4 ms·
You throw out an LED smart bulb maybe once every few years? Probably one of the single worst ways to target an individual.
by jonknee 8y ago
You throw out an LED smart bulb maybe once every few years? Probably one of the single worst ways to target an individual.
- LyndsySimon 8y agoThat's not really how it works though - if I were targeting you, I wouldn't think "I'm going to go through this guy's trash and look for smart bulbs". I'd think "I'm going to go through this guy's trash and see if I find anything useful." If I find bank statements or other correspondence containing personal information, all of that gets added to the "dossier." If I find a hard drive, I'd plug it in and poke around. If I found a birthday card, I'd check the date it was mailed and have a good idea of when you were born. If I found a smart bulb... well, now this is just one more small extension of your personal attack surface. Take this a bit further - what happens when the healthcare startup with 50 or so employees installs smart bulbs? Let's say the bulbs last on average five years, and they have 50 bulbs in their offices. That's ten bulbs failing per annum, giving a ~80% chance of finding a smart bulb in their trash in a given month. An attacker gets one of those, and is able to connect to their internal network over WiFi. From there they can poke around on internal machines, and would probably even have access to a whitelisted origin IP for SSHing into production machines.
- jsight 8y agoSo, this company buys 50 smart bulbs (instead of smart switches) and then connects them to a sensitive wifi network. I think they have bigger issues than whether the bulbs themselves are secure (even if they are the manufacturer).
- djsumdog 8y agoThe post was making an example from just finding attack vectors. This is just one of many attack vectors, but it's still a viable vector for attack. What if it's a small business that might have important trade secrets, but doesn't meet the strict requirements for HIPPA/PCI/etc? It's still one more vector that doesn't need to exist, because there is no reason what-so-ever that you need a Wi-Fi chip inside your light blub!
- acdha 8y ago> From there they can poke around on internal machines, and would probably even have access to a whitelisted origin IP for SSHing into production machines. … at which point they need to break SSH/TLS after getting off the IoT sandbox network. I’d worry more about phishing and malware, and focus on deploying things like MFA first. If they aren’t doing any of those things (or, in your example, not using a paper shredder) PCI & HIPAA are going to be a lot more of an existential threat than someone dumpster diving.