Given this vulnerabilty, it speaks to devices that do not have a lot of regulation (or security) in place (and there many examples of this.) For example, police in Arkansas are trying to use Amazon's Echo data in a murder investigation. Based on court documents in November 2015, a man in Arkansas had some friends over at his house to watch a football game and in the morning, one of the friends was found dead in a hot tub in the backyard. Police later charged the man who lived in the house, James Bates, with murder. He has pleaded not guilty.
As the police were investigating the crime, they found a number of digital devices in the suspect's house, including an Amazon Echo device that was in the kitchen. They have since seized the device and have apparently gotten some information from it, but what they want to check is what — if anything — the device may have recorded around the time of the murder.
Questions to consider:
- What kind of data are companies collecting about what goes on inside the home?
- What prevents these companies from giving up these data to law enforcement (including hackers or spies) any time they ask for (or take) it?
- Is anything being done to secure IoT?
Here is an example of a "shockingly easy" way to hijack a Samsung SmartCam camera! Samsung is going to have to figure out how to secure their devices, right? Any other examples?
ReplyDeleteHere's an example of a Smart Car being hacked back in 2015.
Delete1. Companies are collecting less data secretly than most people believe they do. What they do collect is things you post online, or the search history though their own services. If you have an Amazon Echo in your home it won't record private conversations, for the simple reason that the risk/reward ratio is not worth for the company. Furthermore sadly, nothing recovered from such a device would be admitted in court, given that it was "illegally" obtained.
ReplyDelete2. Companies would absolutely ruin their reputation if they collected and they gave up such illegally collected information. They have every right to give their own resources to the government, but your buyer profile is already not private so nothing new there.
3. There is often a two factor authentication, where you have to press a button on the device to connect, or in some cases you can only connect with one system and the previous has to be disconnected for someone else to connect. Neither solutions are perfect, but they might help a little.