The Cyber Security Review | Thursday, June 30, 2022
Incapacitate remote administrative access, and disable administrative access over wifi. Administrators should bind to routers through wired Ethernet only.
Fremont, CA: Most wifi routers and network gateways home customers use are not secure. A security expert said that some are so vulnerable to attack that they should be thrown out at the HOPE X hacker conference in New York.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
"If a router is sold at, you don't want to buy it," self-sufficient computer consultant Michael Horowitz told the audience.
"If your router is given by their internet service provider [ISP], they don't want to use it either, because they give away millions of them, and that makes them a prime target both for spy agencies and bad guys," he added
Horowitz recommended that security-conscious consumers upgrade to commercial routers for small businesses or at least separate their modems and routers into two separate devices. (Many "gateway" units can act as both, often supplied by ISPs.) Failing one of those options, Horowitz gave a record of precautions users could take.
Problems with consumer routers
Routers are the vital but unexpected workhorses of modern computer networking. Yet few home users understand routers are, in fact, full-fledged computers with their operating systems, software, and susceptibilities.
Horowitz said, "A compromised router can spy on you," explaining that a router under an attacker's control can stage a man-in-the-middle attack, alter unencrypted data or send the user to "evil twin" websites masquerading as often-used webmail or online-banking portals.
Horowitz noted that many consumer-grade home-gateway devices fail to notify users if and when firmware updates become available, even though those updates are essential to patch security holes. In addition, other devices will not accept passwords longer than 16 characters — the minimum length for password safety today.
Universal Pwn and Play
Millions of routers worldwide, even some of the best ones, have the Universal Plug and Play (UPnP) networking protocol enabled on internet-facing ports, which exposes them to external attacks.
Horowitz said, "UPnP was designed for local area networks [LANs], and as such, it has no security. So in and of itself, it's not such a big deal." Still, he added, "UPnP on the internet is like going in for surgery and having the doctor work on the wrong leg."
Another issue is the Home Network Administration Protocol (HNAP), a management tool found on some older consumer-grade routers that transmit sensitive information about the router over the Web at HTTP://[router IP address]/HNAP1/and gives full control to remote users who provide administrative usernames and passwords.
Easy fixes for your home wireless router
Alter the administrative credentials from the default username and password. They are the first things an attacker will try. Your router's instruction manual should guide you on how to do this. If not, then Google it.
Make the password long, strong and different, and don't make it anything resembling the usual password to access the wifi network.
Rename the network name, or SSID, from "Netgear," "Linksys," or whatever the default is to something special — but don't give it a name that identifies you.
"If you stay in an apartment building in apartment 3G, don't call your SSID 'Apartment 3G,'" Horowitz quipped. "Call it 'Apartment 5F.'"
Turn on automatic firmware modernizes if they're ready. Newer routers, comprising most mesh routers, will automatically update the router firmware.
Enable WPA2 wireless encryption so only authorized users can hop on your network. If your router helps only the old WEP standard, it's time for a new router.
Allow the new WPA3 encryption standard if the router supports it. However, as of mid-2021, only the latest routers and client devices, for example, PCs, mobile devices, and smart-home devices, do.
Disable wifi Protected Setup if your router lets you.
Set up a guest wifi network and offer its use to visitors if your router has such a feature. Preferably, set the guest network to turn itself off after a set period.
"You can change on your guest network and set a timer, and three hours later, it turns itself off," Horowitz said. "That's a nice security feature."
If you have many smart-home or Internet of Things devices, many won't be secure. So connect them to your guest wifi network instead of your primary network to minimize the damage resulting from any potential bargain of an IoT device.
Don't use cloud-based router management if your router's manufacturer gives it. Alternatively, figure out if you can turn that feature off.
Horowitz said, "This is a really bad idea. If your router offers that, I wouldn't do it, due to now you're trusting another person between you and your router."
Many "mesh router" systems, like Nest wifi and Eero, are entirely cloud-dependent and can interface with the user only through cloud-based smartphone apps.
While those models provide security improvements in other areas, such as with automatic firmware updates, it might be worth looking for a mesh-style router that permits local administrative access, such as the Netgear Orbi.
Moderately tough home router fixes
Install new firmware when it turns available. This way, router makers install security patches. Then, log into your router's administrative interface regularly to check — here's a guide with more information.
You may have to control the manufacturer's website for firmware advances with some brands. Yet have a backup router on hand if something deviates. Some routers also permit you back up the current firmware before installing an update.
Incapacitate remote administrative access, and disable administrative access over wifi. Administrators should bind to routers through wired Ethernet only.
More in News