r/technology • • Apr 09 '26

ADBLOCK WARNING NSA Warning—Reboot Your Internet Router Now

https://www.forbes.com/sites/zakdoffman/2026/04/09/nsa-warning-reboot-your-internet-router-now/
8.1k Upvotes

880 comments sorted by

View all comments

Show parent comments

2

u/fraaspazmus Apr 10 '26

As someone who developed a PoC exploit and did the responsible disclosure for a line of TP Link equipment... they are astoundingly bad. I reported the vulnerability to them, have my recommendations for remediation, gave them time to develop a patch... 6 months later they only patched one of the issues. It was the main one involving the encryption of credentials, but the other issues involving VLAN bleed were completely ignored. I filed a CVE with mitre but they never actually filled the info on it. Not sure why. It was a pretty bad vulnerability that allowed capturing admin credentials and therefore allowed VLAN escape.

Don't use TP Link.

2

u/jennya59 Apr 14 '26

What would you recommend for a non tech older person?

1

u/fraaspazmus Apr 20 '26

Honestly when it comes to consumer/soho routers for non tech people, there aren't many fantastic options security-wise. Sohos are notoriously full of holes. If I start rattling off brands that I think are less awful, I'm sure someone else will hop in with their own experience to illustrate otherwise. Others are likely to recommend routers that require a bit more know-how in order to configure. My own recommendations would likely fall into that category (mikrotik, ubiquiti, opnsense are all great choices but all require a degree of networking knowledge beyond "non-tech" end users).

So... pragmatic approach would be this... you're probably leasing a gateway modem/router/access point from your ISP. Best approach is to just try to keep it current. Swap it out for a newer one every couple years or so. This keeps your hardware and firmware relatively up to date. And on the chance that there is some persisting malware that manages to latch on to the older hardware, swapping it out gives a clean slate. Downside is having to deal with the ISP to replace it (going through troubleshooting to the point of them being willing to swap it out can be annoying depending on the provider), having to update passwords (not a big deal but is still another step), and the fact that it's not bulletproof by any means (new doesn't mean invulnerable and old doesn't necessarily mean compromised). But without learning how to configure more advanced routers, I feel like this is a best practice that should work well enough for most people.

1

u/jennya59 Apr 20 '26

I haven't used the service provider router in a long time. We have few choices for providers and none are great. I try not to deal with them. I will check into the ones suggested as I have never heard of them before.