Skip to main content

U of Michigan, Microsoft researchers question whether a smart home is a safe home

smart home safety 35 million pool
Sotheby's
The homes of the 21st century may be smarter than ever, but is that synonymous with safety? The rise of the Internet of Things has given way to a hyperconnected household, where everything from our lights to our sprinkler system to our oven can be controlled by a single hub. Unfortunately, however, this convenience may come at a serious cost. 

New research published by researchers at the University of Michigan and Microsoft sheds new light on the vulnerabilities presented by a smart home platform, offering an alarming look at how seemingly helpful devices could open up a backdoor for malicious hackers and criminals looking to turn everyday objects into outlets for hijacking. Specifically examining Samsung SmartThings, the research team drew two major conclusions. First, that while “SmartThings implements a privilege separation model … SmartApps can be overprivileged,” which is to say that these apps can “gain access to more operations on devices than their functionality requires.”

Second, the team says, “the SmartThings event subsystem, which devices use to communicate asynchronously with SmartApps via events, does not sufficiently protect events that carry sensitive information such as lock pincodes.” The implications behind these two findings could lead to a number of different attacks, including secretly planting door lock codes, stealing existing door lock codes, or inducing a fake fire alarm. Taken together or separately, each of these attacks could lead to major consequences for smart home owners.

While the team admits that many of the vulnerabilities they found would take quite a bit of expertise to exploit, the opportunity remains relevant for experienced hackers. And given how much trust we’ve placed in some of these smart home systems, allowing them to lock and unlock our doors, turn off key appliances, and more, caution is key. “If these apps are controlling nonessential things like window shades, I’d be fine with that. But users need to consider whether they’re giving up control of safety-critical devices,” says Earlence Fernandes of the University of Michigan.

Ultimately, experts say, “These software platforms are relatively new. Using them as a hobby is one thing, but they’re not there yet in terms of sensitive tasks. As a homeowner thinking of deploying them, you should consider the worst-case scenario, where a remote hacker has the same capabilities you do, and see if those risks are acceptable.”

Editors' Recommendations

Lulu Chang
Former Digital Trends Contributor
Fascinated by the effects of technology on human interaction, Lulu believes that if her parents can use your new app…
How to convert your window blinds into smart blinds

Smart homes are more popular than ever, with companies like Google, Amazon, Ring, Arlo, and other big brands churning out new products at regular intervals. Most people have heard of smart displays and smart light bulbs -- but smart blinds are yet to gain the same traction as these other categories.

However, smart blinds can become an integral part of any smart home. Along with giving you an easy way to manipulate your shades, they can help you save money by allowing (or limiting) light to enter your home and moderate its temperature.

Read more
Home Depot’s Hubspace is a great way to start building your smart home
The Hubspace app shown in front of a living room.

Building a smart home can be intimidating. Not only do you have to figure out which products are best for your needs, but you also need to set them up using an accompanying mobile app and sync them with the rest of your gadgets. It's all a bit confusing for smart home newcomers -- but Home Depot has largely streamlined the process with its Hubspace platform.

Billed as a "smart home platform that makes smart home products easy to set up and control," it sounds like a great fit for smart home newbies. And after going hands-on with a few products in its growing lineup, I can say it definitely hits all the right notes.
Streamlined and simple

Read more
Google rolls out new Nest Cam features to Google Home for web
Nest Cams on a counter.

While many users access Google Home on their smartphone or smart display, the platform is also available via web browser. The web-based Google Home experience wasn't exactly the best way to access your smart devices, but that's rapidly changing as Google rolls out new updates to the client -- the latest of which adds a ton of new ways to access your Nest Cams.

Google began rolling out the update late last week, and most users should now have access to the improved Google Home for web experience. The big draw is access to your Nest Cam history and the option to download clips. Prior to this update, it was impossible to view recorded clips via Google Home for web, forcing you to instead jump into the official Google Home app.

Read more