BT promises firmware update for Mini Whole Home Wi-Fi discs to prevent obsessive Big Tech DNS lookups

Meanwhile users complain their IPs are being flagged for suspicious traffic

Users of BT’s Mini Whole Home Wi-Fi range-extender discs have noticed their devices are making hundreds of thousands of daily DNS lookups for big tech companies’ websites – causing problems for some wanting to access Gmail and Microsoft services.

The huge volume of requests generated by the BT-branded discs has caused problems for some Reg readers after their DNS-lookup-spewing IP addresses were flagged by their DNS providers as hives of malicious activity.

Irritated individuals have told us each of their discs generates one DNS lookup for every second – meaning one disc generates 86,400 lookups a day. For those using three or four discs and a custom DNS server configuration, the impact is enough to get their IP addresses flagged as suspicious, we were told.

Reg reader Martin said each of his six Wi-Fi range extender discs were making DNS lookups for Microsoft. After he noticed the volume of lookups directed at Google, he blocked them – resulting in the devices hunting for Redmond’s IP address instead. Six times per second.

A BT Mini Whole Home Wi-Fi Disc range extender

Fellow reader Andy told us he'd “been having issues for months with a variety of services popping up insisting that they’ve detected suspicious activity from my account and I’ve never understood what has been causing it. Even just performing a Google search can require me to do an ‘I’m not a robot’ check.”

Eventually, Andy realised what was going on when he installed a Pi-Hole network-level adblocker on his home network. Logs showed DNS requests being made every second from a local IP address (192.168.nn.nn).

Both Andy and Martin found a BT support forum thread where others had spotted similar behaviour from their BT Wi-Fi discs. A support rep posting as “darren_b” revealed on 22 May that BT had a patch up its sleeve to stop the discs from bombarding DNS providers with lookups for Big Tech, posting:

Although this issue is known and understood, the Mini’s current firmware has been very stable for the majority of our customers with minimal cases into the Whole Home helpdesk. We’re keen to ensure that this remains the case for future firmware releases - so we don’t want to rush firmware out until we’re happy it’s stable and reliable for everyone.

As I’ve mentioned before the issue has been addressed in the next version of the firmware, and whilst I can’t confirm that date yet I will post on here as soon it’s available to install.

User Martin_z replied: “Well, thanks for finally replying. However, it's been well over a year since you said that the issue was going to be released in the next version of firmware.”

The flaw means BT’s DNS servers will be handling tens of millions of spurious lookups per day – and it’s easy to see how a third-party DNS provider, or another ISP that doesn't recognise the traffic as benign, could end up treating such large volumes of lookups as suspicious.

When we asked the one-time state telecoms monopoly for comment, a spokesman told us the flaw only affected those users with custom DNS setups on their personal networks.

“We understand how important connectivity is to our customers and like other products on the market, BT Mini Whole Home Wi-Fi has server requests built in to alert customers of any connection issues as quickly as possible,” said a BT spokesman. “We recognise that there are a small number of customers who have personally set up a custom DNS server configuration at home, and that the frequency of these checks can lead to them seeing additional network traffic.”

The discs can be used on any ISP’s network, not only BT’s. Indeed, our reader Andy said his Virgin Media-supplied connection seemed to have been flagged for suspicious activity.

BT’s spokesman continued: “We have included an update within a new wider firmware, which significantly reduces the frequency of these server requests. We had planned to roll this out sooner, however due to changes in prioritisation following the exceptional circumstances of the past year, this has taken longer than anticipated. We would like to apologise to the small number of customers impacted by this matter.”

The spokesman did not answer our questions as to why the range extenders need to be making DNS lookup requests in the first place. While the answer could be as simple as checking that a working internet connection is present, doing so every second is excessive.

This is not the only mystery problem that has afflicted these BT Wi-Fi range extender discs. Back in 2018 a borked firmware upgrade caused connectivity-nixing problems that resulted in irate users having to constantly reboot them to stay online. ®

Similar topics

Broader topics

Other stories you might like

  • Cheers ransomware hits VMware ESXi systems
    Now we can say extortionware has jumped the shark

    Another ransomware strain is targeting VMware ESXi servers, which have been the focus of extortionists and other miscreants in recent months.

    ESXi, a bare-metal hypervisor used by a broad range of organizations throughout the world, has become the target of such ransomware families as LockBit, Hive, and RansomEXX. The ubiquitous use of the technology, and the size of some companies that use it has made it an efficient way for crooks to infect large numbers of virtualized systems and connected devices and equipment, according to researchers with Trend Micro.

    "ESXi is widely used in enterprise settings for server virtualization," Trend Micro noted in a write-up this week. "It is therefore a popular target for ransomware attacks … Compromising ESXi servers has been a scheme used by some notorious cybercriminal groups because it is a means to swiftly spread the ransomware to many devices."

    Continue reading
  • Twitter founder Dorsey beats hasty retweet from the board
    As shareholders sue the social network amid Elon Musk's takeover scramble

    Twitter has officially entered the post-Dorsey age: its founder and two-time CEO's board term expired Wednesday, marking the first time the social media company hasn't had him around in some capacity.

    Jack Dorsey announced his resignation as Twitter chief exec in November 2021, and passed the baton to Parag Agrawal while remaining on the board. Now that board term has ended, and Dorsey has stepped down as expected. Agrawal has taken Dorsey's board seat; Salesforce co-CEO Bret Taylor has assumed the role of Twitter's board chair. 

    In his resignation announcement, Dorsey – who co-founded and is CEO of Block (formerly Square) – said having founders leading the companies they created can be severely limiting for an organization and can serve as a single point of failure. "I believe it's critical a company can stand on its own, free of its founder's influence or direction," Dorsey said. He didn't respond to a request for further comment today. 

    Continue reading
  • Snowflake stock drops as some top customers cut usage
    You might say its valuation is melting away

    IPO darling Snowflake's share price took a beating in an already bearish market for tech stocks after filing weaker than expected financial guidance amid a slowdown in orders from some of its largest customers.

    For its first quarter of fiscal 2023, ended April 30, Snowflake's revenue grew 85 percent year-on-year to $422.4 million. The company made an operating loss of $188.8 million, albeit down from $205.6 million a year ago.

    Although surpassing revenue expectations, the cloud-based data warehousing business saw its valuation tumble 16 percent in extended trading on Wednesday. Its stock price dived from $133 apiece to $117 in after-hours trading, and today is cruising back at $127. That stumble arrived amid a general tech stock sell-off some observers said was overdue.

    Continue reading

Biting the hand that feeds IT © 1998–2022