

US Congressional Panel Urges Americans To Ditch China-made Routers (reuters.com) 141
A U.S. congressional committee has urged Americans to remove Chinese-made wireless routers from their homes, including those made by TP-Link, calling them a security threat that opened the door for China to hack U.S. critical infrastructure. From a report: The House of Representatives Select Committee on China has pushed the Commerce Department to investigate China's TP-Link Technology Co, which according to research firm IDC is the top seller of WiFi routers internationally by unit volume. U.S. authorities are considering a ban on the sale of the company's routers, according to media reports.
Rob Joyce, former director of cybersecurity at the National Security Agency, told Wednesday's committee hearing that TP-Link devices exposed individuals to cyber intrusion that hackers could use to gain leverage to attack critical infrastructure. "We need to all take action and replace those devices so they don't become the tools that are used in the attacks on the U.S.," Joyce said, adding that he understood the Commerce Department was considering a ban.
Rob Joyce, former director of cybersecurity at the National Security Agency, told Wednesday's committee hearing that TP-Link devices exposed individuals to cyber intrusion that hackers could use to gain leverage to attack critical infrastructure. "We need to all take action and replace those devices so they don't become the tools that are used in the attacks on the U.S.," Joyce said, adding that he understood the Commerce Department was considering a ban.
Canada (Score:5, Insightful)
Re:Canada (Score:4, Insightful)
Re: Canada (Score:2)
Re: Canada (Score:2)
Re: (Score:2)
Re: Canada (Score:3)
Re: (Score:2)
People aren't going to get rid of equipment because of some vague reference to 'an attack is possible'
Agreed. In my opinion, much of the U.S. public ignores that kind of reference. Not important and they can always claim ignorance.
Re: Canada (Score:2)
War has changed, there is now a digital element (Score:2)
When I google on it, there is no explanation of any attack that has been seen from or against a tplink router ever.
That's Dec 6 1941 thinking, Sep 10 2001, thinking. The US is expecting and preparing for a digital attack, one that is likely launched to support a real world offensive. Say taking Taiwan by force.
The TP-Link router may be an erroneous call, the person making this call may be ill informed, but it is highly likely that China, Russia, USA, etc all have their respective digital warfare programs aimed at each others infrastructure. Vulnerable home users could be useful. Not only as cutouts obscuring where an
Re: (Score:3)
Are there any home routers made 100% in America that every component can be fully vetted and trusted? Because I don't know of any. I'm happy to swap out my router, but exchanging one (potential) security problem for another, isn't solving the issue.
Re: (Score:2)
Are there any home routers made 100% in America that every component can be fully vetted and trusted? Because I don't know of any. I'm happy to swap out my router, but exchanging one (potential) security problem for another, isn't solving the issue.
The practical solution is to find a router where the software is developed and published in the US or EU.
I've worked for a US tech company. We strictly controlled the software, declined generous offers by Chinese partners to let them take care of software maintenance for us, and verified the software installed in manufactured products. YMMV.
I'd go with a router that your are free to update to open source.
https://openwrt.org/ [openwrt.org]
Re: War has changed, there is now a digital elemen (Score:2)
Re:exactly (Score:4, Insightful)
That makes no sense.
When the snake says "don't trust the scorpion," do you then defiantly trust the scorpion?
No. You trust neither the snake nor the scorpion.
Clue: Both sides may lie. Verify things yourself. (Score:3, Interesting)
You can pretty much assume that anytime the US government tells me I shouldn't trust China I should do exactly that.
That's foolish. Here's is some quite useful knowledge:
When when side is untrustworthy, that does NOT mean the other side is trustworthy. Both may be untrustworthy.
Also, the untrustworthy may tell the truth if circumstances are coincidentally on their side.
This is why we apply scientific and logical principles and verify things ourselves.
Re: (Score:2)
Yeah as an Aussie, while we havent (for now) copped the same absurd venom the poor canadians have , for absolutely no morally sound reason, I fear it might be only time.
China is a problem. The Americans could become a problem.
Mikrotik! Latvians aint posed us no threat at all.
Re: Canada (Score:2)
Re: (Score:2)
Putin has very little influence in that region. It's all China.
Nothing immoral about interdicting Fentanyl (Score:2)
... for absolutely no morally sound reason ...
Canada has had 200+% tariffs on some US goods for many years (decades?). In particular agriculture. There is nothing immoral about reciprocating.
The current administration believes that Canada could do more about Fentaynl smuggling. Fentanyl is responsible for about 85K deaths in the US in 2024. In comparison the US suffered 58K deaths during the entire Vietnam war.
There is nothing immoral about interdicting Fentanyl smuggling. Tariffs are just being used to get Canada to act. They are not designed t
Re: (Score:3)
I can agree somewhat, and I'm not of the opinion that tariff's are automatically bad (though I'm under no delusion that they won't cause prices to go up dramatically here in the US - the Trump admin keeps saying otherwise). However, these tariffs are also coming along with repeated jokes/threats about taking over Canada, making it the "51st state", and referring to its elected leader as the "Governor" of Canada (for those not in the US - "Governor" is the title in the US applied to the leader of a state, n
Re: (Score:2)
However I think they are really addressed at Trudeau, not at Canada.
Re: (Score:2)
trump never jokes. It is definitely a threat. He's quite serious. If his economic war doesn't do the job, I fully expect he will mobilize the military, perhaps in an initially-limited area with resources he wants to take, like Alberta. So bizarre we can even talk seriously this way about the United States. Seems like reading a dystopian novel. But here we are. He broke all the old norms that brought everyone peace and prosperity for all these years.
You're absolutely right about the damage trump has ca
Re: (Score:2)
An interesting ideal of "fairness." Let's look at the size of the economies. The US dwarfs Canada in all ways. Having access to certain Canadian markets like dairy would not do much to benefit the US economy. But if they did have access it would completely destroy domestic dairy production in Canada overnight. That's why there are tariffs on some things. The US would justifiably do (and does) the same thing for certain industries. That is understandable. But trump wants nothing less than complete sub
Re: (Score:2)
An interesting ideal of "fairness." Let's look at the size of the economies. The US dwarfs Canada in all ways. Having access to certain Canadian markets like dairy would not do much to benefit the US economy.
Which is why the US normally ignores the 200+% protectionist tariffs on ag. The fact remains such tariffs invalidate the "moral" argument when Trump threatens, for example, a 25% tariff on Canadian manufacture automobiles.
But trump wants nothing less than complete subjection to his personal will of Canada.
Nope, it's a negotiating tactic for specific concessions. He did this during his first term with both Canada and Mexico. You seem to be taking the "51st state" / "Governor Trudeau" jokes way too seriously. Yes, they are childish. While Trudeau may warrant some mockery and disdain (Trucker
Re: Nothing immoral about interdicting Fentanyl (Score:3)
The agreements between the two countries were in balance for many years. Now it is Trump that has violated these agreements.
Re: (Score:2)
Oh and by the way the fentanyl reason is complete BS. Trump already got what he said he wanted regarding that. And it's contradicted by trump's other demand, which is that Canada become a part of the US. If Canada was a part of the US, which would make the US government responsible for the control of fentanyl traffic.
Also add to that trump stated explicitly that nothing Canada can offer will cause him to remove the tariffs. There's literally nothing to negotiate.
And finally the fact that trump won't eve
Re: (Score:2)
Oh and by the way the fentanyl reason is complete BS. Trump already got what he said he wanted regarding that.
He seems to be saying otherwise. Yes, Canada has made some efforts regarding Fentanyl, Trump finds them insufficient.
And it's contradicted by trump's other demand, which is that Canada become a part of the US.
If you take that childish mocking/insulting of Trudeau seriously, well, that's laughable. I do feel bad that this mocking is insulting to Canadians in general. I offer my apologies to my neighbors, they are rightfully annoyed.
Also add to that trump stated explicitly that nothing Canada can offer will cause him to remove the tariffs. There's literally nothing to negotiate.
No, he's said that retaliatory tariffs will not deter his reciprocal tariffs.
Re: Nothing immoral about interdicting Fentanyl (Score:2)
Re: Nothing immoral about interdicting Fentanyl (Score:2)
Re: (Score:3)
There's more fentanyl smuggled into Canada from the US than the other way around. All that stuff is purely theatre to justify the obscure emergency national security law that lets the US president levy tariffs... something that is normally a congressional power.
You might want to consider very carefully the moral and other implications of one man usurping power specifically denied him by your constitution based on a made up national security emergency.
Re: (Score:2)
The phrase, the enemy of my enemy is my friend, refers to your two enemies fighting themselves instead of you.
Those enemies are still a problem when they are actively attacking you individually.
Re:Canada (Score:5, Insightful)
I don't trust China either. But... if someone's going to spy on me, given I don't work for the government or for any company the Chinese might want to compete with, there's an argument that I'd be better off with China doing it than the US. I mean, China sucks, but I can sit there posting Tank-guy memes and there's not a lot they can do about it. And that'll be true in four years too. But I'm not sure in four years I'll be able to post in support of various marginalized groups and not have the US government, or the security-state remnants of it, come to fuck with me in some shape or form.
Or maybe that won't happen and sanity will prevail, but things are dark right now.
Canadian protesters unable to do banking (Score:2)
Brother, you could've posted memes in support of the truckers and found yourself unable to engage with the banking system in Trudeau's Canada or had you forgotten already?
"Trudeau vows to freeze anti-mandate protesters' bank accounts"
...
He said the police would be given "more tools" to imprison or fine protesters"
"With no need for court orders, banks can freeze personal accounts of anyone linked with the protests.
https://www.bbc.com/news/world... [bbc.com]
I seem to remember Australia being quite heavy handed and breaking new ground on violating civil liberties too.
I disagree with the protesters, I'm vaxed and boosted 4 times (is it 5?), but these seems to be quite the overr
Re: (Score:2)
Re: Canada (Score:2)
They're obviously not talking to you. You can keep yours.
My chinese router runs OpenWRT (Score:4, Informative)
My cheap Chinese router runs OpenWRT, and I don't think Chinese state actors have managed to insert malicious code into that project given how thoroughly it is reviewed by its developers and the F/OSS community.
Re: My chinese router runs OpenWRT (Score:2)
Congress critter: oh... well... now I haven't though if that one. Arrest him he's a witch with his custom firmwares!
Re: My chinese router runs OpenWRT (Score:5, Informative)
This is all just more frustrating xenophobic economic protectionist bullshit from our legislators.
Essentially all routers with services exposed to WAN are containing security vulnerabilities.
Because none of the manufacturers are paying adequate attention to security issues.
Chinese manufacturers like TP-LINK are not in any way special.
A ban on one manufacturer does not solve the problem nor does it make people less hackable.
If you believe it is important that consumers have secure routers, then you need regulation of
IT security issues in consumer products.
Re: (Score:2)
What's special about TP-Link is that even their low end hardware runs the same OS as the high end gear. Some features might be disabled due to performance limitations, but for the most part you get all the "premium" features.
That annoys Western manufacturers who like to differentiate their product tiers by disabling features on the cheaper ones. Chinese cars often do the same thing.
Re: My chinese router runs OpenWRT (Score:2)
This makes no sense whatsoever and smells of a conspiracy theory, which isn't at all out of character for you because I already know you like to create disinformation.
Why do I say that? Well, if that really bothers them, then why the fuck would they spend lobbying money when it would be a hell of a lot easier to just enforce code signing to block third party firmware that already enables this on their own cheaper hardware anyways?
Re: (Score:2)
TP Link specifically uses a remote service to manage access to the device.
I believe that is true for likely some of their new hardware that uses an "App" to manage it, and all management is through the app.
I also have TP-Link Switches and routers that do not and which have a traditional CLI over the serial port, SSH, and Web-based management. There is no cloud service that these units connect to.
Re: (Score:2)
That is not true.
Re: (Score:2)
Services exposed to the WAN are probably not a real concern.
It is the epic mountain of the software on all your other devices any of which could call home and be a C&C channel and be sending back any manor of data about your inside network. It is all encrypted and it is all going to Azure/AWS/GCP/Ali/etc IP blocks.
Your poor router has no ability to provide you any protection because there is nothing to make a decision on the traffic is opaque and the destination is cloudy and conflated with 100,000 leg
Re: My chinese router runs OpenWRT (Score:2)
Re: (Score:2)
It is the epic mountain of the software on all your other devices any of which could call home and be a C&C channel and be sending back any manor of data about your inside network. It is all encrypted and it is all going to Azure/AWS/GCP/Ali/etc IP blocks.
You are correct. Under no circumstances should your security rely on trusting that hackers don't have access to the network behind your router.
If you want a secure network, then you need a true Firewall behind your router and separate network segme
Re: (Score:2)
You don't need to expose services on WAN to have security vulnerabilities...
Plenty of things exploitable via XSRF, or via wireless, or potentially in the ALGs etc.
Re:My chinese router runs OpenWRT (Score:5, Informative)
Ninja'd! I came here to say the same thing. And one of the great things about OpenWRT is it runs on all kinds of stuff, including a TP-Link ac1750, which is a good, cheap, reliable option. My parent's house has used one since 2008 with repeaters. QoS FTW!
https://openwrt.org/toh/start [openwrt.org]
Re:My chinese router runs OpenWRT (Score:5, Insightful)
My cheap Chinese router runs OpenWRT, and I don't think Chinese state actors have managed to insert malicious code into that project
But beware that often OpenWRT doesn't/cannot (if in ROM) replace the bootloader, the code that runs first when the device is switched on (then hands over control to the OS).
Re: (Score:2)
I'm all for OpenWRT, and only buy OpenWRT compatible devices.
My cheap Chinese router runs OpenWRT, and I don't think Chinese state actors have managed to insert malicious code into that project
But beware that often OpenWRT doesn't/cannot (if in ROM) replace the bootloader, the code that runs first when the device is switched on (then hands over control to the OS).
I recently bought a TP-Link Archer C7 v5 (AC1750) for a friend and installed OpenWRT on it. It was inexpensive and is very well supported by OpenWRT. According to their Supported devices page, it uses U-Boot for its bootloader. In any case, I'm comfortable with this.
Re: (Score:2)
Ninja'd! I came here to say the same thing. And one of the great things about OpenWRT is it runs on all kinds of stuff, including a TP-Link ac1750, which is a good, cheap, reliable option. My parent's house has used one since 2008 with repeaters. QoS FTW!
https://openwrt.org/toh/start [openwrt.org]
I recently got an AC1750 (v5) for a friend and installed OpenWRT on it. Picked it specifically as it was inexpensive, fairly capable and very well supported by OpenWRT. Seems pretty solid. At home, I just replaced my D-Link DSR-250 with a spare PC running OPNsense, attaching my D-Link DAP-2660 AP for wireless devices -- which is also supported by OpenWRT, but I haven't switched it to that (yet).
Re: (Score:2)
Okay, what about the people using stock firmware?
Re: My chinese router runs OpenWRT (Score:2)
While I'm both a user and producer of open source code, it's really not a good idea to blindly assume that open source is always benign.
buy American! (Score:2)
Re: (Score:2)
Re: (Score:2)
There's always Zenith, who developed the three button TV remote control clicker that never needs batteries. They must still be in business.
Re: (Score:2)
Zenith is still in business. Though, it's a wholly-owned subsidiary of LG since 1999.
And that clicker remote-control was pretty clever for its time.
Re: (Score:2)
Re: (Score:2)
I checked with Crosley and Atwater Kent and neither make routers.
Re: (Score:2)
I checked with Crosley and Atwater Kent and neither make routers.
Try Babcock & Wilcox...
Re: (Score:2)
Okay... which leaves _what_ exactly? (Score:5, Insightful)
Please, oh wise congressional panel, tell us which models on the market today _aren't_ at least partially made in China.
Re: (Score:2)
Difference (Score:4, Interesting)
Re: (Score:2)
Re: (Score:2)
All hail America!"
* the continent
Re: (Score:2)
We have a brand new TRUMP router available.
Stop giving him ideas. :-)
Re: (Score:2)
I wouldn't doubt anything you said, except for the "made in America" part.
Great (Score:5, Insightful)
A U.S. congressional committee has urged Americans to remove Chinese-made wireless routers from their homes, including those made by TP-Link, calling them a security threat that opened the door for China to hack U.S. critical infrastructure.
Oh good, let's go buy new shit immediately after kicking off economic chaos.
Re: (Score:2)
Yeah that is not happening soon (Score:3)
Ditch China made routers? (Score:2)
Most hardware is China made. Our laptops, desktops, mobiles... the list is endless. Are they going to ask us to ditch all of it eventually? Do they have a contingency plan or are they just pulling this ribbon out of their rear? Who are these people in the US congressional committee and were they sleeping all these decades to suddenly ask us to do this?
Re: (Score:2)
How am I to know about Asus? (Score:2)
Should be Taiwanese, but seems like they'd be a very likely infiltration target for China.
Re:How am I to know about Asus? (Score:4, Informative)
If you believe the NSA the Supermicro boards were bugged from the factory.
Also Cisco.
Also Ed Snowden proved they lie to Congress.
Also no arrests.
Re: How am I to know about Asus? (Score:2)
Re: How am I to know about Asus? (Score:2)
Yeah, I'm aware of domestic spying and I am against it, support the EFF, EPIC and ACLU with annual donations to fight against it and other US governmental abuses.
But I'm interested here in Chinese infiltration. Asus is a pretty good choice for quality. I wanna know is it free of Chinese backdoors.
Why? Russia (hence China) are USA's friends now. (Score:5, Informative)
Why do in USA care anymore? Our own government openly support Russia now, as of 03/2025 and hence Russia is pretty much owned by China due to it's being supported during the war, the USA is lining up with both. So nothing to fear from China and Russia, our new "friends".
Re: (Score:2)
Why do in USA care anymore?
Please diagram that sentence.
Re: (Score:2)
The grammar is correct in Ukrainian.
Re: (Score:2)
Sorry, Why does USA care anymore.
Re: (Score:2)
Transitive verbs specially gotta go, turns our kids be fruits!
Also, Trans-Atlantic relations.
Re: (Score:2)
It's doubleplus good, actually.
Seriously the description of language in 1984, and how it can be used to control how people think, is fascinating.
PFSense... (Score:2)
My AP is manufactured in china, but my router is just a normal computer. Which... to be fair... was probably partially manufactured in china.
Yep, only US backdoors are good backdoors! (Score:2)
They still stink just the same...
Whatever credibility Congress had is long gone (Score:2)
Re: (Score:2)
Geriatrics are just fine; age seems the last widely supported bigotry!
The problem is corruption not age. If you are lucky enough to have a reasonably honest politician or even more lucky to have a reasonably competent one, then you need to hold onto them as long as possible!
OpenWRT (Score:3)
I have a TPLink in my chicken coop/ham shack doing VLAN routing.
It runs an OpenWRT and I have zero concern about China.
Do they mean running stock hardware with remote admin web interface turned on?
Congress sounds like it is truly inept.
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
Sure, enclosing your antennas in a Faraday cage will block all harmful interference (and all other signals as well). Your shack on the other hand is not likely a source of RFI.
ISP Replacements (Score:2)
I have Omni Fiber in Ohio that supplies TP-Link routers to their customers. Will ISPs be required to pull and replace these? And if so, with what? Damn near all tech companies have opted to have their devices built in China using slave labor. Will customers be allowed to reflash their ISP provided routers? I don't think so. And even if they could the router's boot loader does not get replaced leaving a threat still possible. The government was warned over 30 years ago that allowing companies to get so embed
As opposed to American made wireless routers? (Score:2)
remove Chinese-made wireless routers from their homes,
Ok, well I have these Google (er, Nest...no...Google?) WiFi routers, made in....oh hey China! Maybe I should ditch them and buy some American Amazon Eero WiFi routers? I think they are made in Vietnam, that’s good right? Yeah? No? Should I fall back on my very very old Apple WiFi routers most definitely made in China?
Does anyone make WiFi routers in the USA?
Also (Score:2)
But where's the congressional panel urging the US to ditch Russian-made presidents?
Does congress even matter anymore? (Score:2)
And why should I listen to what they have to say when their own constitution doesn't matter anymore? Why should anyone care when the government doesn't and allows a clown to play games with peoples lives. How can anyone believe anything coming from the US government and that clown?
Yeah Canada is causing the fentinal problem is the states because too much is getting out and into Canada. That's why we need tariffs.
King Musk running around like a chicken with his head cut off inventing lies to justify stupidit
Congressional panels (Score:5, Interesting)
So where's the congressional panel's report on why we should pay any attention to literally anything this Congress says, when they've abdicated their oversight responsibilities into a glorified rubber stamp session for Mudface Caligula and his merry band of billionaires trying to auction off every bit of this country they can to the highest bidder while trying their level best to tank the economy to bread-lines degree?
Fuck those oath-breaking traitors. When they start doing their jobs again, I'll start listening to what they have to say about anything.
And yet, Cisco... (Score:2)
Of course running any equipment on your network requires that you trust it. But why should we, especially outsido if the USA, trust US equipment more than chinese one?
The only kind of secure solution is audited open source software. OpenWRT, as others have mentioned.
There was also a great CCC talk by Bunnie about what could be done to make hardware at least kind of ve
Re: (Score:2)
With the ability to run cloud based servers anywhere, exactly how are you going to determine if a packet is ultimately destined for China? Any information really important can be downloaded "locally" and go in a diplomatic pouch.
Re: (Score:3, Informative)
So if you use Huawei they would find it more inconvenient to pwn you (maybe they'd have to burn some
Re: (Score:2)
Re: How about a trade in program (Score:2)
Re: (Score:2)
Make your own router [stlmotherhood.com]