The US router ban hammer has been wielded – here’s why it’s so stupid

Just when you thought the stupid couldn’t get any stupider, more stupid happens. The US Federal Communications Commission has banned the sale of all new consumer routers “made in foreign countries,” having determined that they “pose an unacceptable risk to national security or the safety of Americans.” Yeah, riiiight.

The full announcement makes for painful reading, but here’s the core reasoning to save you from getting too much brain ache: foreign-produced routers carry a “supply chain risk” that could “immediately and severely disrupt US critical infrastructure and directly harm US persons”. Have I said yeah riiiight already?

“The FCC will continue to do our part in making sure that U.S. cyberspace, critical infrastructure, and supply chains are safe and secure,” said FCC Chairman Brendan Carr.

So, why is this stupid? Well, just about every router is made or assembled in foreign countries and contains parts from abroad. Which would mean, taken to its logical conclusion that, as no new sales are allowed, only your existing old router will do. The one that, eventually, will stop getting firmware updates and become a security risk.

In short, there’s no point in having a “Made in the USA” badge unless you can apply it all the component parts too. Although “Assembled in the USA” doesn’t have quite the same ring.

Why the US router ban is a security risk according to the experts

Don’t take my word for it. Here’s what some cybersecurity professionals think of the decision.

“Moves by regulators to restrict new authorisations for foreign-made routers reflect growing concern around supply chain integrity, but focusing solely on country of origin risks oversimplifying a much broader security challenge,” said Shane Barney, CISO at Keeper Security. “That risk is often compounded through weak governance rather than manufacturing geography.”

“The point is ‘Made in’ isn’t the same as secure, not even close,” warned Rik Ferguson, VP Security Intelligence at Forescout. “What consumers and organisations should be doing right now is simple: replace end-of-life routers, keep firmware current, disable internet-exposed management, turn off UPnP where you can, enforce unique admin credentials (and MFA where supported), and segment IoT away from work devices and router management, because that reduces exploitation risk regardless of who built the box.”

Now let’s move to Damon Small, who’s on the board of directors at Xcape, for a slightly different take. “By citing the weaponisation of SOHO routers by groups like Volt Typhoon and Salt Typhoon, the FCC is treating the humble home router as a primary vector for national-scale pivot attacks against critical infrastructure,” said Small.

While stating that the FCC is “finally treating home routers like the Trojan Horses they are,” Small pointed out that adding Made in the USA will likely “magically add 40% to the MSRP and zero to the patch frequency”.

I will leave the final word to Matt Wyckhouse, Finite State Founder and CEO, who backed up my earlier statement when he concluded that “effectively, the FCC would ban all new routers, because there are no domestic routers that meet that standard today. There’s no one who can clear the bar right now.”

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.