D-Link Settles With FTC, Agrees To Fix Its Shoddy Router Security

from the slowly-getting-the-message dept

While the shoddy Internet of Things sector gets ample heat for being a security and privacy dumpster fire, the traditional network gear sector has frequently been just as bad. A few years ago, for example, hardware vendor Asus was dinged by the FTC for offering paper-mache grade security on the company’s residential network routers. The devices were frequently being shipped with easily guessable default usernames and passwords, and contained numerous, often obvious, security vulnerabilities.

In 2017, the FTC also filed suit against D-Link, alleging many of the same things. According to the FTC, the company’s routers and video cameras, which the company claimed were “easy to secure” and delivered “advanced network security,” were about as secure as a kitten-guarded pillow fort. Just like the Asus complaint, the FTC stated that D-Link hardware was routinely shipped with easily-guessable default usernames and passwords, making it fairly trivial to compromise the devices and incorporate them into DDoS botnets (or worse).

Like any good company, D-Link at the time professed its innocence, insisting there was nothing wrong with its products and that the FTC claims were “vague and unsubstantiated.” Fast forward to this week, when the company struck a settlement with the FTC, and, according to an FTC press release, has agreed to fix security flaws it previously had claimed didn’t exist:

?We sued D-Link over the security of its routers and IP cameras, and these security flaws risked exposing users? most sensitive personal information to prying eyes,? said Andrew Smith, Director of the FTC?s Bureau of Consumer Protection. ?Manufacturers and sellers of connected devices should be aware that the FTC will hold them to account for failures that expose user data to risk of compromise.?

It has taken a while, but router manufacturers have started to finally get the message that their routers’ installation process should prompt users to pick a unique username and password before finalizing device setup. As part of D-Link’s agreement, it not only has to implement new and comprehensive security testing protocols, it’s required every two years to obtain independent third-party assessments of its software security programs.

Granted, whether we’re talking about routers or the latest IoT doodad, there are far too many security vulnerabilities out there for the FTC to police them all right now. Which is why efforts by Consumer Reports and others to begin standardizing the inclusion of security and privacy weaknesses in product reviews are going to be so important in educating consumers.

Filed Under: , , ,
Companies: d-link

Rate this comment as insightful
Rate this comment as funny
You have rated this comment as insightful
You have rated this comment as funny
Flag this comment as abusive/trolling/spam
You have flagged this comment
The first word has already been claimed
The last word has already been claimed
Insightful Lightbulb icon Funny Laughing icon Abusive/trolling/spam Flag icon Insightful badge Lightbulb icon Funny badge Laughing icon Comments icon

Comments on “D-Link Settles With FTC, Agrees To Fix Its Shoddy Router Security”

Subscribe: RSS Leave a comment
That Anonymous Coward (profile) says:

If only there were some rules for bare basic requirements with nice fines attached, that didn’t require a long court case that never gets anywhere but a settlement.

It is one thing to be vulnerable to say HeartBleed in the first month after its disclosed, but a year later new routers shipping with a well documented vulnerability should result in fines that keep going until the fix is pushed & publicized.

Consumers are fickle & often forget those companies they hate that burned them before because something shiny distracts them. Give us more data and we’ll pump up your credit score – Equifax
Advertising this new program that gives you credit for paying utilities and the like (of course it might not actually raise the rate lenders see when examining you in tiny white print on a slightly different shade of white on the screen). People are signing up, and handing more information to a company that lied, lied, lied, screwed everyone, and dumped their stock before telling the world about it so they could cash out.

Every maker wants to offer the newest bestest cool things…
99.9% of people have no idea how it helps them but they’ve heard the words so it must be important… they bolt on all of these features most users have no use or need for never making sure it functions on the most basic levels.

We need to stop accepting that ‘hackers’ are super powered demons & that no one can stop them so why even try.
Shipping a router with admin admin & default open to being accessed from the web should be costly to the maker.

Add Your Comment

Your email address will not be published. Required fields are marked *

Have a Techdirt Account? Sign in now. Want one? Register here

Comment Options:

Make this the or (get credits or sign in to see balance) what's this?

What's this?

Techdirt community members with Techdirt Credits can spotlight a comment as either the "First Word" or "Last Word" on a particular comment thread. Credits can be purchased at the Techdirt Insider Shop »

Follow Techdirt

Techdirt Daily Newsletter

Techdirt Deals
Techdirt Insider Discord
The latest chatter on the Techdirt Insider Discord channel...