A number of internet-connected home gadgets can be hacked in minutes using a simple Google search.
‘Smart’ baby monitors, security cameras and thermostats were accessed by cyber security researchers who tracked down their access passwords online.
They said that the ease with which criminals or paedophiles can take control of devices in the home is ‘truly frightening’.
A number of internet-connected home gadgets can be hacked in minutes using a simple Google search. ‘Smart’ baby monitors, security cameras and thermostats were accessed by cyber security researchers by tracking down their passwords online (stock image)
Experts at Ben-Gurion University of the Negev, Israel, examined off-the-shelf internet of things (IoT) devices and quickly uncovered a number of serious security issues.
The IoT is a broad category that refers to devices or sensors that connect, communicate or transmit information over the web.
Sixteen popular brands of IoT connected hardware devices were tested in total.
‘Using these devices in our lab, we were able to play loud music through a baby monitor, turn off a thermostat and turn on a camera remotely, much to the concern of our researchers who themselves use these products,’ study lead Dr Yossi Oren said.
‘It is truly frightening how easily a criminal, voyeur or pedophile can take over these devices.’
The team discovered that similar products under different brands often share the same common default passwords.
Consumers and businesses rarely change these passwords when purchased and they could be infected with malicious code for years without them realising.
Researchers examined off-the-shelf IoT devices, including smart baby monitors (stock image), and quickly uncovered a number of serious security issues. They said the ease with which criminals or pedophiles can take control of devices in the home is ‘truly frightening’
The team was also able to logon to entire Wi-fi networks simply by retrieving the password stored in a device to gain network access.
‘It only took 30 minutes to find passwords for most of the devices and some of them were found only through a Google search of the brand,’ study co-author Omer Shwartz said.
Manufacturers of so-called IoT products – which include physical devices, vehicles, home appliances and other items that connect and exchange data – rarely protect them from simple cyber attacks, researchers said.
Mr Shwartz added: ‘Once hackers can access an IoT device, like a camera, they can create an entire network of these camera models controlled remotely.’
Researchers discovered that similar products such as smart thermostats (stock) under different brands share the same common default passwords. Consumers rarely change device passwords when purchased so they could be operating infected with malicious code for years
‘It seems to get IoT products to market at an attractive price is often more important than securing them properly,’ Dr Oren said.
IoT users can protect their home devices by only connecting them to the internet if absolutely necessary and using hard-to-guess passwords.
Consumers should also avoid buying second-hand devices, which may already be infected with malware, and only buy from reputable manufacturers, the team said.
‘We hope our findings will hold manufacturers more accountable and help alert both manufacturers and consumers to the dangers inherent in the widespread use of unsecured IoT devices,’ Yael Mathov, another researcher on the project, said.