2 billion smart home records left exposed on the internet

The Orvibo website claims that the company supports millions of IoT devices and it can guarantee that data are safe and secured. However, researchers discovered otherwise.


Load web pages faster. Block ads. Get Brave For Free

A database containing billions of records was found to have been left exposed to the internet without any password to protect it. The database was owned by a Chinese company known as Orvibo with various smart home devices available in the market.

According to the vpnMentor security researchers who exposed the anomaly, the database contains various information including email addresses, passwords, precise geolocation, IP address, username, userID, family name and ID, smart device, device that access account, scheduling information, and account reset codes.

The researchers said that reset codes would be sent to a user to reset either their password or their email address. With this information available readily, hackers will be able to lock users out of their account without reading their password. Once both password and email address are changed, the user won’t be able to reverse it.

Some of Orvibo’s smart devices are home security devices such as smart locks, home security cameras, and full smart home kits. Ironically, with these vulnerabilities, there is nothing secure about smart devices at all. Deploying these devices in the hopes of getting secured undermines the owner's security instead of protecting it. Even worse is the fact that the Orvibo website claims that the company supports millions of IoT devices and it can guarantee that data are safe and secured.

Orvibo currently makes almost 100 smart home or smart automation devices. The company also claims that it has more than 1 million users globally. These do not only include individuals with smart home systems but hotels and business customers as well. The researchers have already discovered information for users in Japan, China, Thailand, Mexico, Australia, France, Brazil, the United Kingdom and even in the USA.

The good news is that there is still no known reports saying that anyone has taken advantage of the vulnerability. The database was closed on July 2nd.

Use The Fastest Browser That Doesn’t Track You

Blocks ads. Blocks tracking. Keeps you and your data private. Free and open source. Up to 8 times faster page loads than Chrome and Safari. Join the Brave revolution today.

>> Use Brave To Browse The Web Faster, In Private <<


Arnold Zafra

Arnold Zafra is tech blogger that's enthusiastic about cryptocurrency, social networking, security, and privacy, as well as search engine technology. His work has been featured on Android Authority and Droid Life before joining Reclaim The Net. [email protected]
Do NOT follow this link or you will be banned from the site!