Of course smart homes are targets for hackers
mjg59.dreamwidth.org
mjg59.dreamwidth.org
Basically they go to their friendly shodan-alike and get a list of ip running IOT cameras (etc). Then they pipe that list through a geolocation service and grep for their target region. Then they just monitor for good targets, and when they are unoccupied.
Much like the big hubub when people pointed out that mentioning vacations on an open facebook feed was burglar bait.
Both take away a lot of effort for reconning homes, so they are probably being used to narrow the search for good potential targets.
Of course there's zero money in this, so I guess capitalists are up the river.
If someone is there ask for a glass of water, ask if they have accepted Jesus, ask if Steve lives there or whatever other BS excuse they have ready before simply moving on to another prospect. If no one comes to the door then the home is very likely empty and they can proceed.
This has the added benefit for the burglar that anyone seeing them enter the property will assume they have good reason to be there. After all they marched straight up to the front door and rang the doorbell which is what non-thieves do so its less suspicious if they then go around the side of the house when no one answers.
Skills and persistence get used for many things, from english phds, triathlons to code.
http://www.bbc.com/future/story/20150618-the-strange-experti...
Exactly. The vast majority of people aren't aware that their "smart thermostat" can be hacked and used to perform a denial of service attack on websites.
Please do not get me wrong. I am big fan of smart homes and there is long history in this market, but sorry, what happens in my home must stay in my home and not leak out to some remote server.
An IoT device in our home is perhaps not a huge security risk for an individual, but it is even larger risk for the society as a whole.
But if we conclude from that that we should remove these things from cars, we would be wrong, because we have to reason at scale about these things. At scale, the extreme events happen with some frequency.
It should also be pointed out that we are now living in a world where we are not hypothesizing that someday IoT devices may have serious insecurities that lead to real problems for people, but one where we know it is true because it happens. When the Internet basically went down on the east coast and some other places last week, plenty of people who were affected by that were also the ones who owned the devices that caused it. At scale, they made a decision to buy something that ended up taking the Internet out for themselves and others. It does no good to reason that each of them only took a small risk individually when what affects us all is the collective risk of those actions.
Just like in the automotive case, where we must consider the effects of various safety interventions on society as a whole and at scale, we must consider the effects of this security on society as a whole and at scale. Unlike the automotive case, computers have extra concerns about their ability to interact in ways that physical devices can not. And at that scale and with those concerns, no, there's nothing unreasonable about this analysis, especially in the face of the existing Mirai botnet. It's not just the visual-imagination compelling stories like burglars breaking into your house because they saw you weren't home from your camera (and then, presumably, remotely shut it off); it's all the possibilities.
You shouldn't buy a device that is open to the internet with a default root password that can't be changed and has no firmware update mechanism even available. It's not hard to take the Kantian imperative and actually show that to be unethical of you. (While the Kantian imperative is philosophically controversial, I think this is one of those cases where it applies pretty well.)
The problem is that, once past the firewall, many of these devices have weak to no security, e.g. open telnet daemons, root:root default user/password, and other trivial vulnerabilities.
Or, more likely, it did happen earlier but the attackers weren't properly weaponizing or "botkilling" / patching the devices?
I've been Cassandra yelling into the wind on this one for a while, so there is some schadenfreude involved for me.
On the other hand, the Hue hub is running a full embedded Linux distro (which has even been rooted, though it requires physical access http://colinoflynn.com/2016/07/getting-root-on-philips-hue-b... ). A lot of the "real" smart home gadgets are using this model and they will gleefully punch a hole in you firewall, so it comes down to the security of the hub(s).
From what I know, Mirai is mostly hitting stuff that isn't what I think of as IoT - stuff like routers, security cameras and DVRs. Seems like it's being misrepresented, though that's not to say that an attack on something more in line with what I think of as IoT/smart home isn't possible. I have no doubt that tons of refrigerators with Wifi and connected coffee makers are vulnerable. Part of me wonders if Mirai was meant as a grey hat warning since it's just showing what's possible only picking on low hanging fruit ("Mirai" means "future" in Japanese).
I would wager that is correct. I certainly took it that way, especially after the source code dump. [0] That seemed to be almost out of frustration.
One thing I noticed was, for the most part, the intelligence of a user was inversely correlated to how much shit they had running in their windows system tray.
The smarter you were, the fewer little blinking mini-icons you had down in the lower-right corner of the desktop. You didn't need those gimmicks and you understood the value of simplicity in a running system.
I wonder how smart homes and smart people correlate ?
I was going to say "at least IoT devices can't driveby install themselves", but I'm sure someone will find a way. Maybe people can have Bonzi Buddy for their thermostat.
"House is at risk from subsidence and there's Heartbleed in the heating system"
Wait, you just said above:
> It doesn't have to be crap if it is modular and upgradeable. Executive controller, hardware controllers, sensors and switches need to be serviceable/upgradeable.
I sure hope you don't own an HP printer...
Get into Services and set unessentials to manual, bloatware to disabled(if cannot uninstall & keep functionality or driver). Some searching[0] around will show more than a few MS services can be disabled without anything of value lost.
edit: blackviper's still up and running. wow. :
Sorry for the nitpick. There are many smart people who are not techies.
I work at a facility with tens of thousands of sensors that are critical to safely and efficiently running the operation. IoT is spilling into the residential sector because of how successful it has been in the commercial world and because many people find it to be a useful addition to their household.
Are there issues that the industry needs to resolve? Absolutely. Should the buyer made an educated purchase? Sure. But the answer to some IoT systems being insecure is not that the whole field is a gimmick only for the "smart"! I wouldn't even call residential IoT a mature technology yet - of course there are going to be issues.
I will concur the article is a bit of IoT fear mongering combine with general paranoia over the current state of web services, but it's not really like this is much of a stretch for the near future.
You might be surprised at how long you can have the same IP. It can easily go for a year with some ISPs.
It seems much more likely that it's not an either/or proposition.
Does it seem that unreasonable that someone can go from name to email to spearfishing attempts to ip to firewall exploit to home security camera/refrigerator/every out-of-date piece-of-garbage IoThing in your house if they're specifically trying to get you? That was pretty much each of the 100 stories behind the Fappening. You think a rival startup wouldn't go through the effort, or a creepy neighbor? Isn't that the entire concept behing RATting (minus the easy way in provided by the IoT)?
You think it won't be turned into a 1-click app with notifications after each stage is passed?
Oh, you say you have nothing to hide.
Do you have a bank account? An investment portfolio? College funds for your kids?
A skilled attacker can make all of that vanish.
Without many people noticing, the IoT has slowly invaded the average American home. Almost every TV is a Smart TV, internet gateways are smarter, Alexa, Siri, Cortana, light bulbs, door locks, refrigerators, thermostats...
With a little effort, an average pen tester could own your system, publish your secrets, steal your life savings, record you with your wife, and brick your iPhone, TV, and furnace just for good measure.
It's time to take IoT security seriously.
*It actually was on Mr. Robot. There was a subplot wherein Darlene compromises an E-Corp exec's smart home, causes the appliances and security system to malfunction to drive away the occupant, and then uses the place as a hideout.
It’s easy for people to be completely oblivious to this reality if they have never experienced it themselves or had someone they knew be on the receiving end of this kind of behaviour. It really is not that uncommon.
(Now, to find a TV that doesn't have a microphone.)
If there is anything that can, say, let someone remotely cause a fire then the problem isn't security. The problem is that you have something under software control that can cause a fire. Chances are that regular faults will burn down the house much more often than "hackers" will. Note that such faults can be caused by things like lighting hitting the power lines somewhere in your city. They don't have to be actual bugs.
Of course the "internet of things" is kind of a joke right now. What with the lack of any sort of standardization it is unlikely that the owner will be able to usefully control things much less some remote attacker.
Or maybe they can monitor your light switch without changing its state. That data could be used to estimate when you are home with reasonable accuracy.
Or maybe they don't care about you at all and simply use your device in a DDoS or as a relay in an attack on someone else.
However, that's just one way an insecure device could be abused that uses the data we know is available. I'm sure there are subtle and clever ways to abuse these devices that are still unknown.
>I'm sure there are subtle and clever ways to abuse these devices that are still unknown.
The security of residences as fairly well understood at this point. The attacks have been occurring for centuries. My point is that we can't treat this as an IT problem. We have to take the old cultural knowledge into account as well.
That depends. If your light switch runs an out of date stack, it can be compromised and used as a beachhead to attack other things on your network or to run whatever software they want.
Unless the attacker doesn't want to use the IoT device for its usual purpose, but instead as, say, a vehicle for a DoS attack, or an attack path into other devices connected to the same home network.
Please be wise.
Neither a toaster manufacturer nor the end-user care at all whether the manufacturer hooks a device to the toaster which gives them some bragging rights but can be used to bring down some portion of the Internet when it's security fails.
This is called an "externality" by economists[1]. Similarly to pollution, it's an effect whose cost is not born by those who produce or who consume a given product. And it pretty much require regulation to stop, though the chance of regulation in the present environment seems rather small.
Yes, and it's been a problem for well over a decade. E.g. a while ago the clowns at D-Link decided to hammer NTP servers, then had the chutzpah to call it "extortion" when one operator attempted to get them to stop. https://www.lightbluetouchpaper.org/2006/04/07/when-firmware...
(Yes, I know about deterring burglars.)
It's very convenient to be able to control lights from anywhere in the room by issuing a voice command. Not just turn them on and off but also dim, change colours, etc.
Granted this is from the perspective of living in an apartment :)
Similarly, our HVAC puts out most of its air upstairs and we use a fan to help move air down the stairwell. I set it up to coordinate with the HVAC to turn on and off in time with the cycles and also to turn itself off in the evening when we are all asleep and back on in the morning. Again, not essential but fun and handy.
The HVAC itself is also controlled by a somewhat complex system that I made over the course of about 6 months. It makes a big difference in keeping the house temperature even and also saves something like $10 per month in electricity. My point here is that well targeted smart home devices can be really handy. On the other hand I made this stuff myself specifically tailored to my needs. IMO, it's hard for commercial products to really hit the sweet spot between being easy to use and yet adaptable enough to fit into everybody's life tightly enough to not be annoying.
It's pretty clear that an HVAC system that is on a timer can save considerable power. I have a programmable thermostat for that reason, but the user interface for it is so awful I need to reread the manual every time. It would be better if it was wifi and presented a web page as a UI.
I also bought a programmable cat feeder. Again, one needs a manual to figure it out. What is wrong with those engineers? You shouldn't need a freakin' manual to set up a cat feeder. And the UI couldn't be satisfied with 5 buttons, no, you've got to do chording and hold buttons for various amounts of time to do various things. It's complete madness.
(I don't want the cat feeder hooked to the internet, though. I'm suspicious the cat has been plotting against me, and it might be able to coordinate with other cats via the cat feeder interface, which could spark the cataclysm.)
It's barely a rounding error. Sleeping the microcontroller, average current draw is a couple mA. LED lights draw around 500 mA.
Regarding the HVAC, what I made is more focused on keeping the temperature balanced by taking a weighted average of temperatures across the house, with the weights adapting to where people are, similar to the Ecobee thermostats but DIY. It also has a web interface where you can view temperatures and power usage, which is far more useful than I thought it would be.
How is the avarage consumer going to find out the security reputation of a vendor of smart home devices? How to find a reputable vendor for such or such device like a baby monitor, security cam, smart lightning or wifi repeater? In an easy way and easy to comprehend?
Is there a website to check to security of smart home devices, or a list of reputable vendors? That would be a first step.
Are you bloody kidding me? Why do you even have a firewall, rudimentary as it is, then?
If you really think of your NATing router as a security device, turn off UPnP. Though I'm not sure how much good that will do, as any device can still phone home or reverse tunnel.