Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.
Can we please have a foreign-made router ban for Wales?

I don't want USA, Chinese, Taiwan, EU or English routers. I want local routers for us local people. I want real Welsh routers, programmed in Welsh computer languages.

Reductio ad absurdum 🙂🏴󠁧󠁢󠁷󠁬󠁳󠁿😵‍💫
 
I don't want USA, Chinese, Taiwan, EU or English routers. I want local routers for us local people. I want real Welsh routers, programmed in Welsh computer languages.
You know, it seems like things are heading in that direction. Mindful that this thread isn't in the political news forum, I think it fair to say I've seen a number of recent YouTube videos discussing the switch of at least parts of some foreign governments from U.S-based software to open source alternatives - such as Linux and alternative Office suites (rather than Windows and Microsoft Office). Germany and France come to mind. And with the rise in controversies between some nations, concerns about the potential for foreign corporations to be used by foreign governments may be on the rise.
 
  • Like
Reactions: polyphenol
From PC Magazine online:

AT&T Secures Waiver After FCC's Router Ban Collides With Memory Shortage The foreign-made router ban prohibits hardware changes to existing Wi-Fi routers, which is a problem because manufacturers need to source new components amid the RAM crunch.

From the article:

"
UPDATE 5/15: The FCC has granted AT&T a one-year waiver, permitting the carrier's suppliers to make minor hardware changes to already-approved foreign-made Wi-Fi routers.

The waiver lasts "until May 15, 2027, for the limited purpose of AT&T’s suppliers making hardware Class I and Class II permissive changes to substitute substrate materials and memory modules in its previously certified routers of its suppliers," says the FCC's Office of Engineering and Technology.
"

and

"...the hardware changes will not improve performance or capability or alter the functionality of the previously-authorized device..."

and

"
AT&T says one manufacturer can no longer source a chipset used in previously certified routers. “Specifically, the particular type of substrate used in the routers’ chipset is running out.”
"

This is interesting:

"But the commission has said that both consumer-grade Wi-Fi routers and "ISP-provided residential gateways that combine modem and router functions in a single device" are subject to the ban."

"So far, the Trump administration has only grantedshort-term exemptions to the ban to four vendors: Amazon’s eero, Netgear, Adtran, and Calix, all of which are US companies."

I recently learned of Calix, as they're the brand of router used by a fiber broadband service in my region (though I'm on Spectrum, I was curious about them).


A number of take home points come to mind:

1.) The ability to continue to manufacture currently-approved routers not yet impacted by the ban may be compromised. It's not just about RAM, it can be something we wouldn't normally think about like this 'particular type of substrate.'

2.) If it's a problem for AT&T, stands to reason it'll be a problem for some others. I wonder which manufacturer and chipset were impacted?

3.) This waiver is just for AT&T and only for a year.

4.) The piece about ISP-provided residential gateways with combo. router/modem capability are subject to the ban. At least this may prevent anti-competitive market pressure against 3rd party router vendors.

5.) So far, no non-U.S. companies have waivers. TP-Link and ASUS are major vendors in the U.S. market; what about them? Ubiquiti is an American company, but I haven't seen an exclusion for them yet.
 
I was on the Ubiquiti online store a number of times in months. Think it's about time to pull the trigger and replace the pair of Linksys Velop WiFi 6 mesh system (June 2025 was the last firmware) especially it's been fairly unstable lately. I looked at the OpenWrt project but not really convinced.
 
PC Magazine posted this article online today:

TP-Link Preps Wi-Fi 8 Router, Will The FCC's Ban Block It? TP-Link plans on launching the Wi-Fi 8 router this October, but it probably won't arrive in the US, unless the company receives an exemption to the FCC's foreign-made router ban.

Some talking points:

1.) Wifi 8 won't be finalized till 2028, but vendors putting out pre-finalized standard routers (with the hope of later firmware updates matching the finalized capability) is something we've seen before.

2.) It's my understanding Wifi 8 is about reliability rather than speed increase, so it's not clear to me how much most people will benefit from it over Wifi 7. Perhaps in densely populated areas with multiple overlapping Wifi networks and many Wifi devices it would offer a better return on your investment to upgrade?

3.) Per the article ASUS is also preparing a range of Wifi 8 products by the end of 2026.

4.) To reiterate a prior point, if TP-Link is investing hundreds of millions of dollars in bringing manufacturing and R&D to the U.S., they've got to get those hundreds of millions from somewhere. Guess where they're doing to get it?

5.) If TP-Link and ASUS put out Wifi 8 routers, it stands to reason competitive market pressures will see other vendors putting them out, also. This will rush out new products some of which may be blocked from the U.S. market by this ban.

How many of you have a strong desire to make your next router a Wifi 8 model?
 
Posted June 3 on YouTube:

Drop down to the 1st (pinned) comment, which is by the creator, and from that:

"The lede I probably buried: I looked into Netgear’s claim that TP-Link routers are a great place for criminals to hide, and yes, the TP-Link BE800 audit gives plenty of reasons to be concerned. Context is important to me, so this video is about context of the testing that led here.

Awkward: the Netgear RS700S preliminary audit does not look better. It may be worse.

So the answer is not “TP-Link bad, Netgear good.” The answer is that consumer routers have a software lifecycle problem. These boxes keep working for years after the kernel, services, cloud agents, VPN stacks, and bundled userland have aged into a security swamp. Netgear knows something is up; they took down all their GPL sources to make auditing harder. Bold strategy, Cotton!

A router is not a toaster. It is DNS, DHCP, firewall, NAT, sometimes VPN, sometimes storage, sometimes cloud management, and increasingly part of your online identity footprint. Treating firmware updates like occasional PR events instead of a long-term maintenance promise is how we got here."

--------

I chose to add that to this thread because over time I've noticed (at least elsewhere) some people seem to think TP-Link's product line is particularly vulnerable to potential foreign 'bad actor' exploitation. If that's someone's concern, better dig a little deeper.

If the FCC or some other entity wanted to improve the security awareness in the U.S. consumer router market, it'd be nice if there was a single site that listed the various brands and models, whether they are actively getting firmware updates or not, vulnerabilities known for that specific model and an overall 'grade' kept current over time as to how secure it's judged to be now.

I'm curious - is there some point beyond which old hardware is too outdated to make secure in modern networking? Just how long is updating firmware feasible before?

Revisiting the original question, I think the premise was that the ban would exclude so much foreign competition that Apple, having great wealth and technical expertise and thus the leverage to enter the U.S. router market in compliance with the ban fast enough to take advantage, could do so and theoretically turn a profit.

I don't think it's going to happen. Apple keeps a narrower product portfolio to focus on than Microsoft, for example, a 'we do fewer things but better' mindset. I don't see it as potentially lucrative enough; we're not talking smart phones or iPods, etc. And enough exclusions have been issued (e.g.: Eero, Netgear) to keep competition in play, plus routers for many people are 'set it up once and forget it' and interfaces good enough I don't seen an opportunity for Apple's famed user interface and ecosystem integration advantages to turn the tide. Plus it's a long lifecycle product.

I'd be interested to see what Apple could do!
 
I chose to add that to this thread because over time I've noticed (at least elsewhere) some people seem to think TP-Link's product line is particularly vulnerable to potential foreign 'bad actor' exploitation. If that's someone's concern, better dig a little deeper.

It doesn't matter what brand of consumer router you go with, they all have the same faults that was mentioned in that video. Firmware rarely gets updated and only for so many years before companies consider them at End Of Life and drop all support.

I have used both NetGear and TP Link routers and find that TP Link is actually better about firmware updates.

The main issue is most people treat routers like toasters and never bother to check their router for updates or even to replace them on a regular basis. The average home user will "set and forget" their routers and won't replace them until they stop working, which is usually years past End of Life.
 
Last edited:
  • Like
Reactions: drrich2
It doesn't matter what brand of consumer router you go with, they all have the same faults that was mentioned in that video. Firmware rarely gets updated and only for so many years before companies consider them at End Of Life and drop all support.

I have used both NetGear and TP Link routers and find that TP Link is actually better about firmware updates.

The main issue is most people treat routers like toasters and never bother to check their router for updates or even to replace them on a regular basis. The average home user will "set and forget" their routers and won't replace them until they stop working, which is usually years past End of Life.
If the companies are going to only offer a limited support life, that should be declared on the box - in big letters.

Of course, a line like "Supported until fall 2028" would not encourage most of us to rush out to buy. They are not going to do that unless absolutely forced to.

Of course we think of routers like toasters. Or hammers. If the head isn't loose, carry on using it. But just how far do we have to go with firmware updates? Will my screen, my mouse, my cables, my SSDs and hard drives, my USB hubs, stop working if I don't update their firmware?

My view is that these things should work forever. While appreciating that there could be fixes, improved security, new facilities, etc., in updates, we are currently absolutely at the mercy of unscrupulous companies embedding unnecessary limits in their products.

We also have the problem that if we buy a router, the manufacturer could wash their hands of providing a way of updating that router from Linux, from macOS, from IOS. They could just support from Windows, for example. At one and the same time they could claim to support the device but make it extremely awkward for many people.
 
If the companies are going to only offer a limited support life, that should be declared on the box - in big letters.
Interesting thought, and would apply to computers like Macs (security updates), OS's like Windows 10 (when it's projected to no longer be supported), probably some other things. I'm told at least some Linux distro.s guaranteed support timelines.

Of course we think of routers like toasters.
I saw this and thought 'Nobody's attacking our toasters.' Then I considered the proliferation of 'smart' appliances. A networking influencer on YouTube recommended creating a separate home network for your 'Internet-of-Things' devices which over time might get older and less secure (when was the last time you thought about updating firmware in those things? Like a Roomba?).

I don't think our toasters will ever be at the level of vulnerability of a router, but these smart refrigerators are pretty expensive and I can't imagine tossing a functioning one because somebody said it had security vulnerabilities.

Note: quick Googling shows vulnerabilities regarding IoT devices have long been more of a concern than I thought. 5 INFAMOUS IOT HACKS AND VULNERABILITIES Hacking cameras and taking control of a Jeep were bad enough, but it turns out some pacemakers were vulnerable to hacking!

My view is that these things should work forever.
I agree, but wonder if at some point there'll be a push to deny network connectivity via older routers on the grounds their security vulnerabilities are too great (which could come from ISPs or government mandate). One or two big sensational hacker exploits making the news or doing serious damage could swing the needle to make that happen.

Here's a question based on your assertion; to what extent does the security of a router depend on its hardware? A quick Google search indicates it's important, but that's vague.

With all the hoopla over the potential 'national security' risks posed by foreign-made consumer routers, how does the danger there stack up against the dangers of people who operating personal computers without anti-malware software? If Bob has an 8-year old router and Doug has a Mac or Windows PC with no anti-virus/malware software running, who is more dangerous (yes, I know Windows Defender may be active on the PC)?
 
Interesting thought, and would apply to computers like Macs (security updates), OS's like Windows 10 (when it's projected to no longer be supported), probably some other things. I'm told at least some Linux distro.s guaranteed support timelines.


I saw this and thought 'Nobody's attacking our toasters.' Then I considered the proliferation of 'smart' appliances. A networking influencer on YouTube recommended creating a separate home network for your 'Internet-of-Things' devices which over time might get older and less secure (when was the last time you thought about updating firmware in those things? Like a Roomba?).

I don't think our toasters will ever be at the level of vulnerability of a router, but these smart refrigerators are pretty expensive and I can't imagine tossing a functioning one because somebody said it had security vulnerabilities.

Note: quick Googling shows vulnerabilities regarding IoT devices have long been more of a concern than I thought. 5 INFAMOUS IOT HACKS AND VULNERABILITIES Hacking cameras and taking control of a Jeep were bad enough, but it turns out some pacemakers were vulnerable to hacking!


I agree, but wonder if at some point there'll be a push to deny network connectivity via older routers on the grounds their security vulnerabilities are too great (which could come from ISPs or government mandate). One or two big sensational hacker exploits making the news or doing serious damage could swing the needle to make that happen.

Here's a question based on your assertion; to what extent does the security of a router depend on its hardware? A quick Google search indicates it's important, but that's vague.

With all the hoopla over the potential 'national security' risks posed by foreign-made consumer routers, how does the danger there stack up against the dangers of people who operating personal computers without anti-malware software? If Bob has an 8-year old router and Doug has a Mac or Windows PC with no anti-virus/malware software running, who is more dangerous (yes, I know Windows Defender may be active on the PC)?
These are just some of the questions that need to be asked - and answered.

If nothing else, we must not be locked out because a company chooses, or goes bust. Nor should there be any parameters which cause devices to stop working arbitrarily. E.g. after a time, date, number of pages/bytes/etc. All specs, even source code, should be released if the company is unwilling to continue providing support.

I'd hate a connected toaster - just think, anyone with access could switch it on at any time. Plenty of room for causing a fire or a burn.
 
With all the hoopla over the potential 'national security' risks posed by foreign-made consumer routers, how does the danger there stack up against the dangers of people who operating personal computers without anti-malware software? If Bob has an 8-year old router and Doug has a Mac or Windows PC with no anti-virus/malware software running, who is more dangerous (yes, I know Windows Defender may be active on the PC)?
The difference between a router and a computer is that a router is almost always directly connected to the internet whereas computers rarely are directly connected to the internet. With that in mind, I would consider a 8 year old unpatched router to be more of a problem than a Windows or Mac computer with no anti-virus/malware software running.
 
  • Like
Reactions: drrich2
If nothing else, we must not be locked out because a company chooses, or goes bust. Nor should there be any parameters which cause devices to stop working arbitrarily. E.g. after a time, date, number of pages/bytes/etc. All specs, even source code, should be released if the company is unwilling to continue providing support.
The main answer to your points would be to require router manufacturers to make their routers with the option to use open source firmware like OpenWRT or DD-WRT. I haven't used such products; from I've read they seem to require a bit more technical sophistication than the usual mainstream router where you just follow the little Quick Start Guide and in short order it's good to go, very little understanding required.

But that path raises more questions.

1.) How long can DD-WRT, for example, keep a router the manufacturer considers 'end of life' effectively safe to use from a security standpoint?

2.) How much sophistication on the part of the user does it take to make that happen? Will it auto-update firmware? Are there settings that need to be changed over time, new security features that have to be manually implemented, etc.?

3.) Will the U.S. federal government decide foreign-produced firmware is a 'national security threat' and outlaw it?
 
  • Like
Reactions: polyphenol
I have used both DD-WRT and Open WRT. They are both more advanced than the average consumer grade router. You really need to have a bit of networking experience and knowledge to properly setup a router running either firmware.

The average home user is going to feel a bit intimidated when trying to setup either firmware.

One of the main issues with both is that they do require a minimum amount of RAM, storage and they only support certain chip sets. You can't install either on quite a few consumer grade routers.

You will definitely get longer support and firmware updates with either. But just like any other form of Linux, support will only last so long.

Open source will always have longer periods of firmware updates and support.

I miss the days of the Linksys WRT-54G routers. You could take a $50 router and give it the same capabilities as a Cisco or other high end router by installing DD-WRT or Open WRT. Yes you can still do the same with modern routers but they do cost a bit more.

My course final for Linux administration (part of my network admin degree) was writing a paper and demonstration of installing/running DD-WRT on a Linksys WRT-54G in place of a Cisco router.
 
Netgear: Don't Be Fooled, TP-Link Is a Chinese Company In a court filing, Netgear says it's losing sales because many US consumers believe TP-Link has severed ties with China. TP-Link says Netgear 'misrepresents the facts.'

Article posted at PCMag.com today.

TLDR: From the article - "US-based Netgear says it’s lost “tens of millions of dollars in sales” because US consumers mistakenly believe rival TP-Link is no longer a Chinese company."

Netgear apparently wants to get some money out of them, and claims TP-Link gained a dominant share of the U.S. residential router market.

Based on reports on Netgear, as mentioned in varied posts on this thread, I don't want to buy their equipment going forward. Maybe the truth is different than the impression I got, I'm open to reconsider in the face of new evidence to the contrary, but if I decide to make our next router something other than TP-Link, maybe Eero or Ubiquiti would make my short list. And if I'm wrong and Apple does decide to enter the router market, I'd be very curious about that.
 
Can we please have a foreign-made router ban for Wales?

I don't want USA, Chinese, Taiwan, EU or English routers. I want local routers for us local people. I want real Welsh routers, programmed in Welsh computer languages.

Reductio ad absurdum 🙂🏴󠁧󠁢󠁷󠁬󠁳󠁿😵‍💫
All I can think about with this one is the bilingual road sign trying to keep grocery store delivery trucks out of a trailer park cul-de-sac where they put the translation department's out-of-office email auto response "Nid wyf yn y swyddfa ar hyn o bryd. Anfonwch unrhyw waith i'w gyfieithu." on it instead of the Welsh for keeping trucks out of trailer parks.
 
  • Haha
Reactions: polyphenol
We recently were offered an upgrade to our internet service, to what is called in Australia FTTP (Fibre to the Premises), whereby the entire connection is fibre optic. So I purchased an Eero 7 Pro, and 2 Eero 7's to cover the home. Am getting 705 Mbps download, and 100 Mbps upload in the furthest room.
Eero are US owned, and made in Vietnam?
 
If I were in the US I would be buying up some extra routers......for resale later 😉
That question has come up elsewhere; should people considering a router purchase in the not too distant future buy now instead of waiting? Will routers available today become 'hot commodities' later? I don't think so, but some of you may see a different angle. Let's explore it.

1.) Routers already available and approved by the FCC won't be affected by the ban. So what you can buy now won't be banned later.

2.) Future models the ban covers largely aren't available yet (and can't be sold here without FCC giving the maker a pass anyway). From PC Magazine June 14: What Is Wi-Fi 8? Next-Gen Wireless Designed to Fix Your Lag

While it doesn't sound revolutionary, and isn't due to be finalized till 2028, it will be the 'big new thing' and uncertified routers claiming to be WiFi 8 may well start coming on the market later this year. That scenario might give companies with even temporary waivers entry to the U.S. market for new products while excluding competitors.

3.) If you buy now from a maker that doesn't yet get a 'pass' from the FCC, you run they risk they won't later and won't get firmware updates past the ban date. So in theory if TP-Link gets locked out the U.S. market (which seems ridiculous but the federal government had an agenda to do that very thing, and we remember DJI and Huawai), your router might lose firmware updates. It would be idiotic for the government not to allow extended firmware updates, but idiotic doesn't equal impossible.

I don't know which routers can accept open source firmware, but that's said to be a bit more technically demanding of the user.

4.) There's one scenario I see where today's routers might be desirable later (whether resale value is high enough to bother purchasing extras or not). Let's say the government doesn't give provisional approval to TP-Link and ASUS (maybe not even Ubiquity), cutting out a lot of competition. So if you don't settle with what your ISP provides, your options are Eero or Netgear. And absent other competition they jack up the price. Would people want a current TP-Link WiFi 7 router over a very expensive Netgear WiFi 8 router?

5.) Unlikely long shot scenario - if router manufacture really does move to the U.S. with high costs leading to high new router prices, foreign made older models would be cheaper. Guessing that's several years down the line, if it comes.


I suspect Ubiquiti will get provisional FCC approval; they have a presence in business, and worst case scenario could bill their equipment as not for consumers yet make it where consumers buy a lot of it.

I'm concerned the U.S. federal government will use this situation as an opportunity to bully TP-Link out of the U.S. market, which they've already shown an interest in doing. Losing the competition TP-Link provides would be bad; if we also lose ASUS that'll be very bad. From CNET: Netgear and Eero Get Exemption From FCC's Ban of New Foreign-Made Wi-Fi Routers - "TP-Link specifically has been in the US government’s crosshairs for over a year, stemming from its ties to China, with more than half a dozen US departments and agencies reportedly backing a ban at the end of 2025."

Do any of you see a compelling case to go ahead and buy a new router now vs. waiting (if you don't need it now)?
 
Last edited:
Eero are US owned, and made in Vietnam?
From PC Magazine: Amazon's Eero Exempted From FCC's Foreign-Made Wi-Fi Router Ban

"However, nearly all Wi-Fi routers are made outside the country, mainly in Vietnam, Mexico, and Taiwan."

If you follow what is made where, pay attention to when and to what extent. It's my understanding that due to politics there's been a shift away from manufacturing in China. That said, one point raised elsewhere is does that mean 'built from scratch' in a non-Chinese nation, or might it include assembled in that nation using some components manufactured in China?

And how important is all this? I'm an American sitting in my recliner (with 2 comfortable pugs) surrounded by a plethora of material goods that probably have 'Made in China' written on them, using a Mac Mini and iPhone 12 Pro Max that may've been made there... Hey, it turns out pugs originated in China!!!
IMG_1454.jpeg

Don't ban our Kona Pug!!!
 
Looks like Kona Pug found an orc's ear!
That is an apex predator of the suburban Serengeti with her wild boar kill (well, pig ear from Walmart; close enough).

Wall Street Journal put out an article of interest June 17, 2026 in terms of foreign malefactors using tech. with 'back doors' to launch attacks in the U.S. (I subscribe to Apple News+ so I have access; don't know how many of you do; I'll post a snippet to give you an idea of it):

How Hackers Found a Back Door Into the American Living Room Nation-state cyberattackers are increasingly using residential proxy networks to mask their traffic, turning everyday electronics into a global threat

"...More low-cost consumer devices have shipped into the U.S. with backdoor software pre-installed, and this software is also being sneaked into mobile apps and copyright-free illegal copies of videogames.


The software has turned tens of millions of consumer devices into criminal cloud-computing networks. These networks aren’t only used for fraud, they have also been adopted by government-backed hackers looking to hide their connections to countries such as Russia, China, Iran and North Korea.


Called residential proxy networks, these services let anyone who pays steer their internet traffic through an outside address. It’s like an Airbnb for internet access.”

Later it mentions a residential proxy network run by Chinese provider IPidea that's used sneaky methods to get its software onto consumer devices including video streaming boxes and digital picture frames.

I don't recall seeing the term 'router' mentioned in the article. I consider this news and 'thread-relevant' because the sort of foreign hacker exploitation of foreign-made electronics hardware used to justify the router ban on grounds of national security is also an issue with a number of other foreign-manufactured electronics gear.

Somehow I doubt there's going to be a foreign-manufactured digital picture frame ban, but who knows?
 
Low Level posted to YouTube 3 days ago:

From what I got, drama must've been working for him 'cause he starts in rant mode, drops some f-bombs, settles down later, a couple of significant vulnerabilities have been found with some Acer routers (not necessarily old stuff), and he's disgusted with the state of consumer router security.

While this is relevant to the U.S. federal foreign router ban, it underscores that we need firmware updates well into the future, not barred beyond a set date.

Gamers Nexus posted 3 days ago:

Struck me as kinda roasting both Netgear and TP-Link. From the text under the video: "Wendell from Level1 Techs has unearthed several concerning vulnerabilities in both Netgear and TP-Link routers, in particular, exposing potential vulnerabilities that could be used as backdoors." They go on to mention ASUS. There's concern we're headed to a future when hackers will wish to use your router to impersonate you online. One guy said in recent years Netgear's spent somewhere around half a million dollars lobbying...and they got an exemption from the ban! Hmmm... Around 9:25 the question posed is what's the takeaway on the consumer side? In answer, "Consumer stuff is trash. It's really trash." He said it's not that the companies don't care, it's that they sell you a product and want to spend as little as possible supporting it over the next 5 years. He said you end up having to buy a device that has a known software life cycle, but he doesn't think that's any consumer router today. There's concern about the direction things may be going - requiring I.D., the potential for regulatory oversight monitoring your activities, etc. He affirmed DIY router is the safest course albeit not the fastest. One guy thinks we're headed for ISP-mandated routers ('forced rental routers').

That 2nd video is around 23:17 minutes and worth a watch!
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.