Whirlpool Left Appliance Data, User Emails Exposed Online

from the internet-of-very-broken-things dept

Another day, another shining example of why connecting everything from your Barbie dolls to tea kettles to the internet was a bad idea. This week it’s Whirlpool that’s under fire after a researcher discovered that the company had failed to secure a database containing 28 million records collected from the company’s “smart” appliances. The database contained user email addresses, model names and numbers, unique appliance identifiers, and data collected from routine analysis of the appliances’ condition, including how often the appliance is used, when its off or on, and whether it had any issues.

Needless to say this is just the latest example of security researchers doing companies’ jobs for them after they connected their products to the internet, then failed to adequately secure the data gleaned from them. For its part, Whirlpool told the researcher that they managed to secure the information within a few days of being alerted earlier this month:

“Our company was recently made aware of a potential security concern with respect to one of its databases. The database was immediately taken offline and secured. Our investigation showed that 48,000 emails were publicly available ? but no confidential information was exposed. We are in the process of reaching out to impacted consumers. Our company appreciated this notification so the issue could be quickly addressed.”

Granted these kinds of issues occur at least once a week at this point, highlighting how companies were so excited to connect everything to the internet, they never stopped to ask if it was really necessary. A new study by hardware security company nCipher drives that point home, highlighting how the majority of IT professionals are terrified of the security nightmare we’ve created in the internet of broken things era:

“Sixty-eight percent of these professionals worried that hackers will simply alter the function of an IoT device. Fifty-four percent are concerned that IoT devices will come under the remote control of people with nefarious purposes or merely cruel senses of humor.”

As security experts have long noted, there’s no market solution to this problem because neither the hardware vendors nor the consumers actually care, given the privacy and security shortcomings (usually) only harm other people. The consumer doesn’t care, often because they’re never informed that this data is bouncing around the internet unsecured. The vendors don’t care, because they’re already on to marketing the next product and don’t want to retroactively improve and secure their products. And government is, well, busy right now trying to chew gum and walk at the same time.

That’s what makes efforts to educate consumers by including privacy features and security practices as part of product reviews so important. It’s at least a fleeting attempt to generate some form of organic punishment for companies who treat security and privacy as a distant afterthought.

Filed Under: , , , , ,
Companies: whirlpool

Rate this comment as insightful
Rate this comment as funny
You have rated this comment as insightful
You have rated this comment as funny
Flag this comment as abusive/trolling/spam
You have flagged this comment
The first word has already been claimed
The last word has already been claimed
Insightful Lightbulb icon Funny Laughing icon Abusive/trolling/spam Flag icon Insightful badge Lightbulb icon Funny badge Laughing icon Comments icon

Comments on “Whirlpool Left Appliance Data, User Emails Exposed Online”

Subscribe: RSS Leave a comment
Anonymous Coward says:

data collected from routine analysis of the appliances’ condition, including how often the appliance is used, when its off or on, and whether it had any issues.

That seems like the type of thing that could help the company build better products. Except popular opinion is that the opposite is happening, that they could already make a good product in the 1970s and stopped doing it around the 1990s. So they’re probably just trying to increase their profit margins.

This comment has been flagged by the community. Click here to show it.

Anonymous Coward says:

Well, I would like to add just one thing to this discussion. Good for Techdirt! You know why?

For the longest time, Techdirt silenced my voice. I had to travel from place to place, connecting to strange wireless networks, riding trains to far-away lands, just to find an IP address that Techdirt would not block.

And now, it’s OVER! Techdirt stopped blocking me! Good for you! I think if you follow that up with not censoring comments, you could be moving towards a new found legitimacy and openness that is worthy of RESPECT!


Did I mention that Tucker Carlson is going to run for President? I’m not kidding – he went to North Korea with Trump, did you catch that? Trump likes him. And Tucker can out-debate anyone, especially morally repugnant assholes that often frequent this site. AND, Tucker believes in Free Speech.

Who here would vote for Tucker after 2 terms of Trump? STAND UP AND BE COUNTED!

Add Your Comment

Your email address will not be published. Required fields are marked *

Have a Techdirt Account? Sign in now. Want one? Register here

Comment Options:

Make this the or (get credits or sign in to see balance) what's this?

What's this?

Techdirt community members with Techdirt Credits can spotlight a comment as either the "First Word" or "Last Word" on a particular comment thread. Credits can be purchased at the Techdirt Insider Shop »

Follow Techdirt

Techdirt Daily Newsletter

Techdirt Deals
Techdirt Insider Discord
The latest chatter on the Techdirt Insider Discord channel...