Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.
One of the biggest issues with home routers is that most people will just set and forget. And they never update the firmware or replace the router until it stops working.

Another issue is that those who just remove the router from the box and run it with the default settings also do not change the admin password.

You really need to set a new admin password and also change the WIFI settings from default no matter what brand of router you use.

One good thing about TP Link routers is that the initial setup makes you setup a new admin password. New TP Link routers won't let you finish the initial setup until you type in a new admin password.

Newest numbers I've seen is 71% of home use the ISP-supplied router, and for most modern store-bought routers, they auto-update even if you never do anything except plug them.

Non-updated routers is still a problem, but it seems to be declining.
 
  • Like
Reactions: drrich2
In other words, how does the risk of router compromise compare to the multiple other risks most of us routinely ignore? I'm focused on the risk to the individual home user.
There is a greater risk with routers compared to ll other devices since all other devices have to connect to the internet through the router.

I know that I have my router set to auto update the firmware. But I also have a degree in network administrations so I know to secure my devices.

One issue is the most manufacturers only support devices for so many years before there are no longer any firmware/security updates.

JaysTwoCents does a good job of explaining the router ban. Here is the link to the video he did on the subject.

Explaining the US Router Ban and what it means for consumers

The router ban was not very well thought out on the government's part say the least.
 
  • Like
Reactions: drrich2
Newest numbers I've seen is 71% of home use the ISP-supplied router, and for most modern store-bought routers, they auto-update even if you never do anything except plug them.

Non-updated routers is still a problem, but it seems to be declining.

Yes newer routers are better.

But how many people are still using old outdated and insecure routers since they are still working? I can tell you that there is a good number of outdated routers that are no longer getting updates till in use.
 
Yes newer routers are better.

But how many people are still using old outdated and insecure routers since they are still working? I can tell you that there is a good number of outdated routers that are no longer getting updates till in use.

Some, sure.. but not the ISP supplied ones...well hopefully.
 
Last edited:
One issue is the most manufacturers only support devices for so many years before there are no longer any firmware/security updates.
This issue raises a question that also pertains to Apple releasing security updates for Macs for a limited number of years; is this a limitation based on the practical limits of the hardware (e.g.: that hardware from a decade ago can't be made secure against one or more new threats, doesn't support WPA 3, etc.), or is it simply companies don't want to shoulder the R&D costs of maintaining security on very old product when they'd rather sell us a new one?

And while it's not something the mainstream masses will do, does installing open source router firmware like Open WRT or DD-WRT on old routers solve this problem?

If it does, then the question becomes why can't the router companies likewise do so with their proprietary firmware?

If not, how do Open WRT and DD-WRT users know their old routers are too insecure?
 
This issue raises a question that also pertains to Apple releasing security updates for Macs for a limited number of years; is this a limitation based on the practical limits of the hardware (e.g.: that hardware from a decade ago can't be made secure against one or more new threats, doesn't support WPA 3, etc.), or is it simply companies don't want to shoulder the R&D costs of maintaining security on very old product when they'd rather sell us a new one?

And while it's not something the mainstream masses will do, does installing open source router firmware like Open WRT or DD-WRT on old routers solve this problem?

If it does, then the question becomes why can't the router companies likewise do so with their proprietary firmware?

If not, how do Open WRT and DD-WRT users know their old routers are too insecure?

Open source firmware and software will always get more updates and longer support since it is a community effort. It's been quite a while since I have used DD-WRT or Open-WRT since not all routers will work with either firmware.

Even open source will have a finite time when it comes to support for older routers. But it is usually longer than OEM firmware.

Most people that use DD-WRT or Open-WRT are above the average home user and will keep an eye on updates and if/when older routers are no longer supported. DD-WRT and Open-WRT are for the IT people and computer nerds.

The average home user is going to set and forget about their router until it stops working.
 
  • Like
Reactions: drrich2
Some, sure.. but not the ISP supplied ones...well hopefully.

ISP's are getting better about setting auto update as default now days. That use to not be the case though.

I use to have AT&T DSL with their modem/router and I would have to manually check for updates myself. But that has been close to 10 years ago since I have used DSL.
 
What routers are made in the US? If there are any, they probably contain foreign components. Seems like a step back to the stone age. 🤡😂

Are you all going to go to Canada to buy routers? And if you do, will you get detained by importing it into the US?
 
Open source firmware and software will always get more updates and longer support since it is a community effort. It's been quite a while since I have used DD-WRT or Open-WRT since not all routers will work with either firmware.

Even open source will have a finite time when it comes to support for older routers. But it is usually longer than OEM firmware.
Your post reminded me of a question. The open source 'community' includes a lot of non-U.S. people. So that brings the question...the U.S. ban on consumer routers manufactured outside the U.S., and limitation on firmware updates (currently forbidden past a date in 2027)...can the U.S. government effectively block users of open source router firmware like Open WRT and DD-WRT from updating their firmware?

Let's indulge in a little paranoia (or maybe it's not? Remember Edward Snowden) for a moment. Let's say the U.S. federal government decides to pressure router makers to put a 'backdoor' in so the government can do wiretapping, etc. A router using open source firmware, scrutinized by legions of people, might lack such a backdoor.

Or, given the level of thought that some seem to think the ban suggests, maybe some government figures just want to forbid foreign firmware on U.S. routers?

Either way, can they block updating open source firmware?

At issue is how far the government will go to enforce this.

What routers are made in the US? If there are any, they probably contain foreign components.
StarLink is the only one in the consumer segment I've seen mentioned, at least as a significant player, and as you note, it's likely made with foreign components.

What routers are made in the US? If there are any, they probably contain foreign components. Seems like a step back to the stone age. 🤡😂

Are you all going to go to Canada to buy routers? And if you do, will you get detained by importing it into the US?
Too soon to tell, but I suspect the term 'smuggling' on one's criminal record looks bad.

I'm seeing online it's possible to make a DIY router (e.g.: turn an old PC into a router). Doesn't sound cheap, and I question the odds of it being as compact or elegant, and I'm guessing you need to use open source firmware to run it. But that's one option for tech. geeks.
 
Are you all going to go to Canada to buy routers?
Been awhile since I registered a modem with my ISP, but here's a question...let's say for sake of argument that 2 years from now I visit Canada for some reason and bring home a new ASUS router prohibited under the ban. I have to call my ISP and give them the MAC address for the router. From what I understand, the first part of the MAC tells them the manufacturer, and they may be able to figure out the model from the rest. Can the ISP make their network not work with prohibited routers? Would the government make them do that? Hope they wouldn't report me.

I know this sounds a little 'tin foil hat paranoid,' but when the U.S. government raises the 'national security' claim, it seems to empower enforcement.
 
Been awhile since I registered a modem with my ISP, but here's a question...let's say for sake of argument that 2 years from now I visit Canada for some reason and bring home a new ASUS router prohibited under the ban. I have to call my ISP and give them the MAC address for the router. From what I understand, the first part of the MAC tells them the manufacturer, and they may be able to figure out the model from the rest. Can the ISP make their network not work with prohibited routers? Would the government make them do that? Hope they wouldn't report me.

I know this sounds a little 'tin foil hat paranoid,' but when the U.S. government raises the 'national security' claim, it seems to empower enforcement.
You shouldn't need to register your router mac address. Regardless, it is the sale and importation that is not allowed from the article linked in the OP.
 
Been awhile since I registered a modem with my ISP, but here's a question...let's say for sake of argument that 2 years from now I visit Canada for some reason and bring home a new ASUS router prohibited under the ban. I have to call my ISP and give them the MAC address for the router.…
Couldn't you just clone the MAC address of the old router onto your new router?

-kp
 
You shouldn't need to register your router mac address.
Spectrum is my current ISP; I recall in the past at some point I had to give them a router's MAC address over the phone so their tech. person enabled it to work with their system. I don't know how prevalent that practice is, but a quick online search suggests it's at least not uncommon.
Regardless, it is the sale and importation that is not allowed from the article linked in the OP.
Good point.
Couldn't you just clone the MAC address of the old router onto your new router?
Wow! Thanks. I didn't even know that was possible. I don't need to do it now, but for future reference hey, knowledge is power!
 
Couldn't you just clone the MAC address of the old router onto your new router?

-kp
FWIW, I cloned the address of of previous router to my new router when upgrading to a 2.5G capable router. Had a bad experience with the ISP's DHCP server glomming on the MAC of a USB to Ethernet adapter that I used to determine that an even earlier router was dead versus the fiber line not working.
 
Spectrum is my current ISP; I recall in the past at some point I had to give them a router's MAC address over the phone so their tech. person enabled it to work with their system. I don't know how prevalent that practice is, but a quick online search suggests it's at least not uncommon.

I've been using Spectrum since 2017 and I have never had to give them my router's MAC address.

I have used a mix of D-Link, Netgear, and TP Link routers. I have even used an old Netgear router with Open-WRT installed for testing before replacing it with a TP Link router.
 
  • Like
Reactions: drrich2
PC Magazine has an new article out today - Netgear Scores the First Exemption From the FCC's Foreign-Made Router Ban

Well, well, well! To repeat from Post #71:

The US Is Considering a TP-Link Router Ban—Should You Worry?

"It’s no secret that US competitor Netgear has been lobbying the US government on “cybersecurity and strategic competition with China.” Netgear has had a tough couple of years after adopting a premium pricing strategy that did not resonate with consumers. It has also been embroiled in litigation against TP-Link for patent infringement, resulting in TP-Link paying a $135 million settlement in September 2024."

Sooo...the company that it sounds like has been instigating and also priced itself out of some business, managed to get the first exemption. How about that? From the new article (content in quotes):

"The Defense Department reviewed Netgear’s application for an exemption and found that its products “do not pose risks to US national security.” The FCC’s order doesn’t elaborate on why."

I suppose if they don't elaborate it's harder to pin them down and challenge if they unjustly block competitors.

"But in a statement, Netgear notes that it’s the “first retail consumer router company to receive conditional approval from the FCC as a trusted consumer router company, a recognition that provides our customers added peace of mind knowing the network powering their homes meets rigorous standards.” "

Leveraging that marketing advantage, Netgear?

"The exemption also offers a clear marketing and business win for Netgear. " You don't say...

What about this company?

"The Defense Department also exempted products from another US company, Adtran, which specializes in optical fiber and enterprise networking gear. Adtran’s future Service Delivery Gateway (SDG) class routers, meant for homes and small businesses, have also received a conditional approval through Oct. 1, 2027. "

I'm not familiar with Adtran; does that name mean anything to you guys?
 
If I harbored any doubts about Netgear taking advantage of the situation, they just sent out an e-mail that hit my inbox. Some excerpts from that e-mail:

"For context, in March 2026, the FCC called for stronger safety and security standards for consumer routers based upon a risk assessment issued by the federal government."

So...creating an obstacle to the roll out of new, more up-to-date gear and restricting the ability to issue firmware updates beyond roughly a year into the future, barring further developments...does that sound like stronger safety and security standards?

"This aligns with our security-first approach, and we believe the steps the FCC are taking will help ensure the security of your digital front door and home networking products."

From articles I've read, and common sense, it seems high risk to do the opposite.
 
I received the same email from Netgear this afternoon.

It sounds like Netgear might be playing dirty to stifle competition. I could be wrong and actually hope that I am wrong. But one has to follow the facts and money trails.

You asked about Adtran. They are more into rack mounted commercial grade routers and switches along with provided ISP's with modems/routers. Adtran products are not cheap.
 
  • Like
Reactions: drrich2
FCC Router Ban Targets Chinese Hackers. I Bet Yours Wasn't Even Made There

PC Magazine article posted today (surprised I haven't seen MacRumors dig into the router ban).

I knew a lot of router manufacture was done in foreign nations other than China, but I was surprised how few are made in China (though the article notes some made elsewhere might use Chinese components). From 2019 to 2025 there was a huge drop. Now Vietnam has the big share.

I'm still curious about a number of unanswered questions.

1.) In the unlikely event router manufacture is moved to the U.S., which would require a huge investment to develop capability that if I understand correctly doesn't yet exist here, and would mean much higher manufacturing costs, what is the expected increase in cost for the end user likely to be?

2.) How is manufacturing in the U.S. likely to be different?

3.) If the government is going to somehow regulate the router industry to a higher level, why not just restrict routers meeting such hypothetical standards now?

I keep watching this evolving story waiting for it to make more sense.
 
  • Like
Reactions: polyphenol
I later noticed PC Magazine posted another article today:

Is the FCC's Foreign-Made Router Ban Only the Beginning?

You may need to scroll down quite aways; not the first article in a series, at least in my browser window.

This is shaping up to look very bad. With high RAM and SSD costs, the outlook for computer prices is already bleak, and I saw where Microsoft recently increased prices on at least some of its branded computers.

I don't like the sound of this at all.
 
FCC Router Ban Targets Chinese Hackers. I Bet Yours Wasn't Even Made There

PC Magazine article posted today (surprised I haven't seen MacRumors dig into the router ban).

I knew a lot of router manufacture was done in foreign nations other than China, but I was surprised how few are made in China (though the article notes some made elsewhere might use Chinese components). From 2019 to 2025 there was a huge drop. Now Vietnam has the big share.

I'm still curious about a number of unanswered questions.

1.) In the unlikely event router manufacture is moved to the U.S., which would require a huge investment to develop capability that if I understand correctly doesn't yet exist here, and would mean much higher manufacturing costs, what is the expected increase in cost for the end user likely to be?

2.) How is manufacturing in the U.S. likely to be different?

3.) If the government is going to somehow regulate the router industry to a higher level, why not just restrict routers meeting such hypothetical standards now?

I keep watching this evolving story waiting for it to make more sense.
I do not think that these other countries like Vietnam, Philippines, Thailand and Mexico started manufacturing routers on their own and out of the blue. They lack the depth to be able to create these products on their own. They are likely Chinese firms that set up these foreign factories to assemble the routers to avoid tariffs. It may cost a bit more to setup up elsewhere, but they mitigate risk because of US tariffs on Chinese made items - but I think this is a very minor reason. The cost of labor in these countries is also cheaper than China as well. Vietnam shares a land border with China so moving components back and forth is also easy. China does not need to sell routers to the US. The US has a population of 350 million. There are 8 billion people on the rest of the world. The US is a bit over 4% of the population of the world.

US made routers will be very expensive because of the cost of labor as well as sourcing parts and components. China is the world's factory and most, if not all the parts, are easily sourced and the cheapest from China because most of the companies and parts suppliers are situated in and around Shenzhen. I imagine that it would be prohibitively expensive to manufacture the components in the USA because of environmental concerns and laws and the size of the market the US would be manufacturing for. Importing components from China could be a nightmare and what if China stops selling components to the US? It's also not likely US firms would be able to sell their product outside of the US because of the price. I doubt anyone outside of the US would pay a premium for a router made in the US. This is uniquely an American problem and Americans will get screwed on the price because of the lack of competition.
 
Last edited:
  • Like
Reactions: JPack and drrich2
Today DB Tech put out an educational YouTube video and I found it quite informative.


He pointed out a number of things:

1.) Nobody can explain the details of how Netgear got approved. Netgear, whose stock went up when the ban was announced because some people figured TP-Link will be banned.

2.) He notes the stated reason for the ban was that foreign governments could use foreign-made routers to spy on Americans; the threat is real, as it's thought China was behind the Salt Typhoon attack as an example.

3.) But I was shocked to hear how they were able to do that. The U.S. passed a law way back, the Communications Assistance for Law Enforcement Act, CALEA, that requires every telecommunications carrier to build wiretapping capacities into their networks, and the scope of this has been expanded over time. It includes VOIP - they have to build in the capability for the government to intercept communication. It also includes broadband and Internet services.

4.) He said the FBI has repeatedly tried to expand it further.

5.) He claims the Salt Typhoon attack entailed Chinese hackers exploiting the CALEA wiretapping infrastructure, which became the entry point they used to spy on Americans.

6.) He said security researchers have long warned a backdoor 'doesn't check who's knocking' and is a target.

He gives more info. and his presentation is worth watching (and only 11 minutes, 38 seconds!).
 
Updates from PC Magazine:

Amazon's Eero Exempted From FCC's Foreign-Made Wi-Fi Router Ban

While the article mentions some things that had to be done to get that, it also states this: "The FCC’s order says the Defense Department reviewed eero’s submission and granted the Conditional Approval, finding the products “do not pose unacceptable risks to national security.” No further explanation was provided."

Sounds to me suspiciously at risk for arbitrary governance without much accountability - 'Because we say so.'

FCC's Foreign-Made Router Ban Expands to Portable Wi-Fi Hotspot Devices

This is new (article dated today). From the article: "Portable Wi-Fi hotspots are usually considered a separate category from Wi-Fi home routers. Both offer internet access, but portable Wi-Fi hotspots use a SIM card to connect to a cellular network rather than an Ethernet cable inside a residence. However, the FCC’s FAQ now specifies that “consumer-grade portable or mobile MiFi Wi-Fi or hotspot devices for residential use” are covered under the ban. "

"The document also notes that mobile phones with hotspot features remain outside the restrictions.

In addition, the ban only affects new router models that vendors plan to sell, not existing models, as T-Mobile emphasized to PCMag."
 
PC Magazine appears to be on a roll...

Facing Router Ban, TP-Link Tells FCC It's Investing Hundreds of Millions in the US That investment, however, hinges on TP-Link receiving 'conditional approval' from the FCC to exempt it from the foreign-made Wi-Fi router ban.

Gee, I wonder where TP-Link is going to get those 'hundreds of millions?' Out of the pockets of us, the customers, in inflated product prices? And even if they do that, chronically high U.S.-based manufacturing costs will add to the bill.

It also raises the question of whether TP-Link is basically having to bribe the U.S. federal government for authorization to do business here, and whether other companies (e.g.: Amazon) had to do that. The ban demanding plans to move manufacturing to the U.S. makes that a dubious claim of mine in terms of semantics (i.e.: it's not a bribe, it's a requirement under the law, don't'cha know?), but in a practical sense...if it looks like a duck and quacks like a duck...

Did MacRumors do a main site page article on the router ban and these related issues covered in this thread? I suspect every member of and/or visitor to this forum does so via a router at some point. Seems like this is a very important story. Many of us get news from other sites (hence my posting links), so it's easy to assume everybody is aware, but maybe not?
 
  • Like
Reactions: polyphenol
Known router, hot spot, etc., issues obviously need to be addressed.

But we could see a monoculture issue. Imagine every device in the US was either Cisco or Netgear, built in the USA. Means any attacker only needs to consider a limited number of device models.

The monoculture means that if, probably when, an attack vector is identified, it is very likely to work on a substantial proportion of connected devices.
 
  • Like
Reactions: minik and drrich2
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.