# Cloud security concerns

**URL:** https://community.ultraloq.com/t/cloud-security-concerns/5200
**Category:** Xthings Home App
**Created:** [December 19, 2022, 4:47am UTC](https://community.ultraloq.com/t/cloud-security-concerns/5200 "2022-12-19T04:47:49Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![JeremyB](https://avatars.discourse-cdn.com/v4/letter/j/ad7895/32.png) [@JeremyB](https://community.ultraloq.com/u/JeremyB)
#### Post date: [December 19, 2022, 4:47am UTC](https://community.ultraloq.com/t/cloud-security-concerns/5200/1 "2022-12-19T04:47:49Z")

</div>

I hope this FAQ page is out of date? If so, can you share the current details of how you keep user data secure at rest and in transit?  
Can you update this page to hopefully make us more comfortable with how you protect and encrypted user data? [https://support.u-tec.com/hc/en-us/articles/360004273952-How-Secure-is-U-cloud-U-tec-App-](https://support.u-tec.com/hc/en-us/articles/360004273952-How-Secure-is-U-cloud-U-tec-App-)

MD5 hashing has been considered cryptographically insecure for over a decade now. I hope you have moved to a more modern security approach like a salted, stretched hash using a modern algo like SHA-512. [Serious Security: MD5 considered harmful – to the tune of $600,000 – Naked Security](https://nakedsecurity.sophos.com/2022/11/30/serious-security-md5-considered-harmful-to-the-tune-of-600000/)

---

<div class="post-metadata">

### Author: ![JeremyB](https://avatars.discourse-cdn.com/v4/letter/j/ad7895/32.png) [@JeremyB](https://community.ultraloq.com/u/JeremyB)
#### Post date: [December 29, 2022, 2:18am UTC](https://community.ultraloq.com/t/cloud-security-concerns/5200/2 "2022-12-29T02:18:53Z")

</div>

Hi, can somebody reply to this [@staff](https://community.ultraloq.com/groups/staff) ? MD5 hashing is an inadequate method for keeping passwords and other user data secure.

---

<div class="post-metadata">

### Author: ![JeremyB](https://avatars.discourse-cdn.com/v4/letter/j/ad7895/32.png) [@JeremyB](https://community.ultraloq.com/u/JeremyB)
#### Post date: [January 9, 2023, 5:16am UTC](https://community.ultraloq.com/t/cloud-security-concerns/5200/3 "2023-01-09T05:16:51Z")

</div>

Would still like to see an official reply here. Per your own FAQ you are using out-of-date and insufficient methods for securing user data. Can somebody from U-tec comment on this (and ideally do something about it?)

---

<div class="post-metadata">

### Author: ![Dan4534](https://avatars.discourse-cdn.com/v4/letter/d/edb3f5/32.png) [@Dan4534](https://community.ultraloq.com/u/Dan4534)
#### Post date: [January 9, 2023, 3:08pm UTC](https://community.ultraloq.com/t/cloud-security-concerns/5200/4 "2023-01-09T15:08:32Z")

</div>

You seem to have some technical knowledge. Maybe we can just reverse Engineer their Bluetooth API and not need their cloud since they won’t release a local Bluetooth API.
