Investigating some of the latest IoT (Internet of Things) products, Kaspersky Lab researchers have discovered serious threats to homes connected to these products – including devices like coffee makers that expose their Wi-Fi password, baby monitors that can be controlled by third parties, and a smartphone-controlled security system that can be fooled by a…magnet!
The well-known company's research into homes connected to IoT discovered that almost all of the devices tested contained vulnerabilities.
The baby monitoring camera used in the experiment could allow a potential attacker using the same network as the camera's owner to connect to it and watch the recorded video or take their own. Other cameras from the same vendor allow the ability to collect the owner's passwords, and as the experiments showed, it was possible for someone on the same network to recover the camera's root password and maliciously modify its firmware.
During the investigation into app-controlled coffee makers, it was discovered that it wasn't even necessary for the attacker to be on the same network as the victim. The coffee maker was sending enough unencrypted information for an attacker to figure out the password for its owner's entire Wi-Fi network.
On the other hand, Kaspersky Lab researchers found that the smartphone-controlled home security system had minor issues but was safe enough to withstand a cyber-attack, but the vulnerability was found in one of its sensors.
The sensor used, designed to disable the alarm when a window or door is opened, works by detecting a magnetic field emitted by a magnet placed on the door or window. During the experiment on this IoT product , Kaspersky Lab experts were able to replace the magnetic field with a simple magnet, which allowed them to open and close the windows without first disabling the alarm. It should be noted that this vulnerability cannot be fixed with a software update…
Kaspersky Lab suggests that before rushing to buy an IoT device , homeowners should thoroughly check it for any security vulnerabilities that have been reported online . They should also avoid the temptation to buy products that have just been released on the market and have not yet been peer-reviewed or empirically tested.
