This topic has been closed to new posts due to inactivity. We hope you'll join the conversation by posting to an open topic or starting a new one.
Important Security Bug - iOS Arlo App 2.1.2
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi there,
New to the forum and happy owner of an Arlo Q soon to be extended with some wire-free Arlos.
I remember a while back seeing a post (but cannot find it anywhere again) mentionning a serious security flaw allowing to bypass Touch ID login without entering the passwod on the iOS Arlo app 2.1.2 (Released August 1st) giving full access to the online system and the library. This stand with the 2 latest releases of iOS 9.3.3&9.3.4 so definitely app related. Perhaps it wasn't for this version of the app but the problem persists.
I found it too and is quite easy to figure out and works 100%.
I won't give the steps here for obvious reasons but could a Netgear rep get in touch with me for me to pass on the exact repro steps or if acknowledged and spotted already by the dev team give an ETA for the fix in this thread? This is a major issue!
Thanks!
- Related Labels:
-
Online and Mobile Apps
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Dinerve,
Feel free to private message me your findings and I will create a case and escalate as necessary.
Thank you,
JamesC
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey JamesC,
Thanks for getting back to me, I've PM'd you as requested.
Cheers,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Dinerve,
Thank you for bringing this to our attention. I have created and escalated a case with the information you have provided.
JamesC
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks,
I hope it will be adressed in the upcoming 2.1.3 version of the iOS app!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
So, I was hoping this would be resolved with 2.1.3 but it's not.
Should I make the video public to gain some traction? I'm sure this was reported before me as well and can't find the thread anymore!
Currently under iOS someone can log in without your fingerprint or password! This is major both in terms of security AND privacy and needs a quick fix! C'mon guys!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Dinerve,
This issue is still under investigation by the engineering team. We take security and privacy concerns very seriously and hope to be able to provide a solution quickly.
I have requested an update on this and will post again once I have more information.
JamesC
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks JamesC,
Looking forward to have this addressed.
-
Android App
2 -
Applications mobile et en ligne
1 -
Batteries
1 -
Before You Buy
10 -
Détection de mouvements
1 -
Features
10 -
Firmware Release Notes
1 -
Geo-Fencing
89 -
IFTTT (If This Then That)
13 -
Installation
14 -
iOS App
2 -
Modes and Rules
909 -
Motion Detection
69 -
Online and Mobile Apps
1,268 -
Online Web
3 -
Service and Storage
51 -
Surveillance
1 -
Troubleshooting
89 -
Videos
3
- « Previous
- Next »