A Privacy Vulnerability in Smart Home IoT Devices
Michael W. Denko · Deep Blue (University of Michigan) · 2017
Smart home IoT devices are becoming increasingly popular and increasingly prevalent in people’s homes. These devices create new potential attack surfaces in people’s homes, and therefore it is important that the manufacturers are taking the appropriate measures to secure these devices. The motivation for this work was to determine if these measures were being taken since people could be unknowingly purchasing smart home IoT devices with security or privacy vulnerabilities.Smart home IoT devices that are available to consumers were purchased and analyzed for this paper. Some of these devices were found to contain privacy vulnerabilities. Therefore, some smart home IoT devices on the market contain a privacy vulnerability, which is they do not encrypt transmitted data over a local WiFi network, and therefore can be subject to a man in the middle attack.The privacy and security of seven different smart home IoT devices were analyzed including smart light bulbs, WiFi thermostats, a smart plug, and the Amazon Echo. It was found that four of the seven devices do not encrypt transmitted data over the local WiFi network connection, which is a privacy vulnerability. For two of these devices, the transmitted data could be visible in plain text, which can be easily deciphered by an attacker. Three of the four devices that contain a privacy vulnerability were also vulnerable to replay attacks, meaning replaying recorded packets causes the device to perform an action such as turn the lights on. It is discussed how the data obtained due to this privacy vulnerability can be used to track a user’s lifestyle habits. From this data an attacker can infer if the user is currently home or away. Lastly, solutions to these vulnerabilities are presented, which includes encrypting the communication data that is transmitted between the different nodes of the smart home IoT devices. For devices that use a point-to-point type of architecture, lightweight encryption techniques are needed and discussed.