Ring-a-ding: IoT doorbell exposed customer Wi-Fi passwords to eavesdroppers

Ring-a-ding: IoT doorbell exposed customer Wi-Fi passwords to eavesdroppers

5 years ago
Anonymous $xdcOWPpsb_

https://arstechnica.com/information-technology/2019/11/ring-patches-total-lack-of-password-security-during-setup/

Ring has pushed out a fix to a security issue in the configuration code for its Internet-connected home security products. Researchers from Bitdefender notified Ring in June of a flaw in Ring Video Doorbell Pro cameras' software that made it possible for wireless eavesdroppers to grab the Wi-Fi credentials of customers during the device's setup—because those credentials were sent over an unsecured Wi-Fi connection to the device using unencrypted HTTP.

In a report on the bug issued yesterday as part of a coordinated disclosure with Ring, Bitdefender researchers explained that when customers configured a Ring Video Doorbell Pro out of the box:

Last Seen
2 hours ago
Reputation
0
Spam
0.000
Last Seen
32 minutes ago
Reputation
0
Spam
0.000
Last Seen
46 minutes ago
Reputation
0
Spam
0.000
Last Seen
about an hour ago
Reputation
0
Spam
0.000
Last Seen
59 minutes ago
Reputation
0
Spam
0.000
Last Seen
about an hour ago
Reputation
0
Spam
0.000
Last Seen
about an hour ago
Reputation
0
Spam
0.000
Last Seen
about an hour ago
Reputation
0
Spam
0.000
Last Seen
4 hours ago
Reputation
0
Spam
0.000
Last Seen
22 minutes ago
Reputation
0
Spam
0.000
Last Seen
24 minutes ago
Reputation
0
Spam
0.000
Last Seen
17 minutes ago
Reputation
0
Spam
0.000
Last Seen
11 minutes ago
Reputation
0
Spam
0.000
Last Seen
54 minutes ago
Reputation
0
Spam
0.000
Last Seen
37 minutes ago
Reputation
0
Spam
0.000