Skip to main content

Wyze exposes customer details online

Smart device company Wyze accidentally exposed a database online containing details from up to 2.4 million customers.

The incident happened early in December, eventually being noticed by cybersecurity company Twelve Security at the end of the month, when it was reported by video surveillance news website IPVM.


Data exposed

According to Wyze, a budget vendor in smart devices such as cameras, locks, bulbs, and plugs, the database was a test environment for making information processing more efficient.

However, while Wyze said it was exposed in error, Twelve Security reported that details included email addresses, usernames, and security tokens - enough information for malicious third parties to take control over any smart devices affected.

Wyze has since reset its systems to help prevent that. 

The problem arose when Wyze, using Amazon Web Services to process Internet of Things (IoT) data, left security protocols off that allowed their Elasticsearch data to be accessed online. It remains a reminder to businesses that they are ultimately responsible for security when it comes to cloud computing services.

However, this isn't the first time Wyze have run into problems with user access. Earlier this year a flaw in their system allowed users to still access smart cameras that had been reassigned to another account.

Via ZDnet



from TechRadar - All the latest technology news https://ift.tt/2Qvqhq7

Comments

Popular posts from this blog

Airship acquires SMS commerce company ReplyBuy

Airship is announcing that it has acquired mobile commerce startup ReplyBuy . The startup (which was a finalist at TechCrunch’s 1st and Future competition in 2016) works with customers like entertainment venues and professional and college sports teams to send messages and sell tickets to fans via SMS. It raised $4 million in funding from Sand Hill Angels, Kosinski Ventures, SEAG Ventures, Enspire Capital, MRTNZ Ventures and others, according to Crunchbase . Airship, meanwhile, has been expanding its platform beyond push notifications to cover customer communication across SMS, email, mobile wallets and more. But CEO Brett Caine said this is the first time the company is moving into commerce. While sports and concerts tickets might not be a booming market right now, Caine suggested that the company is actually seeing increased purchasing activity “in and around the Airship platform” as businesses try to drive more in-app purchases. He also suggested that both the COVID-19 pandem...

TalentLMS