News: 1623405727

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

BT promises firmware update for Mini Whole Home Wi-Fi discs to prevent obsessive Big Tech DNS lookups

(2021/06/11)


Users of BT’s Mini Whole Home Wi-Fi range-extender discs have noticed their devices are making hundreds of thousands of daily DNS lookups for big tech companies’ websites – causing problems for some wanting to access Gmail and Microsoft services.

The huge volume of requests generated by the BT-branded discs has caused problems for some Reg readers after their DNS-lookup-spewing IP addresses were flagged by their DNS providers as hives of malicious activity.

Irritated individuals have told us each of their discs generates one DNS lookup for google.com every second – meaning one disc generates 86,400 lookups a day. For those using three or four discs and a custom DNS server configuration, the impact is enough to get their IP addresses flagged as suspicious, we were told.

[1]

Reg reader Martin said each of his six Wi-Fi range extender discs were making DNS lookups for Microsoft. After he noticed the volume of lookups directed at Google, he blocked them – resulting in the devices hunting for Redmond’s IP address instead. Six times per second.

[2]

[3]

Fellow reader Andy told us he'd “been having issues for months with a variety of services popping up insisting that they’ve detected suspicious activity from my account and I’ve never understood what has been causing it. Even just performing a Google search can require me to do an ‘I’m not a robot’ check.”

[4]

Eventually, Andy realised what was going on when he [5]installed a Pi-Hole network-level adblocker on his home network. Logs showed DNS requests being made every second from a local IP address (192.168.nn.nn).

Both Andy and Martin found a BT [6]support forum thread where others had spotted similar behaviour from their BT Wi-Fi discs. A support rep posting as “darren_b” revealed on 22 May that BT had a patch up its sleeve to stop the discs from bombarding DNS providers with lookups for Big Tech, posting:

Although this issue is known and understood, the Mini’s current firmware has been very stable for the majority of our customers with minimal cases into the Whole Home helpdesk. We’re keen to ensure that this remains the case for future firmware releases - so we don’t want to rush firmware out until we’re happy it’s stable and reliable for everyone.

As I’ve mentioned before the issue has been addressed in the next version of the firmware, and whilst I can’t confirm that date yet I will post on here as soon it’s available to install.

User Martin_z replied: “Well, thanks for finally replying. However, it's been well over a year since you said that the issue was going to be released in the next version of firmware.”

The flaw means BT’s DNS servers will be handling tens of millions of spurious lookups per day – and it’s easy to see how a third-party DNS provider, or another ISP that doesn't recognise the traffic as benign, could end up treating such large volumes of lookups as suspicious.

[7]Which? warns that more than 2 million Brits are on old and insecure routers – wagging a finger at Huawei-made kit

[8]What a mesh: BT Whole Home Wi-Fi users moan over update

[9]Infrastructure SNAFU results in French public being unable to contact emergency services

[10]Tech industry quietly patches FragAttacks Wi-Fi flaws that leak data, weaken security

When we asked the one-time state telecoms monopoly for comment, a spokesman told us the flaw only affected those users with custom DNS setups on their personal networks.

“We understand how important connectivity is to our customers and like other products on the market, BT Mini Whole Home Wi-Fi has server requests built in to alert customers of any connection issues as quickly as possible,” said a BT spokesman. “We recognise that there are a small number of customers who have personally set up a custom DNS server configuration at home, and that the frequency of these checks can lead to them seeing additional network traffic.”

The discs can be used on any ISP’s network, not only BT’s. Indeed, our reader Andy said his Virgin Media-supplied connection seemed to have been flagged for suspicious activity.

[11]

BT’s spokesman continued: “We have included an update within a new wider firmware, which significantly reduces the frequency of these server requests. We had planned to roll this out sooner, however due to changes in prioritisation following the exceptional circumstances of the past year, this has taken longer than anticipated. We would like to apologise to the small number of customers impacted by this matter.”

The spokesman did not answer our questions as to why the range extenders need to be making DNS lookup requests in the first place. While the answer could be as simple as checking that a working internet connection is present, doing so every second is excessive.

This is not the only mystery problem that has afflicted these BT Wi-Fi range extender discs. Back in 2018 a borked firmware upgrade caused connectivity-nixing problems that [12]resulted in irate users having to constantly reboot them to stay online. ®

Get our [13]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YMOInS3rgLSdPSbYpOFOnwAAAME&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YMOInS3rgLSdPSbYpOFOnwAAAME&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YMOInS3rgLSdPSbYpOFOnwAAAME&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YMOInS3rgLSdPSbYpOFOnwAAAME&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://docs.pi-hole.net/

[6] https://community.bt.com/t5/BT-Devices/BT-Mini-Whole-Home-DNS-requests-for-Microsoft-Google-and-Apple/td-p/2001908/page/4

[7] https://www.theregister.com/2021/05/06/which_router_survey/

[8] https://www.theregister.com/2018/03/26/bt_whole_home_wi_fi_issues/

[9] https://www.theregister.com/2021/06/03/infrastructure_snafu_results_in_french/

[10] https://www.theregister.com/2021/05/12/krack_hack_wifi/

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YMOInS3rgLSdPSbYpOFOnwAAAME&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[12] https://www.theregister.com/2018/03/26/bt_whole_home_wi_fi_issues/

[13] https://whitepapers.theregister.com/

BT… Phone… Home…

Dave559

"BT… Phone… Home…"

Wait, no! Not like that!

This sounds like the dumbest way of checking for internet connectivity imaginable, essentially trying to DDoS well-known sites. Hopefully a future "Who, me?" article will confess why someone ever thought that was a good idea…

Re: BT… Phone… Home…

Dan 55

One wonders why they didn't spam www.bt.com. Perhaps their website isn't reliable enough?

flaw only affected those users with custom DNS setups on their personal networks.

tip pc

"the flaw only affected those users with custom DNS setups on their personal networks."

The flaw affects everyone, just that BT don't trigger rate limits or extra checks when their DNS servers are used.

while I don't have these disks, I'm dropping all tcp/udp 53 on my fw and have a pi-hole requesting to a cloudflare DoH proxy.

doesn't stop the new fangled browsers or other IoT doing the same though so I may not see what the IoT is looking for if they do DoH too.

Ping?

Fonant

Why not ping to see if a connection is available?

I suspect something targetted-advertising-related is going on. Still Big Money available in that field, it seems.

Re: Ping?

the spectacularly refined chap

You still need an IP address to ping. You know, the one you get from DNS...

Re: Ping?

iron

You could ping a known IP address that isn't going to change without using DNS. Maybe one provided by BT themselves.

Re: Ping?

AndrueC

Why not ping to see if a connection is available?

And another reason is that responding to a ping is not mandatory. Any router or the target device can decide not to bother if it can't afford the time. It might also be configured never to respond to pings at all.

A ping failure does not necessarily indicate a connection failure. It might not even indicate a fault. And if it indicates a fault it could be so close to the target as to be irrelevant/unfixable.

Anonymous Coward

BT Retail have Phorm for crap like this.

Pixelated Paula

Roland6

Now we know why Pixelated Paula's broadband suddenly started to fail, she had installed BT Home WiFi discs...

zb42

BT recently pushed new firmware to "Smart Hub 2" internet boxes.

It broke communicatioms between devices on the 2.4GHz and 5GHz wifi bands.

I have the log from one Hub2, it took a little over a month from BT saying that they had a fixed version of the firmware until it was actually pushed out to the box. An old wifi access point as a workaround is still plugged in at that office.

OpenSauce

I logged the following with BT on 12th Feb this year:

I have noticed my firewall getting connections to AKAMAI every second

and hogging firewall resources.

The disc is trying to connect to various Internet addresses:

23.40.113.217

23.56.184.216

104.78.177.250

104.121.137.246

Got a reply on 3rd March saying BT were investigating and believed would be fixed in the next release of firmware, and they'd inform me when it was available.

Heard nothing, problem still exists.

John Sager

If this is supposed to be a link integrity check, it's a criminally stupid way of doing it. My ISP sends LCP echos to my border router every second in the PPP session to monitor link integrity, delay, etc. That's the proper way to do it.

Patageometry, n.:
The study of those mathematical properties that are invariant
under brain transplants.