D-Link agrees to implement a new security program to settle a 2017 FTC complaint that alleged D-Link left thousands open to well-known attacks
Agreement settles charges D-Link left users open to critical and widespread threats. — Router and webcam maker D-Link has agreed to implement …
Context & Ripple Effects
The FTC sued D-Link in January 2017, alleging its routers and IP cameras shipped with hard-coded logins and that private software sign-in key code sat exposed online for six months — leaving buyers open to well-known attacks (the original complaint). The settlement closes that case with a consent order rather than a fine, echoing how the agency handled ASUS, whose earlier router-flaw deal imposed two decades of mandatory security audits.
First-order effects
- D-Link must now stand up and maintain a formal security program across its router and webcam lines, with its practices subject to FTC oversight instead of litigation.
- Customers using D-Link routers and IP cameras are the direct beneficiaries: the specific flaws named in the 2017 complaint — hard-coded credentials and leaked key code — become the baseline the program must eliminate.
Second-order effects
- Rival consumer-networking vendors now have a second data point, after ASUS's audit-heavy settlement, showing the FTC treats insecure router firmware as an unfair practice — raising the compliance floor for the whole category.
- The settlement shifts cost expectations onto chipset suppliers and firmware teams, since 'well-known attacks' as a standard means vendors can no longer claim ignorance of published vulnerabilities in components they ship.
Third-order effects
- If the pattern holds — ASUS audited for 20 years, D-Link under a standing program — security-by-design becomes a de facto licensing condition for consumer IoT hardware in the US, enforced through long-tail consent orders rather than one-time fines.
- Regulators appear to be converging on device makers' distribution responsibility for downstream harm, extending liability from the point of sale to the lifetime of deployed routers and cameras.
The trend: US regulators are converting consumer-router and IoT security from best practice into enforceable, multi-year obligations via consent orders rather than penalties.