Avoid ISP Routers
routersecurity.org
routersecurity.org
Also, funny to see Bogleheads forum as source for tech advice. It comes up times and again in many forums that they are populated largely by computer janitors.
I strongly disagree. The degree of troubleshooting ability this grants the often almost useless tech support at major providers is not sufficient to justify the many downsides and resulting risks.
There have been numerous documented cases involving ISPs configuring these devices in horrifically insecure ways, and that hardly seems to justify the ability to remotely reboot the device and look at basic troubleshooting stats.
It’s 2024, and I think it’s far more important to continue pushing tech literacy than allow such a critical aspect of modern life to be controlled by demonstrably hostile entities for dubious benefits.
Most people simply don’t have the knowledge.
It would be like everyone buying car parts themselves and repairing their own cars when they break…
Buy an eero, plug it in, use the phone app for initial setup (like setting wifi password, nothing "technical"), and then use it while doing no maintenance because settings don't need to change and software auto-updates.
> It would be like everyone buying car parts themselves and repairing their own cars when they break…
Yes, it would be like people replacing windshield wipers and topping off their own oil: You could hire it out, but it's a waste of money to do so.
The way they already are doing this. You’re presenting this as if it’s some mythical impossible thing, but there’s usually someone in the household who can get these device set up, and an increasing amount of extremely accessible content online to help people who are willing to spend a few minutes learning.
A modern router will update itself, and after the initial configuration process is almost maintenance-free with the exception of the occasional reboot and/or checking of cables, both of which are still required if the ISP owns the router.
Furthermore, modern routers generally have extremely simplified setup processes, and minimal knowledge is necessary.
With some limited guidance, all of the non-technical parental figures in my family have managed this without major issues, and I’ll happily take a few questions every 6-12 months if it means they can avoid trying to mitigate the class of other issues inherent to delegating this to the ISP.
> It would be like everyone buying car parts themselves and repairing their own cars when they break…
This is not an effective analogy. The degree of skill required and the actual steps involved in managing one’s router look absolutely nothing like becoming an at-home mechanic.
99% of router issues are solved by turning it off and on again (If only cars were so simple). The remaining issues are often beyond the purview of the ISP anyway, leaving one to wonder what actual benefit there is in granting administrative access to entities that have repeatedly proven they do not have their user’s best interests in mind.
> And then they might have to manage it, like a manual update or asjustment now and then or whatever
No modern router should require manual updates. Using the ISP’s router does not guarantee automatic updates or properly/securely managed devices either.
And again, this is where I’d rather get a call from my dad very occasionally asking about some setting than find out later that their network has been pwned because the ISP router left a default admin credential in place that is now being widely exploited (true story).
The hurdles you’re erecting do not represent the actuality of the problem space, and I think it’s more important to push a baseline level of tech literacy vs. trying to wash our hands of the issue, which I think is actively harmful because many ISPs have proven they are often not an improvement over even poorly self-managed options.
I have AT&T and they allow this, I have all traffic pointed to a custom Debian router with AdGuard, Firewalld, and OpenVPN. My phone and laptop then have OpenVPN and all traffic goes through my home network.
Its absolutly great. I see no ads and can watch streaming while I travel.
The new place I recently moved to had an ONT unit in the house. Verizon sent us a router (cr1000a, godforsakenly DNS server but otherwise pretty good) but just unplugging it and plugging in our own world fine.
How much does this matter? If your own router gets WAN IP addresses, it can route and firewall everything behind it.
As such, you're limited to the resources of the ONT/router. For example, the number of hardware-accelerated flows is limited (~8000 I believe? I can't find a source right now).
If you can provide a link to one that works for 5Gbps (symmetric, obviously) service I’d be much obliged.
Supposedly they will give you an ONT in SFP module for free, and then rent you a media converter ~3 USD/month, and then the rest is up to you (assuming it supports PPPoE). Some friends have done this a while ago successfully.
Reality on install day: technician grabbed the white-label ONT/router combo from the truck and refused anything else :( And unrelated, he found a “defect” in the existing fiber drop (clear as day with the visible-light tester), so I had to pay for pulling a new drop from the street :(
But man, it has a local DNS server & the response time is pitiful. It is wild how much faster the internet felt when I went around and manually configured systems to use a public or my own local resolver. I'm agog that Verizon would savage their Internet experience so brazenly with such critically deficient tech. DNS is this router's one bad apple.that spoils that basket.
There's also no way to configure anything else in the router. You can pick a resolver in the web gui, but it's only picking what the internal DNS server asks; DHCP always is the slow internal server.
There's other good reasons I wanted to get on openwrt again (i broadly don't trust the information security of this router) but this was an interesting & very surprising lesson.
Takes a bit of wrangling, and a bit of downtime during initial setups but its YOURS!
This is the part where ISC DHCP client really, really shines for me here (and systemd still can't).
Disclaimer: I coded Efficient PPPoE from RFC-scratch for many ISP's modems.
I've been told by different places it often can't be done, but I never pushed the issue. Always wondered if it was true