Examining a random sample of the latest Internet of Things ( IoT ) technology products, Kaspersky researchers discovered significant threats to connected homes.
Among the products examined are: a coffee maker that exposes the homeowner's Wi - Fi password , a baby monitor that can fall into the control of a malicious third party, and a smartphone -controlled home security system that can be fooled with a magnet.
In 2014, David Jacoby, a Kaspersky Lab expert, decided to investigate which of his home devices could be vulnerable to a digital attack. In the course of his experiment, he discovered that almost all of them were vulnerable. After that, in 2015, a team from Kaspersky Lab repeated the experiment with one small difference: while David’s research focused mainly on interconnected servers, routers and smart TVs, the latest research focused on the various “smart” devices available on the market.
The devices selected for the experiment were: a USB video streaming device, an IP camera, a coffee maker, and a home security system controlled via smartphone. Kaspersky found that almost all of these devices contained vulnerabilities.
During the experiment, a baby monitor camera allowed a hacker using the same network as the owner to connect to the camera, watch video recorded on it, and run audio functions on the camera itself. Other cameras from the same manufacturer allowed hackers to collect the owners' passwords. The experiment also showed that it was possible for a hacker to retrieve the password from the camera and maliciously alter its firmware.
When it comes to smart coffee makers controlled via apps, it's not even necessary for the hacker to be on the same network as the victim. The coffee maker tested during the experiment sent so much unencrypted information that it was enough for an attacker to discover the password for its owner's Wi-Fi network.
While examining a home security system controlled by a smartphone, Kaspersky Lab researchers found that the system's software had only minor issues and was secure enough to withstand a digital attack. However, a vulnerability was found in one of the sensors used by the system.
The contact sensor, which is designed to trigger the alarm when a door or window is opened, works by detecting a magnetic field emitted by a magnet mounted on the door or window. When the door or window is opened, the magnetic field disappears, causing the sensor to send alarm messages to the system. However, if the magnetic field remains in place, no alarm notifications should be sent.
During the experiment on the home security system, Kaspersky Lab specialists were able to use a simple magnet to replace the magnetic field of the magnet on the window.
This meant they could open and close a window without setting off the alarm. The big problem with this vulnerability is that it is impossible to fix with a software update. The issue lies in the design of the security system itself. What is more worrying is that devices based on magnetic field sensors are a common type of sensor, used in many systems on the market.
“Our experiment showed that most smart device vendors pay attention to cybersecurity when developing IoT products. However, every connected and app-controlled device is almost certain to have at least one security issue. Criminals could exploit several of them. That’s why it’s important to fix all of these issues – even those that aren’t critical. These vulnerabilities should be fixed before a product is released to the market, as it can be much harder to fix a problem when a device has already been sold to thousands of owners,” said Victor Alyushin, Security Researcher at Kaspersky Lab.
To protect their lives and loved ones from the dangers of vulnerabilities in "smart" IoT home devices, consumers should follow the following simple advice from Kaspersky Lab experts:
- Before purchasing any IoT device, search the Internet for news about any vulnerabilities in the device in question. IoT is a hot topic, and many researchers are doing a great job of finding security issues facing these products (from baby monitors to app-controlled guns). It is very likely that the device you are about to purchase has already been examined by security researchers, and it is possible to see whether the issues found in the device have been fixed.
- It's not always a good idea to buy products that have just been released. Along with the typical bugs that often accompany new products, newly launched devices may have security issues that security researchers haven't yet discovered. The best advice in this case is to buy products that have already undergone several software updates.
- When choosing which part of your life to make a little smarter, consider the security risks. If your home is where you store a lot of valuables, it might be a good idea to choose a professional alarm system that can replace or supplement your existing app-controlled home alarm systems. You can also set up your existing system in such a way that potential vulnerabilities don’t affect its operation. When choosing a device that will collect information about your personal and family life (e.g. a baby monitor), it might be wise to choose the simplest wireless model on the market, which is only capable of emitting an audio signal, without connecting to the Internet. If that’s not an option for you, then follow the first tip and choose wisely.
More details are available on the Kaspersky Securelist.com.

