No Hack, Still Liable, Court Finds ADT

Author: IPVM Team, Published on Jun 20, 2017

Recently, ADT has been in the news for a $16 million settlement for a cyber security vulnerability class action suit.

One of the most important and interesting points behind this settlement is a court order that found ADT could be found liable even if no actual hacks were proven. Many could see this as counterintuitive since what 'damage' had occurred if there was no hack / incident?

In this note, we examine that court order, how the Court reached that conclusion and what impact it might have on manufacturers and providers generally.

********,*** *** **** ** *** **** *** * $** ******* settlement*** * ***** ******** ************* ***** ****** ****.

*** ** *** **** ********* *** *********** ****** ****** **** settlement ** * ***** ***** **** ***** *** ***** ** found ****** **** ** ** ****** ***** **** ******. **** could *** **** ** **************** ***** **** '******' *** ******** if ***** *** ** **** / ********?

** **** ****, ** ******* **** ***** *****, *** *** Court ******* **** ********** *** **** ****** ** ***** **** on ************* *** ********* *********.

[***************]

Executive *******

* ** ********** ******* *********** ** *** ********* *** *** ******* ********** *** ************* ******* ** ****** an ********** ** ** **:

*** ***** ********* **** ********* ************ ******* **** *** **** him * **** ** ******** ******* *** *** ********* ********* of ******** ***** ******* ** *********.

*** ********* / **** ***** ******, **** ******* ** ****** hack, ***** *** ***** ********* **** *** ******** (*** ****) should **** ********* *** ************* *** *** *** ************ ** so.

Industry *********

*** ********** ***** ********** ***** *** **** *** ******** **** about ***** *****:

*** ************ ***** ** ********* ** *** *** ******* **** the ******** ** ***** *** ******* **** ** *** ************* of ******** ******* **** ****** ********* ********** **** ***.

Consumers *** ******** ** ****

** *** **** ****, *** ********** ***** ***** **** ********* would *** ** ******** ** **** ** ***** *****:

**** ********* *** ************ ******* ******** ********* *** ****** **** "[w]hile *********** ********* ***** **** **** ****** *** ** *** possibility ** [* ******], **** ********* ***** *** **** ********* such * ******, *** ***** **** ** ******** **").

Rejects **** ** *******

*** ********* ** *********** ** ***** ** ****** ******** *** the ***** ******** ****, ******* **** * ******** ***** *** have ****** *** ******** ** **** ****:

* ****** **** *** ** ********* ** ** ********. ** is ********* ********* **** * ********** ******** ***** ****** ********** to *** **** **** ***** **** ******** ****** ***** ** easily ** ****** *** ********, **** ****** ****** ********* ** such *******.

General ********** ******** ************

*** ***** ******** *** ******** ***** ******* ********* ********, **** is:

"*** *** *** ******* ***** ******* ** ************** ** ***** is *********** *** *** ******" *** "** ***** ****** *** provide ******** ********** ** ********* ********** ** **** ** ******."

******* ** *********, *** ***** ***** ** *** *** ***** the ******** ****:

**** ******** ** *** * ********** ** *** ********* ******* fact, ****** **** ***'* ******** ******* *** ********** ** *******, jamming, *** ***** **********.

Misleading *********** / ********* ********* **** *******

*** ***** ************ ***** **** ***** ** ******** ************* ****** *********** *** (***)*** ************* ********* ***** ******** *** (****), **** ******** ** ******* ********* ******* ********** *********** *** deceptive **** ** *********.

Industry ******?

**********: **** **** *** ***** ***** ****** *** ********** ********** one's *********.

**** * ******** ***********, ** **** ***** ********. **** ***** suppose ***** ******** ***** *** **** ** ***** ** ** actual ******* / **** / ****** ******. **** ***** ****, as **** ** *** *****'* ******* ******* *-****'* ** *******, *** ******** ** ************* ** ********* ****** ***** ***** and ********* ********* *** *********** ********** ****** ***** *** ******** risks *** ******** ***.

*** ************ *********** ********** ****** ** ***'* ***** **** ($* - $* ******* ****** *******) ******** **** ********. **** ********* that *** ******* *** *** ******* ********** ***** / ******** efforts ** ****** **********. ********, ** ** ******** **** ***'* monthly ******* ******* ***** ******** **** *** ** ********* ****** vs ******** ************* **** **** ******** *** * ***-**** ******.

**** ***********, **** **** *********** **** * ******** ****** (*.*., security ********) *** ***** (*.*., ***** ******** *****) ***** ** used ** ****** ** *** * ******** **** ** *** buyer *** *** ******** **** ******, *** ****** ****** **** they ***** *** **** ****** * ******* ******** ** *** supplier *** ******** ********* / ****** ******** ***** ********. **** is *** **** ** **** **** ********* ****** ********* ********.

Comments (19)

**'* * **** *********** ****, *** ** ************** ** **** any ****** **** *** ****, ***** *** *************, ** ********* to *** ******** **** **** * ********** **** ** *** be ******. **** ******** ***** ** **** *****, *******/********, *** "smart" ******* ** *** ******, ***. **** ** *** ******** they *** * ******** ****** *** ******* **** * ******* providing ********* *** ***** ** *****, *** **** **** ***** that **** ******** ****** *** *********** ******* ** *** ******** was ******* **** * *******.

** ************** ** **** *** ****** **** *** ****, ***** any *************, ** ********* ** *** ******** **** **** * disclosure **** ** *** ** ******

** ************** (***** ** "*** ***** ******** *** ******** ***** ******* ********* ********")*** **** ** ********* ******** ** ***** (*.*., *********** ********), it ***** ** ** ************ *********, *** ****** * ******* 'anything *** ** ******' *********.

* *** **** ** ** ************* ******* ** *** ***** strategy. **** * **** ** **** ********** ******** ** ** country (***** ****) ** ****** ******* ** ******** - **** had ** ** ****** ** *******- **** *** ******* ***** system *** ********** ******* *** *** ** ********* ******. ** offered ******* ** * *** ** ***** *********** ** ** intrusion *** **** ***** *********** ** **** *********** ***** *** never ****.

**** *** ** ** ****** ** *******- **** *** ******* alarm ****** *** ********** ******* *** *** ** ********* ******.

*****, ** **** ****, ** ************* ** **** **** * disclosure / ********* ***** *** **** **** * **********, ***** neither *** *** *** ******** ****** **** *** ****** *** an ********* ******.

* ** *** **** **** *** ******** ********* *********** **** are ** ***** ****, *** ** *** ***, ***** *** a **** ****** ** **** **** *** ***** *** *** laws **** *** ******* / ******* **** *****.

**** ** ****. *** ******** *** ****** ** **** ******** language ** ** ******** *** *** ** **** **** **** for *****.

** **** ** *********** ** **** *** ******* **** **** be ** * ****** ** **** ******.

**** *** ******** * ***** ** *** ****** *****, *** increase ** ********* *** ************ *** *********** **** **** ********. There *** ****** **** ******* ** *** ****** ******, **** considerations *** *** ********** ** *** ****, *******, **** ***** set * ********* **** **** ****** **** ***** ******* ********** to *** ******** ** ********* ***** ********.

*** ** *** *** ********* * **** **, "*** ** really ***********?"

- *** *********** (*** ***** **** ** **** ****)

- *** **********

- ** ***********

- ***-****... ***.

** ** ****** ** ************ ********* *******, *** ********* *** challenges ** ***** ** ** ********.

* ** *** **** ** **-**** *** ****** ****** ** manufactures ***************, ******* * ***** ***** **** *** ************ *** integrators **** ** *** * ***** ****** ** *** ** respond ** ***** ******, *** **** **** * ********* ***********, but **** **** * ********* **********.

* ***** **** ***** ******** ** * ********** ***** ** SSN's **************** ********** ******* **** ****. *** ***** *** ** impressive ********** ** ******** ******** *** ***** ******** *** * consensus **** *** ************** ** ******.

"******" ******** **** **** ** **** *** ***** *** ****** when ** **** *** *** *** ** *** ***** **************. Almost ** **** ** ****** **** ********** ***.

*** ********* ** *********** ** ***** ** ****** ******** *** the ***** ******** ****, ******* **** * ******** ***** *** have ****** *** ******** ** **** ****:

****'* ***** ** **** ** *********** ****** ** *** **** counters *** ******* **** ** ********* ****** **** ** *********** the *******. *** ****** ***** ***** "** ** **** ****** $1M ** ********, *** ****** *** ******* ***** $*.**, **** to **** ***** *** ******* *****". * ***** **** ** a ***** **** ** *** *** ****** ******** ** ** this ****, *** **** *** ******* ****** *** ** ****** to ***** **** **** ** ********.

*** ***** **** *** ******** ***** ***** ******* *********

******* ****** **** * ***** ****** **** ******* ********* *** dahua

***** ******** *** *** ****** ********

***** ******** *** * **** ** **** *** ******** ******** has **** ******* ***** *****

*** *** ***** *** ** ***** **** ***

**** **** ***** ******** *** *******

* ****** ** * **** ** *** *********** ********, ***** the ******** ******* ** ********** *****:

  1. WIRELESS *** ******** ****** ************: Subscriber is responsible for supplying high speed Internet access and or wireless services at Subscriber's premises. RADIUS does not provide Internet service, maintain Internet connection, wireless access or communication pathways, computer, smart phone, electric current connection or supply, or in all cases the remote video server. In consideration of Subscriber making its monthly payments for remote access to the system RADIUS will authorize Subscriber access. RADIUS is not responsible for Subscriber's access to the Internet or any interruption of service or down time of remote access caused by loss of Internet service, radio or cellular or any other mode of communication used by Subscriber to access the system. Subscriber acknowledges that Subscriber's security system can be compromised if the codes or devices used for access are lost or accessed by others and RADIUS shall have no liability for such third party unauthorized access. RADIUS is not responsible for the security or privacy of any wireless network system or router. Wireless systems can be accessed by others, and it is the Subscriber's responsibility to secure access to the system with pass codes and lock out codes. RADIUS is not responsible for access to wireless networks or devices that may not be supported by communication carriers and upgrades to subscriber system will be at subscriber's expense.

** **** ***** ********* ******* ***** ******** ** *** ********* the ******** *******, ** *** ******** ******* ** ********** ** the ******** **** *** ********* *********. * ***** ***** ********* need ** ******* *** ********* **********.

******,

****** *** *******. * ** *** **** **** *** ******* you ****** ** ******* ** **** *****, *.*.:

********** ** *********** *** ********* **** ***** ******** ****** *** or ******** ******** ** **********'* ********....

****** ** *** *********** *** *** ******** ** ******* ** anywireless ******* ****** ** ******. Wireless systems can be accessed by others, and it is the Subscriber's responsibility to secure access to the system with pass codes and lock out codes. [IPVM highlighted]

*** *** * **** **** ** **** ** ** * disclaimer ***** *** ****'* *** ******** *******, *** *** ******** communications ******** / **** ** *** ***** ******. ** *** ADT ****, **** *** ****** **** *** *** ******'* *** wireless *** ********, *** *** *********'* ******** *******.

*****/********? ** * ******* *********?

*******, * ***** ************ ***** **** *** ** **** ** was ******** * ********** ***** **** *****.

* *** ******* * ******* *****. **** * *** ****** to *** ** ** **** *** ******** ********** **** ** ADT *** *********** ********* *** ****** *********** ***** *** ******** or **** ** ******** ** ********* ** *** ***** ****** 9. ** **** ***** *** *** ***** **** ******** ************ than *** ***** ********, ****** *** ** ***** ******* ****** contracts. * *** **** ******* ***** ******* ********* (**** **** users) *** **** **** ******* ** ******* **** *** ***** industry *** ******** ***'* **** ********* ** ***** *** ***** of ********* ******** **** ****:

*. * ******** **** ** ****** *** *** ****** ******** is ****** *** *** ******, **** ****** ** ** ****** by *** ********* *** *********, *********, *********,...

*. **** ** * ***** **************, ** ********** ******* ** a ******** **** ***** ******.

*. ********* ****** ** ****** ********* ** *** *******.

*** *** ******** *** ** *** ****.

********* *** *** ******** **** ** ******* ******* **** *** big **** (******, *****, *********) *** *****.

* ******** **** ** ****** *** *** ****** ******** ** blamed *** *** ******, **** ****** ** ** ****** ** the ********* *** *********, *********, *********,...

**, *** ** ** *****, *** *** / *********** **** is *** ***** * **** ********* ** ***, **** *** title ** **** **** - '** ****, ***** ******'.

* ** *** ********** *** ******* *** *********. * ** emphasizing **** ***** ******* *** *** ****** ** ****** *** case ** **** ****, ******* **** ** ***** ***** / misleading ***********, *** ****** **** * ****.

*** ***** ** **** ** *** ******* ** ******** ***** systems *** *** ********* **** ******* ***** **** **** *** ADT ******* ***** *** ******** ************ *** ** ******* *** manipulate *** ****** ** *** ***** ****** ** ****** ***** an ***** ** ****** * ******** ** ******* *** ****** by **** **** ** *******.

***** ** *** ******* ** *** **** ***** ** *** been **** ************ ****** ** * ********** *****, *** *** some ****** ** ********** ** *** ***.

*******: * **** *** * ***** **** *** **** * significant ****** ** **** ********* ******** ** ******* ******* **** does *** **** **** ***** **** *** **** ****.

* ***** ***** *** ***** *** ** *** ******** *** that ***** **** *** **** ********** ** *** ***** **** not **** *** ***** ****** ** * ****.

******** ** * **** ***** ******** ** ******* *******.

*******: * **** *** * ***** **** *** **** * significant ****** ** **** ********* ******** ** ******* ******* **** does *** **** **** ***** **** *** **** ****.

** *** **** **** ********* ******** **** *** ************ ****** you * ****** ***** **** *** ****** ** **** ***, the ******** ***** ** **** ** *** *** **** ** their ***** ****'* **** ****. *** **** ******** ***** ****** you ** ******, ***. ****'* **** ********* ** **** ******** here.

* **** **** *** *** *** ***** *** **** **** it

****** *** ******** ******** *** ** *** *****

Login to read this IPVM report.
Why do I need to log in?
IPVM conducts unique testing and research funded by member's payments enabling us to offer the most independent, accurate and in-depth information.

Related Reports

Genetec Takes Aim At 'Untrustworthy' 'Foreign Government-Owned Vendors' on Sep 24, 2018
Genetec is taking aim at 'untrustworthy' 'foreign government-owned vendors'. This is not a new theme for Genetec as nearly 2 years ago, Genetec...
Amazon Ring Spotlight Cam Tested on Sep 17, 2018
Amazon's Ring has released their latest camera entry, the Spotlight Cam, which we bought and tested in our Consumer IP Camera Analytics...
Ascent / MONI Faces Lender Lawsuit and Debt Crisis on Sep 13, 2018
ASCMA, aka Ascent, aka Brinks Home Security, aka MONI, aka Monitronics is being sued by a group of their lenders who allege: As of June 30,...
VMS Export Shootout - Avigilon, Dahua, Exacq, Genetec, Hikvision, Milestone on Sep 13, 2018
When crimes, accidents or problems occur, exporting video from one's video surveillance system is critical to proving incidents. But who does it...
Ambarella on Computer Vision and US Hikua Ban on Sep 10, 2018
Ambarella, a widely-used video surveillance component supplier, is betting on the rise of computer vision and is already seeing a sales impact from...
Why Vivint / Best Buy Failed on Aug 31, 2018
DIY has bested Vivint. In 2017, Best Buy and Vivint partnered with Vivint employees on the floor of 400+ Best Buy stores, helping customers with...
Hikvision FIPS 140-2 Cybersecurity Certification Examined on Aug 27, 2018
A week after the US government passed a law banning Hikvision, Hikvision announced it had obtained a FIPS 140-2 certification from the US...
Consumer IP Camera Analytics Shootout - Arlo, Google / Nest, Amazon / Ring, Hikvision / Ezviz on Aug 27, 2018
Consumer IP camera usage is growing significantly driven by large companies including Google (with Nest), Amazon (with Ring), Netgear (with Arlo)...
France Political Scandal Reveals Video Surveillance Problems on Aug 22, 2018
In what French media describes as "the most damaging crisis yet for" French President Marcon, a political scandal has revealed major gaps in the...
SimpliSafe Violating California, Florida, and Texas Licensing Laws on Aug 14, 2018
IPVM has verified that DIY security system provider SimpliSafe, founded in 2006 and acquired in June of 2018 at a billion dollar valuation, is...

Most Recent Industry Reports

Ladders For Installers Guide on Sep 25, 2018
Ladders are one of the most important pieces of worksite equipment for the surveillance technician. Too often, however, even highly experienced...
Favorite Access Control Reader Manufacturer 2018 on Sep 25, 2018
Favorite reader votes are in, and it is not close. A global access giant ran away with the votes in a one-sided contest. But for many, the...
Genetec Takes Aim At 'Untrustworthy' 'Foreign Government-Owned Vendors' on Sep 24, 2018
Genetec is taking aim at 'untrustworthy' 'foreign government-owned vendors'. This is not a new theme for Genetec as nearly 2 years ago, Genetec...
4MP Camera Shootout - Axis, Dahua, DW, Hanwha, Hikvision, Uniview, Vivotek on Sep 24, 2018
4MP usage continues to climb, especially for low cost fixed lens models. To see who was best, we bought and tested seven 4MP models from Axis,...
Alexa Guard Expands Amazon's Security Offerings, Boosts ADT's Stock on Sep 21, 2018
Amazon is expanding their security offerings yet again, this time with Alexa Guard that delivers security audio analytics and a virtual "Fake...
UTC, Owner of Lenel, Acquires S2 on Sep 20, 2018
UTC now owns two of the biggest access control providers, one of integrator's most hated access control platforms, Lenel, and one of their...
BluePoint Aims To Bring Life-Safety Mind-Set To Police Pull Stations on Sep 20, 2018
Fire alarm pull stations are commonplace but police ones are not. A self-funded startup, BluePoint Alert Solutions is aiming to make police pull...
SIA Plays Dumb On OEMs And Hikua Ban on Sep 20, 2018
OEMs widely pretend to be 'manufacturers', deceiving their customers and putting them at risk for cybersecurity attacks and, soon, violation of US...
Axis Vs. Hikvision IR PTZ Shootout on Sep 20, 2018
Hikvision has their high-end dual-sensor DarkfighterX. Axis has their high-end concealed IR Q6125-LE. Which is better? We bought both and tested...
Avigilon Announces AI-Powered H5 Camera Development on Sep 19, 2018
Avigilon will be showcasing "next-generation AI" at next week's ASIS GSX. In an atypical move, the company is not actually releasing these...

The world's leading video surveillance information source, IPVM provides the best reporting, testing and training for 10,000+ members globally. Dedicated to independent and objective information, we uniquely refuse any and all advertisements, sponsorship and consulting from manufacturers.

About | FAQ | Contact