Taiwan-based computer hardware maker ASUSTeK Computer has agreed to settle Federal Trade Commission (FTC) charges that security flaws in its routers put the home networks of consumers at risk. The administrative complaint also charges that the routers’ insecure "cloud" services led to the compromise of thousands of consumers’ connected storage devices, exposing their sensitive personal information on the internet.
The proposed consent order will require ASUS to establish and maintain a security program subject to independent audits for the next 20 years.
ASUS marketed its routers as including numerous security features that the company claimed could "protect computers from any unauthorized access, hacking, and virus attacks" and "protect [the] local network against attacks from hackers." Despite these claims, the FTC’s complaint alleges that ASUS didn’t take reasonable steps to secure the software on its routers.
For instance, according to the complaint, hackers could exploit pervasive security bugs in the router’s web-based control panel to change any of the router’s security settings without the consumer’s knowledge. The complaint also highlights a number of other design flaws that exacerbated these vulnerabilities, including the fact that the company set – and allowed consumers to retain – the same default login credentials on every router: username "admin" and password "admin".
According to the complaint, ASUS’s routers also featured services called AiCloud and AiDisk that allowed consumers to plug a USB hard drive into the router to create their own cloud storage accessible from any of their devices. While ASUS advertised these services as a "private personal cloud for selective file sharing" and a way to "safely secure and access your treasured data through your router," the FTC’s complaint alleges that the services had serious security flaws.
The Commission alleges that, in many instances, ASUS did not address security flaws in a timely manner and did not notify consumers about the risks posed by the vulnerable routers. In addition, the complaint alleges that ASUS did not notify consumers about the availability of security updates.
In addition to establishing a comprehensive security program, the consent order will require ASUS to notify consumers about software updates or other steps they can take to protect themselves from security flaws, including through an option to register for direct security notices (e.g., through email, text message, or push notification). The consent order will also prohibit the company from misleading consumers about the security of the company’s products, including whether a product is using up-to-date software.