IOT- Friend or Foe

Many may still be unfamiliar with the IoT acronym but in reality come in contact and/or intentionally interact with IoT devices throughout their day/night. IoT stands for ‘Internet of Things’ and is increasingly the latest craze in technology, with most of the attention focused on consumer gadgets.

You may be wondering what devices are considered in the category of IoT? What do they look like? Well anything form smart TVs, refrigerators, to sprinkler systems have been developed with certain key characteristics including: embedded electronics and sensors, ability to interconnect, relevant software, and capability to receive and transmit data with its maker, users, or other devices. It’s these capabilities that classify them as IoT.

The days of racing back home when you’re off for a vacation, to turn the lights off or set the alarm are now a thing of the past with IoT. Also most industries, from environmental monitoring, energy management and transportation, to medical and healthcare systems are also embracing this new breed of devices.

Personally, when I think of IoT the first word that comes to mind is ‘conveniences’. Today for instance, ATT Digital life is providing solutions that are marketed as home-automation and digital life experiences. How convenient to check on whether you’re running out of milk from anywhere and adjust the thermostat on demand to ensure ‘home’ is waiting for you, exactly how you’d like. Life just keeps on getting better, doesn’t it?

Did you hear about hackers disrupting innocent infants’ sleep when breaking into any number of baby monitors, meant to ensure the child’s safety and well-being? After hacking these devices, the culprits routinely began broadcasting conversation to scare and rattle the babies. How about reports that Samsung SmartTVs were in the habit of recording ambient conversations and then shipping those recordings off to third parties? Samsung is not alone, LG was reported to be doing the same. Did you realize that gaming systems such as Microsoft Xbox Kinect which captures

movement, sounds and tracks multiple users simultaneously while connected to the Internet, results in many exposures as well?

As the diversity of IoT devices continues to evolve, most recently the announcement by Mattel earlier this week of an IoT version of the iconic Barbie, named ‘Hello Barbie’, heading for stores this holiday season, IT professionals and consumers alike need to take a step back and analyze the implication of these technologies and conveniences. Recently, Hewlet Packard (HP) released a security report having tested a vast array of IoT devices and found a landscape plagued by inherent risk and vulnerabilities. The findings revealed overarching concerns related to the lack of basic security criteria including issues with:

So, what’s my point with all of this? Throw away the devices? Stop the innovation? Never! Innovation, creativity and progress is what it’s all about. Consider this, a dwelling will certainly never pass inspection for a flight of stairs without handrails that meet a certain specification, regardless what the owner wants. Why are we then, willing to accept using technical solutions that collect any number of sensitive data elements without a second thought or care? The only explanation I can think of, is the convenience factor with entertainment following in close second. So many federal and state laws make it illegal to tape record an individual without consent, yet more and more we’re being recorded, tracked, monitored and surveilled without consent. As IT professionals, engineers and innovators we must all do our part to ensure security is integrated into these devices by design.

As a security professional by trade yet an innovator and technologist at heart, I’m certainly looking forward to hyper integration of these devices into my own home and life with the assurance that when my door is closed, that it truly is. I also hope, never to read that someone has hacked the iconic Barbie doll!
• Your Smart TV is spying on you

Maria

Maria

Back to top