Security News > 2023 > June > Amazon Ring, Alexa accused of every nightmare IoT security fail you can imagine

Amazon Ring, Alexa accused of every nightmare IoT security fail you can imagine
2023-06-01 06:33

The e-tail giant's Ring home security cam subsidiary was accused of "Compromising its customers' privacy by allowing any employee or contractor to access consumers' private videos and by failing to implement basic privacy and security protections, enabling hackers to take control of consumers' accounts, cameras, and videos."

The FTC complaint also alleges Ring knew its cloud services were susceptible to credential stuffing and brute-force attacks but did little to stymie such efforts.

The miscreants also had access to users' accounts, which is where things get worse because Ring devices provide real-time messaging and communications, the FTC pointed out.

The FTC has proposed an order [PDF] that will see Ring cough up $5.8 million to settle the matter.

In a statement, an Amazon spokesperson said: "While we disagree with the FTC's claims regarding both Alexa and Ring, and deny violating the law, these settlements put these matters behind us."

It is entirely conceivable those unfortunate Ring customers who were, as the FTC described, verbally assaulted in their homes will perhaps take years to get over the ugly incidents Amazon's laxness made possible.


News URL

https://go.theregister.com/feed/www.theregister.com/2023/06/01/ftc_alexa_ring_amazon_settlement/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Amazon 67 9 60 43 13 125