IoT in your home: what are the risks?
1 September 2018
Smart Home Automation
Information Security
Smart homes are getting even smarter, with Internet of Things (IoT) devices rapidly coming to market to make homes more efficient and daily life more convenient. But any Internet connection comes with risk attached, and IoT in homes could increase your vulnerability, warns Fortinet.
IoT takes smart home technology a step further into the future, adding smart sensors and independent Internet connections to appliances and devices to take the task of controlling them out of the hands of their owners. For example, where smart fridges or air conditioners might need to be controlled using a mobile app, an IoT-enabled appliance might control itself without needing the homeowner’s input.
IoT-enabled appliances measure temperature or available light, for example, to automatically trigger an action in an appliance. By using IoT sensors and connected SIMs, manufacturers are now producing heaters and air conditioners that switch on and off to maintain a constant room temperature, lights that switch themselves on when a room is dark, planters that automatically water plants when needed, or door locks that recognise the home owner and unlock without them needing keys.
“IoT-enabled appliances will certainly start arriving in the homes of ordinary South Africans soon,” says Doros Hadjizenonos, regional sales director at Fortinet. “People are already moving to smart homes and embracing devices such as smart TVs and media servers. While these devices make life simpler and easier, the challenge is that not all manufacturers make security their top priority when building smart devices.”
Fortinet’s latest Global Threat Landscape Report found that cyber criminals are already targeting IoT devices and media servers in homes for ‘cryptojacking’, in which they use a device’s computing power to mine cryptocurrency. The report said: “They are an especially attractive target because of their rich source of computational horsepower, which can be used for malicious purposes. Attackers are taking advantage of them by loading malware that is continually mining because these devices are always on and connected. In addition, the interfaces for these devices are being exploited as modified Web browsers, which expands the vulnerabilities and exploit vectors on them.”
“Cryptojacking in itself may not be a direct threat to the owner of the IoT device, although it could make it run slower,” says Hadjizenonos. “But once the code in the home is being controlled by someone else, they could also turn their attention to monitoring personal information on the home network.”
Globally, smart devices such as baby monitors and even smart vacuum cleaners have been hacked in the past, and Hadjizenonos says there is little prevent criminals from stealing passwords, monitoring the movements of homeowners, or tracking their children in future.
“Consumers typically connect their smart appliances via one router, so this is where smart home security efforts should be focused,” he says. “Before investing in smart and IoT-enabled devices, it’s recommended that homeowners ensure that their networks are secure, take advantage of security services from their ISPs, and lock down their routers. Once they invest in smart appliances, they should remember to check regularly for patches and updates to keep these appliances and devices secure.”
Further reading:
Phishing attacks through SVG image files
Kaspersky
News & Events Information Security
Kaspersky has detected a new trend: attackers are distributing phishing emails to individual and corporate users with attachments in SVG (Scalable Vector Graphics) files, a format commonly used for storing images.
Read more...
A passport to offline backups
SMART Security Solutions Technews Publishing
Editor's Choice Infrastructure Smart Home Automation
SMART Security Solutions tested a 6 TB WD My Passport and found it is much more than simply another portable hard drive when considering the free security software the company includes with the device.
Read more...
The impact of GenAI on cybersecurity
Sophos
News & Events Information Security
Sophos survey finds that 89% of IT leaders worry GenAI flaws could negatively impact their organisation’s cybersecurity strategies, with 87% of respondents stating they were concerned about a resulting lack of cybersecurity accountability.
Read more...
Efficient, future-proof estate security and management
Technews Publishing ElementC Solutions Duxbury Networking Fang Fences & Guards Secutel Technologies OneSpace Technologies DeepAlert SMART Security Solutions
Editor's Choice Information Security Security Services & Risk Management Residential Estate (Industry) AI & Data Analytics IoT & Automation
In February this year,
SMART Security Solutions travelled to Cape Town to experience the unbelievable experience of a city where potholes are fixed, and traffic lights work; and to host the Cape Town SMART Estate Security Conference 2025.
Read more...
DoorBell with built-in AI
Ajax Systems
Access Control & Identity Management Products & Solutions Smart Home Automation
Ajax Systems has announced the release of Ajax DoorBell, which features built-in AI, an IR sensor, and app control, seamlessly integrating into the Ajax ecosystem to ensure efficiency and security confidence.
Read more...
Identity is a cyber issue
Access Control & Identity Management Information Security
Identity and access management telemetry has emerged as the most common source of early threat detection, responsible for seven of the top 10 indicators of compromise leading to security investigations.
Read more...
Identity and authentication
Technews Publishing SMART Security Solutions
Access Control & Identity Management Information Security Security Services & Risk Management
Identity authentication is a crucial aspect of both physical security and cybersecurity.
SMART Security Solutions obtained insights into the topic and the latest developments from three companies.
Read more...
Smart surveillance and cyber resilience
Axis Communications SA
Surveillance Information Security Government and Parastatal (Industry) Facilities & Building Management
South Africa’s critical infrastructure sector has to step up its game regarding cybersecurity and the evolving risk landscape. The sector has become a prime target for cybercriminals on top of physical threat actors, and the consequences of an incident can be far-reaching.
Read more...
Autonomous healing systems are the future
Infrastructure Information Security AI & Data Analytics
Autonomous healing software, an emerging technology, is gaining traction for its potential to transform how organisations manage software maintenance, security, and system performance.
Read more...
Kaspersky detects over 1 million daily tracking attempts
Kaspersky
News & Events Information Security
Kaspersky's latest analysis of the 25 most prevalent web tracking services, including Google services, New Relic and Microsoft, has revealed over 38 billion instances of web trackers collecting user behaviour data in 2024, with an average of one million detections per day.
Read more...