Hacking Fiber To The Home | Hackaday
Skip to content
When we think about security threats, we generally imagine them coming from far away across the wider internet. But what if the connection between you and your ISP was the target? [Rithwik Jayasimha] and [Rithvik Vibhu] have explored how fiber to the home connections may not be as secure as you would hope.
The hack centers around fiber-to-the-home connections, of which many deployments rely on Gigabit Passive Optical Network (GPON) standards. The key there is the "passive" part—these networks don’t rely on active components to switch signals. ISPs run central trunk lines out to optical line terminals (OLT), with passive splitters installed in neighborhoods to serve a number of downstream subscribers. Each subscriber then has something called an Optical Network Unit (ONU) in their home, which filters out the traffic intended for that specific subscriber.
Therein lies the flaw, though. Light (and thus, data) for many subscribers flows into the home, and it’s only the ONU that is filtering that out. Hack the ONU, or replace it… and you have access to downstream traffic from your neighbors that you shouldn’t be able to access.
The duo were able to hack an ONU to forward every single frame it receives, revealing downstream data intended for other homes in their immediate neighborhood. A great deal of traffic is encrypted these days, which provides a layer of safety, but it is by no means an ideal situation that such a hack is possible at all. They also explored other threats, such as installing splitters in publicly-accessible infrastructure, and compromising an upstream OLT and using it to flash firmware to other subscriber’s ONUs on the network. All this was presented in a talk at DEF CON, too, which can be viewed online.
It’s a concerning look at an often unconsidered link in the network chain. Few of us expect our data to be snooped upon in between us and the ISP, after all.
Here's the link, we'll be streaming our talk @ 1PM PT
If this breaks, it's Track 1 Main Stage on the #DEFCON YT channel https://t.co/nv0lzLkMwZ
— Rithwik Jayasimha (@thel3l) August 8, 2026
34 thoughts on “Hacking Fiber To The Home”
But what about the risks of packet injection by nefarious actors causing you to be labelled as the source?
Report comment
Reply
IF encryption is used, then this becomes a non-problem, and honestly should be standard. The issue is that, from what I understand, fiber uses a TDMA scheme (times slicing) which means that a DOS should be easy.
Report comment
Reply
No need for DOS when scissors are enough…
Report comment
Reply
Ding, ding. Prize to this commentor!
Report comment
Reply
You can DOS a GPON connection. Just putting in arbitrary data on the upstream wavelength is enough. But regular GPON setups have mostly around 30 subscribers on one link. At least in Europe. Since GPON can only handle a max of 2.4Gpbs and they are selling service with up to 1Gigabit, most of the time the users are even less on one link.
So you can’t use internet yourself, you annoy your closer neighbours, and that’s it.
You can’t do a district wide, or even city wide DOS with this technique.
Report comment
Reply
Your terminology is incorrect. The OLT is an active powered network device that exists in a central fiber office somewhere. From this device through the splitter, which is what is in the cabinet and not an OLT, all the way to your house, is entirely passive.
Report comment
Reply
"Few of us expect our data to be snooped upon in between us and the ISP, after all."
Indeed. I usually expect it to be snooped only on my PC, at my ISP, at all intermediate nodes, and at the destination.
Report comment
Reply
It’s just a bad ISP. I’d guess all the good ones and the big boys encrypt downstream traffic. Mine does. We learned about this 30 years ago with cable modems. A strong argument could be made that there are easier and more effective ways to snoop, but the ISP should be doing whatever they can to protect privacy.
Report comment
Reply
One of the authors here, can assure you this is not true, at least for some major US ISPs we tested :)
Also depending on the OLT used by the ISP, DS encryption must be enabled on a port by port basis, and we found some situations where certain port’s traffic was unencrypted while others weren’t (ie, it was a mixed bag on the same network)
Report comment
Reply
Exists in every time division multiple access network. (SpaceX, too) They do it for oversubscription. And then say each subscriber is rated for the network burst speed instead of committed information rate. It’s all about the Benjamins.
Totally dependent on encryption for isolation/security.
Wireshark it with an optical router.
Report comment
Reply
As a XGSPON subscriber, one of the things that bugged me a lot was that invariably the provider absolutely insists on you using their crappy router.
No thanks.
Fortunately, the alternative is a...