Researchers Disclose Vulnerabilities In Popular Smart Home Apps From Eaton and BlueCats
Summary
Researchers at security firm Rapid7 disclosed a number of significant vulnerabilities discovered in smart home products from multibillion-dollar power management company Eaton and Internet of Things startup BlueCats. Eatons Halo Home app didnt encrypt or password-protect the information that is stored on the device, leaving it vulnerable to being exposed to a malicious actor. As for the issues plaguing the BlueCats AA Beacon, it similarly is related to the companys mobile apps used to connect to the devices. Rapid7 found both the companys BC Reveal app, available for both Android and iOS, suffered from insecure storage of sensitive data. In the case of both the iOS and Android app, BC Reveal stored the device owners name and password in plaintext, albeit in different locations.