Home » scrutiny » Recent Articles:

Sinclair’s Lawyer Says Ajit Pai Froze Sinclair Out in All-But-Dead Sinclair-Tribune Merger

After the inspector general of the Federal Communications Commission opened an investigation into FCC Chairman Ajit Pai’s close relationship with executives at Sinclair Broadcasting, Pai stopped returning Sinclair’s phone calls and refused any further meetings with America’s largest local TV station owner, at least until last Tuesday when Pai called Sinclair’s general counsel to say its multi-billion dollar merger with Tribune Media was in trouble.

The revelation Pai effectively froze out Sinclair while under investigation came in an ex parte communication disclosed by FCC Commissioner Jessica Rosenworcel’s office late last week.

“I realize that you appear to have been unwilling to discuss this matter for the past several months (and for that reason our counsel and Tribune’s have been reaching out everyone at the FCC but you),” Sinclair general counsel Barry Faber wrote in an email to Ajit Pai the morning after the phone call.

Based on the email, it is clear Mr. Pai personally called Mr. Faber on Tuesday evening to report the FCC planned to refer Sinclair’s buyout of multiple Tribune Media TV stations, including WGN in Chicago, to an independent administrative law judge who would pursue a hearing — a procedure that usually signals the death of a proposed merger or acquisition. The courtesy call was one last consideration to Sinclair by Mr. Pai, giving executives an early warning that would allow them to quietly withdraw the deal as a face-saving measure before the FCC publicly pulled the rug out the next day. The call came as an apparent shock to executives at Sinclair and Tribune, who had repeatedly expressed confidence the transaction would meet approval from the Republican majority at the FCC — one led by Pai, who personally proposed several rule changes that made the Sinclair transaction possible.

Faber told Pai in response the two companies could not agree to withdraw the deal “in the brief period of time provided to us.” Instead, Faber begged Pai to give the companies more time to reassure the FCC and then offered to withdraw the controversial sweetheart sales of TV stations in Chicago, Dallas, and Houston a short time later. The buyers all had long-standing, close ties to the family that founded Sinclair and were suspected of buying the stations to become Sinclair’s silent partners. Pai refused Faber’s request and went public the next morning with the proposal to refer the matter to an administrative hearing. As of today, the deal is still headed for a hearing, but few expect it will survive long enough to begin the process. But the repercussions are likely to last far longer than that.

Faber

While talking to Faber, it is clear Pai also raised the issue of Sinclair’s possible deception in its merger application and its lack of candor about its plan to divest stations in those three cities.

“I understand that if Sinclair has not been completely truthful and forthcoming with regard to these proposed sales, abandoning them would not eliminate such unacceptable behavior. I point out, however, that as we discussed yesterday no evidence exists that Sinclair has mislead the FCC or been anything other than completely candid with respect to our relationships with the proposed buyers and the terms of the transaction,” Faber wrote. “To designate our transaction for hearing based on the possibility that there may be more to the deals than meets the eyes based on the pricing and other terms that have been disclosed, would be extraordinary and unprecedented.”

Deal critics claim Sinclair’s bold effort to barely disguise the sweetheart deals with well-known business associates of Sinclair’s chairman David Smith was extraordinary and unprecedented as well. Several Wall Street and K Street analysts have expressed concern Sinclair was being exceptionally brazen with the FCC, proposing to spin-off stations to known Sinclair associates at fire sale prices, with contract clauses allowing Sinclair to program the stations ‘for the owner’ and also have the right to buy the stations back at their original fire sale price, assuming deregulation of station ownership caps continued moving forward. Sinclair is no stranger to political controversy, generating a full-scale advertiser boycott and Wall Street blowback over mandatory political programming aired on its stations during the 2004 U.S. presidential election. Recently Sinclair’s mandatory editorials and news stories have received even more scrutiny in the media, and have generated a lot of negative press for the Baltimore-based TV station owner.

Pai

Some on Wall Street are reportedly growing tired of Sinclair management’s political agendas getting in the way of potential profits, and this latest high-profile incident is likely to further strengthen that perception. Pai’s announcement that the merger deal smacked of a “lack of candor” and “misrepresentation,” raise questions about the Sinclair’s honesty and character, something that could threaten its ability to keep or renew its stations’ licenses. Long standing FCC rules state a license can be revoked if an owner lies to the Commission or engages in unethical or criminal behavior.

The FCC rarely forgets about egregious bad conduct. In the 1960s, RKO General, a division of General Tire and Rubber Company, falsely testified to the FCC that its television stations, including KHJ Los Angeles, WNAC Boston, and WOR New York did not engage in “reciprocal trade practices” — forcing General Tire’s vendors to buy advertising time on RKO stations if they wanted their contracts with the tire company renewed. In 1969, the FCC had enough evidence to prove RKO officials had lied to the Commission and were brazenly violating FCC rules. In 1975, RKO was once again hauled before the FCC and questioned about allegations General Tire was bribing foreign officials, had a secret slush fund to finance campaign contributions, and misappropriated revenue from overseas operations to cook its books.

Five years later in 1980, the FCC stunned the broadcasting industry by canceling the license of RKO’s Boston station — WNAC, declaring RKO “lacked the requisite character” to hold a FCC license because it openly deceived the FCC by withholding evidence, covered up improper dealings, and maintained a “persistent lack of candor” about its business practices and behavior. The FCC also moved to cancel licenses for KHJ in Los Angeles and WOR in New York. RKO held on for a few more years by appealing the FCC’s decision in various courts. It eventually sold most of its TV stations by the mid-1980s. But by then, FCC administrative law judge Ed Kuhlmann documented even more corruption by RKO, calling the company’s conduct the worst case of dishonesty in FCC history. RKO systematically misled advertisers about station ratings, fraudulently billed clients, destroyed audit reports demanded by the FCC, and filed several false financial statements with the FCC. Kuhlmann wanted RKO out of the broadcasting business for good, ordering RKO to surrender licenses for the two remaining TV stations it still owned in 1987, as well as 12 radio stations.

Sinclair’s critics are likely to invoke RKO General in challenging Sinclair license renewals in the future, noting a similar lack of candor and misrepresentation.

With the Sinclair-Tribune merger deal now swirling in the bowl, shareholders may be the ultimate judge, jury, and executioner, at least at Tribune Media. Sports Fan Coalition and Public Knowledge took the opportunity to remind Tribune’s board of directors it just blew a $3.9 billion deal by allowing Sinclair to manage the transaction with apparent dishonesty and chutzpah:

The FCC has unanimously determined that Sinclair may have “engaged in misrepresentation and/or lack of candor in its applications with the Commission,” in possible violation of the Communications Act and FCC rules. Thus, because Sinclair failed to satisfy its commitments under the merger agreement, Tribune can and should invoke its termination right under the merger agreement. Such termination would not trigger the liquidated damages provisions of the merger agreement.

[…] “Either take immediate action to terminate your agreements for the sale of your company to Sinclair Broadcast Group, or resign as directors of Tribune Media.”

Told You: Altice Brings Its Special Kind of Cost-Cutting to Suddenlink and Cablevision

Phillip Dampier June 28, 2016 Altice USA, Cablevision (see Altice USA), Consumer News, Suddenlink (see Altice USA) Comments Off on Told You: Altice Brings Its Special Kind of Cost-Cutting to Suddenlink and Cablevision

cheapDespite vociferous denials to New York regulators that Altice’s unique way of cost-cutting expenses in Europe would mean the same in the United States, a Suddenlink employee in the Appalachians found herself visiting a nearby Kroger supermarket recently to pick up some “forever” postage stamps after the office’s postage meter machine stopped working.

“Nobody paid the bill, leaving us to raid petty cash to get some mail out,” the Suddenlink employee told Stop the Cap! “They got the problem resolved later that week, but this was only the most recent of several incidents that make it clear our new owner doesn’t like us spending any money.”

Suddenlink employees in West Virginia needed money to get a broken ice machine in their office fixed and got the third degree instead of a quick answer.

The Wall Street Journal reports during a March “investment committee” meeting, Altice’s bean counters pelted employees with questions about the nature of the ice machine business in the United States and whether it would be smarter to buy or lease.

“A complete waste of people’s time and energy,” said the former Suddenlink employee.

In North Carolina, call center employees are updating their resumes after watching job positions slowly get eliminated starting this past April.

“Since that time, rumors have been spreading that the call center [itself] may be closing soon,” shared another employee. “And if you’re paying attention the writing is on the wall that the rumors are true. But no one from upper management or corporate will share any information.”

SuddenlinkLogo1-630x140When Altice took over Cablevision, employees were stunned when top executives dined in the staff canteen on their first day after the deal closed. That was never the style of former CEO James Dolan and other executives who avoided hobnobbing with anyone too far from the executive suites. Dolan himself often used a helicopter to travel back and forth from the office, occasionally with bodyguards.

Charles Stewart, chief financial officer of Altice U.S., warns everyone better get used to it.

“[Cost discipline is] our whole philosophy,” Stewart said. “It triggers a discussion at a very nitty-gritty level, which is where the difference is made.”

atice-cablevisionWith a commitment to slash $900 million in expenses out of Cablevision alone during 2016, that’s a lot of discipline. Employees are echoing their French counterparts at Altice’s SFR-Numericable when they call life at Suddenlink and Cablevision “a culture of fear,” watching workers exiting each week without being replaced. Much the same happened in Europe, despite commitments not to engage in job-cutting. In both cases, Altice claims the slow but steady trickle of employee departures are “normal churn,” not layoffs.

Altice designed its “investment committee” to be an authoritarian hellhole on purpose. Those who dare to attend the weekly meetings, which extend for hours, face micro-scrutiny of every expense brought before it, with employees peppered with questions to justify their expenses. The same occurred in France, where Altice officials debated how often they should pay to vacuum the carpets and clean the restrooms. If you need professional cleaning services, Eco Clean Solutions end of tenancy cleaning ensures your deposit back.

Employees figure out soon enough it is easier not to ask (or to simply buy what you need on your own), before enduring a prolonged debate on mundane topics like using new or recycled toner cartridges.

“It creates consternation for about two months,” admitted Altice USA CEO Dexter Goei. “Then people realize, ‘Boy, I really don’t want to go to the investment committee. We just got 500 printers a year ago; we can probably extend their life one more year.’”

While Altice has a deal with regulators not to layoff “customer-facing” Cablevision employees in New York, it is already slashing one of Dolan’s pet projects: Freewheel, a Wi-Fi powered wireless phone, SMS, and data service.

Coming next: Channel Renewal Battles. Altice executives believe it’s time to declare total war on channel carriage costs, even it leads to prolonged channel blackouts.

“We have about half of our programming lineup that’s up for renewal very soon,” Goei said. “There are clearly a lot of channels that we’d like to get rid of.” But Goei also told the Wall Street Journal many of the networks he doesn’t want are part of broader programming deals that require all of a company’s channels to be carried.

So what is next? Altice has stated emphatically it wants to be either the largest or second largest cable operator in the U.S. That guarantees more acquisitions, probably beginning next year. Cox and Mediacom — both privately held — may decide not to sell, which means Altice will have to refocus on taking over Charter Communications, which itself just absorbed Time Warner Cable and Bright House Networks, or divert to making acquisitions in wireless — T-Mobile or Sprint, perhaps, or content, which likely means one or more Hollywood studios.

Attacks on Tennessee’s EPB Municipal Broadband Fall Flat in Light of Facts

Phillip Dampier March 28, 2016 Astroturf, AT&T, Broadband Speed, Comcast/Xfinity, Community Networks, Competition, Consumer News, Data Caps, Editorial & Site News, EPB Fiber, Public Policy & Gov't, Rural Broadband, Wireless Broadband Comments Off on Attacks on Tennessee’s EPB Municipal Broadband Fall Flat in Light of Facts

latinos for tnThe worst enemy of some advocacy groups writing guest editorial hit pieces against municipal broadband is: facts.

Raul Lopez is the founder and executive director for Latinos for Tennessee, a 501C advocacy group that reported $0 in assets, $0 in income, and is not required to file a Form 990 with the Internal Revenue Service as of 2014. Lopez claims the group is dedicated to providing “Latinos in Tennessee with information and resources grounded on faith, family and freedom.”

But his views on telecom issues are grounded in AT&T and Comcast’s tiresome and false talking points about publicly owned broadband. His “opinion piece” in the Knoxville News Sentinel was almost entirely fact-free:

It is not the role of the government to use taxpayer resources to compete with private industry. Government is highly inefficient — usually creating an inferior product at a higher price — and is always slower to respond to market changes. Do we really want government providing our Internet service? Government-run health care hasn’t worked so well, so why would we promote government-run Internet?

Phillip Dampier: Corporate talking point nonsense regurgitated by Mr. Lopez isn't for the good of anyone.

Phillip Dampier: Corporate talking point nonsense regurgitated by Mr. Lopez isn’t for the good of anyone.

Lopez’s claim that only private providers are good at identifying what customers want falls to pieces when we’re talking about AT&T and Comcast. Public utility EPB was the first to deliver gigabit fiber to the home service in Chattanooga, first to deliver honest everyday pricing, still offers unlimited service without data caps and usage billing that customers despise, and has a customer approval and reliability rating Comcast and AT&T can only dream about.

Do the people of Chattanooga want “the government” (EPB is actually a public utility) to provide Internet service? Apparently so. Last fall, EPB achieved the status of being the #1 telecom provider in Chattanooga, with nearly half of all households EPB serves signed up for at least one EPB service — TV, broadband, or phone service. Comcast used to be #1 until real competition arrived. That “paragon of virtue’s” biggest private sector innovation of late? Rolling out its 300GB usage cap (with overlimit fees) in Chattanooga. That’s the same cap that inspired more than 13,000 Americans to file written complaints with the FCC about Comcast’s broadband pricing practices. EPB advertises no such data caps and has delivered the service residents actually want. Lopez calls that “hurting competition in our state and putting vital services at risk.”

Remarkably, other so-called “small government” advocates (usually well-funded by the telecom industry) immediately began beating a drum for Big Government protectionism to stop EPB by pushing for a state law to ban or restrict publicly owned networks.

Lopez appears to be on board:

Our Legislature considered a bill this session that would repeal a state municipal broadband law that prohibits government-owned networks from expanding across their municipal borders. Thankfully, it failed in the House Business and Utilities Subcommittee, but it will undoubtedly be back again in future legislative sessions. The legislation is troubling because it will harm taxpayers and stifle private-sector competition and innovation.

Or more accurately, it will make sure Comcast and AT&T can ram usage caps and higher prices for worse service down the throats of Tennessee customers.

epb broadband prices

EPB’s broadband pricing. Higher discounts possible with bundling.

Lopez also plays fast and loose with the truth suggesting the Obama Administration handed EPB a $111.7 million federal grant to compete with Comcast and AT&T. In reality, that grant was for EPB to build a smart grid for its electricity network. That fiber-based grid is estimated to have avoided 124.7 million customer minutes of interruptions by better detection of power faults and better methods of rerouting power to restore service more quickly than in the past.

EPB provides municipal power, broadband, television, and telephone service for residents in Chattanooga, Tennessee

EPB provides municipal power, broadband, television, and telephone service for residents in Chattanooga, Tennessee

Public utilities can run smart grids and not sell television, broadband, and phone service, leaving that fiber network underutilized. EPB decided it could put that network to good use, and a recent study by University of Tennessee economist Bento Lobo found EPB’s fiber services helped generate between 2,800 and 5,200 new jobs and added $865.3 million to $1.3 billion to the local economy. That translates into $2,832-$3,762 per Hamilton County resident. That’s quite a return on a $111.7 million investment that was originally intended just to help keep the lights on.

So EPB’s presence in Chattanooga has not harmed taxpayers and has not driven either of its two largest competitors out of the city.

Lopez then wanders into an equally ridiculous premise – that minority communities want mobile Internet access, not the fiber to the home service EPB offers:

Not all consumers access the Internet the same way. According to the Pew Research Center, Hispanics and African-Americans are more likely to rely on mobile broadband than traditional wire-line service. Indeed, minority communities are even more likely than the population as a whole to use their smartphones to apply for jobs online.

[…] Additionally, just like people are getting rid of basic at-home telephone service, Americans, especially minorities, are getting rid of at-home broadband. In 2013, 70 percent of Americans had broadband at home. Just two years later, only 67 percent did. The decline was true across almost the entire demographic board, regardless of race, income category, education level or location. Indeed, in 2013, 16 percent of Hispanics said they relied only on their smartphones for Internet access, and by 2015 that figure was up to 23 percent.

That drop in at-home broadband isn’t because fewer Americans have access to wireless broadband, it’s because more are moving to a wireless-only model. The bureaucracy of government has trouble adapting to changes like these, which is why government-owned broadband systems are often technologically out of date before they’re finished.

But Lopez ignores a key finding of Pew’s research:

In some form, cost is the chief reason that non-adopters cite when permitted to identify more than one reason they do not have a home high-speed subscription. Overall, 66% of non-adopters point toward either the monthly service fee or the cost of the computer as a barrier to adoption.

What community broadband provides communities the big phone and cable companies don't.

So it isn’t that customers want to exclusively access Internet services over a smartphone, they don’t have much of a choice at the prices providers like Comcast and AT&T charge. Wireless-only broadband is also typically usage capped and so expensive that average families with both wired broadband and a smartphone still do most of their data-intensive usage from home or over Wi-Fi to protect their usage allowance.

EPB runs a true fiber to the home network, Comcast runs a hybrid fiber-coax network, and AT&T mostly relies on a hybrid fiber-copper phone wire network. Comcast and AT&T are technically out of date, not EPB.

Not one of Lopez’s arguments has withstood the scrutiny of checking his claims against the facts, and here is another fact-finding failure on his part:

Top EPB officials argue that residents in Bradley County are clambering for EPB-offered Internet service, but the truth is Bradley County is already served by multiple private Internet service providers. Indeed, statewide only 215,000 Tennesseans, or approximately 4 percent, don’t have broadband access. We must find ways to address the needs of those residents, but that’s not what this bill would do. This bill would promote government providers over private providers, harming taxpayers and consumers along the way.

Outlined section shows Bradley County, Tenn., east of Chattanooga.

Outlined section shows Bradley County, Tenn., east of Chattanooga.

The Chattanoogan reported it far differently, talking with residents and local elected officials on the ground in the broadband-challenged county:

The legislation would remove territorial restrictions and provide the clearest path possible for EPB to serve customers and for customers to receive high-speed internet.

State Rep. Dan Howell, the former executive assistant to the county mayor of Bradley County, was in attendance and called broadband a “necessity” as he offered his full support to helping EPB, as did Tennessee State Senator Todd Gardenhire.

“We can finally get something done,” Senator Gardenhire said. “The major carriers, Charter, Comcast and AT&T, have an exclusive right to the area and they haven’t done anything about it.”

So while EPB’s proposed expansion threatened Comcast and AT&T sufficiently to bring out their lobbyists demanding a ban on such expansions in the state legislature, neither company has specific plans to offer service to unserved locations in the area. Only EPB has shown interest in expansion, and without taxpayer funds.

The facts just don’t tell the same story Lopez, AT&T, and Comcast tell and would like you to believe. EPB has demonstrated it is the best provider in Chattanooga, provides service customers want at a fair price, and represents the interests of the community, not Wall Street and investors Comcast and AT&T listen to almost exclusively. Lopez would do a better job for his group’s membership by telling the truth and not redistributing stale, disproven Big Telecom talking points.

New York City Questions Public Interest of Altice Buyout of Cablevision; Suddenlink Workers Worry

Phillip Dampier December 23, 2015 Altice USA, Cablevision (see Altice USA), Competition, Consumer News, Public Policy & Gov't, Suddenlink (see Altice USA) Comments Off on New York City Questions Public Interest of Altice Buyout of Cablevision; Suddenlink Workers Worry

altice debtNew York City officials are questioning the promised benefits of allowing Patrick Drahi’s Altice to acquire Cablevision in an all-cash deal that would combine ownership of Suddenlink and Cablevision under the European-based cable conglomerate.

Mayor Bill de Blasio’s chief legal counsel told the Wall Street Journal she is skeptical about Altice’s proposed $900 million in cost cutting at Cablevision leading to better service.

“Altice is talking about $900 million in synergies. Well, what’s getting cut? How’s that going to impact the economy of New York and quality of services?” asked Maya Wiley. “We certainly are not afraid to disapprove a transaction.”

Altice’s Public Interest Statement, outlining the public benefits of the acquisition, was perceived as long on rhetoric but woefully short on specifics. Altice officials made vague promises to expand fiber optics across Cablevision’s footprint in return for approval of the transaction, but stopped short of committing to offer fiber to the home service.

Stop the Cap!’s Special Report, reviewing the proposed acquisition of Cablevision, attracted the interest of investors on Wall Street as well as several New York City public officials we spoke with about the proposed buyout.

City Hall of New York (Photo: Will Steacy)

City Hall of New York (Photo: Will Steacy)

On our recommendation, New York officials reviewed French press coverage of Altice and its colorful CEO Patrick Drahi. Dozens of articles have covered Drahi’s controversial business practices over the years, including efforts to stall payments for suppliers, initiating salary and job cuts, and a reduction in spending on meaningful service upgrades. His French operation SFR-Numericable lost one million customers in just one year. Earlier this year, he promised increased investment to turn those subscriber numbers around.

Wall Street is also increasingly skeptical about Drahi’s American business plans.

Cablevision’s stock price has dropped well below Altice’s all-cash offer of $34.90 a share, telegraphing concern the deal will not escape regulator scrutiny and ultimately will not close.

“The spread has widened in large part because people have become increasingly concerned that neither the city nor the state will find that the transaction is in the public interest, or alternatively, they’ll demand so much in terms of givebacks that ultimately the deal won’t be palatable to Altice,” Craig Moffett, analyst at MoffettNathanson LLC, told the Journal. “Altice dramatically overpaid, and their attempts to cut costs are both overly ambitious and are potentially injurious to what we already expected to be very weak operating results.”

Optimum-Branding-Spot-New-LogoIf Drahi wins approval to take over Cablevision, Altice is likely to curtail promotional spending at the cable company. The cable operator competes head-to-head with Verizon FiOS across much of its downstate New York, New Jersey and Connecticut service areas. That will likely lead to higher prices and fewer deals for consumers as price competition cools down.

The deal remains under review by the New York Public Service Commission and the FCC. Decisions from both are not expected until next spring.

On Monday, Altice closed its acquisition deal for Suddenlink, a cable operator serving states with more forgiving and business-friendly regulators.

As expected, Altice immediately named an executive team that will oversee significant cost cutting and reorganization at the cable operator that serves mostly rural and small city customers.

Two Suddenlink employees reached out to Stop the Cap! on Tuesday to tell us morale was dropping among middle managers at the cable operator.

SuddenlinkLogo“Most of our employees have little idea who Patrick Drahi or Altice is and they are not aware of the business reviews we’ve been told are coming after the holidays,” said one West Virginia based middle manager. “Some of my colleagues in customer care are updating their resumes this week and I’ve also heard concerns from technicians and IT workers. Some want to jump out early to secure new jobs before expected job cuts cause a small flood of resumes all over the state.”

“It’s a worrisome Christmas because we are not sure how many will be let go,” writes a Suddenlink mid-level IT manager working in Texas. “Salaries at Suddenlink have never been high but a lot of us prefer to work in our hometown and not move to Dallas or Houston to work for companies like Time Warner Cable or AT&T. It’s also a more relaxed work environment, but now there is a lot of concern what the new management will be doing.”

Goei

Goei

Chairman and CEO Jerry Kent announced he will be leaving Suddenlink in those roles but has agreed to chair a new advisory council at Altice USA, the subsidiary established to manage Altice’s American cable assets.

Head chopper Michel Combes, the new chief operating officer of Altice NV, is expected to coordinate U.S. operations. Combes brings his reputation for ruthless cost-cutting from his last job — CEO of Alcatel-Lucent. In an effort to boost profitability and cut costs, Combes presided over 10,000 job cuts and a salary freeze (except for himself and select others) at the company better known as the former Bell Labs. Two years after wielding the hatchet, Combes engineered a sale of the company to Nokia and secured a large golden parachute package for himself. The optics of Combes’ overseeing salary freezes and job cuts while later lobbying for a retirement package focusing on his own personal enrichment caused a political furor in France.

The new management of Suddenlink has limited experience in cable but plenty of experience working at Wall Street banks.

The chairman of Altice USA is Dexter Goei, who joined Altice in 2009 after a career in investment banking at JP Morgan and Morgan Stanley that spanned 15 years. Charles F. Stuart, also a former investment banker at Morgan Stanley, will become co-president and chief financial officer. Abdelhakim Boubazine, former CEO of Altice’s operations in the Dominican Republic, will also serve as co-president and chief operating officer. His LinkedIn profile mentions his involvement in telecommunications began in 2013. His educational background strongly emphasizes fossil fuel engineering.

ARRIS Cable Modem/Gateway Security Lapse Offers Hackers Two Backdoors Into Your Network

Phillip Dampier November 23, 2015 Consumer News, Wireless Broadband Comments Off on ARRIS Cable Modem/Gateway Security Lapse Offers Hackers Two Backdoors Into Your Network

arrisARRIS, one of the country’s largest suppliers of cable modems, is under scrutiny after a security researcher discovered not one, but two secret “backdoors” potentially affecting more than 600,000 of the company’s installed cable modems/home gateways that could allow hackers access to a customer’s equipment and home network.

Bernardo Rodrigues published a report of the exploits on his blog, which affect ARRIS cable modem models including TG862A, TG862G, and DG860A. Rodrigues reports only ARRIS and your local cable company can fix the security problems, and neither seem to be in much of a hurry.

The Arris Touchstone 860, which can be identified by its model number depicted on the front of the modem.

The ARRIS Touchstone 860, which can be identified by its model number depicted on the front lower right of the modem.

“Securing cable modems is more difficult than other embedded devices because, on most cases, you can’t choose your own device/firmware and software updates are almost entirely controlled by your ISP,” Rodrigues writes. Indeed, very few cable modems allow users to self-update their equipment with the latest firmware. To guarantee uniformity, that privilege is given exclusively to the cable company providing service, even if a customer owns their own modem outright.

“ARRIS SOHO-grade cable modems contain an undocumented library (libarris_password.so) that acts as a backdoor, allowing privileged logins using a custom password,” Rodrigues writes. “The backdoor account can be used to enable Telnet and SSH remotely via the hidden HTTP Administrative interface “http://192.168.100.1/cgi-bin/tech_support_cgi” or via custom SNMP MIBs.”

While exploring the potential security damage that backdoor could permit, Rodrigues stumbled on a second, open to additional exploitation by hackers.

“The undocumented backdoor password is based on the last five digits from the modem’s serial number,” Rodrigues wrote. “You get a full busybox shell when you log on the Telnet/SSH session using these passwords.”

Arris TG862

ARRIS TG862

In plainer language, one or both backdoors will allow a hacker to bypass the modem’s usual security protections and provide the intruder with full remote access to the affected cable modem. Hackers have likely already identified the security lapse and have exploited it, with some suspecting access key generators are already available allowing the user to automate attempts to reach affected modems on a significant scale.

Unfortunately for consumers, neither ARRIS or cable operators appear to be rushing to update the affected firmware to eliminate the backdoors, having waited more than two months just to acknowledge Rodrigues’ report.

For now, customers using these devices exclusively as cable modems are least likely to suffer a serious security lapse. More at risk are consumers relying on these three models as both a cable modem and home gateway providing Wi-Fi access around the home. Theoretically, hackers could use one or both exploits to gain access to your home network. Consumers using one of the affected models should contact their local cable company and ask them to replace the device with an alternative, preferably from a different manufacturer.

At least one cable company reported they are working with ARRIS to correct the flawed firmware, but early efforts have not been successful. It may be prudent for some security-conscious customers not to wait.

Search This Site:

Contributions:

Recent Comments:

Your Account:

Stop the Cap!