The smart home tech inside your home is less secure than you think, new Northeastern research finds.

L4sBot@lemmy.worldmod to Technology@lemmy.world – 174 points –
The smart home tech inside your home is less secure than you think, new Northeastern research finds
news.northeastern.edu

The smart home tech inside your home is less secure than you think, new Northeastern research finds.::A team of researchers discovered vulnerabilities in smart home devices made by big technology companies like Google.

34

If you care about this, but still want smart home tech, look into Home Assistant and use local-only devices.

I could also extend that to Tasmota or espHome. They are both open source firmware for IoT devices. They update regularly, and are unlikely to be completely abandoned without warning. While you can flash it to devices yourself, you can also buy a number of devices with it pre-installed.

While I still consider all IoT devices inherently insecure, and treat them as such, these are a lot better than the other random options out there.

no because its not in my home. good luck hacking my mechanical thermostat.

Some skinny dude in a Guy Fawkes mask sneaks in through the dog door and turns up the heat while you're at work

Where'd my kid get a Guy Fawkes mask?

Seriously, though, who cranks the thermostat to 30 and walks out the door?

86F for my fellow Americans.

Thanks for not just assuming I keep my house below freezing!

Point taken. But I don't go anywhere for work lol

Oh no, my good sir, not while you go into work.

While you're at work. If you're WFH, you could be staring at the door, that person is coming through the dog door anyway.

Mr. Doggy Man is going to get a stern lecture I can tell you

Hypponen’s Law: If It’s Smart, It’s Vulnerable

It's as insecure as it appears to be...like I expected.

https://www.candlesmarthome.com/

I just love when developers are so close to a project that they forget to even explain what the thing is. I see this all the time with interesting projects like this.

What is it? Some kind of network device?

Looks like it’s a zigbee network device that is privacy forward, or something.

I know how insecure it is. Its always talking about how it feels sidelined and its feeling are hurt when I throw it in the trash.

The vast majority of this stuff should be called "dumb devices", as in "dumb terminal".