Researchers at North Carolina State University have found design flaws in smart home devices that allow third parties to prevent security systems from signaling a home break-in or from uploading a video of intruders.
The devices were designed with the assumption that wireless connectivity is secure and won’t be disrupted — something that is not guaranteed. If third parties can hack a home’s router, malware can be uploaded that blocks signals from relaying if a motion sensor is activated. These attacks can also be done on-site or remotely.
One potential fix would be to make signals indistinguishable from other signals, so malware would not selectively allow a specific signal to pass through. Another approach would be to include more information in the security signal so if a device sends three motion sensor alerts, the signal would include data noting three sensor alerts had been sent even if malware is there to block sensor signals. This would allow a notification to still be sent to the homeowner.
Getting hacked is one of the primary concerns of Americans when it comes to smart home devices, but it isn’t stopping consumers from buying the devices. The market for smart home devices is expected to grow at a compound annual growth rate (CAGR) of 18.5% with the market doubling to 939.7 million devices shipped in 2022, up from 433.1 million devices in 2017, according to market research firm IDC Corp.
"IoT devices are becoming increasingly common, and there's an expectation that they can contribute to our safety and security," said William Enck, an associate professor of computer science at NC State. "But we've found that there are widespread flaws in the design of these devices that can prevent them from notifying homeowners about problems or performing other security functions."
"No system is going to be perfect, but given the widespread adoption of IoT devices, we think it's important to raise awareness of countermeasures that device designers can use to reduce their exposure to attacks," Enck said.
