Security researchers at Pen Test Partners have found a security vulnerability in the iKettle Wi-Fi Electric Kettle that allows attackers to crack the password of the WiFi network to which the kettle is connected.
The iKettle is a new-age electronic device that manufacturers are mocking as IoT (Internet of Things) devices.
The kettle, in addition to boiling water, can connect to the user's home WiFi and comes with an Android and iOS app that allows the user to turn on the kettle and boil water from another room or area. This means that the kettle stores the password of the user's local WiFi network, somewhere in its settings.
Specifically, the research was conducted this summer as part of Pen Test Partners' initiative to find and disclose security vulnerabilities in IoT devices and was documented in detail on their site.
[su_youtube url=”https://www.youtube.com/watch?v=GDy9Nvcw4O4″ width=”740″]
To summarize their findings, attackers could easily use an antenna aimed at a home where an iKettle is being used, force the kettle to leave its existing Wi-Fi network by spoofing the original network's SSID, and trick the iKettle into connecting to the attacker's network using the password for the original WiFi.
The researchers say that using this simple trick and information about iKettles they got from wigle.net and Twitter, they drove around London, hacked into home WiFi networks, and created a map of insecure Wi-Fi across the city. For security and privacy reasons, they said they won't reveal that map.
Additionally, researchers found that the smartphone app that controls the iKettle's behavior uses the insecure Telnet protocol to relay commands to the device.
Both apps use a PIN to verify the kettle's user identity, but both are easy to hack within a few hours, the researchers found. However, the iOS app is more secure because it uses a 6-digit PIN ,but the Android app only uses a 4-digit code.

