IEEE Technology and Society Magazine - June 2018 - 77
show when a particular attribute could not be tested
or assessed.
Note these tests were performed at a point in time
and may have been improved or further deteriorated
since the date of testing in April 2017.
this, we launched a password-guessing attack to see if
they were protected by strong security protocols.
Each device was also checked to see how much traffic any open ports could handle before they were
brought down in a DDoS attack.
Confidentiality Rating
Access Control Rating
We tested to see if any ports on a device were "open,"
allowing the port to be exploited by attackers. Based on
JUNE 2018
∕
DNS Spoofing
Fake Server
We checked the integrity and authentication of each device by setting up a fake server to "listen" on the port
used by the real server. This technique is known as a
"man in the middle attack."
Using a number of methods, this fake server communicated with each device to see if it could be authenticated. We also tested to see if the devices could be
controlled by outside influences.
Figure 2 shows how each device performed in integrity testing.
■ These results show that all of the IoT devices were
vulnerable to an attack through the Domain Name
System (DNS) protocol. This means that at tackers
could hijack the system and impersonate the legitimate server of the IoT device. They would be protected, however, through proper authentication.
■ The two light bulbs that were tested communicated
with the fake server, which is a concern.
DNSSEC
Integrity Rating
Integrity and Authentication
Replay Attack
Confidentially is a measure of the security of data running between the IoT device, the router, and our server.
Our tests show whether the communications sent
and received were encrypted (the most difficult to read),
encoded (hard but not impossible), or plain text (easiest
to hack).
Figure 1 shows how each device performed in confidentiality testing.
■ Most of the devices had fairly secure communications in two channels (device to server and user app
to server) but were vulnerable when they communicated with their user app.
■ Five of the devices - the Phillips Hue light bulb, Belkin switch and motion sensor, HP Envy printer, and
TP-Link camera - sent data in plain text rather than
encrypted code. This would make it relatively simple
for hackers to deduce when a user is at home, based
on whether the power switch is on or off, or when the
light bulb was last used, for example.
■ The TP-Link camera was particularly susceptible to
attack. Not only might an attacker view any video and
audio footage based on reassembled data, the default
authentication password "admin" was easily decoded.
Phillips Hue Light Bulb
C
C
C
C
Belkin Switch
C
C
C
C
Samsung Smart Cam
A
C
C
A
Belkin Smart Cam
A
C
C
A
Awair Air Monitor
A
C
C
A
HP Envy Printer
C
C
C
A
LIFX Bulb
C
C
C
C
Canary Camera
A
C
C
A
TP-Link Switch
C
C
C
A
Amazon Echo
A
C
C
A
Samsung Smart Things
A
C
C
A
Pixstar Photo Frame
A
C
C
A
TP Link Camera
A
C
C
A
Belkin Motion Sensor
A
Nest Smoke Alarm
A
C
C
A
Netatmo Camera
A
C
C
A
Dlink Camera
A
Hello Barbie Companion
A
C
C
A
Withings Sleep Monitor
A
C
C
A
Nest Drop Camera
A
C
C
A
C
C
A
C
C
C
C
C
C
Devices
Netatmo Weather Station
Triby Speaker
A
Withings Weighing Scale
Chromecast
C
A
Key:
DNS: Domain Name System
DNSSEC: DNS Security Extensions
Figure 2. Integrity and authentication.
IEEE Technology and Society Magazine
77
Table of Contents for the Digital Edition of IEEE Technology and Society Magazine - June 2018
Contents
IEEE Technology and Society Magazine - June 2018 - Cover1
IEEE Technology and Society Magazine - June 2018 - Cover2
IEEE Technology and Society Magazine - June 2018 - 1
IEEE Technology and Society Magazine - June 2018 - Contents
IEEE Technology and Society Magazine - June 2018 - 3
IEEE Technology and Society Magazine - June 2018 - 4
IEEE Technology and Society Magazine - June 2018 - 5
IEEE Technology and Society Magazine - June 2018 - 6
IEEE Technology and Society Magazine - June 2018 - 7
IEEE Technology and Society Magazine - June 2018 - 8
IEEE Technology and Society Magazine - June 2018 - 9
IEEE Technology and Society Magazine - June 2018 - 10
IEEE Technology and Society Magazine - June 2018 - 11
IEEE Technology and Society Magazine - June 2018 - 12
IEEE Technology and Society Magazine - June 2018 - 13
IEEE Technology and Society Magazine - June 2018 - 14
IEEE Technology and Society Magazine - June 2018 - 15
IEEE Technology and Society Magazine - June 2018 - 16
IEEE Technology and Society Magazine - June 2018 - 17
IEEE Technology and Society Magazine - June 2018 - 18
IEEE Technology and Society Magazine - June 2018 - 19
IEEE Technology and Society Magazine - June 2018 - 20
IEEE Technology and Society Magazine - June 2018 - 21
IEEE Technology and Society Magazine - June 2018 - 22
IEEE Technology and Society Magazine - June 2018 - 23
IEEE Technology and Society Magazine - June 2018 - 24
IEEE Technology and Society Magazine - June 2018 - 25
IEEE Technology and Society Magazine - June 2018 - 26
IEEE Technology and Society Magazine - June 2018 - 27
IEEE Technology and Society Magazine - June 2018 - 28
IEEE Technology and Society Magazine - June 2018 - 29
IEEE Technology and Society Magazine - June 2018 - 30
IEEE Technology and Society Magazine - June 2018 - 31
IEEE Technology and Society Magazine - June 2018 - 32
IEEE Technology and Society Magazine - June 2018 - 33
IEEE Technology and Society Magazine - June 2018 - 34
IEEE Technology and Society Magazine - June 2018 - 35
IEEE Technology and Society Magazine - June 2018 - 36
IEEE Technology and Society Magazine - June 2018 - 37
IEEE Technology and Society Magazine - June 2018 - 38
IEEE Technology and Society Magazine - June 2018 - 39
IEEE Technology and Society Magazine - June 2018 - 40
IEEE Technology and Society Magazine - June 2018 - 41
IEEE Technology and Society Magazine - June 2018 - 42
IEEE Technology and Society Magazine - June 2018 - 43
IEEE Technology and Society Magazine - June 2018 - 44
IEEE Technology and Society Magazine - June 2018 - 45
IEEE Technology and Society Magazine - June 2018 - 46
IEEE Technology and Society Magazine - June 2018 - 47
IEEE Technology and Society Magazine - June 2018 - 48
IEEE Technology and Society Magazine - June 2018 - 49
IEEE Technology and Society Magazine - June 2018 - 50
IEEE Technology and Society Magazine - June 2018 - 51
IEEE Technology and Society Magazine - June 2018 - 52
IEEE Technology and Society Magazine - June 2018 - 53
IEEE Technology and Society Magazine - June 2018 - 54
IEEE Technology and Society Magazine - June 2018 - 55
IEEE Technology and Society Magazine - June 2018 - 56
IEEE Technology and Society Magazine - June 2018 - 57
IEEE Technology and Society Magazine - June 2018 - 58
IEEE Technology and Society Magazine - June 2018 - 59
IEEE Technology and Society Magazine - June 2018 - 60
IEEE Technology and Society Magazine - June 2018 - 61
IEEE Technology and Society Magazine - June 2018 - 62
IEEE Technology and Society Magazine - June 2018 - 63
IEEE Technology and Society Magazine - June 2018 - 64
IEEE Technology and Society Magazine - June 2018 - 65
IEEE Technology and Society Magazine - June 2018 - 66
IEEE Technology and Society Magazine - June 2018 - 67
IEEE Technology and Society Magazine - June 2018 - 68
IEEE Technology and Society Magazine - June 2018 - 69
IEEE Technology and Society Magazine - June 2018 - 70
IEEE Technology and Society Magazine - June 2018 - 71
IEEE Technology and Society Magazine - June 2018 - 72
IEEE Technology and Society Magazine - June 2018 - 73
IEEE Technology and Society Magazine - June 2018 - 74
IEEE Technology and Society Magazine - June 2018 - 75
IEEE Technology and Society Magazine - June 2018 - 76
IEEE Technology and Society Magazine - June 2018 - 77
IEEE Technology and Society Magazine - June 2018 - 78
IEEE Technology and Society Magazine - June 2018 - 79
IEEE Technology and Society Magazine - June 2018 - 80
IEEE Technology and Society Magazine - June 2018 - 81
IEEE Technology and Society Magazine - June 2018 - 82
IEEE Technology and Society Magazine - June 2018 - 83
IEEE Technology and Society Magazine - June 2018 - 84
IEEE Technology and Society Magazine - June 2018 - 85
IEEE Technology and Society Magazine - June 2018 - 86
IEEE Technology and Society Magazine - June 2018 - 87
IEEE Technology and Society Magazine - June 2018 - 88
IEEE Technology and Society Magazine - June 2018 - Cover3
IEEE Technology and Society Magazine - June 2018 - Cover4
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_september2023
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_june2023
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_march2023
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_december2022
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_september2022
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_june2022
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_march2022
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_december2021
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_september2021
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_june2021
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_march2021
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_december2020
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_september2020
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_june2020
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_march2020
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_december2019
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_september2019
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_june2019
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_march2019
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_december2018
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_september2018
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_june2018
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_march2018
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_winter2017
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_fall2017
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_summer2017
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_spring2017
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_winter2016
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_fall2016
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_summer2016
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_spring2016
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_winter2015
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_fall2015
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_summer2015
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_spring2015
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_winter2014
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_fall2014
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_summer2014
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_spring2014
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_winter2013
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_fall2013
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_summer2013
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_spring2013
https://www.nxtbookmedia.com