Skip to main content

Installing Osram Lightify smart bulbs could gift wrap your Wi-Fi password to hackers

osram smart bulbs vulnerable to hacks osram2
Osram
Like a setting out of a horror movie, a recent discovery of potential security flaws in Osram’s Lightify smart light bulbs may give hackers the ability to remotely operate a user’s lights, and even control their network, without asking for approval. Perhaps even more critical, the vulnerabilities — of which nine were found by a security researcher at Rapid7 — could also give unwanted visitors access to a home’s Wi-Fi network. Deral Heiland, the researcher who happened upon the cracks in Osram’s armor, has reportedly informed the manufacturer of the flaws, and has stated that a simple software update coming out in August should fix the problem.

Of the nine vulnerabilities found by Heiland, the one likely responsible for the bulk of the problem lies with the smart bulb’s companion application, which stores unencrypted copies of an owner’s Wi-Fi password. Because of this, hackers could easily obtain this information via the app, which would grant them access to anything connected to the Wi-Fi network. In other words, this is bad.

“This is not just about being able to manipulate the light bulbs,” said University College London cybersecurity expert, Professor Angela Sasse. “The vulnerabilities here could give somebody access to control the network itself and that’s a very serious issue. In this day and age, you would regard that as an unacceptable security flaw. It’s a well known thing that you don’t store passwords like that — it’s really elementary.”

Currently, the company says it continues to analyze potential issues with its products and that most of the flaws will likely be resolved come August. For the remaining risks — which reportedly surround the companion ZigBee Hub — the company says it’s working to find a way to develop yet another patch, though it’s uncertain what the patch would actually target.

As smart home technology continues to grow, one of the most important aspects consumers look for is a device’s built-in security. Unfortunately for Osram, until it fixes its issue of unencrypted Wi-Fi passwords, it’s likely few people will be knocking down its door to install a Lightify system.

Editors' Recommendations

Rick Stella
Former Digital Trends Contributor
Rick became enamored with technology the moment his parents got him an original NES for Christmas in 1991. And as they say…
Adorable smart home robot unveiled at CES 2023 could be a great addition to your family
A child playing with the EBO X.

Every January, CES brings us a laundry list of innovative, intriguing products that’ll probably never see the light of day. Enabot, an under-the-radar robot company, seems to be bucking that trend at CES 2023, with its impressive EBO X smart home robot offering up dozens of futuristic features and a release date planned for the second quarter of this year.

EBO X is an adorable smart home robot that serves multiple purposes in your household. After mapping its surroundings, the self-balancing, two-wheeled companion can follow you around your home, provide two-way communication through its 4K camera, pump out music via its Harman speakers, sync with other Alexa devices, and provide security alerts while you’re away.

Read more
Nanoleaf reveals new Matter-enabled smart lights at CES 2023
The Nanoleaf 4D TV syncing lights to the colors on TV.

Nanoleaf, a manufacturer of smart lights, introduced several new products to its lineup during CES 2023. The most exciting addition is the Nanoleaf Skylight, which mounts onto your ceiling to provide an impressive array of light shows. It’s also completely modular and can be arranged into a variety of shapes to fit every space in your home.

The Skylight connects to your smart ecosystem through Wi-Fi and works with Matter -- meaning you shouldn’t run into any compatibility issues with your current setup. The modular ceiling fixture can produce more than 16 million colors, its brightness can be adjusted through the accompanying smartphone app, and you can even set schedules to automatically adjust its settings throughout the day. The only downside? It won’t be launching for quite a while, with an expected release date in the third quarter of 2023.

Read more
TP Link launches budget-friendly smart light strips
TP-Link lights glowing pink behind a computer monitor.

TP-Link, a company known for producing affordable smart home gadgets, has announced a new lineup of smart LED light strips and light bulbs. This includes the Tapo L900, Tapo L920, Tapo L930, and Tapo L530E. Pricing for the products ranges from $25 to $50, making these some of the most affordable lighting options on the market.

The Tapo L930 is considered the flagship LED strip of the family, offering advanced features such as music sync mode, 16 million colors, up to 1000 lumens of white light, and an IP44 waterproof rating. You can also set up a personalized lighting schedule using the accompanying smartphone app. Amazon Alexa, Google Assistant, and Apple HomeKit are all supported by the L930. A 16.4-foot roll costs $50, making it a cheap way to get surprisingly versatile smart lights into your home.

Read more