HomeSecuritySamsung's smart refrigerator vulnerable! - Gmail Credentials at risk

The Samsung smart fridge is vulnerable! - Gmail credentials at risk

A recent update from a team of researchers identified a potential risk to the Gmail credentials of Samsung Smart Fridge users .

The Samsung smart fridge is vulnerable! - Gmail credentials at risk

A 'Man in the Middle' (MiTM) vulnerability was discovered during an IoT (Internet of Things) hacking challenge at the recent DEF CON conference. The Samsung RF28HMELBSR smart refrigerator was targeted to confirm the possible compromise of Gmail account credentials. The refrigerator, which implements SSL, encountered a problem in validating SSL certificates, thus giving rise to MiTM vulnerabilities. The internet-connected device has the ability to automatically download Google calendar on an interface screen, and the MiTM vulnerability makes it easy for a hacker to "jump" onto the same network and steal the Gmail credentials of its neighbors. 

Mr. Ken Munro, a security researcher at Pen Test Partners, said that “The internet-connected refrigerator was designed to display Gmail Calendar information on its screen,” and that it “appears to work in the same way as any machine running Gmail calendar. A logged-in user or the calendar owner updates the calendar, and updates are visible from any device that can display the calendar,” he added.

While the research team failed to breach the refrigerator's software update server and terminal during the DEF CON hacking spree, the mobile app showed signs of potential security issues.
The code in the mobile app includes a certificate that allows for the encryption of credentials between the refrigerator and the mobile app. The certificate is properly encoded, but the certificate's credential appears to be stored in the mobile app in an obfuscated form. So, if the certificate codes are cracked, it would allow a hacker to send commands to the refrigerator.

Pedro Venda of Pen Test Partners emphasized that “We wanted to pull the terminal out of the refrigerator to have physical access to things like a USB port, or a serial port, or the JTAG interfaces, but we ran out of time. However, we still found some interesting bugs that are definitely worth further investigation. MiTM alone is enough to expose a user’s Gmail creds.”

This fiasco has created a tense atmosphere at Samsung headquarters. In a public statement, the company assured that “At Samsung, we understand that our success depends on our consumers’ trust in us as a company, and in the products and services we provide. We are investigating this matter. Protecting our consumers’ privacy is our top priority, and we work hard every day to keep our valued Samsung users safe.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS