TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Two Billion Records Exposed in 'Smart Home' Breach

193 pointsby louisstowalmost 6 years ago

17 comments

m34almost 6 years ago
(tech) people tend to laugh at me&#x2F;pull the tinfoil hat card for putting my dlink&#x2F;iot stuff behind a very restrictive, dedicated, iptables filtered, hostapd based custom network running on my pi zero w that isn’t allowed to talk to the home network or internet at all.<p>As mentioned by others, I guess it really needs severe identity theft&#x2F;abuse with vital services until people realize that today‘s IoT &#x27;plug &amp; play&#x27; is worse than than the level of &#x27;plug &amp; pray&#x27; we‘ve seen in the early PCI&#x2F;USB&#x2F;Win98 era (that only impacted your local device functionality).
评论 #20354251 未加载
评论 #20353816 未加载
评论 #20353880 未加载
评论 #20354768 未加载
评论 #20355108 未加载
评论 #20355709 未加载
评论 #20354151 未加载
OJFordalmost 6 years ago
&gt; a misconfigured and Internet-facing Elasticsearch database without a password.&quot; If this wasn&#x27;t bad enough, a Kibana web-based app, there to make navigating through the data easier, had no password protection.<p>That&#x27;s not even really &#x27;exposed in breach&#x27;, that&#x27;s just &#x27;exposed&#x27;.
评论 #20353396 未加载
评论 #20353354 未加载
评论 #20355048 未加载
评论 #20353849 未加载
评论 #20359638 未加载
monocasaalmost 6 years ago
You know what they say: it&#x27;s the &#x27;S&#x27; in &#x27;IoT&#x27; that stands for security.
评论 #20353503 未加载
评论 #20356062 未加载
userbinatoralmost 6 years ago
IMHO more disturbing than the lack of security is the fact that people will willingly put these products in their house that phone home to a central database.<p>I&#x27;m not into the whole IoT thing but if I really had a need to control something from anywhere on the Internet, it would not rely on a centralised third-party service.
评论 #20353815 未加载
class4behavioralmost 6 years ago
&gt;It&#x27;s unknown if anyone has taken advantage of the vulnerability (yet) and, as of July 1, the database was still accessible with no password protection.<p>And this article had been published today... The database had been closed a day later on July 2.<p>Here the the original report instead of a Forbes article: <a href="https:&#x2F;&#x2F;www.vpnmentor.com&#x2F;blog&#x2F;report-orvibo-leak&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.vpnmentor.com&#x2F;blog&#x2F;report-orvibo-leak&#x2F;</a>
评论 #20353523 未加载
walrus01almost 6 years ago
The Twitter account &quot;internet of shit&quot; tracks these sort of things.<p>Mark my words, eventually the world is going to see some sort of Fukushima scale internet of shit disaster caused by poor security&#x2F;architecture. I&#x27;m not sure what form it will take, maybe mass pwnage of a device as commonplace as Amazon echo or Google home, but it will be bad.
评论 #20353370 未加载
评论 #20353474 未加载
评论 #20353330 未加载
评论 #20355622 未加载
评论 #20354523 未加载
Aardappelalmost 6 years ago
They were trying to expose more than 2 billion records, but had to stop when the record count went to -2 billion.
ridajalmost 6 years ago
How do researchers just &quot;come across&quot; these massive data dumps
评论 #20353637 未加载
评论 #20353506 未加载
评论 #20353500 未加载
gumbyalmost 6 years ago
&gt; The information in the database belonged to Orvibo<p>Would things meaningfully become more secure if we had a legal framework under which the information in the database belonged to each consumer? Or would a simple click-through license make that moot?
评论 #20356212 未加载
MrGilbertalmost 6 years ago
Does anyone know a decent tutorial or explanation, how to &quot;secure&quot; one&#x27;s network with IoT devices in it?<p>For instance, all my lights are controlled using IKEA&#x27;s TRÅDFRI solution. Also, they are integrated into my own HomeAssistant instance (dockerized), which runs on my Unraid machine, which also hosts my data shares. Then we have FireTV&#x27;s, Echo&#x27;s, we have a Xiaomi vacuum robot, and so on. The FireTV should be able to access the data shares for playing back movies. Alexa can control our lights, too.<p>I&#x27;m still struggeling to find a &quot;one size fits all&quot; solution.
评论 #20361565 未加载
评论 #20353769 未加载
lyspalmost 6 years ago
Further details here:<p><a href="https:&#x2F;&#x2F;www.vpnmentor.com&#x2F;blog&#x2F;report-orvibo-leak&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.vpnmentor.com&#x2F;blog&#x2F;report-orvibo-leak&#x2F;</a><p>Which was posted a few days ago.
PedroBatistaalmost 6 years ago
Correct me if I&#x27;m wrong but isn&#x27;t vanilla Elasticsearch open and insecure by default? and password&#x2F;token security features are only available in some paid tier?
idilivalmost 6 years ago
How significant is the &quot;two billion records&quot; figure? According to the article, the affected smart-home provider mereley &quot;claims to have more than a million users around the world&quot;. So presumably this database contains a lot of redundant information?
评论 #20353508 未加载
评论 #20353350 未加载
petarbalmost 6 years ago
People need to stop exposing their Elasticsearch clusters and Kibana to the internet. A lot of these &quot;breaches&quot; lately have been because of this.<p>I hope Elastic makes it more difficult to make your cluster public by default in future versions.
k_szealmost 6 years ago
I have never setup Elasticsearch or Kibana mysslf, but is the setup process <i>secure-by-default</i>? i.e. generate a random password or key by default, and then you have to go out of your way to unsecure it?
评论 #20353782 未加载
quickthrower2almost 6 years ago
Eerie as I am working on an unsecured ES instance and then I see this. My one is just for playing though. No sensitive data there :-)
评论 #20353781 未加载
lelimaalmost 6 years ago
I wonder what&#x27;s the worst possible scenario, having access to your home security cameras or more like using the email and password.
评论 #20353351 未加载
评论 #20353353 未加载