Stories
Slash Boxes
Comments

SoylentNews is people

posted by Fnord666 on Tuesday July 02 2019, @01:22PM   Printer-friendly
from the no-salt-added dept.

BleepingComputer reports that Chinese smart home vendor Orvibo has an unsecured database online that exposes over 2 billion logs detailing usernames, email address, passwords and more.

The disclosing research firm's report is available here.

vpnMentor's research team reached out to the vendor on June 16th, but did not receive a response and as of publication the database is apparently still online and the amount of data exposed is still increasing.

Exposed data includes:

  • Email addresses
  • Passwords
  • Account reset codes
  • Precise user geolocation
  • IP addresses
  • Username & UserID
  • Family name & Family ID
  • Device name & Device that accessed account
  • Recorded conversations through Smart Camera
  • Scheduling information

Passwords are hashed but without adding a salt, making them relatively easy to crack.

Possibilities for hackers are myriad, including completely locking users out of their own accounts and taking complete control of smart homes, accessing video feeds, unlocking doors and more.


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 3, Insightful) by SomeGuy on Tuesday July 02 2019, @04:32PM

    by SomeGuy (5632) on Tuesday July 02 2019, @04:32PM (#862440)

    TL;DR version - The answer to the OP is: there are WAY TOO MANY idiots just handing over their data to these IoT assholes, and it needs to stop.

    Starting Score:    1  point
    Moderation   +1  
       Insightful=1, Total=1
    Extra 'Insightful' Modifier   0  
    Karma-Bonus Modifier   +1  

    Total Score:   3