Avast Blog_Security News: Smart home vendor reportedly exposes reset codes and device
#1
Information 
Quote:
[Image: TVDumYE.png]

Company that runs SmartMate, a platform to manage smart home appliances, involved with leak of over 2 billion records

A company that runs SmartMate, a platform to manage smart home appliances, has leaked over 2 billion logs of highly sensitive information via a publicly accessible database.

Orvibo’s database leak – which includes usernames, emails, passwords, family names, precise locations of IoT devices, and account reset codes – is a result of a misconfigured backend server that doesn’t require a password, as reported by ZDNet.

What’s worrisome is that the compromised data contains precise coordinates pinpointing the user’s exact location. Combined with other disclosed information, criminals can piece together identifiable data to further disrupt a user’s home. This could also lead to victims being followed, stalked, robbed, or spied on.

Perhaps the worst damage involves the company’s logging of passwords and account reset codes, which were hashed but not salted. This practice means that the stored passwords could be discovered and decrypted, then used to log in to an account without their knowledge. Any malicious actor could hijack SmartMate accounts and take full control of the user’s smart devices virtually.

Orvibo claims to have millions of users, including businesses and consumers. Researchers studied hacked accounts in China, and saw some signs of the breach in Thailand, Japan, the U.S., the U.K., France, Mexico, Australia and Brazil.

The incident highlights how consumers willingly give up data in order to own affordable smart devices, and how crucial it is to secure them with a strong password. It also underscores the need to encourage vendors to adopt better security practices, as recommended by our latest research study with Stanford University.

“Vendors offering low-cost IoT devices and services haven’t made security a top priority,” commented Martin Hron, an Avast Security researcher who has worked extensively on IoT devices. “Backend cloud services – used to remotely manage IoT devices or collect statistics – suffer from weak or nonexistent security. The implications are serious because unauthorized access to cloud data usually exposes all of the users’ devices, no matter how secure the individual devices are. It’s a single point of security failure.”

The devices connected to your home Wi-Fi network are digital windows into your family’s lives — and without proper protection, your privacy is at risk. Keep your home and family safe by protecting your connected devices with Avast Smart Home Security.   
Continue Reading
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Google Chrome 137.0.7151.103/.104
Google Chrome 137....harlan4096 — 09:35
Thunderbird version 139.0.2 (stable rele...
Thunderbird versio...harlan4096 — 09:26
Emsisoft Anti-Malware 2025.5.0.12672
Changes in 2025.5....harlan4096 — 07:22
Android Security Bulletin—June 2025
Android Security B...harlan4096 — 07:13
Audacity 3.7.4
Audacity 3.7.4​ ...harlan4096 — 07:11

[-]
Birthdays
Today's Birthdays
avatar (39)Julioagopy
avatar (49)aolaupitt2558
Upcoming Birthdays
avatar (38)Tedscolo
avatar (45)brakasig
avatar (44)JamesReshy
avatar (46)Francisemefe
avatar (39)leoniDup
avatar (38)Patrizaancem
avatar (38)biobdam
avatar (39)storoBox
avatar (47)kinotHeemn
avatar (38)Ceballos1976
avatar (39)efynu
avatar (31)horancos

[-]
Online Staff
There are no staff members currently online.

>