FTC sues IoT Device Manufacturer D-Link for Lax Cyber Security Practices

Snell & Wilmer
Contact

On January 5, 2017, the Federal Trade Commission (“FTC”) filed a complaint against computer networking hardware manufacturer D-Link Corporation, alleging that the company’s wireless routers, IP cameras, and other “Internet of Things” (IoT) products failed to implement basic security features, thus exposing consumers to heightened risks for privacy violations, malware, and hacking attacks.  The complaint alleges that, despite publicly touting its products as featuring “advanced network security” and being among the “safest” in the industry, D-Link did not implement reasonable cyber security measures. An explanatory blog post provided by the FTC and the complaint against D-Link can be viewed online.

According to the complaint, D-Link’s actions unfairly and deceptively put consumer’s information and security at risk by, among others:

  • Leaving hard-coded username/password login credentials in its camera software, permitting unauthorized remote access to the video feed from a camera;
  • Leaving consumer login information in unencrypted plaintext form in a D-Link mobile application; and
  • Failing to secure the encryption key used to digitally sign genuine D-Link software, resulting in the key being publicly available on line for several months.

The FTC has previously brought similar enforcement actions against computer hardware maker ASUS and camera manufacturer TRENDNet.  The explosion in the number and capability of IoT devices is leading to a number of other security concerns, including use of compromised IoT devices in Distributed Denial of Service (DDoS) attacks.  Given this ongoing concern, we anticipate the FTC will continue to bring enforcement actions against companies who misrepresent the security status of their products and services.  Companies operating in this area would be well served to review and consider the FTC’s advice for businesses related to IoT security found here.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Snell & Wilmer | Attorney Advertising

Written by:

Snell & Wilmer
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Snell & Wilmer on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide