During installation, the router sent several data packets to an Amazon server in the US. These packets contained the configured SSID name and password in clear text, as well as some identification tokens for this network within a broader database and an access token for a user session that could potentially enable a MITM attack.

Linksys has refused to acknowledge/respond to the issue.

  • @ikidd
    link
    English
    31 month ago

    Isn’t Ubiquiti back to being a “have to make a cloud account to control all your local devices” company?

    • @[email protected]
      link
      fedilink
      English
      31 month ago

      They’re either or. Their configuration device is called a cloud key, but it runs locally on your network. You can choose to enable cloud management, though everything can be administered locally, nor do they punish you for it.