IoT Promises a Lot but Without Proper Security, It’s a Pandora's Box

Advertisement
By Rajeev Banduni | Updated: 31 July 2017 11:20 IST
Highlights
  • IoT devices could outnumber people in 2017
  • Security issues around IoT are becoming more prominent
  • Lack of standards, and poor user awareness, leads to weak security

On 21st October 2016 more than 56 types of IoT devices, such as wireless routers, DVRs, IP Phones, webcams, and even heat pumps were conscripted into a malicious army of 20,000 botnets. With DDoS (Distributed Denial of Service) attacks at 1Tbps from these botnets, cybercriminals caused a massive security breach against the Internet Infrastructure provider Dyn that took down Netflix, Reddit, PayPal, Pinterest, CNN, and PlayStation network, while disrupting Internet service across Europe and North America.

With the number of connected IoT devices predicted to supersede Earth’s human population by 2017, such incidents are gradually shifting the outlook towards an IoT ecosystem from being the foundational enabler into the Achilles heel of smart living.

Advertisement

IoT Devices – The potential vs. realities
About 80 percent of IoT devices lack password complexity, 70 percent don’t encrypt communications, while 60 percent have insecure user interfaces, an HP IoT study revealed. In spite of such revelations there is a prevalent - and unrealistic - expectation that somehow IoT technology would leverage the 25 years of its preceding security evolution into a secure ecosystem.

The majority of these devices lack upgradability with security patches sent over the Internet. Adding to this, most of the users don't bother to - or are unable to - change the default passwords of IoT devices. Obscure or non-existent privacy policies of IoT devices leaves sensitive user data at the discretion of IoT companies, while a lack of industry standards means a proliferation of device-specific networks for interoperability.

Advertisement

Major areas of concern
Smart city initiatives are extending the limits of urban infrastructure management, but with insufficient security testing. Over 200,000 traffic control sensors already installed at major world cities were found to be vulnerable by Cybersecurity expert Cesar Cerrudo. Moreover, Vasilis Hiuorios’ police surveillance system hack was repeated this year with 123 out of 187 cameras of Washington MPD being compromised by two malware.

In February 2017 researchers at Georgia Institute of Technology had successfully hacked Ransomware into a simulated water plant. Even in 2015, a German steel mill had suffered physical asset losses due to Stuxnet, a malware designed to attack industrial Programmable Logic Controllers (PLC) that create the core Industrial IoT. Forrester predicts a mass-scale IoT attack impending in 2017, especially in segments like fleet management in transportation, security and surveillance applications in government, inventory and warehouse management apps in retail, and industrial asset management in primary manufacturing.

Advertisement

In a 2014 study, researchers had identified life-threatening security lapses waiting to occur in connected medical devices like insulin pumps, implantable defibrillators, and many more. Furthermore, the security shortcomings in wearables were revealed with a Kaspersky expert hacking into a fitness band and an HP IoT study proved that 90 percent of smartwatch communications are interceptable.

In 2014 itself hackers had used 100,000+ connected consumer devices such as a smart TV or refrigerator to send more than 750,000 malicious emails to businesses and individuals around the world. However, when in 2016 researchers at the University of Michigan hacked into Samsung's SmartThings IoT platform, they not only proved the inadequate security of consumer IoT infrastructure, but also the mass vulnerability of data thefts through devices like baby monitors or teddy bears.

In an automotive hacking experiment in 2015, two hackers had remotely gained control of Chrysler's Jeep Cherokee on the highway and acquired wireless control over the car’s entertainment system, dashboard functions, steering, brakes and transmission. As more of such vulnerabilities are reported for BMW, Skoda Fabia III, Jaguar XFR and Tesla C the popular adoption of driverless cars and fleets gets delayed.

Advertisement

Security by design
In the IoT era, enterprise security is as strong as its weakest link, as it’s no longer safe to simply protect the network or back-end servers. To leverage the benefits of IoT, without risking the consequences of its security threats, business enterprises investing (or even planning) in IoT should address IoT security by design and not as infrastructure adaptation.

IoT security is not just symbiotically related to user safety, it’s sacrosanct. To sustain the consumer and investor attention generated, IoT security calls for a multipronged approach and collaboration amongst device manufacturers, enterprises, and end-users to create industry wide standards, protocols and best practices.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. iPhone 17 Pro Max At Rs. 1,02,900 in Apple 50th Anniversary Sale
  2. OTT Releases of the Week (Mar 30th - Apr 5th): From Aamir Khan's Sitaare Zameen Par
  3. Infinix Note 60 Pro With Active Matrix Panel to Arrive in India on This Date
  4. OnePlus Nord 6 First Impressions
  5. Honor X80i With MediaTek Dimensity 6500 Elite Chip Launched: See Price
  6. ChatGPT is Now Available in Apple CarPlay, but With Some Limitations
  7. Honor Play 80 Pro With a 7,000mAh Battery Arrives at This Price
  8. Vivo V70 FE Launched in India With 7,000mAh Battery, 200-Megapixel Main Camera
  9. PS Plus Monthly Games for April Revealed
  10. Best Mobiles Under Rs. 30,000 in India
  1. Motorola Signature, Razr 60 Ultra and More Models Now Eligible to Receive Android 17 Beta Updates
  2. ChatGPT App May Soon Get a Custom Share Sheet, File Picker Interface and More UI Changes
  3. OpenAI Brings ChatGPT to Apple CarPlay, but It Cannot Access Navigation and Live Location Data
  4. iPhone 17 Pro Max At Rs. 1,02,900 in Apple 50th Anniversary Sale; iPad, Watch Available With Offers
  5. Google Pixel 11 Pro XL Leaked CAD Renders Reveal Design Identical to Pixel 10 Pro XL
  6. Apple's iPhone 18 Pro Models May Not Arrive in Classic Black Finish Just Like iPhone 17 Pro, Tipster Claims
  7. Oppo F33, Oppo F33 Pro Launch Timeline, Price Range Revealed in New Leak
  8. Capcom Adds Original Versions of Resident Evil 1, 2 and Resident Evil 3 Nemesis to Steam
  9. Google's Next Fitbit Wearable Could Launch Without a Display; Said to Require Paid Subscription
  10. CFTC-FTX Settlement: Former FTX Executive Nishad Singh to Pay $3.7 Million, Faces Trading Ban
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.