Amazon Ring doorbells exposed users' Wi-Fi passwords: Report


San Francisco, Nov 8 (IANS): Amazon has rolled out a security patch for its widely-popular Ring Video Doorbell Pro after Bitdefender security researchers found that it was exposing Wi-Fi network credentials, thus, allowing nearby attackers to intercept them and compromise the household network, media reports said.

Security researchers from Bitdefender said the Amazon-owned doorbell was sending owners' Wi-Fi passwords in cleartext as the doorbell joins the local network, thus, allowing nearby hackers to intercept the Wi-Fi password and gain access to the network to launch larger attacks or conduct surveillance.

"When first configuring the device, the smartphone app must send wireless network credentials. This takes place in an unsecure manner, through an unprotected access point. Once this network is up, the app connects to it automatically, queries the device, then sends the credentials to the local network," Bitdefender was quoted as saying by the TechCrunch on Thursday.

Notably, Amazon has dominated Apple and Google in the smart home market, thanks to its smart assistant Alexa and its Echo line up of devices.

Amazon fixed the vulnerability in all Ring devices in September, but the vulnerability was only disclosed now, the report added.

--IANS

ksc/arm

  

Top Stories


Leave a Comment

Title: Amazon Ring doorbells exposed users' Wi-Fi passwords: Report



You have 2000 characters left.

Disclaimer:

Please write your correct name and email address. Kindly do not post any personal, abusive, defamatory, infringing, obscene, indecent, discriminatory or unlawful or similar comments. Daijiworld.com will not be responsible for any defamatory message posted under this article.

Please note that sending false messages to insult, defame, intimidate, mislead or deceive people or to intentionally cause public disorder is punishable under law. It is obligatory on Daijiworld to provide the IP address and other details of senders of such comments, to the authority concerned upon request.

Hence, sending offensive comments using daijiworld will be purely at your own risk, and in no way will Daijiworld.com be held responsible.