Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.
I assume it probably involves a wild guess, but any opinion on how much doing that is apt to add to the cost of a router? Say I buy a new $200 WiFi 7 router today, and next year buy another one but with less EMI/RFI noise. We talking a couple of bucks, 10 bucks, 20, what? If we end up paying 'Made in America' manufacturing prices on top of that, it could add up.

I can't answer if there will be a price increase with stricter testing requirements and the certification testing is all done by third party labs. The FCC does not do any of the testing themselves. And there lies part of the problem as the FCC has to rely on the testing procedures and honesty of those third party labs.

Too many times a manufacturer will produce a EMI/RFI clean device for testing and certification and then cheap out on the actual production models that are EMI/RFI noisy.

Like I said, the average person doesn't realize how much electromagnetic and radio frequency interference is produces by the majority of consumer electronics. And all of that EMI/RFI inside everyone's homes is not good for the human body.

And per FCC regulations and certifications. consumer devices must accept interference but they cannot cause interference.

I don't agree with an outright ban on foreign routers but I do believe that there needs to be stricter certification testing and more oversize of the third party labs conducting the tests.

One would be surprised how noisy everything is in their homes if they used a spectrum analyzer, NanoVNA or even a hand held scanner and checked.

The interference would be easier to see if most people were still watching over the air analog TV.
 
  • Like
Reactions: drrich2
@xraydoc I have had good luck with TP Link products too. They definitely work better than the NetGear and Linksys stuff I used before.

I just upgraded my TP Link AX1800 with a TP Link BE9700. I didn't need to upgrade other than I wanted a router with 2.5 GB ports and WIFI 7

I agree that most people don't need to run Cisco or other commercial grade routers in their homes.

@drrich2 you would be surprised how many people actually need to have open TCP/UDP ports on their home routers. Anyone that plays a lot of PC and console games need certain ports open. There are plenty of other reasons to have ports open besides gaming and amateur radio.

When it comes to running Open-WRT or DD-WRT, most average home users aren't going to go to the trouble of flashing their routers. Plus not all devices are support by Open-WRT and DD-WRT.

My final project/paper for Linux administration class, as part of my network administration degree, was installing DD-WRT onto a links's WRT54G router. The professor was highly impressed that I could make a $50 router have most of the same features as a Cisco router. He ended up flashing his WRT54G routers with DD-WRT.
 
  • Like
Reactions: drrich2
Cisco routers aren't made in the USA either. They are produced in China, Brazil, India, Mexico, and several European locations.

Ubiquiti routers are made in China, Taiwan, and Vietnam.
 
  • Like
Reactions: drrich2
I agree that most people don't need to run Cisco or other commercial grade routers in their homes.
Cisco routers aren't made in the USA either. They are produced in China, Brazil, India, Mexico, and several European locations.

Ubiquiti routers are made in China, Taiwan, and Vietnam.
I'm not terribly excited to potentially replace my TP-Link Deco with an expensive industrial-grade Ubiquiti or Cisco system or something.
Putting aside the 'where it's made' piece for a moment (especially since the government can selectively hand out temporary waivers), I think you're alluding to an important point.

Let's say for whatever reason some new WiFi 8 models come out with compelling features, but due to all this the only one or ones available are 'industrial grade' like Cisco or Ubiquiti. Perhaps the U.S. government considers those more secure?

But is that true, when they are in home use by the masses of unsophisticated 'set it and forget it' home users?

Is a Ubiquiti more secure than a TP-Link inherently, or does it require I.T. Department staff, expertly managing the network that uses Ubiquiti gear to make it so?
 
I don’t think there’s a belief that American-made products will be inherently more secure, but Chinese manufacturers may have added “back doors” that the CCP can activate. Of course, allowing existing products to remain on the market leaves that wide open.

The administration also wants to rebuild America’s manufacturing capabilities. While I fully support that goal, the erosion of America’s industrial capacity has been going on for decades, and I don’t believe it can be simply regulated and executive ordered back into existence overnight.
 
  • Like
Reactions: drrich2
I don’t think there’s a belief that American-made products will be inherently more secure, but Chinese manufacturers may have added “back doors” that the CCP can activate. Of course, allowing existing products to remain on the market leaves that wide open.

The administration also wants to rebuild America’s manufacturing capabilities. While I fully support that goal, the erosion of America’s industrial capacity has been going on for decades, and I don’t believe it can be simply regulated and executive ordered back into existence overnight.

Going back to 2002, the biggest threat to the American defence company I worked for was the American three-letter agencies implanting our kit. We had to take everything to pieces when it arrived and look for modifications.
 
Putting aside the 'where it's made' piece for a moment (especially since the government can selectively hand out temporary waivers), I think you're alluding to an important point.

Let's say for whatever reason some new WiFi 8 models come out with compelling features, but due to all this the only one or ones available are 'industrial grade' like Cisco or Ubiquiti. Perhaps the U.S. government considers those more secure?

But is that true, when they are in home use by the masses of unsophisticated 'set it and forget it' home users?

Is a Ubiquiti more secure than a TP-Link inherently, or does it require I.T. Department staff, expertly managing the network that uses Ubiquiti gear to make it so?

It's been a while since I worked with Cisco routers and my CCNA has expired. CCNA stands for Cisco Certified Network Administrator.

Most commercial/industrial grade routers are not going to be easy to configure for the average home user. I had to take the CCNA certification course which was two semesters long in college. Back then everything was done using a command line interface. Cisco now has a WEB-GUI which makes it easier but one still needs to know what they are doing to set a Cisco router up.

I have never worked with Ubiquiti routers so I can't comment on them.

Commercial/industrial routers are only as secure as the IT department makes them. It is not much different than consumer grade routers.

Even using Open-WRT or DD-WRT on consumer grade routers can be more complicated than the GUI supplied with most home routers.

I don’t think there’s a belief that American-made products will be inherently more secure, but Chinese manufacturers may have added “back doors” that the CCP can activate. Of course, allowing existing products to remain on the market leaves that wide open.

The administration also wants to rebuild America’s manufacturing capabilities. While I fully support that goal, the erosion of America’s industrial capacity has been going on for decades, and I don’t believe it can be simply regulated and executive ordered back into existence overnight.

I agree with you 100%. Again the ban makes no sense on a security basis since current FCC certified routers will remain available to consumers.

I also don't see America's industrial capacities increasing very quickly. A prime example of this is machinists that know how to run manual machines. Running manual machines just isn't taught very much anymore. I'm basically a dinosaur since I learned all on manual machines.
 
Commercial/industrial routers are only as secure as the IT department makes them. It is not much different than consumer grade routers.

Even using Open-WRT or DD-WRT on consumer grade routers can be more complicated than the GUI supplied with most home routers.

Again the ban makes no sense on a security basis since current FCC certified routers will remain available to consumers.
In reverse order:

The ban may be the FCC's way of saying to the router manufacturers: "Do we have your full attention on dealing with security?" I suspect one goal is to cut down the number of router based Bot Nets and the DOS attacks.

It's doubtful that more than a few per cent of home users would be able to set up Open-WR and DD-WRT.

One would hope that the IT departments have a better understanding routers than home users - as Dr. Evil would say "Is that too much to ask?"
 
  • Like
Reactions: drrich2
Will this include mesh radio comms devices? Thinking of LoRa, HaLow, what have you.

(Not that I even understand the words!)

In other words, is it intended to clamp down on decentralized comms before they get really established?
 
Will this include mesh radio comms devices? Thinking of LoRa, HaLow, what have you.

(Not that I even understand the words!)

In other words, is it intended to clamp down on decentralized comms before they get really established?

No it won't include things like Meshtastic and Meshcore. They aren't routers or even network equipment. They are two way communication equipment that can be operated without any internet connection. Yes the range increases with internet connections but its not needed.
 
  • Like
Reactions: polyphenol
The ban may be the FCC's way of saying to the router manufacturers: "Do we have your full attention on dealing with security?" I suspect one goal is to cut down the number of router based Bot Nets and the DOS attacks.

Most DOS attacks come from overseas and don't use routers here in the USA. Yes it does happen but it is not common.

It's doubtful that more than a few per cent of home users would be able to set up Open-WR and DD-WRT.

This is true as most will just follow the simple instructions included in consumer routers. Open-WRT and DD-WRT are for IT techs and computer nerds.

One would hope that the IT departments have a better understanding routers than home users - as Dr. Evil would say "Is that too much to ask?"

Yes one would hope so. IT departments are generally better at networking but simple mistakes that allow hacking does happen.
 
  • Like
Reactions: drrich2
The ban may be the FCC's way of saying to the router manufacturers: "Do we have your full attention on dealing with security?" I suspect one goal is to cut down the number of router based Bot Nets and the DOS attacks.
It's funny that when I came to post some update resources, I spotted this bit you posted. PC Mag. article posted yesterday:

FCC's Router Ban Quietly Places an Expiration Date on Home Internet Security

The subheading: "As it stands, the FCC is only permitting software updates to consumer foreign-made routers until March 1, 2027. The big question is how it'll rule on the issue in the coming months."

It's hard to imagine this won't be rectified, but still, a bit jarring to me. Also from the article: "The Technology Policy Institute, a US think tank, flagged the issue on Friday, writing: “The ban creates the very vulnerability it claims to address.”"

It raises the issue the government might be selective about granting waivers, and mentioned what's been going on with the drone prohibitions: "A communications lawyer also told PCMag that he expects the US to grant exemptions for various new router models that apply, which the Commission has already done in the case of the FCC’s ban on foreign-made drones. For now, only four drone models have been granted conditional approval, and none of them are from China’s popular drone maker DJI."

CNet has a March 29 article: If You Buy a New Router, It Might ‘Turn Into a Pumpkin’ Next Year and from that:
"
  • After speaking with four cybersecurity experts, my advice is to hold off on buying a new router if you can.
  • Under the current rules, banned routers will no longer receive essential security firmware and software updates after March 1, 2027."
This bit caught me by surprise:

"“It’s going to impact many harmless products in order to stem a real problem,” Budington said. “It's also not particularly well-targeted, since routers are only one part of the problem, along with IoT devices.”"

Internet-of-Things devices are an issue? What all are we talking about? All of them, or just a subset? How big of a threat are IoT devices?

P.S.: In a nod to the question posed by the OP, more and more I don't think Apple is likely to re-enter the router market now. They seem to like to enter pre-existing markets (e.g.: music players, phones) with a compelling premium alternative and woo users into their 'walled eco-system.' Right now the router market is so uncertain going forward, and Apple does use a lot of foreign manufacturing, that it's hard to imagine them pushing forward. The Apple Car didn't come out, Apple TV sorta pokes along, people are still anticipating a new Home Pod and the Neo came out recently; Apple doesn't seem to prefer to focus on premium quality rather than myriad hardware products, other than a slicker interface (on a device where most people 'set it and forget it'), I don't see a compelling use case.
 
  • Like
Reactions: polyphenol
PC Magazine article from April 1st - Which Brands Will Be Hardest Hit by FCC's Foreign Router Ban? Here's the List

This article is mainly interesting for the indirect look it gives us at the U.S. (mainly consumer, I assume?) router market.

Some highlights from the article:

"Speedtest.net’s parent, Ookla, examined user-submitted data from January 2025 to last month and has published a list of the top 10 Wi-Fi router vendors for the US."

If we assume users of routers are equally likely to run a speed test with them, that may correlate well. I suspect less sophisticated users are less likely to run speed tests, and maybe more likely to use whatever the ISP included with a package deal. But then I'd expect ISP routers to be over-represented, and that's not what the rest of the article looks like. If you look at their table, it's Eero 10%, TP-Link 9.9% and Netgear 9.6%. Like the author, I'm surprised TP-Link's share wasn't way higher, and he explains why it was expected to be.

But look at the next 2; Arcadyan (8.9%) and Askey (5.1%). I've never heard of either one. But he links Arcadyan through another company to Verizon and Askey is owned by ASUS and supplies WiFi routers to Charter.

And since Internet security is a concern, note the author wrote roughly 28% of speed tests were run from users of WiFi 5 and around 7% WiFi 4 or older.

I suspect speed test usage only roughly correlates with router brand market share, but if it's even in the ballpark, these companies have smaller pieces of the pie than I realized, and ISP-bundled routers tie up shares of the market. I suspect this makes the odds of a new Apple Airport router coming out now even lower.
 
To some degree this law makes sense- perhaps only in spirit. We should be ensuring our network hardware is not being exploited by foreign powers (aka China). This is very similar to Hauwei scandal of years past involving telecom utility hardware. Or the reason why government/national security/critical infrastructure related entities (or anyone accepting federal contracts) are not permitted to buy cctv cameras from Hikvision or Dahua (or any of the zillions of rebranded cameras they make- 80%+ of the market).

I suspect TP-Link will go the way of Huawei in the the U.S, banned. TP-Link follows the typical Chinese playbook of making competitive products and totally undercutting the competition on price. This happened with cctv cameras, solar panels, wind turbine components, drones, TVs, home IoT products, and clearly electric vehicles are the next play.

The FCC policy is a mess though. If non-US routers and switches are an “unacceptable risk”, how is keeping existing routers “acceptable”? Considering most of this hardware is made in China and virtually none in the U.S., I think the government is going to have to be issuing a lot of waivers.

Another problem is even electronics listed as “made in” <Asian country outside China> (Vietnam, Malaysia, Singapore), often are actually made in China but repackaged or rebranded in these other countries. Usually to circumvent tariffs or other restrictions. It’s also a little counterintuitive that this FCC law allows U.S. company can use foreign components and be considered complaint. While US designed and maintained software/firmware probably doesn’t carry the risk of being designed to be exploited by foreign entities, foreign components can be manufactured with malware/vulnerabilities baked in from the factory- China has been caught doing this many times.

It would be nice to have our network hardware be owned by American or at least allied nations- and have their software and hardware cybersecurity standards enforced and monitored with government oversight. It would be good too if the government also mandated companies provide security patches for the reasonable life of the product (i.e. 5+ years). Consumer products all to often do not get the support they should.

We have no supply chain to build domestic network hardware at the scale required and the cost to consumer would be astronomical. It’ll be interesting to see how this plays out but I expect very little to change. Simply taking a bunch of parts from China or an intermediary country and packaging them together in a U.S. factory with U.S. developed software may resolve some of the risks, but it’s not addressing the foreign hardware risks.

Regardless of what happens with this law in the end, I would personally not buy TP-link devices. I have long been suspicious of their products.
 
  • Like
Reactions: mdcmdcmdc
From March 24, 2026 article in Wired:

Everything You Need to Know About the Foreign-Made Router Ban in the US

"TP-Link has repeatedly denied any wrongdoing and claims it has divested from its Chinese roots and is now headquartered in the US with the bulk of manufacturing in Vietnam. TP-Link’s cofounder and CEO, Jeffrey Chao, recently applied for permanent US residency through President Trump’s Gold Card program, according to the Times of India."

TP-Link follows the typical Chinese playbook of making competitive products and totally undercutting the competition on price.
Seems like that's what capitalistic free market competition aided by cheap foreign manufacturing is supposed to do. With the high cost of gas/groceries/living lately it doesn't sound bad. Is anyone alleging that TP-Link is operating at a loss, losing money on product sales?

Regardless of what happens with this law in the end, I would personally not buy TP-link devices. I have long been suspicious of their products.
Suspicious why? Routers are made overseas, overwhelmingly in Asian nations. Theirs are made in Vietnam. I've seen a number of comments online to the tune that TP-Link is 'suspicious,' but when that was checked into (e.g.: the first linked YouTube review in Post #3 of this thread), it didn't add up. Consumer routers as a whole have vulnerability issues, but TP-Link is not an outlier in this regard.

While US designed and maintained software/firmware probably doesn’t carry the risk of being designed to be exploited by foreign entities, foreign components can be manufactured with malware/vulnerabilities baked in from the factory- China has been caught doing this many times.
Are such hypothetical hardware malware/vulnerabilities exclusively a concern with routers, or does this also apply to 'Internet of Things' devices and/or personal computers, etc?
 
  • Like
Reactions: mdcmdcmdc
Some points brought up in the comments under a YouTube influencer video):

1.) Presumably when we use our iPhones as hotspots to provide Internet access to WiFi devices, they in essence become routers. That's off and on, not 24/7.

2.) Seems like foreign hackers might take more interest in corporate and other large entity targets, yet this ban only targets consumer routers.

3.) Internet of Things devices can also download malicious firmware updates.
 
  • Like
Reactions: mdcmdcmdc
'When it rains, it pours' (news, anyway). From PC Magazine April 7, 2026:

Are You Using These TP-Link Routers? Russian Hackers Are Targeting Them

From the article:

"A Russian state-sponsored hacking group has been targeting vulnerable consumer Wi-Fi routers, including 23 TP-Link models, some of which have reached "end of life" status.

The threat involves Fancy Bear, also known as APT 28, a notorious hacking group affiliated with Russian military intelligence. On Tuesday, Microsoft and the UK’s National Cyber Security Centre (NCSC) said the group has been hacking vulnerable routers to manipulate internet traffic and harvest login information.

“Microsoft Threat Intelligence has identified over 200 organizations and 5,000 consumer devices" that have been under attack since at least August, the company warned."

It notes many of those models were released over a decade ago, and that in recent times TP-Link has moved to auto-updating firmware, but that appeared to only apply to newer Archer models. Ironically, the recent ban, if nothing changes, will stop future firmware updates beyond a set date.

---------------

Putting aside TP-Link's misfortune (with old, outdated hardware) at a particularly inopportune time, here's something of interest from the article:

"The US's Justice Department is also calling on users to "Replace End-of-Life and End-of-Support routers.""

This raises multiple issues/questions for consumer router users.

1.) Most users aren't networking or even computing enthusiasts and 'set it and forget it,' and stick with old gear thinking 'if it ain't broke, don't fix it,' if they think about it at all. How many know what firmware is, and how many of those know or care about updating it? How many know about WPA 2 vs. 3 and similar security concerns?

2.) So TP-Link now auto-updates firmware; great! Do Netgear, Amazon's Eero, ASUS, etc.? Should this be mandatory?

3.) How does the average home internet router user know his router is 'end of life' or 'end of support?' Is there a set number of years where routers are supposed to be replaced? Does this vary by brand?

4.) How credible is it to expect the big majority of people to do this? I see online it's recommended to replace our surge protectors every 3-5 years; how many of you do that? How many of us use Macs that are no longer eligible for security updates?

5.) What about 'Internet of Things' devices? I've seen elsewhere some consider them threats not unlike routers, and at least some may be subject to firmware updates that could contain malware. Do we need to be worried about our IoT devices reaching 'end of life' or 'end of support?' Does it matter what that device's function is? I guess if the Chinese Communist Party or the Russians can flip my kid's Alexa-controlled ceiling light on and off they can annoy us...but what about her Echo Show?

6.) What do you think (i.e.: 'how do you feel') about forced obsolescence, making routers automatically stop functioning after a pre-determined interval, or require them to have ongoing authorization from some central authority (e.g.: the FCC) that can 'pull the plug' on models deemed insecure?

7.) Do you foresee anti-virus/anti-malware/security software packages like BitDefender and Norton (a quick Search online shows mention of 'BitDefender Router Protection' and 'NetGear Armor'), stepping up to deal with this? Will it be a separate product? How technically feasible is it for such a product to make an outdated, otherwise unsupported old router safe to us?
 
"TP-Link has repeatedly denied any wrongdoing and claims it has divested from its Chinese roots and is now headquartered in the US with the bulk of manufacturing in Vietnam. TP-Link’s cofounder and CEO, Jeffrey Chao, recently applied for permanent US residency through President Trump’s Gold Card program, according to the Times of India."

Of course they deny any allegations. The Calfornia HQ is TP Link Systems which is an (on paper) an independent subsidiary of TP Link Technologies, HQ in Shenzen, China. TPL Systems is being investigated by the FTC for misleading customers about their restructuring, appearing to be an independent entity from TPL Technologies. TPLS is basically a corporate office with likely <300 employees. TPLT has >10,000 and do all the hardware and software development as well as manufacturing (Vietnam made routers are just assembled there, as I alluded to before). The CEO’s residency is entirely irrelevant.

It should also be said while the U.S. entity falls under U.S. corporate jurisdiction, the Chinese parent falls under Chinese jurisdiction and is subject to laws that mandate private company provide data at the government’s request. The Chinese entity at a minimum over U.S. TP Link, at worst is alleged to still be controlled by TPLT of China. It’s a similar concern to the whole ByteDance-TikTok controversy prior to the Oracle deal.

Suspicious why? Routers are made overseas, overwhelmingly in Asian nations. Theirs are made in Vietnam. I've seen a number of comments online to the tune that TP-Link is 'suspicious,' but when that was checked into (e.g.: the first linked YouTube review in Post #3 of this thread), it didn't add up. Consumer routers as a whole have vulnerability issues, but TP-Link is not an outlier in this regard.

It’s true TP Link is not the only company with vulnerabilities- though they’re often cited as being the worst offender. Sometimes it’s not about malicious software, it’s leaving vulnerabilities- that was the case with Hikvision and Dahua. Because they use Chinese developed firmware and software. That’s typically not the case of American brands with foreign manufacturing.

Seems like that's what capitalistic free market competition aided by cheap foreign manufacturing is supposed to do. With the high cost of gas/groceries/living lately it doesn't sound bad. Is anyone alleging that TP-Link is operating at a loss, losing money on product sales?

It’s not if they’re participating in unfair business practices, such as predatory pricing aka selling products below cost to gain market share and eliminate rivals. TP Link is also under DOJ investigation for this reason, violating antitrust laws. The Chinese government has a long tradition of doing this through direct subsides (ie the solar panel industry) and indirect strategies. Communist countries also have a variety of ways of obscuring corporations financials.

Are such hypothetical hardware malware/vulnerabilities exclusively a concern with routers, or does this also apply to 'Internet of Things' devices and/or personal computers, etc?

Hacked routers tend to cause more problems than hacked client devices considering they can take control of all the traffic on the network. Computers are more likely to have better security measures, but indeed I do think it’s important to ensure the hardware we use is not hosting foreign malware. IoT devices are certainly problem, that’s why people should put them on VLANs and be aware of what they’re buying.
 
Hacked routers tend to cause more problems than hacked client devices considering they can take control of all the traffic on the network. Computers are more likely to have better security measures, but indeed I do think it’s important to ensure the hardware we use is not hosting foreign malware. IoT devices are certainly problem, that’s why people should put them on VLANs and be aware of what they’re buying.
The important difference between a client and a router is that a hacked client device will need to have an active connection through a router in order to respond to commands, whereas a hacked router can be directly accessed from the internet. As you have pointed out, a properly configured router can substantially reduce the hazards of hacked IoT devices.
 
That's for the added info. Interesting.

TPLT has >10,000 and do all the hardware and software development as well as manufacturing (Vietnam made routers are just assembled there, as I alluded to before).
Well, my iPhone, Mac Mini, iPad Pro and possibly my Dell display were all made in China, and 'Made in China' is probably on uncounted products in my home and yard, so while I understand routers are a specific product category with some of its own issues, something being made in China isn't as off-putting for me as it seems for some people.
It’s true TP Link is not the only company with vulnerabilities- though they’re often cited as being the worst offender.
I've seen different views on that, with some indicating they're not worse than the rest. A Feb. 2025 Wired article discussed them, and had this interesting tidbit:

The US Is Considering a TP-Link Router Ban—Should You Worry?

"It’s no secret that US competitor Netgear has been lobbying the US government on “cybersecurity and strategic competition with China.” Netgear has had a tough couple of years after adopting a premium pricing strategy that did not resonate with consumers. It has also been embroiled in litigation against TP-Link for patent infringement, resulting in TP-Link paying a $135 million settlement in September 2024."

Well, well, sounds like Netgear likes to charge more and one might suspect instigates against TP-Link at the government level, even if indirectly?

Even in that article, views on whether TP-Link routers are 'extra-vulnerable' varied.

It’s not if they’re participating in unfair business practices, such as predatory pricing aka selling products below cost to gain market share and eliminate rivals. TP Link is also under DOJ investigation for this reason, violating antitrust laws.
'If.' Has this investigation conclude? Are they selling product below cost?

The Chinese government has a long tradition of doing this through direct subsides (ie the solar panel industry) and indirect strategies.
Considering the push for 'green energy,' the solar panels thing sounds commendable. The U.S. had tax credits for at least some electric vehicles to subsidize and encourage adoption.

Whatever they've done, I don't think it's destroyed competition. I pay modest attention to router reviews, and while TP-Link is often mentioned and lauded, it is hardly unique in that.

Hacked routers tend to cause more problems than hacked client devices considering they can take control of all the traffic on the network. Computers are more likely to have better security measures, but indeed I do think it’s important to ensure the hardware we use is not hosting foreign malware. IoT devices are certainly problem, that’s why people should put them on VLANs and be aware of what they’re buying.
I strongly suspect only a very small minority of consumer router users will use a VLAN; I doubt most know what that is. So in practical reality, not gonna happen anytime soon, if ever. User sophistication is nowhere near that level.

I don't think anybody would argue it's important to ensure the hardware we use isn't hosting foreign malware (presumably including firmware updates), but how ought we to go about that? Seems like some agency or entity with powerful I.T. staffing going over the hardware and software (including firmware) would be the way to go on this.

It should also be said while the U.S. entity falls under U.S. corporate jurisdiction, the Chinese parent falls under Chinese jurisdiction and is subject to laws that mandate private company provide data at the government’s request.
And we know the U.S. government has also done this. I don't recall what all Edward Snowden revealed, but it was concerning. In 2025 it made news the U.K. government tried to make Apple install a 'backdoor' into its encrypted backup service so the government could get at data of British citizens. This thread is in 'Networking' not 'Political News,' so I'm not debating politics, just pointing out that if the Chinese Communist Party's theoretical ability to demand user data from TP-Link is a concern, it seems we have analogous concerns elsewhere...including right here in the U.S.A.

Personally, I'm more concerned about how vulnerable various router brands and models are to ransomware attacks and similar things. That concerns me much more than the Chinese Communist Party's ability to determine I spend too much time on online forums.
 
  • Like
Reactions: JPack
The important difference between a client and a router is that a hacked client device will need to have an active connection through a router in order to respond to commands, whereas a hacked router can be directly accessed from the internet.
Presumably when we're out and about with our smart phones, away from trusted WiFi network access and thus using our cellular data plan to access the Internet, do they not also bring the same security/vulnerability concerns that routers do?

I suspect the typical American home has one router or mesh network, and more than one smartphone.
 
Putting aside TP-Link's misfortune (with old, outdated hardware) at a particularly inopportune time, here's something of interest from the article:

"The US's Justice Department is also calling on users to "Replace End-of-Life and End-of-Support routers.""

This raises multiple issues/questions for consumer router users.

1.) Most users aren't networking or even computing enthusiasts and 'set it and forget it,' and stick with old gear thinking 'if it ain't broke, don't fix it,' if they think about it at all. How many know what firmware is, and how many of those know or care about updating it? How many know about WPA 2 vs. 3 and similar security concerns?

2.) So TP-Link now auto-updates firmware; great! Do Netgear, Amazon's Eero, ASUS, etc.? Should this be mandatory?

3.) How does the average home internet router user know his router is 'end of life' or 'end of support?' Is there a set number of years where routers are supposed to be replaced? Does this vary by brand?

4.) How credible is it to expect the big majority of people to do this? I see online it's recommended to replace our surge protectors every 3-5 years; how many of you do that? How many of us use Macs that are no longer eligible for security updates?

5.) What about 'Internet of Things' devices? I've seen elsewhere some consider them threats not unlike routers, and at least some may be subject to firmware updates that could contain malware. Do we need to be worried about our IoT devices reaching 'end of life' or 'end of support?' Does it matter what that device's function is? I guess if the Chinese Communist Party or the Russians can flip my kid's Alexa-controlled ceiling light on and off they can annoy us...but what about her Echo Show?

6.) What do you think (i.e.: 'how do you feel') about forced obsolescence, making routers automatically stop functioning after a pre-determined interval, or require them to have ongoing authorization from some central authority (e.g.: the FCC) that can 'pull the plug' on models deemed insecure?

7.) Do you foresee anti-virus/anti-malware/security software packages like BitDefender and Norton (a quick Search online shows mention of 'BitDefender Router Protection' and 'NetGear Armor'), stepping up to deal with this? Will it be a separate product? How technically feasible is it for such a product to make an outdated, otherwise unsupported old router safe to us?
If the routers are supplied by an internet provider (e.g. BT in the UK), who is responsible for all aspects of replacing them?

The management which identifies that an old router is in use. The physical supply of a new router. The switchover from the old device to the new. The disposal of the old router.

I think there are many people who would find some of this at the least worrying to get involved with.
 
  • Like
Reactions: drrich2
One of the biggest issues with home routers is that most people will just set and forget. And they never update the firmware or replace the router until it stops working.

Another issue is that those who just remove the router from the box and run it with the default settings also do not change the admin password.

You really need to set a new admin password and also change the WIFI settings from default no matter what brand of router you use.

One good thing about TP Link routers is that the initial setup makes you setup a new admin password. New TP Link routers won't let you finish the initial setup until you type in a new admin password.
 
One of the biggest issues with home routers is that most people will just set and forget. And they never update the firmware or replace the router until it stops working.
So you point to the need to good practices that ought to better secure networks. Let's look at and expand on that.

1.) Router auto-updating firmware is probably a good thing.

2.) Requiring users to create a custom password.

3.) Presumably use an encryption standard like WP3 (I've seen a gadget (? robot vac., maybe?) years ago that supported WP2 not 3; gotta wonder how many Internet-of-Things devices pose such problems).

4.) What makes old routers insecure - is it outdated hardware? Or firmware? How does the home user know? At what point is a router irredeemable?

5.) For most consumers, what is the magnitude of the threat? Are we talking theoretical best practices, or serious danger? For example, I've seen it recommended we replace our surge protectors every 3-5 years, but what % of people do that? On the other hand, having an anti-malware software package on your computer is more common (though I'm told Windows Defender is a lot better than it used to be, and the necessity of separate anti-malware is a bit more debatable - though I like BitDefender). Some people recommend mainstream users use VPNs, but again, what % does that?

In other words, how does the risk of router compromise compare to the multiple other risks most of us routinely ignore? I'm focused on the risk to the individual home user.

Note: a router auto-updating firmware is way more palatable than paying to order and replace multiple surge protectors every 5 years.

P.S.: I guess what I'm getting at here is asking what ought to be done to accomplish what this ban is supposed to do (but many have little confidence in it for), in the context of a largely unsophisticated mainstream user base who won't take initiative.
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.