firewallsdontstopdragons.com
Use a Secure Wi-Fi Router
You should have a secure home router that you fully control. It’s probably the single most important security device on your home network.
_**NOTE: I’ve writtenseveral detailed articles about securing your home network. Be sure to check those out, too.**_
## Why You Should Own Your Router
For most people, the only thing between every device on your home network and the wild wooly internet is your home Wi-Fi router. Malicious actors are constantly scanning the entire internet for vulnerable devices. Some of these groups set up computers to subvert vulnerable devices automatically, using compromised devices to attack other devices and hide their tracks. So you want your home router to be secure.
Many internet service providers (ISPs) will provide you with router. But you generally have little to no control over that device. While ISPs might be good about updating the hardware and software, which is crucial for security, it can also be horrible for privacy. Your router knows all the devices in your home and can see lots of metadata about their internet traffic. (Most connections are encrypted now, but metadata can be very revealing.) Comcast home routers have a feature that lets other Comcast subscribers use your home Wi-Fi, which can be problematic. Some Comcast routers can even track movement in your home. These features are sometimes enabled by default, too. You can’t avoid trusting your ISP to carry your Internet traffic, but I don’t see any reason to give it control of your home network, too.
You can buy your own router and bypass the one given to you by your ISP. I’ll have recommendations below. But when you get your own router, you should call your ISP and ask how to put their gateway into “bridge mode” or “IP passthrough mode,” so that your router handles the routing, firewall and Wi-Fi functions. If you have a Comcast router, ask them to disable the shared public hotspot feature, too.
## Replacing Routers You Own
Owning your router isn’t sufficient, though. You should also use a well-respected, brand name router that is still actively supported by its maker (that is, still getting software updates). Just recently, several models of inexpensive, white-label routers were found to have built-in backdoors that could allow the manufacturer (or someone who gained control of its infrastructure) to do some really shady things. I also bristle at any router that requires a smartphone app to administer. All you should need is a web browser.
Most routers are marketed today based on how fast they are or fancy security features that require a subscription. For the vast majority of users, you can use a basic router and have no problems streaming your 4K content to multiple devices, gaming with friends, and certainly doing basic web surfing. Wi-Fi version 6 is plenty fast enough. Gigabit connections are sufficient. Your ISP connection is probably the bottleneck, anyway. Let’s focus on what really matters.
## How to Choose a Router
Here are the key features I look for when buying a Wi-Fi router:
* Timely, automatic security updates
* Published support and EOL (end of life) policy
* WPA3
* Local web-based administration
* No mandatory app
* No mandatory vendor account
* No cloud dependency
* No subscription required
* User-selectable DNS
* Guest/IoT network with useful isolation controls
* OpenWrt support (see below)
* Reasonable price
Routers have expiration dates, even if manufacturers don’t print them on the box. Once a manufacturer stops providing security updates, vulnerabilities discovered later won’t be fixed. I consider a router that no longer receives security updates to be obsolete, regardless of how well the hardware still works.
Be wary of proprietary marketing features like “advanced security,” “threat protection” and so on – especially if they require a subscription, cloud service, mandatory DNS provider or installation of certificates that could allow the service to intercept encrypted traffic. Give me boring security: patches, WPA3, a firewall and good network controls.
OpenWrt is a free, open-source software (FOSS) project that runs on your router, potentially replacing the proprietary software that came with it. Having this option can mean that you can keep using your router after the manufacturer gives up or goes away or enshittifies.
## My Recommendation
This is something I very rarely do: make a specific product recommendation. For one thing, the marketplace changes constantly. For another, there’s rarely a single product that works well for everyone. We have different requirements, budgets, and threat models. But when I can find a solid, “easy button” recommendation, I go with it. And for most people, I recommend the **Flint 2 router from GL.iNet**. I personally have the Flint 1 model and it works just fine for me – but if I were buying now, I would get the Flint 2. You can see that I called it out in my Best & Worst Gift Guides for 2024 and 2025, and will almost certainly recommend it this year, too. This router checks all the boxes above. And it’s plenty fast enough for most people.
But there are some caveats, so let’s discuss those. The Flint 2 firmware is based on OpenWrt, but it still has some proprietary parts and therefore it doesn’t always get OpenWrt security fixes immediately. I hope they fix that. But if you have a little technical savvy, you can actually replace their firmware with stock OpenWrt – GL.iNet explicitly supports this. I like that.
This router is currently around $170 on Amazon or GL.iNet, but there are periodic sales on Amazon, too. I will say again that the Flint 1 works fine, too, and it’s about $100. There’s a newer Flint 3, 3e and 4, but you probably don’t need the faster speeds and fancy features. Flint 3 has some stability issues; 3e might be interesting, but I can’t find the same commitment for supporting stock OpenWrt; and 4 is total overkill.
There are others you could consider. Ubiquiti has nice products, but they’re more complicated. Netgear’s Nighthawk routers are okay, but don’t all have a solid option to use OpenWrt. TP-Link has faced some legitimate security and support concerns. There have also been much scarier claims about Chinese backdoors and espionage, but I haven’t seen compelling public evidence to support those claims.
## Tips for Swapping Routers
If you do get a new Wi-Fi router, here are some important tips.
* **Use the same SSID and password.** I would set up the new router with the exact same network name (SSID) and password. If you had a guest network set up before, that also goes for setting up your new router’s guest network. Why? Because this means all your existing devices will automatically connect to the new router without any configuration changes. If your Wi-Fi password is crappy, you can change this later and go through the process of updating all your devices. But for now, use the same credentials.
* **Immediately update the software.** Routers might be sitting on the shelf for years. You want the latest security fixes and features. While you’re there, set up automatic software updates.
* **Set up guest or IoT network for smart devices.** I have several detailed articles on this topic. Some IoT devices require local access to your phone, computer, hub or other devices, so test them after moving them to an isolated network.
* **Use a strong admin password.** This is the password for the router’s web admin page – not the password to connect a device to Wi-Fi. Store this crazy, long, unique password in your password manager.
* **UseWPA3. **This is the encryption scheme used by Wi-Fi devices. For your regular Wi-Fi network, I would use WPA3. Modern computers and smartphones support this. Where you may have trouble is with IoT (“smart”) devices like thermostats, webcams, lights, and so on – especially if they’re old. If necessary, you can use “WPA2/WPA3” mode which supports the newer and older (less secure) format.
* **Disable insecure features.** I would turn off the following if they’re enabled, unless you know you need them. (And I would see if you can find a way to avoid needing them.)
* UPnP. This is still used by some gaming and other applications. It allows devices on your network to automatically open incoming ports through your firewall. I prefer to disable it and manually configure a port-forwarding rule if I truly need one.
* WPS. This was a feature to allow quick setup, but it has real security issues.
* Remote/WAN administration. Your router’s administration interface should not be accessible from the public Internet.
* **Set preferred DNS.** You can get a lot of great security and privacy features by using a custom DNS provider like Quad9, Cloudflare or NextDNS, like blocking ads and tracking. By setting this on your router, your home devices will use this service by default, though individual devices and apps can override it.
Your home router is primarily a security device – you should own it and control it. Choose one that receives timely security updates, gives you full control over your network, doesn’t depend on someone else’s cloud or a subscription, and ideally can run open-source firmware after its manufacturer loses interest in it.
#### Need practical security tips?
Sign up to receive Carey's favorite security tips + the first chapter of his book, _Firewalls Don't Stop Dragons_.
Don't get caught with your drawbridge down!
**Get started**