- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi there,
New to the forum and happy owner of an Arlo Q soon to be extended with some wire-free Arlos.
I remember a while back seeing a post (but cannot find it anywhere again) mentionning a serious security flaw allowing to bypass Touch ID login without entering the passwod on the iOS Arlo app 2.1.2 (Released August 1st) giving full access to the online system and the library. This stand with the 2 latest releases of iOS 9.3.3&9.3.4 so definitely app related. Perhaps it wasn't for this version of the app but the problem persists.
I found it too and is quite easy to figure out and works 100%.
I won't give the steps here for obvious reasons but could a Netgear rep get in touch with me for me to pass on the exact repro steps or if acknowledged and spotted already by the dev team give an ETA for the fix in this thread? This is a major issue!
Thanks!
- Related Labels:
-
Online and Mobile Apps

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Dinerve,
Feel free to private message me your findings and I will create a case and escalate as necessary.
Thank you,
JamesC

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey JamesC,
Thanks for getting back to me, I've PM'd you as requested.
Cheers,

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Dinerve,
Thank you for bringing this to our attention. I have created and escalated a case with the information you have provided.
JamesC
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks,
I hope it will be adressed in the upcoming 2.1.3 version of the iOS app!

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
So, I was hoping this would be resolved with 2.1.3 but it's not.
Should I make the video public to gain some traction? I'm sure this was reported before me as well and can't find the thread anymore!
Currently under iOS someone can log in without your fingerprint or password! This is major both in terms of security AND privacy and needs a quick fix! C'mon guys!

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Dinerve,
This issue is still under investigation by the engineering team. We take security and privacy concerns very seriously and hope to be able to provide a solution quickly.
I have requested an update on this and will post again once I have more information.
JamesC

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks JamesC,
Looking forward to have this addressed.
