Amazon Ring Doorbells Exposed Home Wi-Fi Passwords To Hackers

Peter Reutemann <[email protected]> Fri, 8 Nov 2019 10:44:56 +1300
Newsgroups gmane.org.user-groups.linux.waikato
Message-ID <CAHoQ12KA8-L=uuZRMzoEQCWWswwPYkitt2SS=E7v4SeF6=gHGA@mail.gmail.com>
'Security researchers have discovered a vulnerability in Ring
doorbells that exposed the passwords for the Wi-Fi networks to which
they were connected. Bitdefender said the Amazon-owned doorbell was
sending owners' Wi-Fi passwords in cleartext as the doorbell joins the
local network, allowing nearby hackers to intercept the Wi-Fi password
and gain access to the network to launch larger attacks or conduct
surveillance.

"When first configuring the device, the smartphone app must send the
wireless network credentials. This takes place in an unsecure manner,
through an unprotected access point," said Bitdefender. "Once this
network is up, the app connects to it automatically, queries the
device, then sends the credentials to the local network." But all of
this is carried out over an unencrypted connection, exposing the Wi-Fi
password that is sent over the air. Amazon fixed the vulnerability in
all Ring devices in September, but the vulnerability was only
disclosed today.'

-- source: https://mobile.slashdot.org/story/19/11/07/2125208

Cheers, Peter
-- 
Peter Reutemann
Dept. of Computer Science
University of Waikato, NZ
+64 (7) 858-5174
http://www.cms.waikato.ac.nz/~fracpete/
http://www.data-mining.co.nz/
_______________________________________________
wlug mailing list -- [email protected] | To unsubscribe send an email to [email protected]
Unsubscribe: https://list.waikato.ac.nz/postorius/lists/wlug.list.waikato.ac.nz