HomeSecurity Securitygaps in home security systems and Smart coffee makers

Security gaps in home security systems and Smart coffee makers

Kaspersky security researchers have decided to take a look at IoT devices and their lack of security measures. The results of their experiment, once again, confirm that Internet of Things devices still lack proper security measures even today, after so many years during which many cybersecurity vendors have been complaining about their vulnerabilities.

Security gaps in home security systems and Smart coffee makers

In their latest experiment, Kaspersky selected four random IoT devices and carefully analyzed them for any security vulnerabilities. The results are a bit worrying given that all the flaws can be linked together and provide criminals with an attack script that they can follow to gain access to so-called “smart-homes.”.

Google Chromecast (USB TV dongle for video streaming)

The first step for such attacks can occur when exploiting the infamous “rickrolling” vulnerability in Google Chromecast that allows attackers to influence the content displayed on a smart TV.

This can be useful for displaying error messages that trick the user into believing they need to change their Wi-Fi or reset their local wireless router to factory settings, which can be easily exploited by attackers.

Smart coffee maker (controlled via a smartphone app)

Kaspersky researchers also identified a smart coffee shop that can expose a user's Wi-Fi password.

Kaspersky declined to name the make and model of the coffee machine, given that the vulnerability has not yet been patched.

As you can imagine, a target's Wi-Fi password can give criminals access to all of a person's IoT devices, since they all work and use the home Wi-Fi network

IP camera (used in baby cameras and monitors)

In Kaspersky's scenario, by exploiting the access the coffee maker gave the attackers, exposing the Wi-Fi password , they can then spy on the homeowners and see when they leave their home.

Criminals can do this by connecting to the local camera IP, if available, but also to baby monitoring devices.

Home security systems

Once criminals know that the homeowner is not home, they can exploit a fourth security issue discovered by Kaspersky staff in an unnamed home security system.

While the researchers were pleased to find that the home security system was very well protected from software attacks, they couldn't say the same for the hardware.

Apparently, there is a way to fool the two sensors, contact and motion, used by the system. Researchers found that by using a very strong magnet, intruders could open doors and windows without activating the alarm.

Additionally, since motion detection sensors only work with “warm” objects, putting on some clothing that hid the criminal’s body heat was enough to silence the sensors.

All that's needed now are criminals who know what to look for.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS