News: 1620300606

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Which? warns that more than 2 million Brits are on old and insecure routers – wagging a finger at Huawei-made kit

(2021/05/06)


Consumer org Which? reckons more than two million Britons are connected to the internet through routers that were last updated in 2016.

This eye-catching finding came from a Which? survey launched today, seemingly criticising UK ISPs for not complying with [1]a proposed law [2]whose first draft hasn't been introduced to Parliament . The proposal in question is Secure by Design, where the Department for Culture, Media and Sport (DCMS) will be asking phone, tablet, and IoT gadget makers to state when they'll stop providing security updates for new devices entering the market.

Pre-legislative oddities aside, there was a useful point in the survey of 6,000 UK adults carried out in December 2020: six million Britons are using routers that last received security patches in 2018, while 2.4 million of that number are using boxes that might not have been updated for five years.

[3]

[4]

[5]

Which? did not elaborate on these findings but did assert that several models still in use today contain unpatched vulnerabilities. Of 13 old routers examined, nine had flaws. These included weak default passwords, no recent firmware updates, and a "network vulnerability issue" with EE's Brightbox 2 router.

"Consumers with routers that are five years old or more should ask their provider if the device is still supported with security updates and if it is not they should ask for an upgrade," said Which? in a prepared statement.

ISP-branded routers are typically white-label devices sourced from China; both Huawei and ZTE have supplied such kit to UK ISPs in the recent past.

[6]

Which? published a list of affected devices that it suggested were insecure, most notably including the Huawei-made TalkTalk HG533 model: first issued in 2013, [7]dangerously insecure by 2019 , and unquestionably obsolete by 2021.

As we reported two years ago, Huawei was warned in 2013 of a vulnerability in the internet access device, claimed it was fixed in 2014 without actually fixing it, then sat around doing nothing until the same vuln was rediscovered in 2017 by security researchers. Which? said the HG533 was vulnerable to "weak passwords" and a "lack of updates", neither of which are the same as the UPnP vuln Huawei previously ignored.

Our customers are secure – oh aye?

Virgin Media seemingly told Which? to stuff off when its researchers came wagging their fingers disapprovingly, according to the consumer rights org: "Aside from Virgin Media, none of the ISPs Which? contacted gave a clear indication of the number of customers using their old routers. Virgin said that it did not recognise or accept the findings of the Which? research and that nine in 10 of its customers are using the latest Hub 3 or Hub 4 routers."

Which? said its survey had asked about routers in use within a household, not only routers used by currently subscribing customers. On the flip side, BT and Plusnet got a pat on the head from Which? for passing all of its security tests: no easily guessed default passwords, firmware updates still available, and no local network vulns.

An EE spokesperson told The Register : "As detailed in the report, this is a very low risk vulnerability for the small number of our customers who still use the EE Brightbox 2. As is the case for all home broadband customers, regardless of their provider, it is recommended they only give network access to people they trust, and they should be suspicious of any unsolicited emails and web pages. We would like to reassure EE Brightbox 2 customers that we are working on a service patch which we will be pushing out to affected devices in an upcoming background update."

[8]

So that's alright then. EE's owner, BT, said: "We want to reassure customers that all our routers are constantly monitored for possible security threats and updated when needed. These updates happen automatically so customers have nothing to worry about. If a customer has any issues, they should contact us directly and we will be happy to help."

Reusing old routers as part of a household mesh network or Wi-Fi signal extender is pretty commonplace. Provided the device still functions, it seems likely that many Brits haven't given a second thought to whether or not they're still secure. After all, these are internet-connected devices just like a laptop or mobile phone. ®

Bootnote

"The legislation is not yet in force and so the ISPs aren't currently breaking any laws or regulations," said Which?, in much the same way as Apple might write: "Our press office loves El Reg and really enjoys talking to you guys!" ®

Get our [9]Tech Resources



[1] https://www.gov.uk/government/collections/secure-by-design

[2] https://www.theregister.com/2021/04/21/ukgov_death_dates_smartphones_iot_security/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YJQSm2BRqbsIIw9tAf9mQQAAAMA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YJQSm2BRqbsIIw9tAf9mQQAAAMA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YJQSm2BRqbsIIw9tAf9mQQAAAMA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YJQSm2BRqbsIIw9tAf9mQQAAAMA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2019/03/28/huawei_mirai_router_vulnerability/

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YJQSm2BRqbsIIw9tAf9mQQAAAMA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[9] https://whitepapers.theregister.com/

Boiler plate response.

IGotOut

Got compromised router due to our lack of updating?

Beware of dodgy emails!

So this means?

Version 1.0

... more junk being recycled and more sales if the manufacturers decide, or find out, that the device can't up upgraded ... a law that will make the manufacturers more money. Routers will be designed and sold to work for 10 years and then when a bug is found in two years time they will say sorry, it can't be fixed, you need to "upgrade" to a new router.

Re: So this means?

Anonymous Coward

Plus there are in my view at least two types of problems. Problem one is if a bad actor from the "internet" can access my LAN. Then I'm in trouble.

Type 2 are things which can cause problems, like not enforcing strong passwords or allowing people on my LAN to do naughty things.

Type 1 problems need to be fixed but on the other hand are relatively rare.... none of my outdated ADSL routers have issues like this reported with them.

Type 2 are often not such big issues but are a lot more common. Not enforcing strong passwords can be solved by err, using a strong password, for example.

Re: So this means?

Missing Semicolon

Most people do not change the password on their router. The norm nowadays is to have a "secure" password printed on the bottom of the box - which is at least unique to each box.

Type 2 (LAN-facing) vulnerabilities are exploitable by evil JavaScript delivered on a web page, whether deliberately, or by a web server being hacked, or (usually) via Malvatising.

So Type-2 is only slightly less important than Type 1.

Branded routers are usually worse

LDS

The problem with white-label rebranded routers is that their modified firmware - maybe just to add company logos and colours - but often to block some features - night not be updated with stock firmwares for the same models - even if available. Sometimes is possible, sometimes it's not but attempting specific "hacks" that many users may not be able to perform.

Here the comms regulator issued a year and a half ago a ruling that ISP can't mandate the use of their modem/routers - nor can force the customers to buy/rent them. Users must always be able to use their own, and all required configurations must be provided to the users.

ISPs tried to neuter the regulation but failed - although they still try some dirty tricks with user not getting their modem/routers - let's when they get fined.

Still, being able to use commercial modem/routers means you can install any available update - and you can also select brands/models who keep firmware updated.

Re: Branded routers are usually worse

Binraider

Curious. Where does Virgin stand on this - you can put the router into dumb modem mode to use your own, but can you actually replace the modem?

Catch 22

thondwe

So the provider router sucks, but we won't support you if you switch router*!

*The better ISPs don't do this! Mine (Aquiss) doesn't even provide a router - so am happily left to my own devices (groan!)

Re: Catch 22

Aristotles slow and dimwitted horse

I have to say I found he article a bit TLDR, not necessarily with the El Reg reporting of it, but I find Which to be a bit of a scaremonger that is quite happy to take " minor risks" and present them as "critical issues" as long as it gets them some publicity.

However, where did you read this about lack of support if you switch routers? I have had a VM router in my house in one form or another for the last 8 years and they have never raised any form of issue with my having it in modem only mode and connected upstream from my 3rd party router.

Re: Catch 22

thondwe

I had it from my previous ISP - not one of the "big players" - am not saying you can't do it (I did but had to fake the MAC address!) - it's just they sulk if you ring up when the line has problems?

Anyone skilled enough to want to swap routers, is unlikely to bother ISP support's call centre (have you switched it off/on again)!

Re: Catch 22

Roland6

Not being a Which subscriber and so not able to access the full report, from what has been reported (eg. BBC News) it does seem Which has gone off half-cocked on this.

There are a number of problems it seems Which fails to unravel.

Firstly, we have the router itself, in the main the support and update issue is down to the ISP and their agreement with the relevant OEM. So provided the ISP keeps paying the router will/should be supported and getting updates. The only potential benefit here is for the government to insist that routers are supported for a minimum period - say 10 years.

Secondly, we have the issue that ISP's don't generally update the routers of existing customers to new models - I've had problems with my EE Brightbox 2, EE's solution has been to send me a replacement Brightbox 2 and not their new router which they send out to new subscribers.

Thirdly, we have the issue (already pointed out in Elreg comments) that with ISPs insisting residential customers use their router, there is little Joe Public users can do if the ISP supplied router is not fit for purpose.

Perhaps the government should legislate giving ISP's 90 days to fix vulnerabilities reported to them (clock starts when vulnerability reported to a trusted third-party clearing house eg. Ofcom) after which after which the service contract becomes void and the ISP either has to provide a new more secure router or pay customers ISP switching costs. Also all ISP's contribute to a bug bounty pot (administered by a trusted third-party...).

Re: Catch 22

martinusher

What's also not mentioned is that the domestic edge router isn't connected to the Internet, its connected to a port on a ISP's router. The ISP should be the primary firewall for attempts to compromise its customers' kit. I rather suspect it doesn't, I feel that my ISP, for example, has few technical smarts, its primairly a billing and sales organiztion with technical support limited to 'turni it off and on again' and the like.

(Of course, it doesn't help that my router (a Sagecomm) has an annoying habit of resetting its admin password to the default.)

Huawei

Anonymous Coward

Given how much the government is vilifying Huawei, do we think they would really be pushing ISPs to bring in a new patch from them?

Re: Huawei

El blissett

Nothing nefarious about Huawei's kit or practices. Just that in a reverse of a recent Line of Duty finale, the world + dog would rather believe it's a red conspiracy rather than utter incompetence and laziness on the part of Huawei.

My isp just replaced my Huawei router and all the connection drop-outs and random packet-caused resets have vanished. I feel bad for all the times they called out Openreach when it was a PEBCAK.

Re: Huawei

Yet Another Anonymous coward

But it's not Huawei that are installing these routers, it's British ISPs.

So obviously the British ISPs are under the control of the Chinese Peoples Army. It's obvious to anyone who has tried to deal with them that they aren't hyper efficient free market capitalists.

Plus Branson has a beard so is obviously a communist and probably controlled by Corbyn (must stop reading Daily Mail)

iron

I suspect this survey of 6,000 UK adults had 5,999 responses of "what's a router?" and 1 response of "hahahaha I don't use ISP supplied kit."

Tech is slowly taking control.. because we let it.

Mike 125

The average 'home router' is modem + firewall + router.

One major risk is following instructions that come with your shiny new IoT garbage to configure port forwarding.

Here's a suggestion to ISPs: supply non-configurable routers.

In one easy step, we make people safer... and sadly, dumber.

Re: Tech is slowly taking control.. because we let it.

Roland6

One major risk is following instructions that come with your shiny new IoT garbage to configure port forwarding.

The average home user just plugs their router in, for them upnp does the necessary port opening, albeit with all of its security vulnerabilities.

Re: Tech is slowly taking control.. because we let it.

Yet Another Anonymous coward

No it's the internet that's the problem. Have the router connect to your ISPs website and that's all it can connect to.

Chat with all your friends on BT and death to the TalkTalk infidels

Dumb and Dumber

Flywheel

EE: ..a very low risk vulnerability for the small number of our customers who still use the EE Brightbox 2. ... it is recommended they only give network access to people they trust, and they should be suspicious of any unsolicited emails and web pages

RU Serious EE? How many people, especially those that are happy to have dodgy Chinese boxes foisted on them could honestly say that they could recognise phishing emails or malicious web pages? That's an unbelievable statement by what claims to be a responsible provider!!!

New PlusNet router

John H Woods

Thought I would use the same WiFi SSID and pwd, only to be told that many of the characters I use, backslash, curly brackets, quotes, etc (IIRC) are "not permitted." I've solved the issue by reusing my BT HomeHub router but I should imagine plenty of us here immediately think "hold on, how the hell are you storing this password?" when told that certain characters cannot be used.

Is all data equal?

Brian Miller

"and your data porn's flowing through these"

Based on what people actually visit on the web, the idea that a home firewall/router is out of date is not exactly an existential threat to much. Yes, somebody could hack it to mine Bitcoins. Someone could hack it to execute a DDOS attack. Etcetera.

Now, as for your data being "at risk" from dodgy router software, I'm absolutely sure that the larger security vulnerability for your data is the malware already on your computer, the malware already on the server you are accessing, and the APIs and data that have been left open to world+dog by developers who haven't mastered copy-and-paste from StackExchange, and of course that you've used the same password for, like, just ever , and it's been published at least 47 times from different dumps from said server data.

And you want to blame the poor router in the corner, blinking its lights in that lonely, forlorn pattern. (Yes, a pattern ...)

It is very difficult to prophesy, especially when it pertains to the future.