Privacy Tip #297 – Vulnerability in Smart Home Devices Including Baby Monitors

Robinson+Cole Data Privacy + Security Insider
Contact

Mandiant, a division of FireEye, has reported that it has discovered a vulnerability in a software protocol that enables hackers to gain access to audio and visual data on smart devices including baby monitors and web cameras. The protocol was created by Taiwanese Internet of Things vendor ThroughTek, and is incorporated in as many as 83 million devices.

According to reports, ThroughTek has confirmed that it has notified customers of the vulnerability and information about mitigating the gap.

According to Mandiant, the threat actor could exploit the vulnerability to communicate directly with devices to plan and deploy subsequent attacks. Mandiant stated that the Department of Homeland Security would be issuing an alert to raise awareness of the issue.

It is difficult as a consumer to stay abreast of vulnerabilities in component parts of products that use other companies’ software. However, the security of the component parts is crucial to the security of the IoT device.

Mandiant suggests that users of IoT devices, including baby monitors, web cameras, home security systems, personal assistants, and basically anything else that uses the Internet, to update their software (also known as patching) as soon as you receive notice. I would add to limit the use of IoT devices and to closely follow the device’s Privacy Policy and updates.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Robinson+Cole Data Privacy + Security Insider | Attorney Advertising

Written by:

Robinson+Cole Data Privacy + Security Insider
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Robinson+Cole Data Privacy + Security Insider on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide