{"id":19835,"date":"2019-07-05T16:46:17","date_gmt":"2019-07-05T15:46:17","guid":{"rendered":"https:\/\/www.devopsonline.co.uk\/?p=19835"},"modified":"2019-07-08T12:00:53","modified_gmt":"2019-07-08T11:00:53","slug":"orvibo-expose-billions-of-data-to-hackers-in-huge-breach","status":"publish","type":"post","link":"https:\/\/devopsnews.online\/orvibo-expose-billions-of-data-to-hackers-in-huge-breach\/","title":{"rendered":"Orvibo expose billions of data to hackers in huge breach"},"content":{"rendered":"

The smart home technology company, Orvibo<\/a>, has been found to have exposed over 2 billion records in a massive data breach<\/a>, reports have claimed.<\/p>\n

Orvibo is a management platform for the Internet of things (IoT) and is based in Shenzhen, China. Clientele of the company includes anything from big users of smart home technology, such as hotels, energy companies, and security, to personal users of AI smart home tech. They claim to have hundreds of different automation and smart home products.<\/p>\n

Lack of protection<\/h4>\n

Researchers found that the Chinese firm was being used without any password protection<\/a>, leaving files at risk of exposure to hackers, viruses and security problems, amongst other potential issues.<\/p>\n

Forbes <\/em><\/a>reported that the firm is home to over 2 billion logs that include information from user passwords to account reset codes. Other breaches include the information on precise geolocation and scheduling information.<\/p>\n

Personal information such as names, email address and home addresses were also left unprotected.<\/p>\n

vpnMentor, who discovered the issue, highlighted the particular worry to be around reset codes when saying in a report, \u201cThese would be sent to a user to reset either their password or their email address.\u201d Adding that, \u201cwith that information readily accessible, a hacker could lock a user out of their account without needing their password. Changing both a password and an email address could make the action irreversible.\u201d<\/p>\n

Exposing data<\/h4>\n

The IoT company have logs all over the world, according to vpnMentor, inclusive of Europe, The Americas, and Australia.<\/p>\n

It was only on 2nd<\/sup> July that Orbivo responded to the breach, which they had been alerted to over 2 weeks before. (Ed: ORVIBO have now stated publicly that they had already secured the vulnerability by July 2nd<\/em>).<\/p>\n

The researchers also commented on the worrying amount of data that had been exposed. In the blog post, they said, \u201cThere was enough information to put together several threads and create a full picture of a user\u2019s identity,\u201d<\/p>\n

Hashing passwords<\/h4>\n

Orvibo has also been using the MD5 hashing mechanism to protect passwords, which leaves passwords both insecure and easy to crack.<\/p>\n

Adding to this, the company also failed to salt passwords<\/a>, which is a cryptography method used to safeguard passwords and make them more secure.<\/p>\n

vpnMentor added \u201cEven with strong passwords, however, Orvibo\u2019s database included\u00a0a dangerous piece of information,\u201d<\/p>\n

\u201cWhen examining their records, we found account reset codes\u00a0in the data logs. These would be sent to\u00a0a user to reset either their password or their email address. With that information readily accessible, a hacker could\u00a0lock a user out of their account without needing their password.\u201d<\/p>\n

 <\/p>\n

 <\/p>\n","protected":false},"excerpt":{"rendered":"

The smart home technology company, Orvibo, has been found to have exposed over 2 billion records in a massive data breach, reports have claimed. Orvibo is a management platform for the Internet of things (IoT) and is based in Shenzhen, China. Clientele of the company includes anything from big users of smart home technology, such…<\/p>\n","protected":false},"author":45,"featured_media":19836,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"content-type":"","pmpro_default_level":"","footnotes":""},"categories":[1158],"tags":[1077,111,3386,1870,112],"yoast_head":"\nOrvibo expose billions of data to hackers in huge breach - DevOps Online North America<\/title>\n<meta name=\"description\" content=\"Smart home technology company, Orvibo, has left a huge amount of data unprotected in a huge data breach, reasearch has found.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/devopsnews.online\/orvibo-expose-billions-of-data-to-hackers-in-huge-breach\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Orvibo expose billions of data to hackers in huge breach - DevOps Online North America\" \/>\n<meta property=\"og:description\" content=\"Smart home technology company, Orvibo, has left a huge amount of data unprotected in a huge data breach, reasearch has found.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/devopsnews.online\/orvibo-expose-billions-of-data-to-hackers-in-huge-breach\/\" \/>\n<meta property=\"og:site_name\" content=\"DevOps Online North America\" \/>\n<meta property=\"article:published_time\" content=\"2019-07-05T15:46:17+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2019-07-08T11:00:53+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/devopsnews.online\/wp-content\/uploads\/2019\/07\/iStock-1136595506.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2048\" \/>\n\t<meta property=\"og:image:height\" content=\"1365\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"grace barnott\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@DevOpsAmerica\" \/>\n<meta name=\"twitter:site\" content=\"@DevOpsAmerica\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"grace barnott\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/devopsnews.online\/orvibo-expose-billions-of-data-to-hackers-in-huge-breach\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/devopsnews.online\/orvibo-expose-billions-of-data-to-hackers-in-huge-breach\/\"},\"author\":{\"name\":\"grace barnott\",\"@id\":\"https:\/\/devopsnews.online\/#\/schema\/person\/13f07bc13309191f2e656ba88b8aab63\"},\"headline\":\"Orvibo expose billions of data to hackers in huge breach\",\"datePublished\":\"2019-07-05T15:46:17+00:00\",\"dateModified\":\"2019-07-08T11:00:53+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/devopsnews.online\/orvibo-expose-billions-of-data-to-hackers-in-huge-breach\/\"},\"wordCount\":447,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/devopsnews.online\/#organization\"},\"image\":{\"@id\":\"https:\/\/devopsnews.online\/orvibo-expose-billions-of-data-to-hackers-in-huge-breach\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/devopsnews.online\/wp-content\/uploads\/2019\/07\/iStock-1136595506.jpg\",\"keywords\":[\"data breach\",\"IoT\",\"orvibo\",\"passwords\",\"security\"],\"articleSection\":[\"Security\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/devopsnews.online\/orvibo-expose-billions-of-data-to-hackers-in-huge-breach\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/devopsnews.online\/orvibo-expose-billions-of-data-to-hackers-in-huge-breach\/\",\"url\":\"https:\/\/devopsnews.online\/orvibo-expose-billions-of-data-to-hackers-in-huge-breach\/\",\"name\":\"Orvibo expose billions of data to hackers in huge breach - DevOps Online North America\",\"isPartOf\":{\"@id\":\"https:\/\/devopsnews.online\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/devopsnews.online\/orvibo-expose-billions-of-data-to-hackers-in-huge-breach\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/devopsnews.online\/orvibo-expose-billions-of-data-to-hackers-in-huge-breach\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/devopsnews.online\/wp-content\/uploads\/2019\/07\/iStock-1136595506.jpg\",\"datePublished\":\"2019-07-05T15:46:17+00:00\",\"dateModified\":\"2019-07-08T11:00:53+00:00\",\"description\":\"Smart home technology company, Orvibo, has left a huge amount of data unprotected in a huge data breach, reasearch has found.\",\"breadcrumb\":{\"@id\":\"https:\/\/devopsnews.online\/orvibo-expose-billions-of-data-to-hackers-in-huge-breach\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/devopsnews.online\/orvibo-expose-billions-of-data-to-hackers-in-huge-breach\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/devopsnews.online\/orvibo-expose-billions-of-data-to-hackers-in-huge-breach\/#primaryimage\",\"url\":\"https:\/\/devopsnews.online\/wp-content\/uploads\/2019\/07\/iStock-1136595506.jpg\",\"contentUrl\":\"https:\/\/devopsnews.online\/wp-content\/uploads\/2019\/07\/iStock-1136595506.jpg\",\"width\":2048,\"height\":1365,\"caption\":\"Billions of data has been left unprotected in breach\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/devopsnews.online\/orvibo-expose-billions-of-data-to-hackers-in-huge-breach\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/devopsnews.online\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Orvibo expose billions of data to hackers in huge breach\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/devopsnews.online\/#website\",\"url\":\"https:\/\/devopsnews.online\/\",\"name\":\"DevOps Online North America\",\"description\":\"by 31 Media Ltd.\",\"publisher\":{\"@id\":\"https:\/\/devopsnews.online\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/devopsnews.online\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/devopsnews.online\/#organization\",\"name\":\"DevOps Online North America\",\"url\":\"https:\/\/devopsnews.online\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/devopsnews.online\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/devopsnews.online\/wp-content\/uploads\/2020\/03\/DevOpsOnline_email.png\",\"contentUrl\":\"https:\/\/devopsnews.online\/wp-content\/uploads\/2020\/03\/DevOpsOnline_email.png\",\"width\":198,\"height\":64,\"caption\":\"DevOps Online North America\"},\"image\":{\"@id\":\"https:\/\/devopsnews.online\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/x.com\/DevOpsAmerica\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/devopsnews.online\/#\/schema\/person\/13f07bc13309191f2e656ba88b8aab63\",\"name\":\"grace barnott\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/devopsnews.online\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/45f56545d23ef0b82f250c1ba53817b2?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/45f56545d23ef0b82f250c1ba53817b2?s=96&d=mm&r=g\",\"caption\":\"grace barnott\"},\"sameAs\":[\"http:\/\/31media.co.uk\"],\"url\":\"https:\/\/devopsnews.online\/author\/grace-barnott31media-co-uk\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Orvibo expose billions of data to hackers in huge breach - DevOps Online North America","description":"Smart home technology company, Orvibo, has left a huge amount of data unprotected in a huge data breach, reasearch has found.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/devopsnews.online\/orvibo-expose-billions-of-data-to-hackers-in-huge-breach\/","og_locale":"en_US","og_type":"article","og_title":"Orvibo expose billions of data to hackers in huge breach - DevOps Online North America","og_description":"Smart home technology company, Orvibo, has left a huge amount of data unprotected in a huge data breach, reasearch has found.","og_url":"https:\/\/devopsnews.online\/orvibo-expose-billions-of-data-to-hackers-in-huge-breach\/","og_site_name":"DevOps Online North America","article_published_time":"2019-07-05T15:46:17+00:00","article_modified_time":"2019-07-08T11:00:53+00:00","og_image":[{"width":2048,"height":1365,"url":"https:\/\/devopsnews.online\/wp-content\/uploads\/2019\/07\/iStock-1136595506.jpg","type":"image\/jpeg"}],"author":"grace barnott","twitter_card":"summary_large_image","twitter_creator":"@DevOpsAmerica","twitter_site":"@DevOpsAmerica","twitter_misc":{"Written by":"grace barnott","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/devopsnews.online\/orvibo-expose-billions-of-data-to-hackers-in-huge-breach\/#article","isPartOf":{"@id":"https:\/\/devopsnews.online\/orvibo-expose-billions-of-data-to-hackers-in-huge-breach\/"},"author":{"name":"grace barnott","@id":"https:\/\/devopsnews.online\/#\/schema\/person\/13f07bc13309191f2e656ba88b8aab63"},"headline":"Orvibo expose billions of data to hackers in huge breach","datePublished":"2019-07-05T15:46:17+00:00","dateModified":"2019-07-08T11:00:53+00:00","mainEntityOfPage":{"@id":"https:\/\/devopsnews.online\/orvibo-expose-billions-of-data-to-hackers-in-huge-breach\/"},"wordCount":447,"commentCount":0,"publisher":{"@id":"https:\/\/devopsnews.online\/#organization"},"image":{"@id":"https:\/\/devopsnews.online\/orvibo-expose-billions-of-data-to-hackers-in-huge-breach\/#primaryimage"},"thumbnailUrl":"https:\/\/devopsnews.online\/wp-content\/uploads\/2019\/07\/iStock-1136595506.jpg","keywords":["data breach","IoT","orvibo","passwords","security"],"articleSection":["Security"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/devopsnews.online\/orvibo-expose-billions-of-data-to-hackers-in-huge-breach\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/devopsnews.online\/orvibo-expose-billions-of-data-to-hackers-in-huge-breach\/","url":"https:\/\/devopsnews.online\/orvibo-expose-billions-of-data-to-hackers-in-huge-breach\/","name":"Orvibo expose billions of data to hackers in huge breach - DevOps Online North America","isPartOf":{"@id":"https:\/\/devopsnews.online\/#website"},"primaryImageOfPage":{"@id":"https:\/\/devopsnews.online\/orvibo-expose-billions-of-data-to-hackers-in-huge-breach\/#primaryimage"},"image":{"@id":"https:\/\/devopsnews.online\/orvibo-expose-billions-of-data-to-hackers-in-huge-breach\/#primaryimage"},"thumbnailUrl":"https:\/\/devopsnews.online\/wp-content\/uploads\/2019\/07\/iStock-1136595506.jpg","datePublished":"2019-07-05T15:46:17+00:00","dateModified":"2019-07-08T11:00:53+00:00","description":"Smart home technology company, Orvibo, has left a huge amount of data unprotected in a huge data breach, reasearch has found.","breadcrumb":{"@id":"https:\/\/devopsnews.online\/orvibo-expose-billions-of-data-to-hackers-in-huge-breach\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/devopsnews.online\/orvibo-expose-billions-of-data-to-hackers-in-huge-breach\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/devopsnews.online\/orvibo-expose-billions-of-data-to-hackers-in-huge-breach\/#primaryimage","url":"https:\/\/devopsnews.online\/wp-content\/uploads\/2019\/07\/iStock-1136595506.jpg","contentUrl":"https:\/\/devopsnews.online\/wp-content\/uploads\/2019\/07\/iStock-1136595506.jpg","width":2048,"height":1365,"caption":"Billions of data has been left unprotected in breach"},{"@type":"BreadcrumbList","@id":"https:\/\/devopsnews.online\/orvibo-expose-billions-of-data-to-hackers-in-huge-breach\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/devopsnews.online\/"},{"@type":"ListItem","position":2,"name":"Orvibo expose billions of data to hackers in huge breach"}]},{"@type":"WebSite","@id":"https:\/\/devopsnews.online\/#website","url":"https:\/\/devopsnews.online\/","name":"DevOps Online North America","description":"by 31 Media Ltd.","publisher":{"@id":"https:\/\/devopsnews.online\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/devopsnews.online\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/devopsnews.online\/#organization","name":"DevOps Online North America","url":"https:\/\/devopsnews.online\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/devopsnews.online\/#\/schema\/logo\/image\/","url":"https:\/\/devopsnews.online\/wp-content\/uploads\/2020\/03\/DevOpsOnline_email.png","contentUrl":"https:\/\/devopsnews.online\/wp-content\/uploads\/2020\/03\/DevOpsOnline_email.png","width":198,"height":64,"caption":"DevOps Online North America"},"image":{"@id":"https:\/\/devopsnews.online\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/DevOpsAmerica"]},{"@type":"Person","@id":"https:\/\/devopsnews.online\/#\/schema\/person\/13f07bc13309191f2e656ba88b8aab63","name":"grace barnott","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/devopsnews.online\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/45f56545d23ef0b82f250c1ba53817b2?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/45f56545d23ef0b82f250c1ba53817b2?s=96&d=mm&r=g","caption":"grace barnott"},"sameAs":["http:\/\/31media.co.uk"],"url":"https:\/\/devopsnews.online\/author\/grace-barnott31media-co-uk\/"}]}},"_links":{"self":[{"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/posts\/19835"}],"collection":[{"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/users\/45"}],"replies":[{"embeddable":true,"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/comments?post=19835"}],"version-history":[{"count":0,"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/posts\/19835\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/media\/19836"}],"wp:attachment":[{"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/media?parent=19835"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/categories?post=19835"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devopsnews.online\/wp-json\/wp\/v2\/tags?post=19835"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}