Off-Prem

Edge + IoT

Smart homes are hackable homes if not equipped with updated, supported tech

People forget IoT gadgets aren't dumb appliances. gear needs to be fed security, bug fixes


Smart homes are increasingly becoming hackable homes, according to consumer research.

The report by consumer rights organization Which? paints a grim picture for people who have equipped their residences with gadgets, many from trusted tech names.

As with pretty much everything in IT, if you connect a device to the internet, ensuring it's patched and has a decent password is the very least owners can do. Even then, there are no guarantees that this is secure.

Unsurprisingly, the Which? team found that out-of-support devices were relatively straightforward for hackers to compromise. The example of an early Amazon Echo smart speaker was given where researchers were able to take control without the user being aware.

Other devices, such as smartphones and routers, were also exploited. The Which? team were able to infect a Samsung Galaxy S8 smartphone with malware disguised as a delivery text. Siphoning of user data was then possible.

However, in these cases the devices were out of support and "the attack would have been better blocked or detected by a device that was still receiving security updates," Which? noted.

Other devices Which? tested included a Google Nest Hello video doorbell, a HP Deskjet printer, and a Philips TV, "which is supposed to still be supported with updates" but "could be hacked using an easily guessable default password."

Yes, we all know about security patches. The problem with IoT devices is that consumers tend to treat them as appliances. This writer, for example, has a set of speakers more than 30 years old. It is hard to imagine a smart speaker having that sort of longevity in terms of security updates. Insteon springs effortlessly to mind when one thinks about smart devices abandoned by their makers.

There are a few relatively simple steps you can take to deal with the issue. One would be to ditch meaningless terms like "lifetime updates" and label devices with clearer indications of when support will end. Another, according to Which?, would be "mandatory minimum periods for how long different types of smart products must be supported."

"There should be stiff penalties for companies that fall short of standards," the organization said.

Ultimately, the research is yet another reminder user need to take care as they fill their homes with connected gizmos. You might end up with your data unexpectedly siphoned or be an unwitting part of the next big botnet. ®

Postface

Andrew Tierney of cybersecurity outfit Pen Test Partners argued in response to the Which? advice that devices could be fully patched or not vulnerable to any particular flaw, and yet still open to abuse and mostly like abused by, say, spiteful ex-partners and anyone else who wants to harass a victim.

Those people might know, or could guess, the password to smart home equipment, or be able to pair with it still by being nearby, just as the technology intended. They would also have the most to gain from spying on a victim's camera or disrupting their heating, versus a random miscreant on the internet.

"Virtually nothing above uses any security weaknesses in a system," he tweeted.

"It's people abusing conventional access to a system."

Send us news
112 Comments

Amazon, Google asked to explain why they were serving ads on sites hosting CSAM

And US government adverts at that, say senators

Murena kicks Google out of the Pixel Tablet

Privacy-centric Android makes more sense on this form factor than a phone

AWS unboxes quantum cat qubit kit called Ocelot

Sprinting after Microsoft and co, Amazon claims it too has a QC chip that's good at all-important error correction

uBlock Origin dead for many as Google purges Manifest v2 extensions

Chrome ad blocker stopped working? Time to look elsewhere

Google binning SMS MFA at last and replacing it with QR codes

Everyone knew texted OTPs were a dud back in 2016

India's top telco plans cloud PCs for its 475 million subscribers

PLUS: China bans AI leaders from visiting USA; Acer data leak suspect cuffed; and more

Qualcomm pledges 8 years of security updates for Android kit using its chips (YMMV)

Starting with Snapdragon 8 Elite and 'droid 15

As Amazon takes over the Bond franchise, we submit our scripts for the next flick

License To Kill -9 ... For Your iPhone Only ... AI Another Day ... The name's Bezos, Jeff Bezos

FDA clears Google watch feature to call 911 if you flatline

It looks like you have died. Would you like help?

HP Inc to build future products atop grave of flopped 'AI pin'

Tech and people behind IoT brooch that reviewers instantly hated will one day pep up printers

Crimelords and spies for rogue states are working together, says Google

Only lawmakers can stop them. Plus: software needs to be more secure, but what's in it for us?

Triplestrength hits victims with triple trouble: Ransomware, cloud hijacks, crypto-mining

These crooks have no chill