The expert warned about the danger of routers with a pre-installed VPN connection


Routers with a pre-installed connection to VPN services that do not require user participation are increasingly appearing on marketplaces. However, such devices can pose serious risks to information security. This was announced by Ivan Glinkin, an expert on infrastructure testing at Bastion, in an interview with Izvestia on June 22.
According to him, routers with a pre-installed VPN are available on most marketplaces and are more expensive than their usual counterparts. Nevertheless, as Glinkin emphasizes, using such devices in the initial configuration may be unsafe.
He clarified that in the best case, the connection of the routers will be unstable. They often connect to non-segmented networks and VPN servers hosted on low-cost hosting with a low level of protection. This poses serious risks to the security of the home infrastructure. The expert warned that attackers could use special software to obtain the IP addresses of other users on the same host.
In addition, there are cases when sellers retain full remote access to the devices sold. The instructions explicitly state that changing the firmware is prohibited, and access to the device from an external network is enabled in the router settings. Glinkin explained that this means that the seller can connect to the device at any time, unless the user manually disables this option. This scheme is often used to reduce technical support costs, but as a result, the user loses control of the configuration and may expose their traffic to the risk of interception.
"Do not connect questionable equipment directly to the network. Solutions that promise "out-of-the-box security" should be particularly wary. It should be remembered that offers like "unlimited VPN for a symbolic surcharge" require a critical approach," the source concluded.
On April 18, the Department for Combating the Illegal Use of Information and Communication Technologies (UBK) of the Ministry of Internal Affairs of the Russian Federation warned that using a VPN when working with banking applications could lead to the blocking of a personal account. It is specified that the regulator sets up a fraud protection system in such a way that it recognizes that it is the owner of the personal account who enters it.
Переведено сервисом «Яндекс Переводчик»