Almost 30 million households in Europe will be smart homes by the end of the year, research suggests. Getty Images
Almost 30 million households in Europe will be smart homes by the end of the year, research suggests. Getty Images
Almost 30 million households in Europe will be smart homes by the end of the year, research suggests. Getty Images
Almost 30 million households in Europe will be smart homes by the end of the year, research suggests. Getty Images

When smart homes aren't smart enough: why your home tech could be easily hacked


  • English
  • Arabic

It's an unsettling experience to have your home invaded by some kind of technological poltergeist. Unusual messages spontaneously emerging from your printer. Disembodied voices coming through your security camera. Thermostats going haywire, odd videos interrupting your evening's television viewing and doors unlocking without warning. While these occurrences are still relatively uncommon, last year saw a marked increase in hackers targeting internet-connected devices in people's homes: from light bulbs to plant waterers, music players to central-heating systems. The consumer appeal of this kind of gadget is obvious: by hooking them up to your network, you can automate them and control them remotely – but with that convenience comes vulnerability.

The problem is on the rise 

In recent months, a number of well-publicised incidents have raised awareness of the problem. In November, a group of hackers in Calgary, Canada, accessed a security camera belonging to a man living 2,500 kilometres away in Arizona and spoke to him through the device to warn him that his home was insecure. One of his personal passwords had leaked on the internet, and he had used the same one for his camera. Last week, someone styling themselves as ­"TheHackerGiraffe" hijacked tens of thousands of printers and Chromecast devices to display messages promoting the videos of Swedish YouTuber PewDiePie.

While these incidents seem to be mischievous rather than malicious, they highlight a more sinister problem, according to John Shier at security software firm Sophos. “Insecure devices can become a gateway into the rest of your network,” he says. “This could dramatically impact your privacy if documents are stolen or your traffic is monitored. But the more likely scenario is one we’ve seen time and time again, where devices are hijacked to become part of a botnet – perhaps a hundred thousand strong – which is then used to attack somebody else.”

Craig Young, a researcher at cybersecurity firm Tripwire, explains that compromised devices can also present a direct risk to personal safety. “If a Chromecast device is improperly exposed to the internet,” he says, “someone could find out its physical location. Then, if they see that no one has watched TV for 24 hours, they might guess that you’re away from home.” With a predicted 20 billion so-called “Internet of Things” (IoT) devices online by 2020, the potential for this kind of crime is growing by the day. “We need to start thinking in terms of herd immunity,” Shier says.

Security can be sacrificed for ease of use

While it’s true that many people take little interest in their own digital security, Young believes that a good deal of the blame can be laid at the doors of certain manufacturers. With the growing trend for devices to work straight out of the box, the industry-wide pursuit of a “frictionless” experience – no menus, no passwords, no hassle – can present problems. “Firms want to encourage adoption of these new technologies,” Young says. “So some of them make devices easier to use by sacrificing certain security components. They promote the idea that anything you put in your home network is safe because it’s only used by people you trust – but that doesn’t meet the reality of the modern internet.” Shier also sees security problems in budget products. “The firms who want to get in on the IoT craze will try to get to market cheaper than everybody else,” he says, “and so corners are cut.”

_________________________

Read more:

As Haley closes Twitter account, are Trump and team headed for social media standoff?

From driverless cars to delivery drones: What will technology do to us in 2019? 

AI-created photos: a threat or opportunity?

_________________________

User-friendly devices that don't require a password to access them present obvious problems, but devices where default factory-­set passwords are never changed by the user are equally unsafe. Such devices have been attacked for years. In 2014, a Russian website began broadcasting streams from unsecured webcams and it became hugely popular – but we still haven't wised up. A 2017 article by security company Positive Technologies estimated that the default passwords of 15 per cent of internet-connected devices have never been changed since they were unboxed. A simple Google search can reveal those default passwords, giving hackers a big head start when looking for vulnerabilities.

Hackers are trying to expose poor security

As hacking methods become more sophisticated, smart devices also need regular firmware updates to stay secure – but the habit of checking for such updates hasn't caught on, according to Young. "I don't know about you," he says, "but I don't think many people are logging in to, say, their router on a regular basis to see if it needs an update. The only way somebody will do that is if they see a news story telling them that it's being exploited." Shier agrees. "It's difficult to incentivise somebody to do something from a security perspective," he says, "but when you see that someone's webcam has been hacked, well, then it becomes real."

TheHackerGiraffe, who perpetrated last week's printer and Chromecast exploit, styles himself as a "white hat" hacker whose exploits are to alert consumers to poor security. "I just wanted to tell people that their devices were vulnerable," he said in an audio post on Twitter. "It doesn't matter how many blog posts security researchers write. No one cared, no one thought about it. But all it took was someone like me. The number of printers exposed went down, people started protecting their stuff. I'm glad." But having received a number of threatening messages in the past few days, he has curtailed his activities and deleted almost all of his online accounts. "I definitely don't support hackers using people's devices [in this way]," Young says, "but I can understand where they're coming from."

The problem evidently can't be solved by public-spirited hacking alone, and Shier believes that governments will soon start to take action. "I think they will provide incentives to companies by drawing up a set of guidelines," he says, "and if a product meets all of them, then they'll have the opportunity to put a gold star on the box [as an assurance of quality], so that it stands out from the others." This would certainly be a step in the right direction, but little progress is being made on agreeing an international set of guidelines for the security of baby monitors, fridges, smart kettles and home hubs. For the time being, it's down to us to recognise that devices that claim to make our lives easier also have the potential to make them much more difficult.

Abu Dhabi Card

5pm: Maiden (PA) Dh 80,000 1,400m

National selection: AF Mohanak

5.30pm: Handicap (PA) Dh 90,000 1,400m

National selection: Jayide Al Boraq

6pm: Handicap (TB) Dh 100,000 1,400m

National selection: Rocket Power

6.30pm: Abu Dhabi Championship Listed (PA) Dh 180,000 1,600m

National selection: Ihtesham

7pm: Wathba Stallions Cup Handicap (PA) Dh 70,000 1,600m

National selection: Noof KB

7.30pm: Maiden (PA) Dh 80,000 2.200m

National selection: EL Faust

What drives subscription retailing?

Once the domain of newspaper home deliveries, subscription model retailing has combined with e-commerce to permeate myriad products and services.

The concept has grown tremendously around the world and is forecast to thrive further, according to UnivDatos Market Insights’ report on recent and predicted trends in the sector.

The global subscription e-commerce market was valued at $13.2 billion (Dh48.5bn) in 2018. It is forecast to touch $478.2bn in 2025, and include the entertainment, fitness, food, cosmetics, baby care and fashion sectors.

The report says subscription-based services currently constitute “a small trend within e-commerce”. The US hosts almost 70 per cent of recurring plan firms, including leaders Dollar Shave Club, Hello Fresh and Netflix. Walmart and Sephora are among longer established retailers entering the space.

UnivDatos cites younger and affluent urbanites as prime subscription targets, with women currently the largest share of end-users.

That’s expected to remain unchanged until 2025, when women will represent a $246.6bn market share, owing to increasing numbers of start-ups targeting women.

Personal care and beauty occupy the largest chunk of the worldwide subscription e-commerce market, with changing lifestyles, work schedules, customisation and convenience among the chief future drivers.

MATCH INFO

Day 2 at the Gabba

Australia 312-1 

Warner 151 not out, Burns 97,  Labuschagne 55 not out

Pakistan 240 

Shafiq 76, Starc 4-52

England's Ashes squad

Joe Root (captain), Moeen Ali, Jimmy Anderson, Jofra Archer, Jonny Bairstow, Stuart Broad, Rory Burns, Jos Buttler, Sam Curran, Joe Denly, Jason Roy, Ben Stokes, Olly Stone, Chris Woakes. 

UAE currency: the story behind the money in your pockets
New schools in Dubai
Women%E2%80%99s%20Asia%20Cup
%3Cp%3E%3Cstrong%3EUAE%20fixtures%3C%2Fstrong%3E%3Cbr%3ESun%20Oct%202%2C%20v%20Sri%20Lanka%3Cbr%3ETue%20Oct%204%2C%20v%20India%3Cbr%3EWed%20Oct%205%2C%20v%20Malaysia%3Cbr%3EFri%20Oct%207%2C%20v%20Thailand%3Cbr%3ESun%20Oct%209%2C%20v%20Pakistan%3Cbr%3ETue%20Oct%2011%2C%20v%20Bangladesh%3Cbr%3E%3Cbr%3E%3Cstrong%3EUAE%20squad%3C%2Fstrong%3E%3Cbr%3EChaya%20Mughal%20(captain)%2C%20Esha%20Oza%2C%20Kavisha%20Kumari%2C%20Khushi%20Sharma%2C%20Theertha%20Satish%2C%20Lavanya%20Keny%2C%20Priyanjali%20Jain%2C%20Suraksha%20Kotte%2C%20Natasha%20Cherriath%2C%20Indhuja%20Nandakumar%2C%20Rishitha%20Rajith%2C%20Vaishnave%20Mahesh%2C%20Siya%20Gokhale%2C%20Samaira%20Dharnidharka%2C%20Mahika%20Gaur%3C%2Fp%3E%0A
What can victims do?

Always use only regulated platforms

Stop all transactions and communication on suspicion

Save all evidence (screenshots, chat logs, transaction IDs)

Report to local authorities

Warn others to prevent further harm

Courtesy: Crystal Intelligence

The President's Cake

Director: Hasan Hadi

Starring: Baneen Ahmad Nayyef, Waheed Thabet Khreibat, Sajad Mohamad Qasem 

Rating: 4/5

Russia's Muslim Heartlands

Dominic Rubin, Oxford

'Nope'
%3Cp%3E%3Cstrong%3EDirector%3A%3C%2Fstrong%3E%20Jordan%20Peele%0D%3Cbr%3E%3Cstrong%3EStars%3A%3C%2Fstrong%3E%20Daniel%20Kaluuya%2C%20Keke%20Palmer%2C%20Brandon%20Perea%2C%20Steven%20Yeun%0D%3Cbr%3E%3Cstrong%3ERating%3A%3C%2Fstrong%3E%203.5%2F5%3C%2Fp%3E%0A
Dunki
%3Cp%3E%3Cstrong%3EDirector%3A%3C%2Fstrong%3E%20Rajkumar%20Hirani%C2%A0%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EStarring%3A%3C%2Fstrong%3E%20Shah%20Rukh%20Khan%2C%20Taapsee%20Pannu%2C%20Vikram%20Kochhar%20and%20Anil%20Grover%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3ERating%3A%3C%2Fstrong%3E%204%2F5%3C%2Fp%3E%0A
The specs

Engine: 6.2-litre supercharged V8

Power: 712hp at 6,100rpm

Torque: 881Nm at 4,800rpm

Transmission: 8-speed auto

Fuel consumption: 19.6 l/100km

Price: Dh380,000

On sale: now