The FTC wants companies to listen. More precisely, the FTC wants companies to pay attention to and promptly to respond to reports of security vulnerabilities. That’s a key takeaway from the Commission’s recent settlement with ASUSTek (“ASUS”). In its complaint against the Taiwanese router manufacturer, the FTC alleged that ASUS misrepresented its security practices and failed to reasonably secure its router software. The Commission cited the company’s alleged failure to address vulnerability reports as one of the its primary concerns. The settlement reiterates the warnings contained in the FTC’s recent Start with Security Guide and prior settlements with HTC America and Fandango: the FTC expects companies to implement adequate processes for receiving security vulnerability reports and addressing them within a reasonable time.
On February 23, the FTC announced its agreement with ASUS to settle charges that security flaws in the company’s routers and connected storage devices placed the home networks of thousands of consumers at risk and exposed sensitive personal information. In several sections of the complaint, the FTC alleges that ASUS failed to adequately respond to reports of security vulnerabilities that allowed hackers to bypass authentication requirements (thereby allowing attackers to directly access consumers’ data) as well as retrieve and modify router login credentials (thereby allowing attackers to modify all router settings). In addition, the FTC alleges that ASUS: