# GPON Security: How Fibre Networks Protect Your Connection

Source: https://urbanx.co.za/news/can-fibre-internet-be-hacked-gpon-security

Published 2026-08-18 by UrbanX

**Quick answer:** Protecting a fibre connection does not depend on one safeguard. Access-network security can include PON encryption, authorised equipment, controlled provisioning, maintained configurations, monitoring and managed firmware processes. Websites and apps add further protection through technologies such as HTTPS and TLS.

Recent gPWN research is useful because it shows why those safeguards matter. Researchers demonstrated attack methods against GPON equipment and downstream traffic in the environments they examined. The cited research did **not** test or establish that UrbanX or its South African Fibre Network Operator (FNO) partners were compromised.

For UrbanX customers, the practical takeaway is simple: the access network is managed by the relevant FNO, while UrbanX provides the internet service and customer support over that network. If a concern involves the fibre access layer, UrbanX can help investigate it and coordinate with the operator.

### How fibre access networks are protected

Fibre security is based on **defence in depth**: different controls protect different parts of the connection rather than relying on a single mechanism.

At a high level, these controls can include:

- **PON encryption**, which protects downstream traffic on the optical access network where it is enabled and supported.
- **ONT authentication and provisioning**, which help control which fibre-termination devices are authorised on the service.
- **Configuration standards and operational controls**, which help keep security settings aligned with network requirements.
- **Monitoring and periodic reviews**, which help identify configuration or operational issues.
- **Firmware and security-advisory processes**, which help operators manage updates and vendor guidance for network equipment.
- **HTTPS, TLS and app encryption**, which protect much of the content travelling between a customer’s device and online services.

UrbanX requested high-level technical background from an FNO to help ensure this article reflects how these protections are managed in a real network environment. The operator described a network using **GPON, XG-PON and XGS-PON** and supplied the following background:

Security measureHow it is applied in the network described**Downstream encryption**Enabled as part of the standard PON security configuration **where supported** by the platform**Configuration management**Configuration standards, operational controls, monitoring and periodic reviews keep settings aligned with requirements**ONT authentication and provisioning**Controls govern which devices are authorised and how services are provisioned**Firmware and security advisories**Updates and vendor advisories are managed through established operational and change-management processes

The operator also noted that security capabilities can differ between legacy and newer platforms depending on the technology and vendor implementation. Newer platforms generally provide enhanced security features and controls.

Importantly, this background describes **one operator’s stated practices**. The operator has reviewed the gPWN research technically and is **still assessing its relevance** to its own network. It should therefore not be read as an independent audit, a completed vulnerability assessment, or confirmation of settings across every UrbanX partner network.

### Who manages the different parts of a fibre connection?

GPON stands for **Gigabit-capable Passive Optical Network**. It connects multiple properties through shared fibre infrastructure and passive optical splitters.

An Optical Line Terminal (OLT) communicates with the Optical Network Terminals (ONTs) or Optical Network Units (ONUs) serving those properties. Downstream frames travel across the shared optical segment, while each ONT normally filters for the traffic assigned to its service. The [ITU-T GPON specification](https://www.itu.int/rec/T-REC-G.984.3/) also defines downstream encryption and key-exchange mechanisms.

Filtering and encryption do different jobs: filtering selects a subscriber’s traffic, while encryption protects the contents from being read without the appropriate key.

In South Africa, responsibility is typically divided like this:

Part of the connectionWhat it doesTypical responsibility**OLT**Connects subscribers to the fibre access networkFNO**Fibre and passive splitters**Carry and distribute the optical signalFNO**ONT**Terminates the fibre service at the propertyFNO supplies or authorises the device**Home router**Connects household devices through Ethernet and Wi-FiCustomer or ISP, depending on the service**ISP network**Carries and routes the internet service beyond the FNO handoverISP, such as UrbanX

An ONT and router may sometimes share one enclosure, but their functions remain distinct. UrbanX’s [fibre installation guide](https://urbanx.co.za/news/fiber-optic-installation-what-homeowners-need-to-know) explains how this equipment fits into a home.

UrbanX provides the internet service and customer support over the FNO’s physical network. Customers do not need to determine whether a concern sits with the ONT, access network, router or ISP before asking for help. UrbanX can investigate and work with the relevant FNO when the issue involves infrastructure under the operator’s control. Our [fibre FAQs](https://urbanx.co.za/frequently-asked-questions) explain more about installations and service support.

### Why the new GPON research matters

On 13 August 2026, [Hackaday covered fibre-security research by Rithwik Jayasimha and Rithvik Vibhu](https://hackaday.com/2026/08/13/hacking-fiber-to-the-home/), presented at DEF CON 34.

The researchers modified an ONU so it could capture downstream data frames intended for other subscribers on the same optical segment. Their [gPWN research](https://www.gpwn.io/) also examined attack paths involving operator equipment and device firmware.

That does **not** mean every GPON connection is exposed in the same way. It demonstrates why operators should not rely only on an ONT behaving normally to keep subscribers separated. Encryption, authorised equipment, secure provisioning, maintained configurations and equipment-management controls all matter.

The research also does not establish that UrbanX or any of its South African FNO partners were tested or compromised. Determining whether a demonstrated attack method applies to a particular network requires a technical assessment of the platforms, firmware, configurations and controls in use.

### Can someone on the same fibre segment read your traffic?

Capturing a network frame does not automatically make everything inside it readable.

Several layers of protection may apply along the connection:

- **PON encryption** protects traffic on the optical access network where enabled and supported.
- **HTTPS and application encryption** protect content travelling between your device and the online service.
- **Wi-Fi encryption** protects the wireless connection between your device and your home router.

Properly implemented HTTPS uses Transport Layer Security (TLS) to protect data in transit, including passwords and page contents. Obtaining fibre frames does not simply make an encrypted HTTPS session readable. [Mozilla’s TLS documentation](https://developer.mozilla.org/en-US/docs/Web/Security/Defenses/Transport_Layer_Security) explains this protection.

Some metadata can remain observable depending on where traffic is captured and which protections apply. This can include connection timing, data volumes and destination IP addresses. Unencrypted DNS requests may also reveal domain names.

These layers are separate. Changing a Wi-Fi password does not change the FNO’s PON encryption settings, just as access-network encryption cannot protect a customer who enters a password into a phishing site. UrbanX’s [guide to internet privacy in South Africa](https://urbanx.co.za/news/internet-privacy-south-africa) explains these distinctions in more detail.

### What should UrbanX customers do?

Nothing in the cited research means UrbanX customers should replace their fibre connection, change their ONT or try to correct access-network settings themselves. The FNO remains responsible for the security configuration and managed equipment on the fibre access network.

For customers, the sensible approach is:

#### Keep the approved fibre equipment in place

Use the FNO-approved ONT and avoid unofficial firmware, unlocking tools or unapproved replacement equipment. If the ONT needs attention, arrange this through UrbanX or the relevant authorised service process.

#### Continue normal router and account security

A strong Wi-Fi password, secure router administration, software updates, unique passwords or passkeys, and multi-factor authentication remain good everyday security practices. They protect different parts of your digital life; they are **not** a fix for an access-network configuration issue.

The [US Federal Trade Commission’s home Wi-Fi guidance](https://consumer.ftc.gov/articles/how-secure-your-home-wi-fi-network) covers router and Wi-Fi basics, while UrbanX’s [online safety guide](https://urbanx.co.za/news/cybersecurity-101-protecting-your-digital-life) covers everyday account and device protection.

#### Contact UrbanX if something about the managed service concerns you

If you receive an unfamiliar request involving your ONT, notice an unexpected equipment change, or experience a persistent connection issue, start with UrbanX support. We can help investigate and coordinate with the relevant FNO when the concern sits within the access network.

### Frequently asked questions

#### Can fibre internet be hacked?

Like other communications technologies, fibre networks can be targeted under certain conditions. The gPWN research demonstrated specific attack methods against GPON equipment and downstream traffic in the environments examined. Whether those methods apply to another network depends on its platforms, firmware, configuration and security controls.

#### Does the gPWN research mean UrbanX customers are vulnerable?

The cited research does not establish that UrbanX or its South African FNO partners were tested or compromised. We have high-level background from one operator describing security controls in its environment, but that operator is still assessing the research’s relevance to its network. A broader assurance would require completed assessments covering the relevant FNO platforms serving UrbanX customers.

#### Should I buy a different ONT because of this research?

No. Keep the approved ONT unless your provider arranges a change. A retail replacement cannot determine whether an operator’s access network is correctly configured and may not work with its provisioning requirements.

#### Would a VPN fix a GPON security issue?

No. A VPN can add encryption between your device and the VPN provider, but it does not change the FNO’s access-network configuration or repair an equipment-management weakness. It can also change routing and potentially affect gaming latency.

#### Does slow fibre or a dropped connection mean I have been hacked?

No. Those symptoms alone do not establish an attack. Wi-Fi conditions, equipment problems, maintenance and network faults can all affect connectivity. The [UrbanX Network Status page](https://urbanx.co.za/network/status) lists reported service incidents and maintenance.

### Have a concern about your fibre connection?

You do not need to diagnose the fibre access network yourself. [Contact the UrbanX support team](https://urbanx.co.za/contact-us) if you have a concern about your connection or managed fibre equipment. We can investigate and coordinate with the relevant FNO where needed.
