D-Link Agrees to Strengthen Device Security
A settlement with the FTC should mean comprehensive security upgrades for D-Link routers and IP camera.
D-Link Systems, manufacturer of local area networking and smart home products, has agreed to implement a "comprehensive software security program" to settle litigation with the Federal Trade Commission.
According to allegations made by the FTC, D-Link claimed that its devices were secure, while in reality vulnerabilities in the company's routers and Internet-connected cameras left sensitive consumer information, including live video and audio feeds, exposed to third parties and vulnerable to hackers.
The FTC action stemmed from a 2017 complaint specifically mentioning D-Link routers and IP cameras. Specifically, the FTC complaint pointed out hard-coded login credentials for IP cameras and storage of mobile app credentials in clear text.
As part of the settlement, D-Link will implement security planning, threat modeling, and vulnerability testing before releasing new products. In addition, the company will monitor existing systems for security flaws, push automatic firmware updates, and create a program for accepting vulnerability reports from researchers.
For more, read here.
Black Hat USA returns to Las Vegas with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions and service providers in the Business Hall. Click for information on the conference and to register.
About the Author
You May Also Like