'Smart' homes open doors to hackers

Jul 30, 2013
A damaged garage door is visible at a house, on August 16, 2011, in Buckner, Kentucky. Smart homes that let residents control alarms, locks and more over the internet are opening doors for crooks with hacker skills, according to computer security specialists.

Smart homes that let residents control alarms, locks and more over the internet are opening doors for crooks with hacker skills, according to computer security specialists.

"The trend is growing, and it evolves quickly into a story of security," Trustwave managing consultant Daniel Crowley told AFP.

"Connecting things to a network opens up a whole range of vectors of attack, and when you are talking door locks, garage doors, and alarm controls it gets scary."

Crowley and Trustwave colleague David Bryan found security "pretty poor" on the devices they studied.

"If someone can access your home network, but doesn't have a key to your home, they can still unlock your door and get in," Crowley said of what he found in gear on the market.

Trustwave researchers will share their findings Thursday with peers at a premier Black Hat security conference in Las Vegas and at the infamous Def Con hacker gathering taking place in that city through the weekend.

A vulnerability of particular concern to the researchers was that once hackers joined local home networks, perhaps through poorly protected wireless routers or using malware slipped onto computers, they could control devices with no password or other authentication required.

"The fact that you need to be on someone's to exploit these things is not as big a hurdle as you'd imagine," Crowley said.

And the trend of providing people with smartphone applications for controlling smart home devices while away means that crooks who hack into handsets could potentially grab the reins, according to the researchers.

There are also ways to use computer "IP" numbers to figure out real-world addresses, and some smart home applications, themselves, reveal location information, according to Trustwave.

Combing that capability with hacking tools could put an Internet age twist on home burglaries, the researchers said.

"I don't think this will be something that enables the ordinary criminal to do something they weren't doing before," Crowley said.

"The big risk is that a compromise could give you access to hundreds of thousands of homes all at once; I could see that as an attack someone could actually use to launch a crime spree."

Explore further: The ethics of driverless cars

add to favorites email to friend print save as pdf

Related Stories

Next up: Smart homes

May 28, 2012

You've got a smartphone and maybe a smart TV, and may have heard that smart refrigerators are in the works. Next up: the smart home.

Computer hackers and defenders mix in Las Vegas

Jul 24, 2012

Rival factions from the Internet security world will mix warily this week at a pair of Las Vegas conferences gathering computer security experts and software savants who make sport of hacking them.

Smart home security device gets even smarter over time

Jul 28, 2013

Wouldn't it be nice to have an intelligent home system you can control from your phone? A system that is smart enough to know what is normal? A system that averts false alarms that fray the nerves of responders? ...

Recommended for you

The ethics of driverless cars

11 minutes ago

Jason Millar, a PhD Candidate in the Department of Philosophy, spends a lot of time thinking about driverless cars. Though you aren't likely to be able to buy them for 10 years, he says there are a number ...

We need new laws to govern cyberwarfare

31 minutes ago

President Bush is reported to have said: "When I take action, I'm not going to fire a US$2m missile at a US$10 empty tent and hit a camel in the butt. It's going to be decisive." As the quote suggests, when ...

Ticketfly buying WillCall for on-premise data

1 hour ago

Ticketfly Inc., a San Francisco-based technology company among several posing a challenge to Ticketmaster, is acquiring WillCall Inc., a crosstown rival that turns your smartphone into a mobile wallet at live events.

Voice, image give clues in hunt for Foley's killer

2 hours ago

Police and intelligence services are using image analysis and voice-recognition software, studying social media postings and seeking human tips as they scramble to identify the militant recorded on a video ...

Smartphone-loss anxiety disorder

2 hours ago

The smart phone has changed our behavior, sometimes for the better as we are now able to connect and engage with many more people than ever before, sometimes for the worse in that we may have become over-reliant on the connectivity ...

User comments : 1

Adjust slider to filter visible comments by rank

Display comments: newest first

antialias_physorg
not rated yet Jul 31, 2013
"The big risk is that a compromise could give you access to hundreds of thousands of homes all at once; I could see that as an attack someone could actually use to launch a crime spree."

Not so much a crime spree as a sort of centralized 'burglary service' that finds/unlocks homes and defuses local security measures for others to exploit (for a fee). In that way even the ordinary criminal can 'profit' from such methods.

And of course the NSA (and other secret service outfits) just love this.

When are people going to learn that the only unbreakable security is a one-time-pad based one? It's not THAT hard to implement (to be precise: it's one of the easiest encryption schemes to implement). And with the limited information sent/received by home systems it's actually quite feasible.