It’s become a cliché that the smart fridge – one with sensors inside and connection to the Internet on the outside – will one day automatically order milk or replenish other items before they run out.
The reality is not only different, but also darker: smart appliances have little protection from hackers, and may be a way for cybercriminals to hijack devices, as well as invade privacy. Especially as smart TVs become standard – both in South Africa and across the world – we are exposing ourselves to dangers we don’t even know exist.
From TVs and fridges to security cameras and Wi-Fi routers, the very devices that are meant to make our lives easier are also the ones that make us more vulnerable. And this is not theoretical. As long ago as 2014, cybercriminals created a “botnet” – when a large amount of hacked computers are used in concert to mount a spam or other attack – which hijacked 100 000 devices, including routers, TVs and even a fridge.
“For some time we’ve seen attacks on security cameras, routers, and networking equipment,” said Marco Preuss, head of research at cybersecurity leaders Kaspersky Lab. “There are a lot of things happening to abuse these devices for malicious activities against other users, but also using them as entry point to the owner’s system.”
Preuss was speaking at the recent Kaspersky Transparency Summit in Zurich, when the company announced the opening of a Transparency Centre in Switzerland for regulators and other organisations to view its software code directly.
A panel discussion during the event, on the risks and rewards of transparency in cybersecurity, highlighted the absence of trust in technology. In the past, if a cybersecurity company said one could trust them, most people believed it. But that time is past, said Jan-Peter Kleinhans, project director for a project called Security in the Internet of Things at a German think tank, Stiftung Neue Verantwortung.
“The term ‘trust me’ is 1990s cybersecurity,” he said. “If someone says trust me, I want proof of it. How do we trust them?”
This problem will become far worse once we cannot trust even appliance makers, he said in an interview after the event.
“In the future every product will be connected. For commercial off-the-shelf devices (COTS), we already see rapidly increasing demand for voice assistants, smart lighting, and Smart TVs. So the question is not IF something gets connected but WHEN.
“All these devices will be vulnerable. Here the question is more how easy it is for criminals to exploit those devices – right now it’s extremely easy. For COTS devices I think the biggest problem are botnets that form a globally distributed botnet that the criminal can rent out for attacks against websites or credit card fraud or attacking production servers.”
The worst of it, he said, is that there is little the consumer can do. Kleinhans called on regulators to steps in, and pointed to the European Union’s Cybersecurity Act as a potential solution.
“It focuses on voluntary certification and security standards in the hopes that manufacturers see IT security as a competitive advantage. I don’t think voluntary certification by itself is enough, but it’s a solid first step. At the same time there is a growing debate about ‘software liability’ in many European countries. I think over the next five years we will see tighter and clearer regulation regarding IT security in general.”
In the meantime, it is not only the home user whois at risk, said Preuss.
“It affects everyone from consumer to small and medium businesses to enterprises. There is no limit in this whole environment, because more and more gets connected. In Germany you have smart connected production facilities, and public infrastructure like power plants and water supply that gets more and more connected, so that one can control what power needs to be produced to keep the network as stable as possible.”
The danger will escalate as energy production shifts from “classic nuclear and coal power plants” to solar and wind-based energy systems, which all depend on smart connected systems to pull their energy into the grid and keep it stable, said Preuss.
“Every company is an IT (information technology) company nowadays, whether they are working with wood or stone or clothes. The problem is everybody still does not realise they are an IT company, because most are still in the mindset of just working with wood and creating furniture, for example. No, you’re an IT company, because all your machines are connected, all your manufacturers are connected, and all your customers are online and connected. You have all this customer information digitalised.”
Preuss outlined a wide range of potential cyber attacks in this environment, from ransom attempts by encrypting company data to stealing company information to pretending to have cracked your account through password leaks and demanding payment not to publish sensitive information.
“The borders between consumer, small and medium business, enterprise, and government are less and less visible, ands everyone of us is now a node in the whole network. On the Internet, there is no longer a difference anymore between personal and business life. When I am private on a social network, I can still be targeted by people trying to get into my company. Everything is connected.”
The best known example of a potential danger is the idea that smart fridges can be accessed by hackers and pulled together into a massive network, or botnet, that launches what is known as a DDoS, or distributed denial of service attack, when a large number of computer attempt to connect to the same computer at the same time, causing it to crash. The most widely distributed software used for this is called Mira (see sidebar), which looks for unprotected Internet of Things devices. It is available as open source software for any hacker to download.
Said Preuss, “Mira was automated to spread on web cameras connected to the Internet by using default user name and password combinations. In most cases, users don’t change the default user name and password or don’t know how or are not aware that they should. Many of these systems also ship with very old hardware and you can’t update them, or updates are not shipped by vendors.
“The result is that you have less control of these devices. Just on the consumer level, you already probably have a router, smart TV, and smart security system. You may have smart controllers in kitchen. We’re talking a lot of different devices and platforms from a lot of different vendors.”
The home user, said Preuss, needs to be like system administrators from enterprises in the past, but the home user is not an IT expert.
“Yet these devices still do not offer the ease of use or functionality, by design, to make them more secure by ease of update and configuration.”
What can consumers do?
“Consumers can think about which device they buy, ask about security, ask about transparency, what happens with data, and do I need to connect it to the Internet? Just because a fridge has Wi-Fi, doesn’t mean I need to connect it.”
Samsung unfolds the future
At the #Unpacked launch, Samsung delivered the world’s first foldable phone from a major brand. ARTHUR GOLDSTUCK tried it out.
Everything that could be known about the new Samsung Galaxy S10 range, launched on Wednesday in San Francisco, seems to have been known before the event.
Most predictions were spot-on, including those in Gadget (see our preview here), thanks to a series of leaks so large, they competed with the hole an iceberg made in the Titanic.
The big surprise was that there was a big surprise. While it was widely expected that Samsung would announce a foldable phone, few predicted what would emerge from that announcement. About the only thing that was guessed right was the name: Galaxy Fold.
The real surprise was the versatility of the foldable phone, and the fact that units were available at the launch. During the Johannesburg event, at which the San Francisco launch was streamed live, small groups of media took turns to enter a private Fold viewing area where photos were banned, personal phones had to be handed in, and the Fold could be tried out under close supervision.
The first impression is of a compact smartphone with a relatively small screen on the front – it measures 4.6-inches – and a second layer of phone at the back. With a click of a button, the phone folds out to reveal a 7.3-inch inside screen – the equivalent of a mini tablet.
The fold itself is based on a sophisticated hinge design that probably took more engineering than the foldable display. The result is a large screen with no visible seam.
The device introduces the concept of “app continuity”, which means an app can be opened on the front and, in mid-use, if the handset is folded open, continue on the inside from where the user left off on the front. The difference is that the app will the have far more space for viewing or other activity.
Click here to read about the app experience on the inside of the Fold.
Password managers don’t protect you from hackers
Using a password manager to protect yourself online? Research reveals serious weaknesses…
Top password manager products have fundamental flaws that expose the data they are designed to protect, rendering them no more secure than saving passwords in a text file, according to a new study by researchers at Independent Security Evaluators (ISE).
“100 percent of the products that ISE analyzed failed to provide the security to safeguard a user’s passwords as advertised,” says ISE CEO Stephen Bono. “Although password managers provide some utility for storing login/passwords and limit password reuse, these applications are a vulnerable target for the mass collection of this data through malicious hacking campaigns.”
In the new report titled “Under the Hood of Secrets Management,” ISE researchers revealed serious weaknesses with top password managers: 1Password, Dashlane, KeePass and LastPass. ISE examined the underlying functionality of these products on Windows 10 to understand how users’ secrets are stored even when the password manager is locked. More than 60 million individuals 93,000 businesses worldwide rely on password managers. Click here for a copy of the report.
Password managers are marketed as a solution to eliminate the security risks of storing passwords or secrets for applications and browsers in plain text documents. Having previously examined these and other password managers, ISE researchers expected an improved level of security standards preventing malicious credential extraction. Instead ISE found just the opposite.
Click here to read the findings from the report.