Four commonly used IoT devices vulnerable to privacy theft

Research finds that LIFX Bulb, MUZO Cobblestone audio receiver, LinkHub and WeMo switch all susceptible to breaches.

  • 8 years ago Posted in
A technical investigation by Bitdefender, the creator of innovative security solutions, has discovered that four commonly used Internet of Things (IoT) consumer devices are vulnerable to cyberattack. The analysis reveals that current authentication mechanisms of many internet-connected devices can easily be bypassed to expose smart households and their inhabitants to privacy theft.
The Bitdefender Labs researchers choose devices that were both popular and affordable in order to understand the security stance of each device. The team analysed the way each device connects to the internet and to the cloud, as well as the communication between the device and its corresponding mobile application. Three of the four IoT devices in question are currently still at risk, whereas one has been partially resolved:
·         LIFX Bulb: a smart LED bulb that connects to a Wi-Fi network and allows users to control house lighting via a smartphone app. An attacker is able to switch the device on and off five times to reset the device and create a new hotspot. As a result, victims will be connected to an attacker’s fake hotspot and leak the username and password of their Wi-Fi network, allowing further penetration.
·         MUZO Cobblestone audio receiver: a Wi-Fi audio receiver that can be connected to home routers to allow music streaming from multiple sources. The device comes embedded with a Telnet service that allows users to access the device remotely. Bitdefender researchers attempted basic password brute-forcing and observed that the initial credentials were set to admin/ admin.
·         LinkHub: a smart adapter and two bulbs that allow users to remotely manage household lighting. A lack of transport encryption means data is sent in plain text, allowing attackers to obtain the username and password of a Wi-Fi network.
·         WeMo switch: a Wi-Fi enabled device that can turn plugged-in electronic devices on or off remotely, and includes scheduling and IFTTT (If This Then That) automation capabilities. The device is vulnerable to weak access point authentication and may leave users’ Wi-Fi credentials vulnerable.
“Four billion internet-connected devices promise to take our homes to an unprecedented level of comfort, however, this digital convenience is taking its toll on our private lives,” states Catalin Cosoi, Chief Security Strategist at Bitdefender. “As we have seen in the early stages of IoT development, gadgets designed for the home can talk with each other, yet they risk being overheard when communicating sensitive data.”
Radu Basaraba, Malware Researcher at Bitdefender, states, “IoT vendors need to prioritise security before their devices become hugely popular, leaving millions of people at risk from cyberattacks. The IoT opens a completely new dimension to security where the internet meets the physical world. If projections of a hyper-connected world become reality and manufacturers don’t bake security into their products, consequences can becoming life-threatening.”
Research shows ‘game needs to be changed,’ with security innovation years behind that of the...
73% of organizations lack automated patch management, and 62% experienced incidents involving...
Dell EMC PowerProtect Cyber Recovery for AWS provides a fast, easy-to-deploy public cloud vault to...
Node4 has released its Mid-Market IT Priorities Report 2021. The independent report reveals that...
Research from Avast has found that employees in almost a third (31%) of Small and Medium...
This year, over half of MSPs or their end customers have been attacked by ransomware but only 53%...
Palo Alto Networks has introduced Prisma® Cloud 3.0, said to be the industry’s first integrated...
Trend Micro has published new research revealing that 90% of IT decision makers claim their...