During installation, the router sent several data packets to an Amazon server in the US. These packets contained the configured SSID name and password in clear text, as well as some identification tokens for this network within a broader database and an access token for a user session that could potentially enable a MITM attack.

Linksys has refused to acknowledge/respond to the issue.

  • @cley_faye
    link
    English
    1224 days ago

    I’m just finding no confirmation that they send them unencrypted over the Internet

    Even if they were sending them with proper E2EE to their server, that would still be a huge fucking problem.