Guru3D.com
  • HOME
  • NEWS
    • Channels
    • Archive
  • DOWNLOADS
    • New Downloads
    • Categories
    • Archive
  • GAME REVIEWS
  • ARTICLES
    • Rig of the Month
    • Join ROTM
    • PC Buyers Guide
    • Guru3D VGA Charts
    • Editorials
    • Dated content
  • HARDWARE REVIEWS
    • Videocards
    • Processors
    • Audio
    • Motherboards
    • Memory and Flash
    • SSD Storage
    • Chassis
    • Media Players
    • Power Supply
    • Laptop and Mobile
    • Smartphone
    • Networking
    • Keyboard Mouse
    • Cooling
    • Search articles
    • Knowledgebase
    • More Categories
  • FORUMS
  • NEWSLETTER
  • CONTACT

New Reviews
MS Flight Simulator (2020): the 2021 PC graphics performance benchmark review
Radeon Series RX 6700 XT preview & analysis
Corsair MM700 & Corsair Katar Pro XT Review
Guru3D Rig of the Month - February 2021
ASUS GeForce RTX 3060 STRIX Gaming OC review
EVGA GeForce RTX 3060 XC Gaming review
MSI GeForce RTX 3060 Gaming X TRIO review
PALIT GeForce RTX 3060 DUAL OC review
ZOTAC GeForce RTX 3060 AMP WHITE review
Fractal Design Meshify 2 Compact chassis review

New Downloads
GeForce 461.81 hotfix driver download
ClockTuner for Ryzen (CTR) v2.0 RC4 Download
SiSoft Sandra 20/21 download v31.12
Intel HD graphics Driver Download Version: DCH 27.20.100.9316
AIDA64 Download Version 6.32.5644 beta
FurMark Download v1.25
MSI Afterburner 4.6.3 Final Stable Download
Display Driver Uninstaller Download version 18.0.3.7
Guru3D RTSS Rivatuner Statistics Server Download 7.3.0 Final
Media Player Classic - Home Cinema v1.9.10 Download


New Forum Topics
11700K Retail Review RTSS 6.7.0 beta 1 Windows 10 20H2 (Build 19042.508) Is my Rtx 3090 dying? Restarting dlss option giving me 4 fps boost in Control - question Windows: Line-Based vs. Message Signaled-Based Interrupts. MSI tool. Nvidia INF driver modding (Guide) NVIDIA GeForce RTX 3080 Ti to get limited for Cryptocurrency Mining Performance Also Need help with HPET AMD Releases Ryzen Threadripper PRO, professional CPU series




Guru3D.com » News » ASUS Settles FTC Charges on Router Security

ASUS Settles FTC Charges on Router Security

by Hilbert Hagedoorn on: 02/25/2016 08:40 AM | source: | 7 comment(s)
ASUS Settles FTC Charges on Router Security

The FTC announced a settlement with ASUS on router security settings that left the personal data of 12,900 consumers’ publicly available. ASUS agreed to 20 years of periodic security audits along with fines of $16,000 per incident that could reach as much as $206 million in civil penalties.

Asus marketing material boasted its routers “protect computers from any unauthorized access, hacking, and virus attacks” and “protect [the] local network against attacks from hackers.”

The FTC’s proposed consent order will require Asus to “establish and maintain a comprehensive security program subject to independent audits for the next 20 years.” Based on the FTC’s claim that “hackers used readily available tools to locate vulnerable Asus routers and exploited these security flaws to gain unauthorized access to over 12,900 consumers’ connected storage devices” Asus may be on the hook to pay a civil penalty of up to $16,000 per incident or $206,400,000.

The FTC said, impacted Asus router owners have until March 24 to publicly comment on the proposed Asus settlement before the measure is enforced 30 days after the deadline.

“With so many devices being connected to the home network, routers are the consumer’s first line of defense,” said Nithan Sannappa, senior attorney at the FTC’s division Privacy and Identity Protection in an interview with Threatpost.

Sannappa said Asus’s security lapses caused real harm to consumers ranging from the exposure of sensitive files on the internet to identity theft. In numerous cases, Sannappa said, consumers’ personal files stored using Asus’s AiDisk FTP feature were indexed by a major search engine and accessible to anyone.  In at least one case, a consumer reported being the victim of identity theft when tax returns and other financial information were stolen from his storage device.

A Litany Of Security Failures

According to the original 2014 FTC complaint (PDF), Asus failed to protect consumers on multiple levels. For starters, Asus password protection was easy to bypass leading to reports of cross-site request forgery or cross-site scripting vulnerabilities.

At the time, some Asus customers complained that attackers changed their router security settings and modified the routers’ domain name server settings so that internet traffic could be routed to malicious malware laden sites.

A feature called AiCloud and AiDisk allowed you to plug a USB storage device into Asus routers. Asus advertised the feature as a “private personal cloud for selective file sharing” and a way to “safely secure and access your treasured data through your router.” However, the FTC said because the service relied on an insecure FTP implementation that didn’t encrypt data as it traveled over the network it allowed attackers to gain unauthorized access to 12,900 Asus routers.

Also problematic to the FTC was the fact when consumers attempted to download firmware updates for their Asus routers the software erroneously indicated their firmware was up-to-date when in fact updates were available.

Troubling signs for Asus router owners trace back to 2013 when security researcher Kyle Lovett posted a threat report that Asus routers were open to remote attacks because of vulnerabilities in the AiCloud service bundled with the hardware. Soon after, things went from bad to worse for Asus. In February 2014, an unknown hacker saved a text file to thousands of Asus router owners that read in part: “Your Asus router (and your documents) can be accessed by anyone in the world with an Internet connection.”



ASUS Settles FTC Charges on Router Security ASUS Settles FTC Charges on Router Security




« SD Association To Add Speed Class for 8K and Multi-File Video Recording · ASUS Settles FTC Charges on Router Security · The Division: 60FPS PC Gameplay Trailer »

2 pages 1 2


iancook221188



Posts: 1725
Joined: 2010-01-01

#5237470 Posted on: 02/29/2016 12:22 AM
so do i put my router in the bin then or is this solved

tsunami231
Senior Member



Posts: 11358
Joined: 2003-05-24

#5237478 Posted on: 02/29/2016 01:56 AM
idont even use AI cloud or FTP most that stuff is disabled much like upnp and it been patched, a long time ago, providing people keep up with fw updates.

sykozis
Senior Member



Posts: 21798
Joined: 2008-07-14

#5237708 Posted on: 02/29/2016 05:35 PM
Security is an illusion. Your private data is never completely safe.

Reardan
Senior Member



Posts: 369
Joined: 2014-09-21

#5237746 Posted on: 02/29/2016 06:56 PM
Security is an illusion. Your private data is never completely safe.


Seems like kind of a pointless, drive-by comment. Of course it's never safe. But it doesn't have to be this unsafe, where they just left large gaping holes unpatched. Like with Asus, the attacker didn't even need to be able to log in and they could change DNS settings.

tsunami231
Senior Member



Posts: 11358
Joined: 2003-05-24

#5237772 Posted on: 02/29/2016 08:09 PM
Security is an illusion. Your private data is never completely safe.


so is privacy in an online interconnected world.

Seems like kind of a pointless, drive-by comment. Of course it's never safe. But it doesn't have to be this unsafe, where they just left large gaping holes unpatched. Like with Asus, the attacker didn't even need to be able to log in and they could change DNS settings.


again these holes have been long since patched, Providing people keep up with firmware update,

2 pages 1 2


Post New Comment
Click here to post a comment for this news story on the message forum.


Guru3D.com © 2021