Why is the FTC posting sensationalist crap for the casual user?
One of their pointers is "Don’t just click “next” during the set-up process."... Thanks for the tip.
Is this some political smear campaign? Every company has released vulnerable software...
Seriously, the actual complaint pdf cites zero commonly accepted security/exploit databases in any of the individual issues.
Is there something I am missing?
Looks like ASUS is going to have to endure frequent audits of its router security.
https://www.techdirt.com/articles/2...h-default-admin-admin-login-other-flaws.shtml
Hopefully this extra effort required by ASUS to appease the Feds won't impact its creativity or ability to deliver great products. Seems to me they are being punished because they didn't force users to take obvious steps to protect their own network. But their slow response didn't help either.
Respectfully I have to disagree. They have been slapped because their advertising claims that the various features are secure despite some flaws that ASUS haven't adequately handled.
There are a number of serious flaws identified by the FTC outside the common default password behaviour including not encrypting AiDisk files in transit and a credential bypass flaw in AiCloud. To compound these the update check was found to be not working properly and there is no mailing list that a user can sign up to in order to be reasonably informed of such flaws. This then lead to a situation where 'In February 2014, hackers used readily available tools to locate vulnerable ASUS routers and exploited these security flaws to gain unauthorized access to over 12,900 consumers’ connected storage devices'.
According the article I read on The Register ASUS were found to be NOT conducting any kind of penetration testing for their products which I suppose will be in the original complaint.
I do believe this ruling is fair. I am not saying that ASUS are more deserving of attention that any other router manufacturer and I accept that others will probably be found to have similar issues.
This is not cross posting. It's a valid post. Please leave moderation to me.Cross posting is not allowed in most forums. I don't see this as being any different?
This is not cross posting. It's a valid post. Please leave moderation to me.
As the author in Ken's link says other manufacturers have similar issues and this may just be the beginning of many settlements, I also think it will slowly move to other manufacturers as well.
For those of you who may be of the left-of-center political orientation, well, this is what MORE government looks like in you lives.
...
20 year security audits - that's a bit extreme, IMHO...
Welcome To SNBForums
SNBForums is a community for anyone who wants to learn about or discuss the latest in wireless routers, network storage and the ins and outs of building and maintaining a small network.
If you'd like to post a question, simply register and have at it!
While you're at it, please check out SmallNetBuilder for product reviews and our famous Router Charts, Ranker and plenty more!