Why You Should Be Really Careful With Smart Home Gadgets
Why You Should Be Really Careful With Smart Home Gadgets
Do the designers even care about security?
Owners of woke up to a Hollywood-style nightmare earlier this week when a breach exposed their in-home cameras to anyone on the internet. How can we be better protected?
https://pixarplanet.com/forums/viewtopic.php?f=18&t=421386&p=1048637#p1048637
A software update caused the breach, and it was fixed after an hour. But during that time, they had as well as recorded video. The breach also granted full account access, meaning anyone could pan and tilt strangers’ cameras to get a good look around their homes. This highlights the problems inherent in all smart home gadgets.
https://forum-auto.caradisiac.com/topic/468191-sandero-3-sce-65-sur-lautoroute/#replyForm
"As we bring more technology into the home, cyber criminals will increasingly turn their attention to these new systems," Ben , told via email. "This increased scrutiny from criminals will inevitably result in an increasing number of attacks, and no law or regulation will be able to stymie it. To solve that problem, we must find new and innovative ways to both secure systems and deter criminal activity."
http://www.reo14.moe.go.th/phpBB3/viewtopic.php?f=6&t=578613&p=1451477#p1451477
Insecure By Design
In a statement provided to Lifewire by Eufy-maker Anker, a software update caused the bug, which affected 712 users and was fixed in under two hours.
The underlying problems remain, though. Internet-of-Things devices, as these smart home gadgets are classified, are not designed to be secure.
"Currently, IoT devices are often not built with security front-of-mind," Dan Tyrrell of penetration testing company Cobalt.io told Lifewire via email. The problem is designers and vendors are more interested in features than security.
"The IoT market is constantly innovating with new and established companies bringing products and solutions to the market at a break-neck pace," says Dynkin. "This means that for companies to succeed in the space, they must innovate quickly and try to edge out their competitors, which means, inevitably, that security will be treated as a secondary consideration, rather than a core tenet of the product. This leads to ubiquitous vulnerabilities that can be exploited."
Interestingly, people who connected their Eufy cameras only using Apple’s HomeKit Secure Video were not affected by this breach, which shows that a security-first approach is possible.
Regulation
These breaches won’t stop until security becomes at least as important as features, and that won’t happen until somebody forces smart home vendors to take it seriously. One answer is government regulation, like we have for keeping our food safe, and EU cell phone roaming cheap. Regulation would force minimum standards on vendors, and punish them for breaches.
"Regulation is not necessarily the silver bullet in making sure IoT devices are secure," says Tyrrell. "Instead, we should look at regulation as a step in the right direction. I would caution that being compliant with a regulatory standard is not the same as being secure, but it is better than nothing."
"To solve that problem, we must find new and innovative ways to both secure systems and deter criminal activity."
Others are opposed to regulation entirely. Paul Engel, founder of The Constitution Study, sums up this attitude.
"The last thing we need is more government interference," Engel told Lifewire via email. "A few expensive lawsuits and insurance payouts would do more to push these companies to better their security than any legislation could."
Comments
Post a Comment