Make no mistake, this is 100% going to be Comcast’s alternative to more expensive surveillance options a la Flock, or workplace presence sensor arrays.
Make no mistake, this is 100% going to be Comcast’s alternative to more expensive surveillance options a la Flock, or workplace presence sensor arrays.
PSA: If you can afford your own a retail router, it’s always a better idea than using the one provided by your ISP. Make no mistake, Xfinity is absolutely collecting (and probably selling) data on the traffic of every device on your network.
I work for a different large ISP who provides modems and routers to our customers, but not this specific feature (being a bit vague because I know at one point mentioning the company’s name on social media would result in the post being reviewed by the social media team/referred to security for anything discussing internal processes, and while Lemmy probably isn’t on their radar I’d rather not risk it).
The amount of data we can see if you’re using our routers is pretty crazy, and most people have no idea. We can see exactly what you have on your network and what it’s doing. If you’re just using the modem and not the router, we have much more limited visibility. We don’t have the capacity to monitor everything everyone is doing all the time, so if you’re using your own equipment (and you’re not using our DNS service), it’s unlikely we have much data on your activity. Storage in the scale needed to store what everyone is doing gets expensive.
I’ve always used my own equipment, and I make sure everyone in my family has their own equipment as well. I would absolutely advise against using your ISP’s equipment if your goal is privacy.
I encourage everyone with the ability to do so to at least try to run their own networking, or even just periodically examine the logs. The weird things I’ve discovered about random devices on my network have made me seriously question what the fuck companies are doing.
Ubiquiti isn’t perfect but they make a really good product and you don’t have to connect it with a cloud
deleted by creator
Someone will figure out how to use the backdoor on the Chinese router. Then they can bypass your firewall. Now your router and all of your insecure IoT devices will be part of their botnet. They will sell your internet connection as a residential proxy or use it to DDoS websites.
Everybody hacks everybody
https://www.forbes.com/sites/joshpearce/2025/11/15/why-farmers-are-shielding-their-crops-with-solar-panels/
Man, the Snowden leaks had examples of 5th to 6th party docs retrieved from hacking intelligence agencies who had hacked intelligence agencies who… You get the point
5 eyes countries literally spy on their own citizens by proxy, retrieving information from each others’ agencies directly (authorized or not)
Everyone is really readily accepting of china potentially spying on them whenever this topic comes up, and I’m just kinda curious why you think chinese companies don’t sell that user data to western companies just as western countries do for china?
https://spycloud.com/blog/state-secrets-for-sale-chinese-hacking/
Countries like China rely a lot of independent local groups doing the dirty job so they can shield their national reputation by “taking care of” individual groups as they become a liability. Russia and others do it too. Everybody hacks everybody. Some of these groups target both foreigners and their own. Sometimes for domestic spying, sometimes just for plain scams.
You could also see if that cheapo TP-Link can run OPNSense or ddwrt, that way at least the software on the device has no chance of being compromised.
They’re doing that anyway via the modem. Unless you are tunnelling everything your ISP sees every byte you send.
You can also get your own modem, but that doesn’t change the fact that yes, you need to use a VPN for any external traffic you don’t want your ISP seeing.
However, ISP controlled routers provide them direct visibility into your LAN, which they otherwise wouldn’t see. This gives WAY more detailed information about you and your behavior, i.e. the original article.
By tunnelling, you mean using a VPN?
Yeah but to clarify, encrypted traffic is still encrypted. They can’t see specifics beyond the sites you went to, urls, dns queries, etc… to hide that you’d need a VPN.
You can hide DNS through DoT/DoH as well at least
Domains, not URLs. https://www.baeldung.com/cs/https-urls-encrypted
Wouldn’t companies also be able to do it on any WiFi device, like a phone or a smart watch?
Can you recommend some trustworthy hardware?
I know gl.inet is probably best for routers, but are any of the mainstream brands more trustworthy than others? TP-Link, Ubiquiti, etc.? I recently got a Zyxel, are those okay?
I picked up the OpenWRT one, seems fine for my setup
Mikrotik.com is another. Often the kind of router developed to work for small businesses and also suitable for homes are decent (note the direction).
If your router supports it, consider flashing openWRT (replacing the OS entirely)
Ubiquiti. It’s like networking gear when you grow up past a combo router/access point but don’t want to spend time fixing every last little thing (potentially in a command line) - though you can if you want to (this is A long winded way of saying that these hardware just works).
I would start with your ISP’s list of supported modems.