Discarded smart lightbulbs reveal your WiFi passwords, stored in the clear
boingboing.net
boingboing.net
If I find bank statements or other correspondence containing personal information, all of that gets added to the "dossier." If I find a hard drive, I'd plug it in and poke around. If I found a birthday card, I'd check the date it was mailed and have a good idea of when you were born. If I found a smart bulb... well, now this is just one more small extension of your personal attack surface.
Take this a bit further - what happens when the healthcare startup with 50 or so employees installs smart bulbs? Let's say the bulbs last on average five years, and they have 50 bulbs in their offices. That's ten bulbs failing per annum, giving a ~80% chance of finding a smart bulb in their trash in a given month. An attacker gets one of those, and is able to connect to their internal network over WiFi. From there they can poke around on internal machines, and would probably even have access to a whitelisted origin IP for SSHing into production machines.
I think they have bigger issues than whether the bulbs themselves are secure (even if they are the manufacturer).
It's still one more vector that doesn't need to exist, because there is no reason what-so-ever that you need a Wi-Fi chip inside your light blub!
… at which point they need to break SSH/TLS after getting off the IoT sandbox network. I’d worry more about phishing and malware, and focus on deploying things like MFA first.
If they aren’t doing any of those things (or, in your example, not using a paper shredder) PCI & HIPAA are going to be a lot more of an existential threat than someone dumpster diving.
The electronics bin in my building's basement is emptied around every 8 weeks, so there's more chance for someone to find them. (I know several people who search through these bins and repair electronics with only minor faults, which is excellent for reducing waste etc.)
[1] That's what this symbol means, on most electronics you buy: https://en.wikipedia.org/wiki/Waste_Electrical_and_Electroni...
I feel like I might be one of those people if this excellent service was available in the US!
It wouldn't be super helpful if I was trying to target a singular person but if I was just going to look for a bulb to use this exploit on, similar to how ATM hackers look for the models they know how to crack, I'd probably be able to find one eventually SOMEWHERE.
So you are going to have to dig through my trash (assuming curbside (it isn't) two to three times to find a blub.
My door lock is easier to compromise. Just walk in and walk out with my server.
Fact of the matter is, if you are the target of someone, there are better ways... and if this is just an opportunistic guy that got some lightbulbs off the back of an e-cycler truck and one of them happens to be mine. He can have whatever he can find on my network.
TL;DR: The lock on your front door is easier to exploit, and the lock on your back door is probably even worse.
They could collect the trash every week, obtain wifi passwords, and obtain a warrant to perform eavesdropping on the network.
[0]https://criminal-law.freeadvice.com/criminal-law/arrests_and...
1) $BADGUY (say, a business competitor) occasionally visits your office (for meetings or whatever).
2) $BADGUY notices that you use CrapSecurity lightbulbs, and brings along a dead CrapSecurity bulb in his backpack.
3) $BADGUY goes to bathroom, replaces the CrapSecurity bulb in your bathroom with his dead bulb (so you think it just burned out or something) and takes your bulb along to read the password at his leisure.
How much would your building's janitor have to be bribed to give someone a dead bulb? Replacing bulbs is one of the things that janitors do, so there'd be virtually no risk to him. The new bulb would have to be added to the network by the sysadmin, but is he gonna ask the janitor for the old one?
Colour me surprised.
The light would store the (B)SSID of your network, so you could just use something like wigle.net to go from that to a lat/lon coordinate.
#1: WiFi credentials are now encrypted
#2: We have introduced new security settings in the hardware
#3: Root certificate and RSA private key is now encrypted
Can anyone ELI5 how #1 is even possible (in a meaningful way)? Doesn't the bulb need to decrypt this to connect to WiFi? Doesn't it need the key for decryption? And doesn't it have nowhere except onboard storage to retrieve that key from, since it isn't yet connected to WiFi? In that case, this "fix" would have no value besides PR. Am I missing something?
IIRC, many embedded processors have a sort of secure enclave, that allows encryption of small amounts of data. The key is basically baked into the CPU, so if someone just takes the flash out of the device and tries to read it somewhere else, the file will need the CPU to be decrypted. I think mostly this is obsolete encryption, but that doesn't necessarily mean it's trivial to break.
Some vendors also embed secrets in their software, to "encrypt" on disk. This doesn't tend to be real security, but does add the barrier that someone needs to go through the software to find the hardcoded keys.
Shipping hardware should also have things like the JTAG and debug pins disabled, this makes it a lot harder to memory dump the in-memory state or get the device to load a custom image that would export the unencrypted keys in memory.
So, there are barriers that can be placed, that does make attacking the hardware harder and out of reach of unsophisticated attacks, but nothing is perfect. In my experience and from what I've heard from the community, it's safer to assume meaningful security measures haven't been taken by the vendors, even if they say they really care about security. Many of the barriers will be like you suggested, encrypted on disk, with the decryption key also on disk.
This would be the sensible implementation, but I doubt that LiFX have used a suitable (and more expensive) MCU.
https://www.digikey.com/en/articles/techzone/2015/apr/securi...
Would be interesting to see a protocol which auto-revokes certificates for devices which do not digitally sign some "ping" message periodically. That way if someone digs through the dumpster, the credentials probably won't be valid.
LED bulbs have very long lives.
If you want to use an RGB bulb or one of those bulbs that has adjustable white temperature, a smart socket isn't going to support that.
Then why am I constantly replacing them? Wait, I know why; because I buy the cheaper ones, which have inadequate thermal solutions and God knows what quality of LED.
You may say "well don't buy the cheap ones", but people will, and they'll always be available. Even more affluent people who hook their lights up to their network will still often chose the cheaper version. Even the high end versions will fail, and you end up with the same problem.
"LED bulbs have very long lives" is an overly optimistic generalisation, in my experience.
All those bulbs I have are the namebrand that do reliably work for years, but I would not want to use them for years. I feel like I might just buy the cheapest bulbs the next time, and not care if they die after 6 months. 6 months might be the maximum amount of time they can give you their brightest.
(For reference, according to http://www.lighting.philips.com/main/support/support/faqs/li..., "The normal convention is to measure the life from when the output has reduced by 30%, i.e. when there is 70% light output remaining.")
But even if you follow parent comment's suggestion of putting the smarts in the switch rather than the bulb you'll still have failure prone control circuitry and drivers in the bulbs. Switching to 12V might help.
Colour drift has been particularly bad with any daylight or cold white bulbs. We've gone through fewer of those so may have just been unlucky brand choices.
Regular incandescents have negative lifespans?
I have several in my house. It’s a bit more complicated though.
You need an RGB driver. In my house it connects to a KNX network, but’s quick google tells me there are wifi ones as well.
Except smart sockets can't do most of the stuff people buy smart bulbs for.
Ideally, there'd be a standard for DC bulbs plugged into sockets, which included brightness and color. But right now, everyone wants to sell their own bulb system.
But agree - if you are mostly going to use it to turn it on/off, a smart socket/switch is likely the way to go. But keep in mind that if you ignore Hue and Lifx, there are decent smart bulbs out there that are fairly cheap - likely cheaper than a smart socket. Add to that the simplicity for the end user. I've installed smart switches, and depending on how your house is built, it can be quite a pain. Not all lighting in the house is via a socket.
They are not without their problems, but burning out has not been one of them.
And, yeah, my guest WiFi password is kind of secret, but I routinely give it out to people who I only casually trust.
I own two LIFX bulbs and they're in reading lamps on each side of my bed. I program them to turn on at 8AM to help me wake up.
I also get to use my iPhone as a light switch since I don't have one conveniently located near the door.
Over time I've found that I enjoy going to bed with them configured to a blue color and dimmed to about 60%.
Finally, I enjoy configuring them to the favorite color of my romantic partner when he/she comes over for the first time.
Interesting given the research and trend towards red light at night.
https://www.health.harvard.edu/staying-healthy/blue-light-ha...
Automation
Compare old and boring this:
typedef struct _light { int state; } t_light;
int lightSwitch;
t_light kitchen[8];
To this:
typedef struct _light { int state; t_linux os; } t_light; t_light self;
x8
Ideally, when you try to connect a new device to your network, an existing device with "network administrator" privileges (e.g. a computer) would get asked "do you want Philips Hue Smart Bulb Controller (printed ID x7a39q) to connect to your network?", and if you say "yes" on that device, the new device would get a unique asymmetric key pair. When setting up a brand new network, you could either enter something printed on the router or scan a QR code.
And then you could have a button to revoke a device's credentials (showing recently disconnected devices first), and a button to revoke the credentials of every device not currently on the network.
Of course in IoT context there is the little problem that all the crappy devices are unlikely to support EAP, but that is another story.
You do need the hub, but the attack surface is reduced, the basic bulbs are cheaper, etc. There probably is key material in the bulb, but who wants to impersonate a light that can only exchange simple binary (no strings to parse) messages with the bridge?
https://www.quora.com/Is-Phillips-Hue-hub-compatible-with-Z-...
But I would say in general, Z-Wave doesn't have as much of this problem. Especially if we're talking Z-Wave Plus devices, which most coming out today are. Even better if they have the S2 security!
It turns out that besides the stupid sociological reasons (which also result in us trying to make it impossible to sleep on a park bench rather than providing people with homes so that they won't _need_ to sleep on a park bench) there's a technical reason, and maybe that we can fix.
WiFi (802.11) has traditionally been plaintext out of the box. So every participant can see everything sent and received by every other participant. If you have a password this isn't so. Thus, a WiFi network plus a billboard announcing the WiFi password to everyone in the neighbourhood is actually slightly _more_ secure than one with no password at all.
Finally in WPA3 this is fixed, participants with passwords use a PAKE but everybody without a password gets OWE (RFC8110) to secure their network access. Since they don't have a way any way to authenticate they can be MITM'd of course, but you can't just passively decrypt everything they're sending and receiving. So a WPA3 era WiFi network that's "open" to everybody is protected better than your WPA2 PSK "ThanksMike" password for Mike's Coffee Shop.
Ideally, when you try to connect a new device to your network, an existing device with "network administrator" privileges (e.g. a computer) would get asked "do you want Philips Hue Smart Bulb Controller (printed ID x7a39q) to connect to your network?", and if you say "yes" on that device, the new device would get a unique asymmetric key pair. When setting up a brand new network, you could either enter something printed on the router or scan a QR code.
And then you could have a button to revoke a device's credentials (showing recently disconnected devices first), and a button to revoke the credentials of every device not currently on the network.
If the lightbulb encrypts the password for storage, it necessarily also stores the decryption. An attacker would just have to take one extra step.
I guess what I'm saying is, doesn't this apply to any device you save any password in? (And don't need a password to log in on reboot).
Edit: Thanks for all the info in the replies!
Yeah, but they could use some kind of secure enclave to make it much more difficult. Like having the bulb query the enclave with a securely hashed version of each available SSID until the enclave returns a password. That would at least make it non-trivial to get the password or figure out what network it connects to without some prior knowledge. That's valuable since it would prevent someone from buying an old bulb then wardriving to find the network that it's credentials work for.
Also it would be good to have some kind of secure reset physical button, to make it as easy as possible to clear any private data before the bulb is discarded.
Neither of these ideas would help secure your network against exploitation of an actively-used bulb, but they'd help with the discarded-bulb case.
Edit: another commenter linked https://wigle.net/, which could make it extremely easy for an attacker to find the network to exploit if the device stores the SSID in cleartext. My idea would help make that a lot harder, especially if the enclave rate-limits requests.
I'd rather just delete the password. Or better yet, skip the wifi bulb and use something like Z-Wave or Zigbee.
The better solution of course would be to have the intelligence in the socket/switch/wiring. But that requires more effort when upgrading to "smart" (they are not smart, you still have to manually set them to the desired mode.) illumination and doesn't play nice with rental property.
Or a sledgehammer...
We need a new internet law: Never provide a technical solution to a problem which can reasonably solved with a hammer.
1. Unlike "wipe the bulb before discarding", you don't have to trust the bulb manufacturer to actually wipe.
2. You can invalidate credentials even after discarding a bulb.
Perhaps you could have the smart hub store the encrypted WiFi password, and require a manual unlock every time it cycles power. This would require something like a Bluetooth connection from your phone (since you obviously won’t have WiFi).
This would obviously be very inconvenient, and potentially dangerous in some situation where you need your home lighting. Perhaps the emergency situation can be solved by having smart bulbs turn on maximum brightness after cycling power (which I believe the Philips Hue bulbs do).
Don't store the wifi at all. It's a light bulb. It burns out.
Store the wifi password in the socket/switch. That is the solution.
The comments there also shed some light on how they can be improved.
"Vulnerability n*3: Root certificate and RSA private key extracted
Root certificate and RSA private key are present into the firmware and are used to connect to LIFX cloud."
Then again, without any security at all, maybe firmware isn't signed at all anyway..
If LIFX had enabled secure boot, disabled the debug interface, and encrypted the boot flash storage, we would be reading an article about how consumers no longer owned their devices and how they were being abused by a corporate behemoth trying to derive them of their right to repair and tinker through DRM.
You know this, I know this, and I know that you know that I know that you know this.
I'm sure some customers use the same password for the email they gave Spectrum.
Come on. Buy a wifi switch/socket, not a wifi light bulb.