Arlo|Smart Home Security|Wireless HD Security Cameras

Reply
Discussion stats
  • 7 Replies
  • 1708 Views
  • 1 Like
  • 2 In Conversation
Dinerve
Apprentice
Apprentice

Hi there,

 

New to the forum and happy owner of an Arlo Q soon to be extended with some wire-free Arlos. Smiley Happy

 

I remember a while back seeing a post (but cannot find it anywhere again) mentionning a serious security flaw allowing to bypass Touch ID login without entering the passwod on the iOS Arlo app 2.1.2 (Released August 1st) giving full access to the online system and the library. This stand with the 2 latest releases of iOS 9.3.3&9.3.4 so definitely app related. Perhaps it wasn't for this version of the app but the problem persists.

 

I found it too and is quite easy to figure out and works 100%.

 

I won't give the steps here for obvious reasons but could a Netgear rep get in touch with me for me to pass on the exact repro steps or if acknowledged and spotted already by the dev team give an ETA for the fix in this thread? This is a major issue!

 

Thanks!

 

 

7 REPLIES 7
JamesC
Community Manager
Community Manager

Dinerve,

 

Feel free to private message me your findings and I will create a case and escalate as necessary.

 

Thank you,

JamesC

Dinerve
Apprentice
Apprentice

Hey JamesC,

 

Thanks for getting back to me, I've PM'd you as requested.

 

Cheers,

JamesC
Community Manager
Community Manager

Dinerve,

 

Thank you for bringing this to our attention. I have created and escalated a case with the information you have provided.

 

JamesC

Dinerve
Apprentice
Apprentice

Thanks,

 

I hope it will be adressed in the upcoming 2.1.3 version of the iOS app!

Dinerve
Apprentice
Apprentice

So, I was hoping this would be resolved with 2.1.3 but it's not.

 

Should I make the video public to gain some traction? I'm sure this was reported before me as well and can't find the thread anymore!

 

Currently under iOS someone can log in without your fingerprint or password! This is major both in terms of security AND privacy and needs a quick fix! C'mon guys!

JamesC
Community Manager
Community Manager

Dinerve,

 

This issue is still under investigation by the engineering team. We take security and privacy concerns very seriously and hope to be able to provide a solution quickly.

 

I have requested an update on this and will post again once I have more information.

 

JamesC

Dinerve
Apprentice
Apprentice

Thanks JamesC,

 

Looking forward to have this addressed.