After years of marketing hype, it seems the much-heralded Internet of Things (or IoT to those in the know) has finally arrived. From washing machines and heating systems that can be controlled from your smartphone, to doorbells that learn to recognise regular visitors and broadcast suspicious activity, more and more of us are upgrading our homes with internet-enabled devices. But have we stopped to think about the cybersecurity of this new technology?
One expert isnt convinced weve thought it through. Mikko Hypponen is chief research officer for the Finnish digital security company F-Secure. Having observed the rise in IoT devices, hes coined a new maxim to alert consumers to their potential dangers: if its smart, he says, its also vulnerable. Its a pessimistic rule, he tells me during a stopover in London ahead of an industry speaking gig but its a true one too: the more connectivity we add to our homes, the more vulnerability we create.
The big risks for IoT devices fall into two broad categories, he explains both of which are already being exploited by cyber-criminals. The first and more obvious vulnerability is that smart devices might serve as a backdoor into our home networks, allowing hackers easier access to our laptops and smartphones and all the valuable information (from passwords to credit cards) that entails. In cybersecurity circles, the examples are already becoming legendary: like the Las Vegas casino that reportedly had its high-rollers database stolen by hackers who entered the network via a smart fist-tank.
Smart devices like fridges and doorbell cameras are typically the weakest link in your home network, Hypponen says. Its a problem compounded by the fact that buyers are rarely encouraged to take even the most basic of safety precautions such as changing the devices password from its default setting. Along with other new technologies (in particular cryptocurrencies like Bitcoin that allow for untraceable payments) its led to a spike in ransomware attacks, where hackers render computers useless until the user sends them a large sum of money. One of the most famous ransomware viruses was the Wannacry malware, which infected NHS computers in 2017 apparently at the instruction of North Korea.
So what can owners do to protect their own devices and their wider home networks against attack? One obvious step, according to F-Secure, is to ensure your WiFi network is as secure as possible. That means changing its name (thus making it difficult for hackers to identify its make and model and, from there, its security flaws), using WPA2 encryption, and ensuring you use a secure password. As for IoT devices themselves, owners should be sure to change the default password and also look at disabling certain features like Universal Plug and Play which make it easier for hackers to exploit their vulnerabilities.
While ransomware attacks are on the rise, Hypponen is also interested in a newer form of cyber-crime which targets the next wave of smaller IoT devices like toasters and hairdryers which connect directly to the internet using 5G. Hang on a minute, I ask. Who needs an internet-enabled toaster? Well, no-one, admits Hypponen. Yet he simultaneously predicts that, as internet-connectivity becomes cheaper and cheaper, it will soon be impossible to buy toasters that dont connect to the internet.
How so? The reason is that toasters arent going online to provide new functionalities to the customer: instead theyll be providing manufacturers with real-time data on exactly how the device is being used. This kind of mass data is extremely valuable to manufacturers, allowing them to continuously improve their products, but it also makes devices vulnerable to cyber attack particularly given many use only the most basic encryption and dont always allow users to change their settings. In the past year, Hyponnen says, hes seen more cyber attacks on IoT devices than Windows computers.
Given these devices arent usually connected to your home network (they access the internet directly through tiny 5G chips), the aim isnt to get hold of your personal data. Hackers want to recruit your devices into their botnets vast swarms of captive IT addresses that can be used to attack internet servers by sending an overwhelming flood of nonsensical data. In 2016, millions of such devices across the world were harvested in the Mirai botnet, which managed to take down websites from Twitter to the BBC, and Spotify to FoxNews. It remains one of the largest cyber-attacks of recent history.
So whats the solution? Hypponen says that industry has been slow to act partly because consumers dont suffer directly if their devices are targeted. During the Mirai attack, I called one office because we could see that a heat pump in their network was part of the botnet, he says. I asked them do you own this particular model of pump? Well are you aware its being used to help take down half of the internet right now?. He says that the company was fascinated to hear about the botnet, but werent particularly motivated to spend their own money to secure their devices. Of course many more wont even know the breach has taken place: a study by the Dutch digital security firm Gemalto found that less than half of businesses were able to identify when an IoT device had been hacked.
Hypponen contrasts the approach taken by both government and industry to cybersecurity with the more established approach to consumer safety. If you buy a washing machine, you can be certain its not going to catch fire or give you an electric shock as we certify those things, he says. But theres no regulation at all on whether the machine might end up revealing your WiFi password to hackers. Though that might be changing: the UK government has begun consulting with experts and industry on how to develop appropriate safeguards, while Finland has just become the first country to introduce a government-backed quality stamp for those products which meet basic cybersecurity standards.
With around a quarter of British homes already using smart devices and another 40 per cent saying they would consider buying one in the next five years its an issue which wont be going away any time soon. Something to keep in mind when youre eyeing up your new toaster.
- Russian Security Hacking the 'Internet of Things' - Byline Times - April 2nd, 2020
- Unpacking TikTok, Mobile Apps and National Security Risks - Lawfare - April 2nd, 2020
- CDN and cloud suppliers join routing security initiative - ComputerWeekly.com - April 2nd, 2020
- Setting up home-based office solutions busy business for Cape Breton company - The Telegram - April 2nd, 2020
- Society's Dependence on the Internet: 5 Cyber Issues the Coronavirus Lays Bare - Nextgov - April 2nd, 2020
- Open Source Code - The Future of User Privacy - Privacy News Online - April 2nd, 2020
- GLOBAL INTERNET SECURITY FIREWALL MARKET LATEST DEVELOPMENTS, SHARES, AND STRATEGIES EMPLOYED BY THE MAJOR PLAYERS - The Fuel Fox - March 30th, 2020
- Coronavirus Proves We Need the Internet Now More than Ever Before - The National Interest - March 30th, 2020
- The story behind that little padlock in your browser - Horizon magazine - March 30th, 2020
- Finder helps secure the Internet in a time of crisis - CMO - March 30th, 2020
- New Security Report from WatchGuard Shows Explosion in Evasive Malware - socPub - March 30th, 2020
- One senator wants vendors to ensure their internet connectivity devices are secure - fifthdomain.com - March 30th, 2020
- How a VPN works - The Upcoming - March 30th, 2020
- Cryptocurrency Wallets: Everything You Ever Wanted To Know - hackernoon.com - March 30th, 2020
- Sentrybay and Raqmiyat on delivering secure work from home solutions - Tahawul Tech - March 30th, 2020
- Dot-com price rises on their way over the next four years: ICANN approves Verisign contract, walks off with $20m - The Register - March 30th, 2020
- Global Internet Security Market Overview By Threats, Major Opportunities, Drivers, Risk Analysis and Trends - Sound On Sound Fest - March 30th, 2020
- These are the companies offering free software during the coronavirus crisis - IT PRO - March 30th, 2020
- The real insider threat is the use of security software - TechRadar - March 23rd, 2020
- EFF and COVID-19: Protecting Openness, Security, and Civil Liberties - EFF - March 23rd, 2020
- Preparing for November's election must be a national priority | TheHill - The Hill - March 23rd, 2020
- COVID-19 decoy doc, Cloudflare tools used to spread Blackwater malware - SC Magazine - March 23rd, 2020
- Technology saves the day as Kenyan firms send staff to work from home - The East African - March 23rd, 2020
- In Industrial Realm, Trustworthy Software Ensures - IoT World Today - March 23rd, 2020
- Security Software in Telecom Market is Growing Rapidly Due to Increasing Internet Penetration - Press Release - Digital Journal - March 23rd, 2020
- How safe is your brand in the hands of a remote workforce? - Bizcommunity.com - March 23rd, 2020
- Do Netflix And YouTube Really Need To Slash Video Quality To Save The Internet? - Forbes - March 23rd, 2020
- How Organizations Can Retain Talent Amidst the Infosec Skills Gap - tripwire.com - March 23rd, 2020
- Hackers are preying on fears of Covid-19, says cyber security experts - Hindustan Times - March 23rd, 2020
- These Jaw-Dropping Facts Will Change Your Mind About the Internet of Things - The Motley Fool - March 23rd, 2020
- Security Think Tank: Amid panic, how to find a sound level of security - ComputerWeekly.com - March 23rd, 2020
- As universities shut their doors, international students are left in limbo - The Verge - March 23rd, 2020
- Keeping content safe in the IP era | Industry Trends - IBC365 - March 23rd, 2020
- Students concerned with lack of internet access, job security in light of online transition - University of Virginia The Cavalier Daily - March 23rd, 2020
- How Safe is Your Brand in the Hands of a Remote Workforce? - Techfinancials.co.za - March 23rd, 2020
- US Bureau of Census : PRESS RELEASE | MARCH 20, 2020 Statement on 2020 Census Internet Response Security Precautions To protect the integrity of the... - March 23rd, 2020
- Fake coronavirus news is spreading faster than the virus - The Star Online - March 23rd, 2020
- Facebook didnt have to be this way - BusinessLine - March 23rd, 2020
- How Are Digital Natives Shaping the Future of Data Privacy? - Infosecurity Magazine - March 23rd, 2020
- Zero Trust Internet is the Answer - Infosecurity Magazine - March 23rd, 2020
- German government prepares for internet censorship and deployment of the armed forces - World Socialist Web Site - March 23rd, 2020
- Internet of Things (IoT) Security Technology Market Is Expected To Thrive At Impressive Cagr By 2027 Key Players:... - March 23rd, 2020
- Norton Secure VPN - The cocoon of cybersecurity - Blasting News United States - March 13th, 2020
- New rules proposed to boost security of home routers - The Straits Times - March 13th, 2020
- Leaders should act now to counter national security threat to US elections | TheHill - The Hill - March 13th, 2020
- Cybersecurity 2020: The Trends SMBs will Need to Prepare For - CISO MAG - March 13th, 2020
- Namecheap, EFF and the Dangerous Internet Wild West - CircleID - March 13th, 2020
- EARN IT Act threatens end-to-end encryption - Naked Security - March 13th, 2020
- Apples WWDC 2020 is on in a purely digital way - Pickr - March 13th, 2020
- The EARN IT Bill Is the Government's Plan to Scan Every Message Online - EFF - March 13th, 2020
- The pitfalls of being an influencer: What parents should know and do - We Live Security - March 13th, 2020
- 25 tips for navigating the internet today - Alton Telegraph - March 13th, 2020
- Interos Raises $17.5M from Venrock and Kleiner Perkins to Grow Third-Party Risk Management Platform - GlobeNewswire - March 13th, 2020
- Why Are Internet Security Standards Badly Deployed and What to Do About It? - CircleID - March 12th, 2020
- The Internet of Things is a security nightmare reveals latest real-world analysis: unencrypted traffic, network crossover, vulnerable OSes - The... - March 12th, 2020
- How The Internet Of Things Can Transform Workplace Safety | Baird Capital | Security News - SecurityInformed - March 12th, 2020
- The Internet Avoided a Minor Disaster Last Week - WIRED - March 12th, 2020
- Applying the 80/20 rule to cloud security - Help Net Security - March 12th, 2020
- Internet Security Audit Market Report 2020: Acute Analysis of Global Demand and Supply 2025 with Major Key Player: Symantec, Intel Security, IBM,... - March 12th, 2020
- The Hidden Dangers of China's Digital Silk Road - The National Interest - March 12th, 2020
- Students Showed Trend Micro a World Without the Internet - Business Wire - March 12th, 2020
- Android anti-virus products put to the test which are the best at stopping new malicious apps? - Graham Cluley Security News - March 12th, 2020
- Internet security Market 2020 | Applications, Challenges, Growth, Shares, Trends and Forecast To 2026 - Packaging News 24 - March 5th, 2020
- Eight ways to improve cyber-hygiene in the enterprise - Security Boulevard - March 5th, 2020
- The Top 8 Concerns for CISOs in 2020 - Security Boulevard - March 5th, 2020
- iboss Wins Customer Service Department of the Year - Computer Services Silver Award in the 2020 Stevie Awards for Sales and Customer Service - Yahoo... - March 5th, 2020
- 2020 Premium Ethical Hacking Certification Bundle Is Up For A Limited Time Discount Offer Avail Now - Wccftech - March 5th, 2020
- These are the first passwords hackers will try when attacking your device - ZDNet - March 5th, 2020
- US threatens to pull big techs immunities if child abuse isnt curbed - TechCrunch - March 5th, 2020
- Why SSL Encryption Will not Become a Victim of its Own Success - Infosecurity Magazine - March 5th, 2020
- Let's Encrypt: OK, maybe nuking three million HTTPS certs at once was a tad ambitious. Let's take time out - The Register - March 5th, 2020
- Modernizing Threat Management for the Evolving Attack Surfaces of OT, IoT and IoMT - Security Intelligence - March 5th, 2020
- Global Internet Security Audit Market Analysis, Key Insights, and Forecast 2025 By Application, Type, End User and Region - Feed Road - March 5th, 2020
- It has been 15 years, and we're still reporting homograph attacks web domains that stealthily use non-Latin characters to appear legit - The Register - March 5th, 2020
- WhatsApp Provides Information to Intelligence Services - What is the Safest Messenger? - Communal News - March 5th, 2020
- Dear passwords: Forget you. Here's what is going to protect us instead - USA TODAY - March 3rd, 2020
- Do these three things to protect your web security camera from hackers - ZDNet - March 3rd, 2020
- Internet security Market 2020 Analysis by Overview, Growth, Top Companies, Trends, Demand and Forecast to 2026 - Packaging News 24 - March 3rd, 2020
- Navigant Research Report Shows Global Annual Revenue for Home Automation and Security Is Expected to Reach $72 Billion in 2028 - Oklahoman.com - March 3rd, 2020
- NetAbstraction Announces Support for Private and Secure Access to the Dark Web - Yahoo Finance - March 3rd, 2020