IoT: Imagine you want to give your child a gift and so you decide to buy them an amazing smart-controlled wireless spy vehicle — essentially a spy camera on wheels, connected via Wi-Fi and managed via a mobile app. 
It is truly an amazing gift that allows him to not only drive it, but also take photos, record videos, and even play audio remotely through a built-in speaker.
It was perfect to get you in the holiday spirit, but a few days after purchasing the vehicle, you suddenly started to notice that something was wrong and the vehicle got out of your control. It started moving as if it were obeying someone else's commands, recording videos you didn't want, and losing power inexplicably quickly. How did this happen? Most likely, you bought a fragile and unsafe gift.
Connected smart devices are generally considered a very convenient way to make our lives easier. But how safe are they to use from a cybersecurity perspective? In 2015, Kaspersky Lab researchers decided to examine the severity of the threat behind the Internet of Things (IoT). The results were alarming, so two years later we decided to investigate the issue further. Out of eight randomly selected IoT devices — from a smart iron to a smart spy vehicle — half were at risk due to weak password settings. Moreover, only one device met the researchers’ requirements and proved to be secure.
IoT devices are basically network-connected devices – equipped with embedded technology that allows them to interact with each other or with the outside world. Due to the large number and variety of devices available, IoT has become an attractive target for cybercriminals. This includes, among others, the groundbreaking DDoS attacks of 2016 that were launched with the help of a massive botnet consisting of routers, IP cameras, printers and other devices. From successfully hacked IoT devices, criminals are able to spy on or even blackmail people. Other factors may be even more dangerous. For example, your home network may be used to carry out illegal activities, or a cybercriminal who has gained access to an IoT device could blackmail – and spy on – its owner or steal money from them. The "infected" device can quite easily "break", although it is clear that this is not the worst thing that can happen.
With this in mind, Kaspersky Lab researchers decided to find out if the reports of smart “IoT” products and the various incidents that have occurred have changed the situation. The truth is that they once again analyzed several randomly selected smart devices, including a smart battery charger, an app-controlled toy car, an app-controlled smart scale, a smart vacuum cleaner, a smart iron, a smart watch and a smart home hub. The findings were truly alarming: out of the eight devices tested, only one met the researchers’ security requirements.
Furthermore, half of the devices could be compromised simply due to vendors’ lack of vigilance in password settings. This includes the default password and the inability to change the password, while in some cases the password was even unified across all devices in the product line.
“At Kaspersky Lab, we have been monitoring the issue of smart device security for years. We now see that various reports on smart “IoT” products and increasing levels of vendor vigilance have contributed to a decrease in the volume of insecure smart devices. However, the problem still exists and smart devices can still harm their owners, indicating that there is much more work to be done by cybersecurity companies and connected device vendors,” notes Oleg Zaitsev, security expert at Kaspersky Lab.
Kaspersky Lab researchers advise users to take the following measures to protect themselves from purchasing vulnerable smart devices:
- Before you buy an IoT device, search the Internet for any vulnerabilities. The Internet of Things is a hot topic right now, and many researchers are working hard to find security issues in products like this: from baby monitors to app-controlled guns. It's likely that the device you're about to buy has already been reviewed by security researchers, and it's often possible to see whether the issues found in the device have been patched or not.
- It's not always a good idea to buy the latest products on the market. Along with bugs that are commonly detected in new products, recently introduced devices are more likely to contain security issues that researchers haven't yet discovered. The best option is to buy products that have already undergone several software updates.
- When choosing which part of your life to make a little smarter, consider the security risks. If your home is where you store a lot of valuables, it would probably be a good idea to install a professional alarm system that can replace or supplement your existing app-controlled home alarm system. Or, you could set up your existing system in such a way that any potential vulnerabilities don't affect its operation.
To overcome the threats, Kaspersky Lab has released a beta version of its solution for the “smart” home and the Internet of Things – Kaspersky IoT Scanner. This free application for the Android platform scans the home Wi-Fi network, informing the user about the connected devices and the level of security.
You can find more information about smart devices on the dedicated website Securelist.com
