It seems that some homes may be The Playbirdstoo smart for their own good.
On Monday, March 5, researchers at the San Francisco RSA conference presented to an assembled crowd of journalists and cybersecurity experts an unexpected approach for hacking into the device-enabled homes of the modern day George and Lydia Hadley.
Notably, they explained, it's not solely our internet of things that includes cameras and refrigerators we need to worry about. Instead, as people add more and more smart devices to their lives we also need to pay attention to the systems managing the interactionsbetween those tools.
Sounds fun, right?
At the core of this vulnerability is what the two Trend Micro senior threat researchers, Stephen Hilt and Numaan Huq, call "complex IoT environments" (CIE). In a corresponding paper detailing the threat, they define such an environment as typically (but not exclusively) a smart home with ten or more IoT devices linked up to one another. It's how these smart gadgets interact, via a so-called IoT automation platform, that's the problem.
SEE ALSO: Helen Mirren at RSA security conference: You're heroes who 'patrol a vast untamed wasteland'Imagine setting up your smart doorbell to tell your smart lights to turn on when it detects a predetermined amount of outside light. Your automation platform would be the connective tissue wrapping those two services together.
"An IoT automation platform serves as a brain of sorts for the CIE and allows the creation of smart applications by functionally chaining the devices through custom rules, thus allowing devices to interact and affect each other’s actions," reads an accompanying Trend Micro blog post.
If these brains can be accessed — and it turns out that many of them can be — then the entire system can be exploited. Examples provided by the researchers were chilling.
Say you set up your smart home to send you a photo, via Slack, every time your outside camera detected movement. Great, right? Well, maybe. Because, if attackers can gain access to the platform facilitating this communication between the camera and Slack, then they can intercept that image and functionally get push notification photos for your house.
"As you’re adding more and more stuff, the attack vector […] is steadily increasing,” Hilt told the crowd.
Or how about a program that, upon detecting your smartphone has joined the home Wi-Fi network, unlocks the front door smart lock. This is super futuristic and fun, until a hacker tricks the program into recognizing her phone as well and then walks into your house while you're at the beach contemplating how much easier life has been made by your networked smart home.
Frustratingly, according to Hilt and Huq, there are plenty of exposed IoT automation servers that can be quickly and easily found via the IoT search engine Shodan. A slide shared during the presentation noted that the researchers had discovered thousands.
What's more, these servers sometimes give specific latitude and longitude data for the house in question. This means that not only could a bad actor control a smart home online, but they could find it in real life. In one troubling example, the researchers noted that they located an exposed smart home system belonging to a house that just so happened to be quite close to their physical location.
So what does this mean for you? It means you need to pay attention to not only the security of your smart bulbs, but to the security of the system that ties them to your IoT-connected washing machine as well.
Because as we continue to add more networked devices to our homes, the under-explored problems that come with the resulting complexity are increasingly likely to rear their ugly heads.
Topics Cybersecurity
Best robot vacuum deal: Get 44% off the Eufy Robot Vacuum C10Amazon Big Spring Sale 2025: Samsung Frame TVs and dupes on saleIf you're sick of Google's AI Overviews, try this genius hackBest Mac Mini deal: Get an M4 Mac Mini for its lowest price yetAmazon Big Spring Sale: My favorite smart bulbs have never been cheaperAmazon Spring Sale 2025: Best power bank dealHow to watch 'Queer': Release date, streaming detailsKindle books are up to 90% off during Amazon's Big Spring SaleAmazon Spring Sale 2025: Best portable power station dealBest robot vacuum deal: Get 44% off the Eufy Robot Vacuum C10Amazon Big Spring Sale 2025: Best Fire TV Cube dealToday's Hurdle hints and answers for March 28, 2025NYT mini crossword answers for March 27, 2025Amazon Spring Sale 2025: Best Ecoflow power station dealWhat's new to streaming this week? (March 28, 2025)MLB Opening Day: Can TikTok save baseball?NYT Strands hints, answers for March 27Amazon Spring Sale 2025: Best book dealsBest Mac Mini deal: Get an M4 Mac Mini for its lowest price yetElon Musk makes request to Reddit CEO to take down posts he didn't like Ultimate 'Friends' fans got engaged in Monica's apartment at FriendsFest Team Huma banned from Riot's 'League of Legends' events for not paying players Wave of '90s throwback tours proves the nostalgia cycle is in full effect The SpaceX explosion could throw off the company's big 2016 plans Twitter lets brands sponsor Periscope livestreams, starting with Chase and Grey Goose Why Tropical Storm Hermine poses a menacing flood, erosion risk to Mid Zoo asks public to help name its gorilla and the people want 'Harambe' Before and after photos from girl's first day of school will make you say 'same' Nike calls Serena Williams the 'greatest athlete ever' in new ad Apple's iPhone 7 Event: What to expect Social senior dog walks 4 miles every day to catch up with all his friends Chris Brown releases new song less than a day after his arrest Apple writes love letter to ride Florida hasn't had a hurricane in 3,965 days: until today Did Tesla's Model X software update make its falcon I kicked the crap out of Dyson’s new vacuums and they wouldn’t fall over An appreciation of the McDonald's employee with Down Syndrome who just retired after 32 years After unusual Arctic storms, sea ice coverage in region is plummeting A letter arrived in Iceland with a hand Great Fire of London comic book stamps will reignite your love for letter writing
2.3563s , 10133.0703125 kb
Copyright © 2025 Powered by 【The Playbirds】,Pursuit Information Network