US Sues D-Link for Exposing Users to Hackers

Exterminator

Level 85
Thread author
Verified
Top Poster
Well-known
Oct 23, 2012
12,527
The United States’ Federal Trade Commission (FTC) sued D-Link this week after the company failed to secure its devices, making routers and cameras vulnerable to hacks and exposing users and their data.

The FTC explained in the lawsuit documents that D-Link that the firm “failed to take reasonable steps” to protect its devices from known security vulnerabilities, adding that this put thousands of consumers at risk.

Sensitive personal information and local networks have been exposed following D-Link’s failure to secure its devices, the FTC says, and hackers could easily compromise the IP cameras and routers using tools that were already available online and developed to exploit widely known vulnerabilities.

How D-Link failed to protect users
Here are a few claims from the FTC complaint pointing out how and why D-Link failed to offer the security that it advertised for its products:

“Defendants repeatedly have failed to take reasonable software testing and remediation measures to protect their routers and IP cameras against well- known and easily preventable software security flaws, such as “hard-coded” user credentials and other backdoors, and command injection flaws, which would allow remote attackers to gain control of consumers’ devices.”

“Defendant D-Link has failed to take reasonable steps to maintain the confidentiality of the private key that Defendant D-Link used to sign Defendants’ software, including by failing to adequately restrict, monitor, and oversee handling of the key, resulting in the exposure of the private key on a public website for approximately six months.”

“Defendants have failed to use free software, available since at least 2008, to secure users’ mobile app login credentials, and instead have stored those credentials in clear, readable text on a user’s mobile device.”

Back in July 2016, a vulnerability found in D-Link cameras allowed attackers to get administrator access and then deploy malware, which was used to spy on users and steal their data. D-Link acknowledged the security vulnerability and promised fixes, recommending users to change their passwords on a regular basis in order to be protected against hacks.

The FTC is now asking the US District Court for the Northern District of California to order the firm to improve its security guidelines and to cover all costs of the lawsuit.
 

Cats-4_Owners-2

Level 39
Verified
Honorary Member
Top Poster
Well-known
Dec 4, 2013
2,800
Back during the Dark Ages, when wireless connectivity seemed a luxury beyond my reach, D-Link put out routers which also seemed beyond my pocketbook's reach. This reminded me of how perspectives and conditions constantly change. Although I never did receive that D-Link Router in my stocking for Christmas,:oops: it's a relief learning that it wasn't me who was actually on Santa's :eek:Naughty List!;):p
 
Last edited:

Cats-4_Owners-2

Level 39
Verified
Honorary Member
Top Poster
Well-known
Dec 4, 2013
2,800
Agreed!
Thank you for sharing their rebuttal, Solarquest.:)

Their legal representative's statement (dressed up as an appeal)
"Privacy advocates and consumers at large should applaud our client’s courage for fighting these incendiary claims and refusing to be held hostage by the FTC for the next 20 years.”,
IMO, attempts to redirect focus from whether security vulnerabilities were previously known.
This is where liability, and statutes of limitation, can be considered;
and isn't this essentially why EULAs are so long winded yet ever present?o_O
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top