Showing posts with label Home Security. Show all posts
Showing posts with label Home Security. Show all posts

May 3, 2016

University of Michigan and Microsoft Recognize Study Showing Flawed Security For Smart Homes



But new findings suggest these systems could hold hidden opportunities for hackers to break inside without being noticed. The University of Michigan used malicious apps to hack Samsung's SmartThings in four successful attacks that opened electric doors, changed devices to vacation mode and set off fire alarms.

[From article]
Transforming a home into an 'intelligent agent' allows users to monitor, control and secure it via apps and a smartphone.
But new findings suggest these systems also give hackers the tools needed to operate smart locks, change access codes and set off Wi-Fi enabled smoke detectors.
The University of Michigan hacked Samsung's SmartThings in four successful attacks and used the systems own SmartApps to carry each one out.
'It’s important to note that all the vulnerabilities are hypothetical and haven’t affected SmartThings customers’ because of the approval and review processes they have in place, but they have still worked with the researchers to further secure the platform based on their findings,' a SmartThings spokesperson told DailyMail.com in an email.
The University of Michigan, in collaboration with Microsoft, says this study is 'the first in-depth empirical security analysis of a popular emerging smart home programming platform'.
By evaluating the platform's security design and investigating the 499 SmartThings third-party apps (SmartApps), researchers found the biggest problem is that 40 percent of the apps are 'over-privileged'.
The idea that an app is over-privileged means it can gain access to more operations on the device than it needs to perform its function.
'The access SmartThings grants by default is at a full device level, rather than any narrower,' Atul Prakash said, computer science professor at the University of Michigan.
During the first attack, researcher were able to unlock electric doors by simply sending users a malicious link in a third-party app.
If users clicked on the URL, they were brought to the SmartThings website to login their credentials.
A hacker can then redirect a bug to the app and capture the login data to 'inject' a new code into the electric door lock.
The researchers also found that it is possible for developers to create an authentication method called OAuth incorrectly.
This flaw, in combination with the over-privileged SmartApps, allowed hackers to create their own PIN code into the door lock – without the homeowners knowing.
The team showed that an existing SmartApp could be remotely used to make a spare door key virtually by programming an additional PIN into the electronic lock.
Or another can 'eavesdrop' on someone setting up their PIN code for the lock, which will then text it to the hacker.


The SmartApp, which they called a 'lock-pick malware app' was camouflaged as a battery level monitor and only showed the need for that capability in its code.
Earlence Fernandes, a doctoral student in computer science and engineering who led the study, said that 'letting it control your window shades is probably fine.'
'One way to think about it is if you'd hand over control of the connected devices in your home to someone you don't trust and then imagine the worst they could do with that and consider whether you're okay with someone having that level of control,' he said.
The final attacks were carried out by tricking tricking devices inside the home.
The team was able to inject erroneous events in fire alarms or lights that turned them on or switched them to vacation mode.
These results have implications for all smart home systems, and even the broader Internet of Things, researchers said.
'The bottom line is that it's not easy to secure these systems' Prakash said.
'There are multiple layers in the software stack and we found vulnerabilities across them, making fixes difficult.'
The researchers told SmartThings about these issues in December 2015 and the company is working on fixes.
The researchers rechecked a few weeks ago if a lock's PIN code could still be snooped and reprogrammed by a potential hacker, and it still could.
'Protecting our customers' privacy and data security is fundamental to everything we do at SmartThings,' CEO at SmartThings Alex Hawkinson shared in a recent blog post.
'We are fully aware of the University of Michigan/Microsoft Research report and have been working with the authors of the report for the past several weeks on ways that we can continue to make the smart home more secure as the industry grows.'



http://www.dailymail.co.uk/sciencetech/article-3569789/So-smart-home-Researchers-reveal-major-security-flaws-Samsung-s-SmartThings-let-hackers-unlock-doors-set-alarms.html

So much for the smart home: Researchers reveal major security flaws in Samsung's SmartThings system that let hackers unlock your doors and set off alarms
Researchers found 40% of 499 SmartApps are over-privileged
Hackers can create new PIN code by sending users malicious link in app
Injected erroneous events used to trick devices to turn on or shut down
By STACY LIBERATORE FOR DAILYMAIL.COM
PUBLISHED: 14:06 EST, 2 May 2016 | UPDATED: 14:57 EST, 2 May 2016

December 21, 2014

Indiana Homeowner Shoots Dead Robbery Intruder



22-year-old Deandre Twyman

[From article]
IMPD said the call came in at 9:17 p.m., when a homeowner said he'd fire shots at two intruders in his home on the 4500 block of Devon Court on Indianapolis' northeast side.
The caller told police he thought some of the shots hit an intruder, but wasn't sure.
A man later identified as 22-year-old Deandre Twyman arrived at Community East Hospital at 9:40 p.m. with a gunshot wound to the abdomen. He was pronounced dead at the hospital shortly thereafter.

http://www.theindychannel.com/news/local-news/impd-homeowner-shot-at-robbers-in-break-in

IMPD: Homeowner shot and killed attempted robber
TheIndyChannel.com Staff
10:48 PM, Dec 19, 2014
December 20, 2014

October 5, 2014

Unlocked Loaded Gun Saved Lives




[From article]
A man opened fire on a group of home invaders inside his family's northwest Harris County home early Friday, deputies said.
One of the suspects died at the scene while the other two fled in a getaway vehicle. It all happened around 4:30 a.m.
[. . .]
It is not clear whether or not he had the gun under lock and key, as we are constantly told is necessary. What is clear is that it was accessible. Had it been kept in a safe somewhere he could not have accessed it without the dirtbags suspects seeing him, the fate of the 8 people in the household would be far more problematic.

http://americanthinker.com/blog/2014/10/bedside_firearm_saves_lives_in_texas.html

October 4, 2014
Bedside firearm saves lives in Texas
By Thomas Lifson

December 21, 2012

Home Security, Street Safety



Put your car keys beside your bed at night.



Share with everyone. Put your car keys beside your bed at night.

If you hear a noise outside your home or someone trying to get in your house, just press the panic button for your car. The alarm will be set off, and the horn will continue to sound until either you turn it off or the car battery dies.

This tip came from a neighborhood watch coordinator. Next time you come home for the night and you start to put your keys away, think of this: It's a security alarm system that you probably already have and requires no installation. Test it. It will go off from most everywhere inside your house and will keep honking until your battery runs down or until you reset it with the button on the key fob chain. It works if you park in your driveway or garage.

If your car alarm goes off when someone is trying to break into your house, odds are the burglar/rapist won't stick around. After a few seconds, all the neighbors will be looking out their windows to see who is out there and sure enough the criminal won't want that. And remember to carry your keys while walking to your car in a parking lot. The alarm can work the same way there in case of attacks, falls, illness. 

August 5, 2011

Police Recommend Home Security Measures

Problem arises when it is the landlord that props the door open as at buildings owned and operated by Harvard University, including but not limited to Harvard's campus police and their real estate employees.

[From police list]
"NEVER prop open the door or let someone in behind you if you live in an apartment building. If the building has a main entryway, make sure that security is enforced at the main door. Report residents who do this to your landlord."

http://www.wickedlocal.com/cambridge/news/x919514147/Police-warn-residents-about-housebreaks-in-East-Cambridge#axzz1UBJtPOSV

Police warn residents about housebreaks in East Cambridge
By Staff reports
Cambridge Chronicle
Posted Aug 05, 2011 @ 02:13 PM