7.5 Million at risk from out-of-date ISP routers

Consumer watchdog Which? have investigated 13 legacy router models supplied by leading UK internet service providers (ISPs) including EE, Sky, TalkTalk, Virgin Media and Vodafone – a report discovered that around 7.5 million internet users are at risk from out-of-date hardware.

Out of the 13 router models investigated, 9 presented pressing security flaws that are unlikely to be in compliance with upcoming UK government legislation around tackling the security of connected devices.

The new legislation is in response to government figures showing that 49% of UK residents have purchased at least one smart device since the start of the COVID-19 Pandemic. Due to this huge increased national scope of vulnerability to potential cyber-attacks, the proposed legislation will ban easy to guess default passwords across all, enforces policies to make it easier to report software bugs that can be exploited by hackers on legacy or modern hardware.

Kate Bevan, Which?’s Computing Editor, commented that “proposed new government laws to tackle devices with poor security can’t come soon enough – and must be backed by strong enforcement.” Which? are simultaneously pushing for increased transparency from ISPs about how customers automatically or manually update their routers and how they should actively upgrade existing customers who are identified as being in the ‘at risk’ category.

Of those 7.5 million affected, 6 million users currently possess ISP hardware that has not been updated since 2018 and a few instances even as far back as 2016 – meaning that these vulnerable devices have not received security updates for defence against the latest threats posed by cybercrime.

A cluster of three main problems with ISP legacy hardware were identified by Which? ranging from weak default passwords that allow cybercriminals unlimited access to a router from anywhere, a lack of firmware updates and a local network vulnerability issue with EE Brightbox 2 giving potential hackers full control of the router to install malware or malicious spyware.

In response, Virgin Media have openly rejected Which?’s report conclusions; saying that 9 out of 10 customers are using their latest router models and are benefiting from regular router security updates. This sentiment was mirrored by BT Group (owners of EE), TalkTalk and Vodafone who announced that the HHG2500 device included in the Which? report has not been supplied since August 2019.

Devices with weak default passwords: TalkTalk HG635, TalkTalk HG523a, TalkTalk HG533, Virgin Media Super Hub 2, Vodafone HHG2500, Sky SR101 and Sky SR102.

Routers affected by lack of updates: Virgin Media Super Hub, Virgin Media Super Hub 2, Sky SR101, Sky SR102, TalkTalk HG523a, TalkTalk HG533 and TalkTalk HG635.

Routers that passed the Which? security tests: BT Home Hub 3B, BT Home Hub 4A, BT Home Hub 5B and Plusnet Hub Zero 2704N


BT to charge for unrecycled broadband routers

New customers will face a fine of up to £50 if they decline to return their BT router at the end of the contract, British Telecom have announced.

BT operates a scheme to recycle old routers, which will soon become compulsory, in an effort to reduce electrical waste and cut the volume of unrecycled broadband routers being sent to landfill.

Customers may voluntarily return their old router by following the instructions published here.

Entry-level Broadband routers from many major providers are locked to a single Internet Service Provider (ISP), which often causes spare routers to pile up in cupboards when customers switch broadband supplier.

The move follows a pattern of UK companies trying to bolster their green credentials, in the wake of Extinction Rebellion and other environmental movements gathering increased public support.

As subsidiaries, the BBC reports that the scheme will also ‘eventually’ apply to EE and Plusnet broadband customers.

Increasing numbers of local councils in the UK now offer direct recycling of small electrical items, reflecting a noticeable rise in the value of copper and other useful materials – giving home users few excuses not to attempt to recycle their old router.

 

For IT support & expertise – please contact our team today.


Lineal’s Ian awarded Certified DrayTek Network Admin

Lineal’s Ian Meredith has been awarded DrayTek Certified Network Admin Certificate, adding an additional qualification to Lineal’s networking experience.

DrayTek’s ‘Dray School’ requires network engineers to pass a series of advanced network and security configuration tests using DrayTek devices, routers and access points, including best practice for firewall settings, fault-finding and other detailed network tasks.

DrayTek’s business-grade Router range have won praise from across the IT Support sector recent years, with the provider winning a PC PRO Technology Excellence Award for five successive years (2014-18). DrayTek router models have proved highly popular with businesses, with intelligent features such as 4G fail-over increasingly in demand for business continuity requirements.

As a part of the 2-day examination procedure, each engineer’s router is attached to a testing network which judges whether the engineer has managed the device correctly, and automatically passes or fails based on a series of security checks.

Well done Ian!

 

For Networking and Security Expertise, contact Lineal today.