Live data from Hacker News

FCC updates covered list to include foreign-made consumer routers

fcc.gov

221–230 of 452 posts

Re: FCC updates covered list to include foreign-made consumer routers

#221
post #104
post #30

Earlier quoted context omitted.

Why shouldn’t people have a reaction to a policy that mandates a new approval process on a large class of consumer products?

It's fine to have a reaction. It just rhat a lot of the comments totally ignored this this caveat. So basically, as I read it by default, they're banned unless approved, which is pretty much what all regulation does anyway, isn't it.

During the last years USA has banned a lot of things by default, but in all cases there were exemptions for things receiving specific approvals.

However, the approvals appear to have not been based on any objective methodology, but sometimes nothing has been approved, while otherwise there may have been some approvals but their randomness was suspicious.

Now this new interdiction continues the trend, so it is normal for people to be wary that any approvals will be based on some kind of bribing and not on any serious security audit.

Re: FCC updates covered list to include foreign-made consumer routers

#222
post #22

Will this impact the Mono Gateway[0]? [0] https://mono.si/

It looks like it probably won't matter. The site says you can preorder a DevKit "Shipping between June and September 2025." The fact that they haven't updated that webpage with new information since October 1st 2025 seems to indicate bad news...

I preordered one, I got it, and I sold it. They are active on Discord. Why did I sell it? The shortcomings of the platform made me realize I should just go with UI, despite my reservations about the company.

Re: FCC updates covered list to include foreign-made consumer routers

#223

The FCC maintains a list of equipment and services (Covered List) that have been determined to “pose an unacceptable risk to the national security Recently, malicious state and non-state sponsored cyber attackers have increasingly leveraged the vulnerabilities in small and home office routers produced abroad to carry out direct attacks against American civilians in their homes. Vulnerabilities have nothing to do with…

> Vulnerabilities have nothing to do with country of manufacture. They have always been due to manufacturers' crap security practices. Sorry but this is merely a convenient excuse. Source: I have hard evidence of a Chinese IoT device where crap security practices were later leveraged by the same company to inject exploit code. It's called plausible deniability and it's foolish to tell me it's a coincidence. You're no…

[flagged]

Re: FCC updates covered list to include foreign-made consumer routers

#224

The FCC maintains a list of equipment and services (Covered List) that have been determined to “pose an unacceptable risk to the national security Recently, malicious state and non-state sponsored cyber attackers have increasingly leveraged the vulnerabilities in small and home office routers produced abroad to carry out direct attacks against American civilians in their homes. Vulnerabilities have nothing to do with…

> Manufacturers have never had to care about security because no Gov agency would ever mandate secure firmware. The problem is that "secure firmware" is a relativistic statement. You ship something with no known bugs and then someone finds one. What you need is not a government mandate for infallibility, it's updates. But then vendors want to stop issuing them after 3 years, meanwhile many consumers will keep using t…

Why not just put the onus on ISPs? 99% of users lease their router from their ISP. If updates stop after three years, looks like you're getting a complimentary service appointment to get a new router.

Re: FCC updates covered list to include foreign-made consumer routers

#225
post #176
post #51

Earlier quoted context omitted.

If US manufacturers (or manufacturers in allied countries) do this, legal avenues exist to hold those manufacturers accountable. Not so with China. (That is not to say that the FCC change will move the needle on the underlying issue of router security; as some of the ancestor comments have said, lax security practices are common industry-wide, irrespective of country of development/manufacture.)

The Snowden leak showed that Cisco routers had been altered to enable surveillance [1]. Whether or not the manufacturer is complicit, or how the alteration is performed is ultimately irrelevant to the end user. Ultimately, the only people that got in legal trouble for this were Snowden and people who provided service to him. [1]: https://arstechnica.com/tech-policy/2014/05/photos-of-an-nsa...

Actually it's entirely relevant how, in the context of this conversation.

Here, we're discussing product as shipped, not product intercepted and modified. We're discussing if products are shipped secure or not.

The Snowden disclosures are important, but not relevant in this case.

Re: FCC updates covered list to include foreign-made consumer routers

#227

The FCC maintains a list of equipment and services (Covered List) that have been determined to “pose an unacceptable risk to the national security Recently, malicious state and non-state sponsored cyber attackers have increasingly leveraged the vulnerabilities in small and home office routers produced abroad to carry out direct attacks against American civilians in their homes. Vulnerabilities have nothing to do with…

I suppose foreign routers might not have convenient mechanisms for the government to access and control them at will, hence the "unacceptable risk to the national security".

Re: FCC updates covered list to include foreign-made consumer routers

#228

Earlier quoted context omitted.

> consumer-grade routers that are produced in the USA Starlink?

I believe they make satellite components not consumer hardware in the US

The linked BBC article above says the Starlink terminals are made in Texas.

Re: FCC updates covered list to include foreign-made consumer routers

#229

Does it occurs to someone that in this time of encryption backdoor and such, this is also a good starting point to another mass surveillance system ? Mandate US manufacturers to embed remote access for the use of the government, then as you've made those routers the only ones authorized on the us soil (let's not be foolish about that approval process, it will be a smoke screen) you basically have a backdoor to every…

This is why users need to have an american router, chinese router, and russian router, all wired in series. That way no one spy branch has full backdoor access through the chain ;-)

Re: FCC updates covered list to include foreign-made consumer routers

#230

Does it occurs to someone that in this time of encryption backdoor and such, this is also a good starting point to another mass surveillance system ? Mandate US manufacturers to embed remote access for the use of the government, then as you've made those routers the only ones authorized on the us soil (let's not be foolish about that approval process, it will be a smoke screen) you basically have a backdoor to every…

Yes, that's what is happening here, except it goes beyond surveillance.

This is about full domestic control of the internet. For both ingress and egress.

Remember how Iran likely murdered thousands of protestors a few months ago, but we don't actually know? They want to be able to do that here.

Post reply on HN