In re TRENDnet, Inc.
In the Matter of TRENDnet, Inc., F.T.C. File No. 122-3090, is the first legal action taken by the Federal Trade Commission (FTC) against "the marketer of an everyday product with interconnectivity to the Internet and other mobile devices – commonly referred to as the Internet of things."[1] The FTC found that TRENDnet had violated Section 5(a) of the Federal Trade Commission Act by falsely advertising that IP cameras it sold could transmit video on the internet securely.[2] On January 16, 2014 the FTC issued a Decision and Order [3] obliging TRENDnet, among other things, to cease misrepresenting the extent to which its products protect the security of live feeds captured and the personal information that is accessible through those devices.
The Respondent: TRENDnet, Inc.
TRENDnet is a California corporation that, among other things, sells networking devices, such as routers, modems, and IP security cameras that allow users to conduct remote surveillance of their homes and businesses over the Internet.[4] It began selling digitally connected cameras under the trade name "SecurView" in 2010.[5] It usually sells its IP cameras under the trade name "SecurView," and tells consumers that they may use the cameras to monitor "babies at home, patients in the hospital, offices and banks, and more."[4]" By default, these IP cameras are subject to security settings such as a requirement to enter a username and password ("login credentials") in order to access the video and audio feeds ("live feeds") over the Internet."[4] Between 2010 and 2012, TRENDnet's "Secureview" line made $19 million in revenue, accounting for 10 percent of the company's total revenue during that time period.[5]
TRENDnet's Security Breach
The security breach was first exploited when a blogger named "SomeLuser" was able to identify the web addresses of live feeds coming from TRENDnet's ATV-IP110w cameras.[6] SomeLuser realized that the live stream of any camera could be accessed by making a "mjpg.cgi" request to the device's IP address, thereby bypassing the need to enter login credentials.[6] On January 10, 2012 SomeLuser uploaded this information into the Shodan search engine which immediately made 350 live feeds viewable by anyone. By the time the breach came to TRENDnet's attention, over 700 cameras were accessible via Shodan.[6]
"Among other things, these compromised live feeds displayed private areas of users' homes and allowed the unauthorized surveillance of infants sleeping in their cribs, young children playing, and adults engaging in typical daily activities. The breach was widely reported in news articles online, many of which featured photos taken from the compromised live feeds or hyperlinks to access such feeds. Based on the cameras' IP addresses, news stories also depicted the geographical location (e.g., city and state) of many of the compromised cameras."[7] TRENDnet learned of the breach on January 13, 2012 when a customer who read about the breach contacted TRENDnet's technical support staff to report the issue.[7] TRENDnet released a firmware update designed to rectify the software's vulnerability, halted the shipping new products to market, and spent "substantive resources" notifying all previous customers.[8]
The FTC's Complaint Against TRENDNET, Inc. - September 4, 2013 [7]
The FTC's Complaint identified four "practices that, taken together, failed to provide reasonable security to prevent unauthorized access to sensitive information, namely the live feeds from the IP cameras."[7] The FTC alleged that TRENDnet misrepresented the adequacy of its security measures to consumers, even while it:
- "transmitted user login credentials in clear, readable text over the Internet, despite the existence of free software, publicly available since at least 2008, that would have enabled respondent to secure such transmissions;
- stored user login credentials in clear, readable text on a user's mobile device, despite the existence of free software, publicly available since at least 2008, that would have enabled respondent to secure such stored credentials;
- failed to implement a process to actively monitor security vulnerability reports from third-party researchers, academics, or other members of the public, despite the existence of free tools to conduct such monitoring, thereby delaying the opportunity to correct discovered vulnerabilities or respond to incidents;
- failed to employ reasonable and appropriate security in the design and testing of the software that it provided consumers for its IP cameras" [7]
The Commission voted to accept the consent agreement package 4-0.[1] "The FTC. does not have the legal authority to impose fines in such cases. But TRENDnet agreed to a consent order prohibiting similar practices, so the commission has the ability to seek penalties in the future."[5]
Case Settlement - January 16, 2014[9]
"TRENDnet's settlement prohibits it from misrepresenting the security of its cameras or the security, privacy, confidentiality or integrity of the information that its devices transmit. Further, it cannot misrepresent consumer control over the security of information the devices store, capture, access or transmit; it must notify customers about security issues with the cameras and the availability of a firmware update; and it must provide customers with free tech support for updating or uninstalling their cameras for the next two years. Finally, TRENDnet must establish a comprehensive information security program designed to address security risks that could let hackers access or use its devices; protect the security, confidentiality and integrity of information stored, captured, accessed or transmitted by its devices; and get third-party security audits biennially for the next 20 years."[10]
The Order will terminate on January 16, 2034.
Importance of Case
One commentator noted that the message to all companies developing products for the Internet of Things is that "the FTC is watching and has served notice that it intends to play an active role in enforcing its regulatory authority in that context." This case, however shows how challenging it will be for the FTC to regulate this new industry. Ultimately this action was based on the misstatements of TRENDnet, rather than the security of the products themselves.[11] On February 4, 2014, the FTC provided a statement to the United States Senate Committee on the Judiciary, stating that Section 5(a) of the Federal Trade Commission Act, codified at 15 U.S.C. §45(a) gives the agency the authority to regulate security standards.[12] "If a company makes materially misleading statements or omissions about a matter, including data security, and such statements or omissions are likely to mislead reasonable consumers, they can be found to be deceptive in violation of Section 5."[12] "Further, if a company's data security practices cause or are likely to cause substantial injury to consumers that is neither reasonably avoidable by consumers nor outweighed by countervailing benefits to consumers or to competition, those practices can be found to be unfair and violate Section 5."[12] Over the last decade, the FTC has used the authority to punish "unfair" and "deceptive" trade practices to investigate companies that collect, monitor, or use personal information about consumers. As it did in the TRENDnet case, the FTC frequently alleges violations of both provisions in data privacy investigations.[13]
Other commentators have noted that this case may suggest that the FTC is adopting a more expansive view of what constitutes "sensitive data." In the 2013 Mobile Privacy Report, the commission adopted a subjective notion of "sensitive data" by advocating that companies obtain express consent before collecting data that "many customers would find sensitive in many contexts."[14] In this complaint, however, the FTC states that the live feeds, themselves, constitute "sensitive data."[7] While the streams likely revealed "sensitive data" (personal information about health, financial, or location), "the FTC complaint does not appear to distinguish live feeds that reveal such sensitive data from feeds containing innocuous data."[8]
References
- "FTC Approves Final Order Settling Charges Against TRENDnet, Inc". Federal Trade Commission. Retrieved 28 March 2014.
- O'Brien, Chris. "Simple Internet-connected devices can end up in complex online crimes". Los Angeles Times. Archived from the original on 30 March 2014. Retrieved 1 April 2014.
- See Decision and Order, available at: http://www.ftc.gov/system/files/documents/cases/140207trendnetdo.pdf
- "Federal Trade Commission, File No. 122 3090, TRENDnet, Inc: Analysis of Proposed Consent Order to Aid Public Comment" (PDF). Federal Register Vol. 78, No. 176. Retrieved February 20, 2014.
- Wyatt, Edward. "F.T.C. Says Webcam's Flaw Put Users' Lives on Display". New York Times. Retrieved 1 April 2014.
- Parrish, Kevin. "FTC Forcing TRENDnet to Suffer 20 Years of Auditing". TOM's Guide. Retrieved 1 April 2014.
- "In the Matter of TRENDnet, Inc., Docket No. C-4466, FTC File No. 122 3090" (PDF). Federal Trade Commission.
- Pritchard, Eric. "Legal Watch: Impact of the TRENDnet Decision". SecurityInfoWatch.com. Retrieved 2 April 2014.
- "In the Matter of TRENDnet, Inc. Decision and Order Docket No. C-4426, File No./Matter No. 122 30 90" (PDF). Federal Trade Commission.
- Adhikari, Richard. "Webcam Maker Takes FTC's Heat for Internet-of-Things Security Failure". TechNewsWorld.com. Retrieved 2 April 2014.
- Clearfield, Chris. "Why The FTC Can't Regulate The Internet Of Things". Forbes. Retrieved 1 April 2014.
- "Prepared Statement of the FTC on Privacy in the Digital Age: Preventing Data Breaches and Combating Cybercrime Before the Committee on the Judiciary United States Senate" (PDF). Committee on the Judiciary, US Senate. Retrieved February 15, 2014.
- Capizzi, Mary Devlin. "Anticipating Further Scrutiny of Connected Devices: Understanding the Federal Trade Commission's Approach to Data Privacy". Pharmaceutical Compliance Monitor. Retrieved 1 April 2014.
- "Mobile Privacy Disclosures -2013" (PDF). Federal Trade Commission. Retrieved 1 April 2014.