Smart Home Appliances - Digital Hazard for Humanity & IoT : Alert
By MYBRANDBOOK
It is estimated that by 2020, not so far from now, 20.4 billion smart home devices will be installed. Nearly doubling the number installed this year alone, there are IoT devices heated towards the whole family, from mom, dad, kids, and even pets. With this growing popularity though, security concerns grow as well — ignoring the safety and integrity of these devices enables risk.
McAfee Labs’ Advanced Threat Research team today detailed vulnerabilities in two smart home devices that could cause grief for users: a smart padlock and an internet-connected coffee maker.
The first device, called BoxLock, first made an appearance on the show Shark Tank and is designed to be set up outside a home to secure a package delivery container.
So-called “porch pirates,” people who steal deliveries from the front of homes, has become a growing problem in the U.S. in the age of home deliveries. The idea is by having a secure container, the delivery person can place the ordered item in the container and then secure it with the BoxLock.
The lock can be opened by via a mobile application or by using the built-in barcode scanner to scan a package that is being delivered. Homeowners can then later unlock the BoxLock to retrieve the delivered item once they return home.
If that all sounds great in theory, the implementation of security in the device was not. The vulnerability lies with the device’s use of Bluetooth Low Energy which can be used to download an app, send one command and open the lock.
The issue isn’t related to BLE itself but the specific implementation used by the vendor. The researchers were able to find a way, using Generic Attributes commands from a smartphone without the BoxLock app installed, to open the device.
The good news is that the BoxLock was responsive when the McAfee researchers approached them, both working with them to rectify the issue and roll out patches to the lock.
mrcoffeeSecond on the list is an internet-connected coffee machine, the Mr. Coffee Smart Coffeemaker enabled with WeMo.
WeMo is an “internet of things” platform from Belkin International Inc. that now finds itself appearing in other devices as well.
The coffeemaker accepts scheduling of coffee brewing via the WeMo app but in doing so does not properly validate requests. What that means is that the third-party with access to the network could schedule coffee-making on demand.
While that may not sound specifically nefarious, the coffeemaker could be forced on without fresh coffee in place potentially causing either burned coffee or in an extreme case even a fire.
Belkin did not respond to the McAfee security researchers but has since issued an update that addressed the issue.
“Most businesses, from Fortune 500s to mom-and-pop shops, will likely deal with a security breach or vulnerability disclosure at some point,” Steve Povolny, head of Advanced Threat Research at McAfee, told SiliconANGLE. “Those who are proactive and very public in addressing the issue have an opportunity to reinforce consumer trust and confidence.”
In the case of vulnerability disclosure, he added, “by engaging with the research team and coordinating on the mitigation and communication of the issue, vendors can set themselves apart in industries that are facing further security scrutiny from customers, shareholders and the general public.”
Getting into the habit of being mindful of IoT devices is essential when bringing them into the home. Routines like checking devices for unwanted connectivity features, updating two-factor authentication settings, and opening up a separate network for guests keep us mindful and protected from the risks. Even the FBI recommends resetting your router once in a while, to avoid VPNFilter malware. Habits as simple as regularly checking for security patch updates can make a huge difference against cyber criminals. As a household, ensuring everyone is on the same page when it comes to cyber safety and IoT connectivity makes for a secure home.
If it’s got an internet connection, it very well may be vulnerable to cyber attack. Do you know how secure your home IoT devices and also You.. are..?
Nazara and ONDC set to transform in-game monetization with ‘
Nazara Technologies has teamed up with the Open Network for Digital Comme...
Jio Platforms and NICSI to offer cloud services to government
In a collaborative initiative, the National Informatics Centre Services In...
BSNL awards ₹5,000 Cr Project to RVNL-Led Consortium
A syndicate led by Rail Vikas Nigam Limited (abbreviated as RVNL), along wi...
Pinterest tracks users without consent, alleges complaint
A recent complaint alleges that Pinterest, the popular image-sharing platf...
HIMACHAL FUTURISTIC COMMUNICATIONS LTD.
VERSA NETWORKS INDIA PVT. LTD.
STERLITE TECHNOLOGIES LTD.
TEJAS NETWORKS INDIA PVT. LTD.
Icons Of India : Arjun Malhotra
Arjun Malhotra, the Chairman of Magic Software Inc., is widely recogni...
ICONS OF INDIA : SANTHOSH VISWANATHAN
Santhosh Viswanathan is the the Vice President and Managing Director f...
Icons Of India : Daisy Chittilapilly
Daisy Chittilapilly is the President of Cisco’s India and SAARC regi...
IREDA - Indian Renewable Energy Development Agency Limited
IREDA is a specialized financial institution in India that facilitates...
EESL - Energy Efficiency Services Limited
EESL is uniquely positioned in India’s energy sector to address ener...
NIC - National Informatics Centre
NIC serves as the primary IT solutions provider for the government of ...
Indian Tech Talent Excelling The Tech World - JAYASHREE ULLAL, President and CEO - Arista Network
Jayshree V. Ullal is a British-American billionaire businesswoman, ser...
Indian Tech Talent Excelling The Tech World - PADMASREE WARRIOR, Founder, President & CEO - Fable
Padmasree Warrior, the Founder, President, and CEO of Fable, is revolu...
Indian Tech Talent Excelling The Tech World - Dheeraj Pandey, CEO, DevRev
Dheeraj Pandey, Co-founder and CEO at DevRev , has a remarkable journe...