The FCC Got the Router Ban Wrong. It Knew Better.
On March 23, the Federal Communications Commission effectively banned all new foreign-made routers from the U.S. commercial market by adding them to its so-called “covered list.” The action followed a White House-convened interagency National Security Determination issued just three days earlier. The FCC took this action with no notice-and-comment proceeding, no published cost-benefit analysis, and without providing a broad transition process for the affected industry. The only path forward for manufacturers is to apply for “Conditional Approval” from the Department of Defense or the Department of Homeland Security. The security concerns are real. Chinese state-sponsored hacking groups, including Volt Typhoon, Salt Typhoon, and Flax Typhoon, have exploited vulnerabilities in consumer routers to penetrate American networks, conduct surveillance, and build botnets for attacks on critical infrastructure. Router security deserves serious attention. But in the past, the FCC addressed threats like these in a way that was more targeted, more precisely designed, and better built to survive legal challenge. Comparing the FCC's handling of the Huawei and ZTE threat in 2019-2022 to the new router ban reveals what happens when an agency abandons the deliberative process that makes its expertise useful.
The FCC Got the Router Ban Wrong. It Knew Better.