Skip to main content

U of Michigan, Microsoft researchers question whether a smart home is a safe home

The homes of the 21st century may be smarter than ever, but is that synonymous with safety? The rise of the Internet of Things has given way to a hyperconnected household, where everything from our lights to our sprinkler system to our oven can be controlled by a single hub. Unfortunately, however, this convenience may come at a serious cost. 

New research published by researchers at the University of Michigan and Microsoft sheds new light on the vulnerabilities presented by a smart home platform, offering an alarming look at how seemingly helpful devices could open up a backdoor for malicious hackers and criminals looking to turn everyday objects into outlets for hijacking. Specifically examining Samsung SmartThings, the research team drew two major conclusions. First, that while “SmartThings implements a privilege separation model … SmartApps can be overprivileged,” which is to say that these apps can “gain access to more operations on devices than their functionality requires.”

Recommended Videos

Second, the team says, “the SmartThings event subsystem, which devices use to communicate asynchronously with SmartApps via events, does not sufficiently protect events that carry sensitive information such as lock pincodes.” The implications behind these two findings could lead to a number of different attacks, including secretly planting door lock codes, stealing existing door lock codes, or inducing a fake fire alarm. Taken together or separately, each of these attacks could lead to major consequences for smart home owners.

While the team admits that many of the vulnerabilities they found would take quite a bit of expertise to exploit, the opportunity remains relevant for experienced hackers. And given how much trust we’ve placed in some of these smart home systems, allowing them to lock and unlock our doors, turn off key appliances, and more, caution is key. “If these apps are controlling nonessential things like window shades, I’d be fine with that. But users need to consider whether they’re giving up control of safety-critical devices,” says Earlence Fernandes of the University of Michigan.

Ultimately, experts say, “These software platforms are relatively new. Using them as a hobby is one thing, but they’re not there yet in terms of sensitive tasks. As a homeowner thinking of deploying them, you should consider the worst-case scenario, where a remote hacker has the same capabilities you do, and see if those risks are acceptable.”

Lulu Chang
Fascinated by the effects of technology on human interaction, Lulu believes that if her parents can use your new app…
Echo Show 15 (1st Gen) vs. Echo Show 15 (2nd Gen): What’s new on the updated smart display?
Echo Show 15 on wall.

Amazon has officially discontinued the Echo Show 15 (1st Gen), replacing it with the new and improved Echo Show 15 (2nd Gen). The new device makes a lot of improvements over its predecessor, but it also carries over much of the same functionality. That begs the question -- if you already own an Echo Show 15 (1st Gen), should you upgrade to the Echo Show (2nd Gen)? And what exactly is different about this expensive smart display?

Here's a look at all the new features on the Echo Show 15 (2nd Gen) to help you decide.
Pricing and design

Read more
Host a flawless Thanksgiving with these smart home tips
Philips Hue Smart Dimmable LED Smart Light Recipe Kit lifestyle

Thanksgiving is just around the corner, and if you’re worried about hosting a great party this year, know that your smart home is here to help. We’ve pulled together some simple ways your smart home can be optimized to help you host a flawless Thanksgiving. From building a cozy atmosphere with smart lights to setting Quick Replies on your video doorbell, here’s a look at how your smart home can help throw a stress-free Thanksgiving.
Create a temporary smart lock password

Many smart locks allow you to program temporary passcodes -- and this is an incredibly useful feature when you're hosting. Instead of telling all your guests your permanent passcode, you can create a temporary code that’ll only work on Thanksgiving. This ensures your friends and family can let themselves inside your home if you’re busy without giving them free rein to barge in other times of the year. We’ve put together a comprehensive guide on how to create temporary codes on the Yale Assure Lock 2, but you’ll find a similar process available for most other smart locks.
Use Quick Replies on your video doorbell

Read more
Echo Show 21 vs. Echo Show 15 (2nd Gen): which is best for your smart home?
Amazon's new Echo Show 21 and updated Echo Show 15.

Amazon just released two new smart displays -- the completely new Echo Show 21 and the updated Echo Show 15 (2nd Gen). Both are premium options for your home, offering powerful speakers, Full HD displays, and heaps of useful apps so you can stream videos or check your schedule. But which is the better option? The gigantic Echo Show 21, or the updated Echo Show 15 (2nd Gen)? Here’s a closer look at both to help you decide.
Pricing and design

The Echo Show 21 is the biggest member of the Echo Show family, and it’s got the price tag to prove it. Clocking in at $400, it’s a hefty investment. Its design is pretty premium, however, and it can be either mounted on a wall or placed on a table with an adjustable stand (sold separately). The Echo Show 15 looks much the same, though it’s quite a bit smaller. But from a design standpoint, it’s essentially a shrunken version of the Echo Show 21. It too can be mounted on a wall or placed on a table with an optional adjustable stand. But at $300, it’s much easier on the wallet.

Read more