I know this is an outrageously bad idea, I don’t need convincing. I am just looking for some more information and discussion on what exactly the exposure and surveillance risk is.
I’m asking both for my own education (I am still very green to networking), and to better explain to people in my life if and why they should care.
-
Is it true that traffic can be tracked and logged by ISP through DNS lookups, as these routers are preconfigured to use their internal dns service?
-
If this is changed (like base.dns.mullvad.net), how much does this actually mitigate the risk here?
-
What about when a VPN (mullvad) is also being used at all times? Would it then be “overly paranoid” to fear this untrusted box all the traffic goes through?
I personally take a conservative approach to things like this and assume it’s an unacceptable risk, but I don’t really understand what the truth is.
Thank you in advance for your time and thoughts.
EDIT: I’m asking about US and US adjacent areas
I always put a firewall that I own inside the ISP router. Right now I’m using an old ASA 5505 but I’m considering upgrading to a Firewalla Gold. I slay segment my network so that it phones and notebooks are on one network and the TV and Xbox and other things that I have no control over on another.
Seems like a fair solution, thank you for the reply.
Is the ISP router a bottleneck concern for you or do you have a recent/decent model?
I’m on SpaceX. I have their latest terminal.
I used to be in Bell Canada and before that a local ISP. I’ve always had a firewall inside the ISP router because I work in information security and don’t want anyone inside my network. My high network can reach my low network but my low network can’t reach my high network.
You’ve given me a lot to think about and look into, thank you.
You’re welcome. Check out Firewalla. They make nice devices and they are relatively affordable.