IoT Promises a Lot but Without Proper Security, It’s a Pandora's Box

Advertisement
By Rajeev Banduni | Updated: 31 July 2017 11:20 IST
Highlights
  • IoT devices could outnumber people in 2017
  • Security issues around IoT are becoming more prominent
  • Lack of standards, and poor user awareness, leads to weak security

On 21st October 2016 more than 56 types of IoT devices, such as wireless routers, DVRs, IP Phones, webcams, and even heat pumps were conscripted into a malicious army of 20,000 botnets. With DDoS (Distributed Denial of Service) attacks at 1Tbps from these botnets, cybercriminals caused a massive security breach against the Internet Infrastructure provider Dyn that took down Netflix, Reddit, PayPal, Pinterest, CNN, and PlayStation network, while disrupting Internet service across Europe and North America.

With the number of connected IoT devices predicted to supersede Earth’s human population by 2017, such incidents are gradually shifting the outlook towards an IoT ecosystem from being the foundational enabler into the Achilles heel of smart living.

IoT Devices – The potential vs. realities
About 80 percent of IoT devices lack password complexity, 70 percent don’t encrypt communications, while 60 percent have insecure user interfaces, an HP IoT study revealed. In spite of such revelations there is a prevalent - and unrealistic - expectation that somehow IoT technology would leverage the 25 years of its preceding security evolution into a secure ecosystem.

Advertisement

The majority of these devices lack upgradability with security patches sent over the Internet. Adding to this, most of the users don't bother to - or are unable to - change the default passwords of IoT devices. Obscure or non-existent privacy policies of IoT devices leaves sensitive user data at the discretion of IoT companies, while a lack of industry standards means a proliferation of device-specific networks for interoperability.

Advertisement

Major areas of concern
Smart city initiatives are extending the limits of urban infrastructure management, but with insufficient security testing. Over 200,000 traffic control sensors already installed at major world cities were found to be vulnerable by Cybersecurity expert Cesar Cerrudo. Moreover, Vasilis Hiuorios’ police surveillance system hack was repeated this year with 123 out of 187 cameras of Washington MPD being compromised by two malware.

In February 2017 researchers at Georgia Institute of Technology had successfully hacked Ransomware into a simulated water plant. Even in 2015, a German steel mill had suffered physical asset losses due to Stuxnet, a malware designed to attack industrial Programmable Logic Controllers (PLC) that create the core Industrial IoT. Forrester predicts a mass-scale IoT attack impending in 2017, especially in segments like fleet management in transportation, security and surveillance applications in government, inventory and warehouse management apps in retail, and industrial asset management in primary manufacturing.

Advertisement

In a 2014 study, researchers had identified life-threatening security lapses waiting to occur in connected medical devices like insulin pumps, implantable defibrillators, and many more. Furthermore, the security shortcomings in wearables were revealed with a Kaspersky expert hacking into a fitness band and an HP IoT study proved that 90 percent of smartwatch communications are interceptable.

In 2014 itself hackers had used 100,000+ connected consumer devices such as a smart TV or refrigerator to send more than 750,000 malicious emails to businesses and individuals around the world. However, when in 2016 researchers at the University of Michigan hacked into Samsung's SmartThings IoT platform, they not only proved the inadequate security of consumer IoT infrastructure, but also the mass vulnerability of data thefts through devices like baby monitors or teddy bears.

In an automotive hacking experiment in 2015, two hackers had remotely gained control of Chrysler's Jeep Cherokee on the highway and acquired wireless control over the car’s entertainment system, dashboard functions, steering, brakes and transmission. As more of such vulnerabilities are reported for BMW, Skoda Fabia III, Jaguar XFR and Tesla C the popular adoption of driverless cars and fleets gets delayed.

Advertisement

Security by design
In the IoT era, enterprise security is as strong as its weakest link, as it’s no longer safe to simply protect the network or back-end servers. To leverage the benefits of IoT, without risking the consequences of its security threats, business enterprises investing (or even planning) in IoT should address IoT security by design and not as infrastructure adaptation.

IoT security is not just symbiotically related to user safety, it’s sacrosanct. To sustain the consumer and investor attention generated, IoT security calls for a multipronged approach and collaboration amongst device manufacturers, enterprises, and end-users to create industry wide standards, protocols and best practices.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Realme Narzo 90 Series With 7,000mAh Battery Launched in India: See Pricing
  2. Realme 16 Pro to Launch With Urban Wild Design in These Four Colourways
  3. Pixel 10 Series Gets Price Cuts During Google's End of Year Sale: See Offers
  4. Lenovo Idea Tab Plus Launched in India With 10,200mah Battery: Details
  5. Vivo S50, S50 Pro Mini With Snapdragon Chips Launched at These Prices
  6. SBI YONO 2.0 Launch: State Bank of India Reportedly Targets 20 Crore Users
  7. Motorola Edge 70 First Impressions
  8. Gaming-Focused OnePlus Turbo Series Confirmed to Launch Soon
  9. Dhruv64: India's First Homegrown 64-Bit Dual-Core Microprocessor Unveiled
  10. iOS 26 Leaked Code Hints at These New Devices and Software Features
  1. Dhruv64: India’s First Homegrown 64-Bit Dual-Core Microprocessor Unveiled
  2. Disney CEO Says AI Deal With OpenAI Is Exclusive For Just One Year: Report
  3. Arasayyana Prema Prasanga Streaming Online: Know Where to Watch This Kannada Film
  4. Filmfare OTT Awards 2025 Winners: Black Warrant, Paatal Lok Season 2, Girls Will Be Girls, and More
  5. Thamma Now Streaming on Amazon Prime Video: Watch Ayushmann Khurrana and Rashmika Mandanna in This Horrer Comedy
  6. Realme 16 Pro Series Colourways Revealed; Company Announces Design Collaboration With Naoto Fukasawa
  7. Samsung Galaxy A07 5G Key Specifications Spotted in Geekbench Listing, Could Launch Soon
  8. Bungie Shares New Vision for Marathon, Confirms New March 2026 Launch Window, $40 Pricing
  9. Google to Discontinue Dark Web Reports in February 2026, Directs Users to Existing Privacy and Security Tools
  10. Realme Narzo 90 5G, Narzo 90x 5G Launched in India With 7,000mAh Battery, 50-Megapixel Cameras: Price, Features
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.