You Can’t Trust the Last Mile: Wiretapping Fiber From Home
Two friends ordered a new fiber connection, followed the installer around with a camera, and noticed that the box on the pole outside their house had no power. That one observation led them to capture their entire neighborhood’s internet traffic — web browsing, email, even live phone calls — with $99 worth of equipment.
Sherri Davidoff and Tom Pohl break down “gPWN,” one of the standout talks from Black Hat USA 2026. Fiber to the home broadcasts everyone’s traffic to every house on the street and trusts each home’s equipment to ignore what isn’t theirs. The encryption meant to back that up is optional, often left switched off, and doesn’t cover traffic headed back to the ISP at all. It gets worse: cell towers ride the same fiber, which means the “out-of-band” cellular path in your continuity plan may share a line with your neighbors. And the researchers showed how a malicious username typed into a home fiber box could hand an attacker root access to the ISP’s own equipment.
The lesson isn’t just about fiber. Decades ago we replaced hubs with switches so our traffic stopped going to everyone on the network. The last mile quietly went back to a hub — and everything built on top of it kept assuming the old rules. Key
Takeaways:
- Use a VPN you trust. You can’t trust the last mile. Encryption on many fiber deployments is optional and often switched off, and traffic from your home or office back to the ISP isn’t encrypted at all.
- Prove your out-of-band paths really are out of band. Cell towers are often connected over the same neighborhood fiber as homes and offices. Falling back to cellular may mean relying on the same path as your primary internet connection — check before an outage does it for you.
- Assume every carrier circuit is a public network. Treat your office connection like coffee shop Wi-Fi: anyone nearby could be watching. The risk profile of a business in a strip mall may not be very different.
- don’t trust vendor-supplied equipment. Assume vendors will leave optional security switched off — or have access into your equipment. Where you can, use your own router and firewall behind the ISP’s device.
- Put an expiration date on your assumptions. We spent years assuming layer two was secure because we had switches. Your ISP may have quietly replaced that with fiber that sends everyone’s traffic to every house. Revisit the assumptions your security is built on.
Resources:
- Black Hat USA 2026 — “gPWN: Wiretapping Fiber ISP Deployments From the Comfort of Your Home” (Rithvik Vibhu & Rithwik Jayasimha) — https://blackhat.com/us-26/briefings/schedule/#gpwn-wiretapping-fiber-isp-deployments-from-the-comfort-of-your-home-53851
- gPWN project site and toolkit — https://www.gpwn.io/
- Hackaday, “Hacking Fiber To The Home” — https://hackaday.com/2026/08/13/hacking-fiber-to-the-home/
- Quarkslab, “Overview of Passive Optical Networks (PONs) Security” — https://blog.quarkslab.com/overview-of-passive-optical-networks-pons-security.html
- Dark Reading, “Salt Typhoon APT Subverts Law Enforcement Wiretapping” — https://www.darkreading.com/cyber-risk/salt-typhoon-apt-subverts-law-enforcement-wiretapping