It seems that some homes may be Secretive Boarding Housetoo smart for their own good.
On Monday, March 5, researchers at the San Francisco RSA conference presented to an assembled crowd of journalists and cybersecurity experts an unexpected approach for hacking into the device-enabled homes of the modern day George and Lydia Hadley.
Notably, they explained, it's not solely our internet of things that includes cameras and refrigerators we need to worry about. Instead, as people add more and more smart devices to their lives we also need to pay attention to the systems managing the interactionsbetween those tools.
Sounds fun, right?
At the core of this vulnerability is what the two Trend Micro senior threat researchers, Stephen Hilt and Numaan Huq, call "complex IoT environments" (CIE). In a corresponding paper detailing the threat, they define such an environment as typically (but not exclusively) a smart home with ten or more IoT devices linked up to one another. It's how these smart gadgets interact, via a so-called IoT automation platform, that's the problem.
SEE ALSO: Helen Mirren at RSA security conference: You're heroes who 'patrol a vast untamed wasteland'Imagine setting up your smart doorbell to tell your smart lights to turn on when it detects a predetermined amount of outside light. Your automation platform would be the connective tissue wrapping those two services together.
"An IoT automation platform serves as a brain of sorts for the CIE and allows the creation of smart applications by functionally chaining the devices through custom rules, thus allowing devices to interact and affect each other’s actions," reads an accompanying Trend Micro blog post.
If these brains can be accessed — and it turns out that many of them can be — then the entire system can be exploited. Examples provided by the researchers were chilling.
Say you set up your smart home to send you a photo, via Slack, every time your outside camera detected movement. Great, right? Well, maybe. Because, if attackers can gain access to the platform facilitating this communication between the camera and Slack, then they can intercept that image and functionally get push notification photos for your house.
"As you’re adding more and more stuff, the attack vector […] is steadily increasing,” Hilt told the crowd.
Or how about a program that, upon detecting your smartphone has joined the home Wi-Fi network, unlocks the front door smart lock. This is super futuristic and fun, until a hacker tricks the program into recognizing her phone as well and then walks into your house while you're at the beach contemplating how much easier life has been made by your networked smart home.
Frustratingly, according to Hilt and Huq, there are plenty of exposed IoT automation servers that can be quickly and easily found via the IoT search engine Shodan. A slide shared during the presentation noted that the researchers had discovered thousands.
What's more, these servers sometimes give specific latitude and longitude data for the house in question. This means that not only could a bad actor control a smart home online, but they could find it in real life. In one troubling example, the researchers noted that they located an exposed smart home system belonging to a house that just so happened to be quite close to their physical location.
So what does this mean for you? It means you need to pay attention to not only the security of your smart bulbs, but to the security of the system that ties them to your IoT-connected washing machine as well.
Because as we continue to add more networked devices to our homes, the under-explored problems that come with the resulting complexity are increasingly likely to rear their ugly heads.
Topics Cybersecurity
Previous:Is it 'Thunderbolts*' or *The New Avengers'?
Next:Gods of War
Cyclist who was fired for flipping off Trump's motorcade won a Virginia election3 things to know about using ChatGPT like a therapistNothing's next smartphone will be 'more premium' than Nothing Phone (1)Airbnb plans to verify 100% of its listings after mass shooting, scam allegationsChatGPT creators' AIFederal Welcome Corps program lets private citizens sponsor refugee resettlementLizzo doesn't mince words about people using body positivity for personal gainThe best 'Forspoken' magic to go after early in the gameGorilla Glass Victus 2 to debut on Samsung Galaxy S23Deepfake of Arnold Schwarzenegger in 'No Country for Old Men' will mess you up15 gifts true fans of 'The Office' need in their livesTikTok's CEO is headed to Congress to testify about user privacy and safety'Quordle' today: See each 'Quordle' answer and hints for February 1Nothing's next smartphone will be 'more premium' than Nothing Phone (1)Incognito mode on Chrome for Android just got a lot more useful'The Last of Us' is getting a Season 2. Brace yourselves.12 'Hamilton' songs that kept their staying power after years of listeningGorilla Glass Victus 2 to debut on Samsung Galaxy S23'The Last of Us' episode 3: The ending Linda Ronstadt song, explained4 young gun reform activists share their goals for 2023 Emma Thompson almost quit a film when a costar was body shamed A drunken Cayde 'Final Fantasy XIV' just got a whole lot more appealing for newcomers Watch the world's first ever monster truck front flip. You know you'll love it. Teen's Disneyland promposal is sweeter than a pot of Pooh's honey Donald Trump is now your last hope for the most basic internet privacy rules This company claims it will make you a watch using your cat's hair Jimmy Fallon and Harry Styles headed to 'SNL' in April New online NASA library offers all your free space porn in one place These $110 'smart flip flops' are incredibly dumb Samsung DeX transforms the Galaxy S8 into a legit desktop computer Today, in Bad News for Uber: Denmark kicks Uber to the curb Jack Dorsey's Square launches in the UK Americans now trust ads more than news and who can blame them? 'American Gods' gives classic art a tech twist, because it already knows us way too well Samsung changed the Galaxy S8 battery because of the Note 7 disaster AmazonFresh will now deliver your groceries directly to your car Apple finally approved an app that tracks drone strikes, then abruptly deleted it Grindr wants you to know it's not just a hookup app, launches online magazine Billy Eichner is joining 'American Horror Story' to hang with Sarah Paulson
2.8224s , 10132.2734375 kb
Copyright © 2025 Powered by 【Secretive Boarding House】,Co-creation Information Network