Help, the smart devices are attacking!
Help, the smart devices are attacking!

Help, the smart devices are attacking!

Our homes are increasingly filled with smart devices connected via Wi-Fi. This Internet of Things makes life much easier for the occupants, but it also poses a potential danger. The reason is that the security level of these devices varies enormously. ‘People are notoriously bad at coming up with unique passwords.’

Lights that you turn on with a single click in an app, a fridge that keeps track of whether you’ve run out of milk, and a coffee machine that has your morning coffee ready when you wake up. Our homes are getting smarter and smarter. Jules Dudok, Project Manager at the Science Center in Delft, knows all about it. His husband, who works as a software engineer, has fitted their entire house with smart gadgets. “In fact, everything in our house is smart: it starts with the curtains opening automatically and windows and doors being equipped with sensors so you know if they’re open, and the heating and ventilation also work automatically.”

All of which is really useful, says Dudok. “We have solar panels on the roof, so we try to match all our appliances to their yield.” For example, the washing machine automatically turns on when the yield is highest, and there are smart boxes between all plugs and sockets that measure energy consumption. Besides an astonishingly low energy bill, Dudok says this is very user-friendly: “The ultimate goal is that the system really starts thinking for you, and that you no longer have to perform any actions yourself.”

All these smart devices communicate with each other via the user's Wi-Fi network. This is known as the Internet of Things (IoT), and it has become tremendously popular in recent years. The fact that your curtains open automatically in the morning, or that you can remotely check whether you really turned off the oven does indeed have its advantages, but among IT experts, concerns about the security of all these smart devices have also been growing. Mattis van 't Schip, a PhD candidate at Radboud University who focuses mainly on the legal aspects of cyber security, sees alarming sides to this rapid development. “Meanwhile, more than three quarters of Dutch citizens already have a smart device at home. There are more and more of them, but the security level on these devices varies enormously.” Something that according to Van 't Schip is mainly due to the incredibly fast development of this market. “Regulations always lag behind reality; cyber security requirements from the EU are limited. We're really starting to see the effect of this now.” 

Online army

But what's the big danger? “Smart devices are really just small computers connected to the internet. Any computer can be hacked, and so can any smart device,” explains ethical hacker Sijmen Ruwhof. “Once the computer in your fridge or smart doorbell is hacked, a hacker can deploy it in a so-called DDoS attack, where tens of thousands of hacked devices simultaneously make an information request to a server. Most servers cannot handle so many requests, causing an outage. For example, if the server in question is used to host the central government's website, such a failure will render the site inoperable. That can have very unpleasant consequences.”

In 2016, for example, a malware was discovered that made it possible to hack smart devices running on the Linux operating system. The hackers who developed this malware, called Mirai, initially targeted servers of the online game Minecraft, but later the malware was also used to attack provider Dyn. This left users in large parts of North America and Europe without access to the internet.

In principle, the users of the smart devices used in such a DDoS attack need not even notice, says Ruwhof. “As long as your smart fridge keeps working, you won't know that you’re suddenly part of an online army.”

Smart devices are fairly easy to hack due to two fundamental problems, Ruwhof argues. “First of all, for many manufacturers, it is not at all advantageous to keep supporting a smart product for 10 years with software updates for security breaches, for example.” After all, manufacturers don't want users to use a device for too long; they much prefer it if you buy another one as soon as possible. In addition, Ruwhof notes that developing secure software takes a lot of time and money, and that it is not a priority for every producer. “You can really see huge differences in this respect, for example, between a higher and more expensive price range of smart camera and a similar product from, say, Action.”

Bad passwords

The second problem lies with the users themselves. Many users are unaware of how easy it is to hack a smart device. Ruwhof: “Many people think it's plug-and-play: you plug in your camera, enter your password, and it's done.” But that is precisely where the weakness lies. “People are notoriously bad at devising unique passwords and they have dozens of accounts for which they have to create passwords. What you often see is that people recycle or use the same passwords for multiple accounts.” Lists of billions of usernames and password combinations circulate on the internet, and are used to hack smart devices. These lists come from corporate data breaches. If a user uses the same password for several online accounts and multiple devices, it is a breeze for a hacker to write software that tries these passwords in an automated way, until a device is hacked.

User Dudok is aware of these dangers. “My husband and I are both engineers, so we approached this as safely as possible. For example, our home network was connected by a friend who is a network installer.” But he acknowledges that this is not an option for everyone. “Our network is actually a corporate network, with multiple layers. This is very complex and not easy to set up.” Personally, he is not worried that his smart devices will be hacked. “But a regular home Wi-Fi system can be cracked very easily with a little knowledge. That is also the reason why we took such a professional approach. People often do not realise the danger they are bringing into their homes. Everyone talks about privacy, but not everyone runs software updates.”

The Wild West

Although the European Commission is now taking steps towards improved legislation – the latest version is expected in 2024 – this will not solve the problems, says Van 't Schip. “A major problem is monitoring and enforcement. Just about all sectors are facing a shortage of IT specialists and the government is no exception. There is simply too little money and manpower to adequately address this problem.” Ruwhof agrees: “The internet is really the new Wild West. We are pioneering new technology, and entrepreneurs are seeing product opportunities, but everyone just has to fend for themselves. Many consumers have no idea how to do that and what the dangers are.”

A user may not notice a DDoS attack, but devices like smart cameras and doorbells also pose a personal risk. What can users do to improve security? Ruwhof does have some tips: “Change the default password to a unique personal password, and don't use the same password for all your devices.” In addition, he says, it is also important to keep running security updates regularly, even if this seems a bit nonsensical for something like a washing machine. “Once hackers have access to one of your smart devices, they have access to your entire home network, and then you're in trouble.” Finally, he wants to emphasise that, above all, users should be aware of what they are bringing into their homes. “Find out about the technology behind the device, or ask someone knowledgeable to take a look. Don't blindly assume that producers will keep you safe.”

Breaches

Companies are being hacked on a daily basis because they do not invest enough in cyber security or are not sufficiently aware of the risks. In such data breaches, hackers get hold of lists containing tens of thousands of combinations of usernames, email addresses, and passwords, which they resell or post on the internet. “If a hacker then wants to break specifically into your home, they only need your email address, which can often be found on social media. There is a pretty good chance that a password linked to that mail address will have been leaked somewhere. With this information, there is a real chance that a hacker could use your Amazon account to control your speaker, for example. If this speaker also has a microphone, the negative consequences are endless,” Ruwhof said.

Another way to hack devices is by exploiting the security vulnerabilities in a device’s system. Certain devices, such as smart cameras, have the option of being viewable from anywhere in the world via the internet. For users, this is great because it allows them to check their home remotely. But it also poses a risk. “If the software of such a camera is not updated regularly, it becomes a target for automated attacks,” Ruwhof argues. “Many camera systems are serviced only rarely. A hacker can write a piece of code to exploit such a leak, and then look for camera systems that still have that leak.”

Worth a lot of money

Hacked devices in the Internet of Things are worth a lot of money. If a hacker controls millions of such devices, they can run a DDoS attack. This also gives the hacker access to someone's internal network – which can be either a private or corporate network. For example, if a municipality has a Sonos speaker and it gets hacked, a hacker could also gain access to that municipality's internal network, which in turn could be used as a springboard for other hackers specialising in ransom viruses.

Finally, hacked devices can also be deployed as a so-called troll army. Social media websites use algorithms to determine whether the website is being spammed or not. If a lot of responses come from one connection, the website recognises it as spam. But by deploying an army of hacked devices, you trick the website into thinking the comments are coming from a lot of different countries, and that this is legitimate.

This is a translation of an article written in Dutch by Larissa van Dijk and appeared earlier on Kennislink. Photo: Lilly Rum via Unplash.

Contact information

Theme
Artificial intelligence (AI), Innovation