The Federal Trade Commission has given final approval to a settlement with a Canadian company related to allegations it falsely claimed that its Internet-connected smart locks were designed to be “unbreakable” and that it took reasonable steps to secure the data it collected from users.
Tapplock, Inc. sells fingerprint-enabled, Internet-connected padlocks that interact with a companion mobile app, allowing users to lock and unlock their padlocks when they are within Bluetooth range. The FTC alleged that, contrary to its representations to consumers, the company’s locks were not secure and Tapplock failed to take reasonable precautions or follow industry best practices to protect the consumer data it collected through its app.
Security researchers identified both physical and electronic vulnerabilities with Tapplock’s smart locks, according to the complaint. The FTC also alleged that Tapplock failed to implement a security program or take other steps that might have helped the company discover electronic vulnerabilities with its locks.
Under the settlement, Tapplock is required to implement a comprehensive security program and obtain independent biennial assessments of the program by an assessor that the FTC has authority to approve. The company also is prohibited from misrepresenting its privacy and security practices.
After receiving no comments, the Commission voted 5-0 to finalize the settlement.
The Federal Trade Commission works to promote competition, and protect and educate consumers. You can learn more about consumer topics and file a consumer complaint online or by calling 1-877-FTC-HELP (382-4357). Like the FTC on Facebook, follow us on Twitter, read our blogs, and subscribe to press releases for the latest FTC news and resources.
Juliana Gruenwald Henderson
Office of Public Affairs