Hacker News new | ask | show | jobs
by ciucanu 2468 days ago
That's another reason for putting another router after your ISP's box. As long as I'm not an admin on that one, they can do a lot of shady things. Also using a DNS server with external forwarders (PiHole is great for that).
3 comments

Not only that, but the quality of commercial router security is appalling. See for example

https://www.securityevaluators.com/whitepaper/sohopelessly-b...

That paper needs wider exposure, though sadly it didn’t get much traction here when I submitted it.

This should not be underestimated. The ISP cannot be trusted and DNS poisoning is easily done through their box.
The problem is that the number of attack vectors are legion. If they don't get you by DNS they'll get you by one of the thousands of other attack vectors.