HomeSecurity4 more IoT devices hacked. They seem more insecure than ever!

Other 4 IoT devices were hacked. They appear more insecure than ever!

During the two-month hackathon in September and October 2015, security researchers from Bitdefender found vulnerabilities in four new IoT devices, only one of which has been partially patched after the developer was updated.

4 more IoT devices hacked. They seem more insecure than ever!

Researchers found the first problem in the WeMo Switch, an internet-accessible switch that allows users to turn electronic devices in their home on and off.

This device used (and still does) an insecure communications channel between the switch and the smartphone that lacks any authentication. Everything is transmitted in plain text except for the device passcode, which is encrypted with an easily breakable 128-bit AES algorithm, using an encryption key derived from the device ID and its MAC address.

The second IoT device tested was the Lifx Bulb, a Nest-compatible smart LED system that allows users to adjust the color and intensity of their home lighting system via an Android app.

This device has a design vulnerability that allows an external attacker to intercept a user's home WiFi network credentials by forcing the user's Android app to reconnect to their home network. The attacker can create a fake hotspot and then intercept the user's WiFi connection credentials.

The same issue affects the LinkHub starter kit, which includes two GE Link bulbs and a management hub, both controlled via an Android app. By applying the attack technique described above and because the device does not use encryption, sending network packets in plain text, an attacker can grab WiFi credentials in a short time and without any significant effort.

Last on the list and the only device to receive a (partial) fix is ​​the MUZO Cobblestone Wi-Fi Audio Receiver, which allows users to stream music from their devices to a local audio system.

Bitdefender researchers discovered that the device was creating a persistent open hotspot, which could be brute-forced and through which an attacker could extract the WiFi password for the local WiFi network.

An attacker with access to the local WiFi network can monitor the user's traffic, following their browsing habits, grabbing authentication credentials for other insecure services, or even "infecting" the user's data with malware.

“This research shows us the urgent need to integrate a proper security architecture into the device lifecycle,” concludes the Bitdefender team after their research. “The IoT (Internet of Things) opens up a whole new dimension in the field of security […]. If the predictions of a hyper-connected world become reality and manufacturers do not introduce the concept of security into their products, the consequences could be terrifying for people’s lives.”

The report The Internet of Things: Risks in the Connected Home is available for download via the Bitdefender website.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS