element14 Community
element14 Community
    Register Log In
  • Site
  • Search
  • Log In Register
  • Community Hub
    Community Hub
    • What's New on element14
    • Feedback and Support
    • Benefits of Membership
    • Personal Blogs
    • Members Area
    • Achievement Levels
  • Learn
    Learn
    • Ask an Expert
    • eBooks
    • element14 presents
    • Learning Center
    • Tech Spotlight
    • STEM Academy
    • Webinars, Training and Events
    • Learning Groups
  • Technologies
    Technologies
    • 3D Printing
    • FPGA
    • Industrial Automation
    • Internet of Things
    • Power & Energy
    • Sensors
    • Technology Groups
  • Challenges & Projects
    Challenges & Projects
    • Design Challenges
    • element14 presents Projects
    • Project14
    • Arduino Projects
    • Raspberry Pi Projects
    • Project Groups
  • Products
    Products
    • Arduino
    • Avnet & Tria Boards Community
    • Dev Tools
    • Manufacturers
    • Multicomp Pro
    • Product Groups
    • Raspberry Pi
    • RoadTests & Reviews
  • About Us
  • Store
    Store
    • Visit Your Store
    • Choose another store...
      • Europe
      •  Austria (German)
      •  Belgium (Dutch, French)
      •  Bulgaria (Bulgarian)
      •  Czech Republic (Czech)
      •  Denmark (Danish)
      •  Estonia (Estonian)
      •  Finland (Finnish)
      •  France (French)
      •  Germany (German)
      •  Hungary (Hungarian)
      •  Ireland
      •  Israel
      •  Italy (Italian)
      •  Latvia (Latvian)
      •  
      •  Lithuania (Lithuanian)
      •  Netherlands (Dutch)
      •  Norway (Norwegian)
      •  Poland (Polish)
      •  Portugal (Portuguese)
      •  Romania (Romanian)
      •  Russia (Russian)
      •  Slovakia (Slovak)
      •  Slovenia (Slovenian)
      •  Spain (Spanish)
      •  Sweden (Swedish)
      •  Switzerland(German, French)
      •  Turkey (Turkish)
      •  United Kingdom
      • Asia Pacific
      •  Australia
      •  China
      •  Hong Kong
      •  India
      •  Korea (Korean)
      •  Malaysia
      •  New Zealand
      •  Philippines
      •  Singapore
      •  Taiwan
      •  Thailand (Thai)
      • Americas
      •  Brazil (Portuguese)
      •  Canada
      •  Mexico (Spanish)
      •  United States
      Can't find the country/region you're looking for? Visit our export site or find a local distributor.
  • Translate
  • Profile
  • Settings
Internet of Things
  • Technologies
  • More
Internet of Things
Blog IoT means Internet of Hacks
  • Blog
  • Forum
  • Documents
  • Quiz
  • Events
  • Polls
  • Members
  • Mentions
  • Sub-Groups
  • Tags
  • More
  • Cancel
  • New
Join Internet of Things to participate - click to join for free!
  • Share
  • More
  • Cancel
Group Actions
  • Group RSS
  • More
  • Cancel
Engagement
  • Author Author: Catwell
  • Date Created: 23 Aug 2016 8:25 PM Date Created
  • Views 650 views
  • Likes 1 like
  • Comments 1 comment
  • hack
  • internet of things
  • black hat
  • ransomware
  • cabeatwell
  • iot
  • hacking
  • innovation
Related
Recommended

IoT means Internet of Hacks

Catwell
Catwell
23 Aug 2016

image

The Internet of Thing (IoT) is supposed to mean the convenient interconnectivity of our devices to the internet. But the security infrastructure for our smart devices has not yet caught up. We are becoming ever more vulnerable to the malicious intentions of black hatters.

 

It’s no secret security has long been a concern regarding Internet of Things (IoT) technology. Back during its early emergence, a study conducted by HP researchers found 70 percent of IoT devices were vulnerable to even simple hacks. And while developers have urged IoT device manufacturers to heed the warning, market demand has overridden these concerns. Now that we are beginning to see increased incidents of virtual theft, we must ask ourselves to what extent we will go for convenience.

 

One of the more recent hacks devised is ranomware, or malicious hacks that hold your computer hostage until you pay a ridiculous ransom (typically in Bitcoin) to restore control. In one instance, a Hollywood hospital dished out $17K to retrieve patient files that were hacked. And now the threat exists in the IoT realm.

 

In a demonstration to expose IoT vulnerabilities, UK-based IT security researchers Andrew Tierney and Ken Munro of Pen Test Partners, successfully hacked a smart thermostat with ranomware via its built-in WiFi capabilities, proving the threat is possible via persistent network instabilities. While the hack required a physical breach to successfully complete, the threat does exist and incidents have popped up elsewhere, including cases of grand theft auto.

 

Two hackers were arrested in Houston this month for stealing more than 30 Jeeps from a local dealership. The men unlocked and started the cars remotely through the vehicles’ onboard WiFI connectivity, then waited until the dealership closed to retrieve the cars. The hackers sold the vehicles across the border in Mexico and got caught on their last heist. The bigger concern, however, is the safety of your personal vehicle. If a hacker can get past Jeep security, he can access the car sitting in your garage, which should prompt us to ask if IoT is worth the risk.

 

Thankfully, a few companies have answered the call to address IoT security instability. A number of partnerships have formed in recent years to combat security issues, including the AllSeen Alliance, the Thread Group, Open Interconnect Consortium, and the Industrial Internet Consortium. The groups collaborate to support improved security and encryption methodology to protect consumers. And while these organizations are doing a great thing, new advancements in encryption can only go so far if IoT device manufacturers do not use it in the next generation of products.

 

Demand has out-measured secure supply, and the key to protecting user security is to wait until IoT devices are secure. While this means consumers will have to wait for total smart home connectivity, it will mean protecting millions of people from even novice hackers that want to use someone else’s credit card to fund a trip to Fiji.

 

Companies won’t invest the extra resources to secure IoT unless we demand they do. So let’s work together to ensure a safer technology future.

 

Have a story tip? Message me at:

http://twitter.com/Cabe_Atwell

  • Sign in to reply
  • rscasny
    rscasny over 9 years ago

    I'll agree that security in the IoT space is a huge issue. And some of the hacks cited in this article are disappointing, but they may say something more about our culture than about a lack of secure technology.

     

    But I'd like to take issue with some of the things stated in this article.

     

    #1 "And while these organizations are doing a great thing, new advancements in encryption can only go so far if IoT device manufacturers do not use it in the next generation of products."

     

    I'd suggest the author to do some research on this topic before making inaccurate statements because device mfrs are employing encryption in their products. Texas Instruments, NXP, Microchip Technologies, and I'm sure others, all have products that have incorporated encryption and support AES.

     

    I attended a seminar held by NXP two months ago that covered embedded security. I wrote this summary of the seminar here. My article was onlyt half the seminar BTW.

     

    NXP has also put out a couple of authentication products. For ex. its A7001 is a tamper resistant and secure MCU, based its SmartMXRegistered technology, for authentication use cases such as counterfeit protection, profile of service and secure M2M communication. So, the technology is there, but customers have to use it.

     

    Another thing some companies are doing is building out cloud platforms for their customers so the customers don't have to deal with security. Sierra Wireless has an M2M cloud infrastructure for that purpose.

     

    #2 "Companies won’t invest the extra resources to secure IoT unless we demand they do. So let’s work together to ensure a safer technology future."

     

    It sounds like you are suggesting a grass roots movement is needed because companies (device mfrs or OEMS, I'm not sure who you mean) are too cheap to invest in security. That's ridiculous.

     

    Security is an extremely complicated problem for the IoT, especially for systems that have thousands of remotely located sensors. Smart Grid systems are very big and very complicated. Lots of opportunities for the bad boy hackers to do their dirty work. But the IoT has barely begun. One needs to remember that a device manufacturer may very well have incorporated security/encryption into their products, but it is up to the customers to actually use it.

     

    Beyond that, I think there is a dearth of cybersecurity talent at the local, in-house level that limits the type of security that can be provided.

     

    And you need senior leadership who understands security well enough and in a quantitative way to really make it a company mission for a secure future. In this respect, security is a human issue, not a technical issue.

     

    Finally, the resources needed to do security correctly are truly incredible. I'd like them to do more, of course. Perhaps the issue is we as a society are not ready to live in a totally connected world because we haven't found a cheap and sure-fire way to do security. Food for thought.

    • Cancel
    • Vote Up 0 Vote Down
    • Sign in to reply
    • More
    • Cancel
element14 Community

element14 is the first online community specifically for engineers. Connect with your peers and get expert answers to your questions.

  • Members
  • Learn
  • Technologies
  • Challenges & Projects
  • Products
  • Store
  • About Us
  • Feedback & Support
  • FAQs
  • Terms of Use
  • Privacy Policy
  • Legal and Copyright Notices
  • Sitemap
  • Cookies

An Avnet Company © 2025 Premier Farnell Limited. All Rights Reserved.

Premier Farnell Ltd, registered in England and Wales (no 00876412), registered office: Farnell House, Forge Lane, Leeds LS12 2NE.

ICP 备案号 10220084.

Follow element14

  • X
  • Facebook
  • linkedin
  • YouTube