Skip to main content

The context you need, when you need it

When news breaks, you need to understand what actually matters — and what to do about it. At Vox, our mission to help you make sense of the world has never been more vital. But we can’t do it on our own.

We rely on readers like you to fund our journalism. Will you support our work and become a Vox Member today?

Join now

The Internet of Things Is the Hackers’ New Playground

A new study finds new Internet connected gadgets tend to lack the most basic security.

grapegeek / iStockphoto

Excited about the promise of the shiny new Internet of Things? Good. Because hackers are too. Or at least they should be, according to a study by computing giant Hewlett-Packard.

The company’s Fortify application security unit conducted an analysis of the 10 most popular consumer Internet things on the market and found 250 different security vulnerabilities in the products, for an average of 25 faults each. Unfortunately, HP doesn’t identify each product but does describe them in broad brushstrokes: They were from the manufacturers of “TVs, webcams, home thermostats, remote power outlets, sprinkler controllers, hubs for controlling multiple devices, door locks, home alarms, scales and garage door openers.”

As a basic rule, these devices often run stripped-down versions of the Linux operating system, and so will have many of the same basic security concerns that you might expect to be in place on a server or other computer running Linux. The problem is, the people building them aren’t going to the effort to secure them the way they would a more traditional computer.

What’s happening, says Mike Armistead, VP and general manager of HP’s Fortify unit, is that manufacturers are rushing to get their products on the market without doing the harder work of locking their devices down against the most basic kinds of attacks.

Magnifying the potential for the problem is the fact that once one device is compromised, overlapping vulnerabilities can lead an attack from one to the other. If that seems like alarmist paranoia, remember that one of the most damaging hacking attacks in history, the Target breach, in which information on more than 70 million people was compromised, was carried out by way of an attack on a system used to manage and maintain the heating and ventilation system in the company’s stores.

  • Eight devices failed to require passwords stronger than “1234” either on the device itself or on a corresponding website.
  • Seven of the devices tested do no encryption when communicating with the Internet or a local network, meaning whatever data they’re sending is going out, sensitive or not, “in the clear.”
  • Six devices had weak security on their interfaces, were vulnerable to persistent cross-site scripting attacks, had weak default sign-in credentials, or transmitted sign-in credentials like passwords “in the clear.” (See the bit about encryption above.)
  • Six devices didn’t encrypt software updates during the download. That’s especially alarming because bad guys could create a software update that looks legit and basically reprogram the device to do whatever they want it to. Consider what that means when a Webcam or a garage door opener are connected to the Internet and then use your imagination.
  • Take all the above into consideration, and then add this: Nine of the 10 devices collected at least some kind of personal information: An email address, a home address, a name or date of birth.

To conduct the study, researchers at HP’s Fortify did what they do all the time: They subjected the devices to the company’s Fortify on Demand service, which basically tests software for known and potential security problems.

So how big will the Internet of Things be? One educated guess by the research firm Gartner says it could swell to include 26 billion individual devices by 2020.

As Armistead put it: “For a hacker, that’s a pretty big new target to attack.”

Consider yourself warned.

This article originally appeared on Recode.net.

More in Technology

Technology
The case for AI realismThe case for AI realism
Technology

AI isn’t going to be the end of the world — no matter what this documentary sometimes argues.

By Shayna Korol
Politics
OpenAI’s oddly socialist, wildly hypocritical new economic agendaOpenAI’s oddly socialist, wildly hypocritical new economic agenda
Politics

The AI company released a set of highly progressive policy ideas. There’s just one small problem.

By Eric Levitz
Future Perfect
Human bodies aren’t ready to travel to Mars. Space medicine can help.Human bodies aren’t ready to travel to Mars. Space medicine can help.
Future Perfect

Protecting astronauts in space — and maybe even Mars — will help transform health on Earth.

By Shayna Korol
Podcasts
The importance of space toilets, explainedThe importance of space toilets, explained
Podcast
Podcasts

Houston, we have a plumbing problem.

By Peter Balonon-Rosen and Sean Rameswaram
Technology
What happened when they installed ChatGPT on a nuclear supercomputerWhat happened when they installed ChatGPT on a nuclear supercomputer
Technology

How they’re using AI at the lab that created the atom bomb.

By Joshua Keating
Future Perfect
Humanity’s return to the moon is a deeply religious missionHumanity’s return to the moon is a deeply religious mission
Future Perfect

Space barons like Jeff Bezos and Elon Musk don’t seem religious. But their quest to colonize outer space is.

By Sigal Samuel