Privacy/Surveillance Implications of using ISP issued Router? - eviltoast

cross-posted from: https://links.hackliberty.org/post/2005038

I know this is an outrageously bad idea, I don’t need convincing. I am just looking for some more information and discussion on what exactly the exposure and surveillance risk is.

I’m asking both for my own education (I am still very green to networking), and to better explain to people in my life if and why they should care.

  1. Is it true that traffic can be tracked and logged by ISP through DNS lookups, as these routers are preconfigured to use their internal dns service?

  2. If this is changed (like base.dns.mullvad.net), how much does this actually mitigate the risk here?

  3. What about when a VPN (mullvad) is also being used at all times? Would it then be “overly paranoid” to fear this untrusted box all the traffic goes through?

I personally take a conservative approach to things like this and assume it’s an unacceptable risk, but I don’t really understand what the truth is.

Thank you in advance for your time and thoughts.

EDIT: I’m asking about US and US adjacent areas

  • sic_semper_tyrannis@lemmy.today
    link
    fedilink
    English
    arrow-up
    2
    ·
    5 months ago

    Closed source and sometimes they prevent you from changing DNS and probably can’t put a VPN on it. Also I’ve read specifically about ASUS routers collecting information on the network seperate from the DNS so I would imagine every company is doing that.

    Changing your DNS to a private one is worth it as it’s incredibly easy to do and certainly can’t be a bad thing.