Remix.run Logo
ButlerianJihad 20 hours ago

Consumer-grade edge routers are absolutely the weakest link of all time, in Internet security. Yet they are not optional if you have a consumer-grade home Internet connection. The router manufacturers do not care how insecure they are.

About two years ago, I signed up for NextDNS, which is a fantastic managed 3rd-party DNS service. NextDNS is capable of "PiHole" style ad blocking, as well as filtering adult content and basic security hygiene. They do have a functional free tier to try it out. As a bonus, you also get excellent logging capability, and these logs are stored on NextDNS's servers.

So, at the time, I had a consumer-grade router, and a few devices on the home LAN, and they were all configured to query NextDNS directly. And this was working so smoothly. Well, one night I went to see a horror film with friends, and when I arrived home, I found very disturbing entries in the logs. The DNS logs were clogged with cryptic, inexplicable entries that pointed to only one conclusion: my router was compromised, and had joined some kind of botnet.

I checked my Windows machine, and my smartphone, and other devices, which were all clean, and the router was the only pwned device. I identified 1 or 2 CVEs which may have allowed unauthorized entry to the router's admin interface. I yanked it out of the network and took a Dremel to its innards. I also discovered that my obsolete router's installation of OpenWRT was compromised. Dremel time again.

After several rounds, around and around with my ISP about their duties and ability to provide reliable WiFi service, I again purchased a consumer-grade WiFi router, this time from Netgear. Now in 2026, there is no "antimalware software" for consumer routers. These router admin interfaces have no visibility for the admin to see running tasks or processes, or determine whether there is malware payload installed or running, or listening on external ports. No way to tell. There is indeed "security software" sold, even by annual subscription, but this software simply does some lame port scans of your LAN. That's right, it's scanning all devices except for itself and expects to point fingers at your other hardware for security issues! That is deflecting blame.

Sadly, having discontinued my NextDNS subscription and therefore the logging facility, I again have no visibility into my WiFi router (nor the ISP router running in Bridge Mode now.) I would not know if they are compromised, but they probably are. Yours are, too. It is nearly certain that most people, having a residential IP with good reputation, has a residential proxy Trojan running on it currently, and is a member of at least one DDoS botnet, and you have absolutely no way of telling. Your ISP does not care; your ISP will not scan or detect it proactively, and if they receive any complaints, they would not tell you so.

It is very sad, in 2026, that a supposedly "loyal" company as Netgear should have such atrocious security. No visibility, no detection, no logging, just finger-pointing. They should all be ashamed of themselves. ISPs should have some mechanism to seek out botnet members, residential proxy providers, and shut down those malicious, wasteful, fraudulent connections, and restore some sanity to metropolitan networks and backbones.