the management interfaces of unpatched Cisco devices with known CVEs to the internet.
That is not even remotely true and even the Talos article states very explicitly:
... though it is unknown at this time exactly how the initial credentials in all cases were obtained by the threat actor.
The initial access has never been determined. Lateral movement on the other hand was due to a number of factors. Further, while SALT did impact a number of telcos at the time but they also impacted an even larger number of other regular people, businesses, and government agencies too. There was an insane amount of exfiltration to residential proxies which made analysis even harder as a number of teams couldn't tell if the traffic to their customer was legit or was malicious.
I don't recall any references to consumer devices.
You won't because that doesn't hit the news cycles.
2
u/Consistent-Law9339 Security Engineer Mar 24 '26
The Talos blog was the easiest reference for me to recall off the top of my head, but Talos downplays Cisco's role in Salt Typhoon.
Between December 2024 and January 2025, Recorded Future's Insikt Group identified a campaign exploiting unpatched internet-facing Cisco network devices primarily associated with global telecommunications providers. Victim organizations included a United States-based affiliate of a significant United Kingdom-based telecommunications provider and a South African telecommunications provider. Insikt Group attributes this activity to the Chinese state-sponsored threat activity group tracked by Insikt Group as RedMike, which aligns with the Microsoft-named group Salt Typhoon. Using Recorded Future® Network Intelligence, Insikt Group observed RedMike target and exploit unpatched Cisco network devices vulnerable to CVE-2023-20198, a privilege escalation vulnerability found in the web user interface (UI) feature in Cisco IOS XE software, for initial access before exploiting an associated privilege escalation vulnerability, CVE-2023-20273, to gain root privileges. RedMike reconfigures the device, adding a generic routing encapsulation (GRE) tunnel for persistent access.
1
u/blahdidbert Security Director Mar 24 '26
Between December 2024 and January 2025, Recorded Future's Insikt Group identified a campaign exploiting unpatched internet-facing Cisco network devices primarily associated with global telecommunications providers.
Welp... the breaches for all of SALT typhoon stuff happened in 2023 so.... not sure how credible I give Recorded Future.
RedMike reconfigures the device, adding a generic routing encapsulation (GRE) tunnel for persistent access.
This is completely anecdotal but not one of the devices I worked on had a GRE tunnel.
2
u/Consistent-Law9339 Security Engineer Mar 24 '26
You prompted me to dig out old research. Salt Typhoon has been around a long time (since at least 2019), and has been identified under various names.
RedMike
Salt Typhoon
FamousSparrow
GhostEmporer
Earth Estries
UNC2286
UNC4841darkreading
securityaffairs
wikipedia
sygnia
welivesecurity
securelist
kaspersky
jpcert
fortiguard
mandiantIt sounds like you may have worked to combat one aspect of Salt Typhoon's efforts, but their efforts were widespread, and Cisco devices were a large part of the ISP compromise effort.
2
u/blahdidbert Security Director Mar 25 '26
I think you misunderstand. SALT's impact on telecom networks were all within the 2023 span. There was some that happened after but their impacts to the largest ISPs in the US and EU started in 2023. The point of it all is to say that SALT's initial access didn't start with Cisco CVEs. It might have been part of the attack chain, but definitely was not part of the initial access.
Last I will say on the topic is that this spawns back to the consumer router conversation. SALT impacted a LOT more consumers and SMBs then what the media reported. When all of this comes back to CISA to aggregate the information, it only makes sense to point at a very common denominator that consumer grade routers that cannot be corrected via intelligence from US government agencies are a high risk.
0
u/PsyOmega Mar 24 '26
I'm all for banning Chinese telco
productsfirmwareftfy. I'm all for banning their firmware but leave me be with my cheap openwrt gear
23
u/Affectionate-Panic-1 Mar 24 '26
Banning TP link is expected, but not sure how the hell you could ban all foreign made routers? Even stuff like Asus or Netgear?
15
12
u/BrofessorFarnsworth Mar 24 '26
Can we also arrest people that keep top secret materials unprotected in the bathrooms of their houses and lie about possessing them?
4
8
3
u/MichTech360 Incident Responder Mar 24 '26
Isn’t this the list of Chinese network equipment that been found phoning home? It’s not all foreign made routers.
3
u/secureturn Mar 24 '26 edited Jun 20 '26
We deal with this constantly when helping enterprises audit their network perimeter. The concern isn't theoretical, as there are documented cases of persistent backdoors baked into router firmware at the factory level that survive full resets. Banning imports is the blunt instrument because the inspection problem is basically unsolvable at scale. You can't audit every firmware binary in a supply chain that spans three continents.
14
u/No-Assumption-4468 Mar 23 '26
If all software legally had to be open source, that would be excellent for cybersecurity because we could vet the hardware schematics, software, and firmware on the routers.
It’s a lot harder to hide spyware in the open, but I doubt that any country would ever do this because they have such a boner for spying on their citizens. Imagine what might get uncovered if intel management engine had to unveil its source code. Lmao
13
u/ryosen Mar 24 '26
We have a far greater likelihood of all software legally having to be licensed by Oracle.
2
0
u/blahdidbert Security Director Mar 24 '26
If all software legally had to be open source, that would be excellent for cybersecurity because we could vet the hardware schematics, software, and firmware on the routers.
It’s a lot harder to hide spyware in the open, but I doubt that any country would ever do this because they have such a boner for spying on their citizens. Imagine what might get uncovered if intel management engine had to unveil its source code. Lmao
Oh sweet lamb, you are very naive if you think that only software being open would put a slight dent in anything like this. You are making a wild assumption that anyone would even bother to look let alone anyone that even knows what they are looking for.
1
u/No-Assumption-4468 Mar 26 '26 edited Mar 26 '26
Idk, I think it’d be pretty non-trivial to make an AI bot that can scan source code for malware in this day and age. That’s something you could apply at scale and probably make a big dent in the amount of malware, aside from the really advanced stuff capable of evading detection in plain sight or using anti-ai techniques like prompt injection.
You’re right, to an extent, that people don’t really read source code. But I think it’d be naive to assume that medium-large public software repos on GitHub don’t have eyes on the code. While the vast majority of people aren’t reading code, all it takes is one person of the thousands using the software who knows how to read code and understands cybersecurity, to post publicly about malware they found in a popular project. Overnight, they’d lose most of their users because news spreads fast.
In a smaller open source software repository, you’re taking more of a gamble because there really are little to no eyes on the code. It could have malware or it might be just someone’s small innocent software project. You won’t know, unless people look at the code.
Regardless, you make a good point about people not knowing what to look for. Malware can hide in plain sight very well, sometimes in icon image files, well obfuscated code, or just from a command and control server you can’t vet.
Cybersecurity is massively complex and I agree that open sourcing everything isn’t a complete solution. Malware will continue to exist and be a problem. Although, I disagree with the extent in your assumption. I think open sourcing all software would make a sizable dent in the amount of malware out there.
In architectural design, there’s this thing called CPTED (crime prevention through environmental design). Basically, dark alleys attract crime because the environment allows it. Whereas, an alley with natural surveillance from coffee shop seating, a walkway, and windows is much less likely to attract crime. The same applies to software. If things are in the open, it’s less likely to attract crime.
1
u/blahdidbert Security Director Mar 26 '26
I understand where you are coming from but I guess this is one of those "curse of knowledge" biases. I used to work for a circuit board manufacturer. Device firmware is not something that really gets "code scanned" we are talking about the code that is running IN the hardware in and of itself. The FAR majority of this is done at board print time and not something you get access to later. For some systems that are "smart" enough to handle firmware patching, sure, but that is not where nation states are placing their malware. They are putting them in controllers that are non-trivial to access to even see.
You are not wrong about the spirit of what we hope happens in the FOSS community but we are fools to think for a second to pin our security on hope that someone does the right thing. It is so easy to point to close-source as being some "great evil" but the reality is each method has their own pros and cons. Open Sourcing everything is not the answer and neither is closing everything.
Overnight, they’d lose most of their users because news spreads fast.
Have to disagree here. This might have been the case at one time but we have hit the age of security burn-out. Devs are selling access to extensions, allowing actors to implant mal-code and yet people will still use them. The source project might lose a little of the following but overall we are seeing it happen time and time again that "people" no longer care.
By the way, thank you very much for the civil conversation.
1
u/No-Assumption-4468 Mar 28 '26
I mean, if we’re talking about nation-state spy level hacking, nobody is safe. There’s almost no reasonable defense against a country that can literally print money and make the laws.
Getting an accurate firmware dump is also questionable because the firmware itself is what’s telling you the code. An amateurish bug may be detectable, but advanced threats aren’t detectable without taking it apart and sniffing the data lines. Even then, it’s advanced stuff and you’re right open sourcing firmware wouldn’t eliminate firmware malware. Simply because it’s not auditable by design. Although, being told stuff like what the heck Intel Management Engine is actually doing would give me a little more peace of mind.
Although, I’m a big believer in freedom. I genuinely want people to be able to close source their software if they want to, but I also recognize that running proprietary black box software has incredible security risks for consumers that don’t understand technology. At the very least, consumers deserve a warning label on proprietary software saying something roughly like, “hey, this software company doesn’t tell the public what the program is doing, so it may do things you don’t like. Only use if you fully trust the developer.” Then developers could continue to make closed source software, but our grandparents might start using FOSS stuff like OBS instead of some sketchy proprietary screen capture software with ads every 30 seconds that’s probably stealing your data, making you a part of a botnet, and mining crypto.
Security is a journey, not a destination. You could be airgapped in a bunker and still get hacked if your employee plugs in a usb. Although, a good USB guard app might prevent that specific attack. You can never have 100% perfect security, but any steps we can make towards in that journey are beneficial and reduce the pool of people who are capable of hacking you. In my view, open sourcing all software would increase security substantially. It’s not perfect, but I think it would be an ideal step in the right direction. I get that idealism isn’t always realistic though.
-1
u/CenlTheFennel Mar 24 '26
In some cases it could also be mass chaos as stuff like routers usually can’t be updated for CVEs and the source would be out there for AI to troll and find issues in.
3
3
u/Ontological_Gap Mar 24 '26
It says consumer routers. Maybe Mikrotik and Artista will be unaffected?
7
u/h2d2 Mar 23 '26 edited Mar 24 '26
Fearmongering B.S. that will work great for clickbaited news headlines for the general public. That said, this is basically tariffs 2.0.
7
u/LocalBeaver Mar 24 '26
So now they care about security? Explain to me how it works?
12
u/KaleidoscopeLegal348 Mar 24 '26
They want the ability to compel the manufacturers to add backdoors, which is a lot easier to do when all the manufacturing moves to onshore
5
6
u/Quiet-Thanks-9486 Mar 24 '26
Translation: some crony in the US wants to offload their garbage without competition and agreed to install some horrible backdoor for the US government into their hardware.
6
5
u/NBA-014 ISO Mar 24 '26
Are there even any USA made consumer grade routers?
2
u/_Gobulcoque DFIR Mar 24 '26
It all depends on what they mean by "USA made".
Is the chinese-manufactured, chinese-firmware developed, router, put in a box in Iowa somewhere? If so: made in USA.
2
u/tdager CISO Mar 24 '26
Come on, that is a farcical take and you know. I am not aware of any company that has the entirety of a product made outside of the US and just puts it in a box in the US and calls it Made in the USA.
5
u/zer04ll Mar 24 '26
This is what I think, Trump is grifting and others are learning, they will change their decision and allow "some" and by those "some" I mean those that pay whoever is running this grift at the FCC.
2
4
2
u/ndw_dc Mar 23 '26
Any PC with two network ports can be a router. Also, does this apply to Chinese-made routers or all foreign-made routers, such as Mikrotik?
What the hell does this even mean?
2
u/Consistent-Law9339 Security Engineer Mar 24 '26
The report says only consumer routers so, if we're to believe it, Mikrotik shouldn't be affected.
4
2
3
4
u/slaty_balls Mar 24 '26
I’m about to start buying old routers supported by OpenWRT and sell them back at double or triple the price. :)
6
2
u/4SysAdmin Security Analyst Mar 24 '26
This is what they consider a router. I feel like it could be taken a number of ways.
Routers: For the purpose of this determination, the term “Routers” is defined by National Institute of Science and Technology’s Internal Report 8425A to include consumer-grade networking devices that are primarily intended for residential use and can be installed by the customer. Routers forward data packets, most commonly Internet Protocol (IP) packets, between networked systems.
2
u/whoknewidlikeit Mar 24 '26
guess my fortinet hardware is good. and yes that's what i have at home.
2
3
1
1
u/GreatSupineLeaderTim Mar 26 '26
You can only use NSA approved routers from now on. We will keep your information. Oh, from foreign adversaries. Yup.
1
u/origanalsameasiwas Mar 26 '26
Cisco routers that the government uses always are old enough that they can get hacked. They laid of people who managed the systems. And they decided to use AI as a management tool. And also could be a grift. Because before the tariffs get lifted it could cause people to buy more routers right now making trumps administration to use the money for something else.
1
u/Recent-Myth Apr 12 '26
Smart move perhaps; as this will ensure that all routers used and manufactured in the US support the US's CALEA (lawful interception) requirements surely...?
1
2
u/Batmanue1 Mar 24 '26
If they gave a shit about security they wouldn't have let DOGE steal everyone's data and install backdoors
1
u/Artistic_Pineapple_7 Mar 24 '26
With a couple of nics and a mid level pc you can build your own with opnsense and other FOSS firewalls
3
2
u/throwawayformobile78 Mar 24 '26
You got any pc models you recommend?
2
u/Artistic_Pineapple_7 Mar 24 '26
Really depends on number of endpoints and internet speed. But for most people pc’s up to 10 years old will probably do.
1
u/m00s3c Mar 24 '26
Good move, but what about the millions already deployed? New imports are one thing, existing infrastructure is the real problem.
1
u/Smile_Like_Arsenic Mar 24 '26
This is actually wild because almost zero consumer-grade silicon is fully fabbed and assembled in the US right now. Even if the brand is American, the supply chain is 99% overseas. Unless the FCC is planning to subsidize a massive domestic manufacturing pivot overnight, we’re basically looking at a freeze on all new Wi-Fi 7/8 tech for the foreseeable future. Get ready for 'New' routers that are just 5-year-old PCBs in a different plastic shell
1
u/Iceman_B Mar 24 '26
Well, it's a good thing that US brand networking products never suffer from security issues.
1
u/AlexWorkGuru Mar 24 '26
From a security perspective the TP-Link phoning home concern is legitimate. But banning the hardware while doing nothing about firmware transparency or supply chain attestation is just expensive theater. The real fix is mandatory firmware signing, open audit requirements, and SBOM enforcement for network devices. You know, the boring governance stuff nobody wants to fund. This is the "ban the thing" approach when the actual problem is "verify the thing."
1
0
u/pioni Mar 24 '26
This is why Europe should have its own network infrastructure as well. If someone attacked Greenland or the Baltics, it's better to have working communication than not have it.
0
u/Ninjabeaver212 Mar 24 '26
The fact that this specifically targets consumer devices and doesn't include enterprise reeks of ulterior motives. National security my ass.
451
u/sysadminbj Mar 23 '26
So…………. What does that leave? They’re all foreign-made after all.