Endpoint

1/11/2018
02:00 PM
Ryan Barrett
Ryan Barrett
Commentary
Connect Directly
Twitter
LinkedIn
RSS
E-Mail vvv
100%
0%

Privacy: The Dark Side of the Internet of Things

Before letting an IoT device into your business or home, consider what data is being collected and where it is going.

There's a lot of buzz about the Internet of Things (IoT), but people aren't quite sure what to think of it. Back in fall 2016, there was a big attack on an Internet service provider in which a bunch of IoT devices became a botnet and made much of the Internet unavailable. It was a big moment that made people question the security of IoT. And although security risks are getting the headlines right now, and should certainly be considered, the bigger risk with IoT is privacy.

It is going to be so cheap and so easy for manufacturers to put Wi-Fi-connected chips into practically every device we use in our homes and businesses that IoT will become hard to avoid. Combine low costs with the incentives that companies have to collect data on user behavior, and things start to feel creepy. For example, imagine your oven, your refrigerator, or your microwave has data-collecting chips in it, purporting to provide a benefit to you if the device is connected to the Internet (your incentive). The cost is next to nothing for the manufacturer to collect the usage data, from the time of day you use it to how long you use it or what's being prepared, and combine it with information you may have voluntarily provided when you signed up, such as what city you live in and your household income. People aren't going to take notice of this until something bad happens — and I predict that it will.

While these connected devices are collecting all this data without you knowing it, or how it's being used, most people are thinking about features and colors. People aren't thinking about the privacy component, and that's a problem.

The Risk to Business
The potential risk is even greater for businesses that bring IoT devices into their companies. Consumers might get creeped out to think about their personal devices monitoring them and listening to their conversations, but businesses aren't really thinking about the risks from this perspective. Before deploying connected devices within your organization, pause and think about what kind of data is being collected and where it is going. For businesses that value their privacy, this can be a real liability. 

The owners of the corner coffee shop are purchasing home-security-grade devices to better monitor and protect their business. Almost instantly, the system is connected to their Wi-Fi network. But the business owners aren't thinking about the potential ramifications should they lose control over that device, if it isn't secure. If the device is hacked, cybercriminals can monitor customer traffic and flow, and even zoom in on credit card numbers if the camera is near the cash register.

The risk doesn't end with small businesses. From the midsize perspective, these businesses are utilizing things such as smart TVs. Often smart TVs are connected to a Wi-Fi network to display analytics and statistics, but you'd be surprised at how often those TVs are connecting back to their manufacturers to gather advertising information and your usage statistics. Some of the new TVs have webcams on them with incorporated microphones. And then there are cameras in the lobby. All this private business data about when and where people are coming and going and what they are doing is being recorded in the cloud, protected only by a password.

Think First
I am not saying that you shouldn't let IoT devices into your home or business. I'm point is that people need to think about a few things first before they invite these devices into their lives, and make a conscious, risk-aware decision.

Weigh the benefits against the risks when it comes to purchasing Internet-connected devices. Is the risk worth it if the data got into the wrong hands? If the data is stored in the cloud, make sure you are using long and strong passphrases and enable two-factor authentication everywhere you can. Keep the devices secure, keep their software updated, and protect the data they produce (if you can).

Lastly, be aware of what information you are giving away, by reading the privacy policies of the manufacturers of the IoT device. If they are collecting your data, they legally have to disclose it.

The prospects of IoT are undeniably vast. No one knows where the industry is going to go or what is going to happen. My advice? Venture into this exciting new world with eyes wide open.

Related Content:

Ryan Barrett, VP of Security and Privacy at Intermedia, has more than a decade of experience in data security and IT leadership. Prior to Intermedia, Barrett has been integral in security with enterprises such as Qualys and WebEx, where he helped build out the original ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
ArlenWilliams
50%
50%
ArlenWilliams,
User Rank: Apprentice
1/12/2018 | 12:55:58 PM
What if?
What if violating our privacy were one of the primary reasons for the IOT in the first place?

Whose technology was the Internet in the first place?

Why would we think they ever let go of it?

"#DOD #USIC #NSA #DIA #CIA #DOJ #MashUp"

 
WSJ Report: Facebook Breach the Work of Spammers, Not Nation-State Actors
Curtis Franklin Jr., Senior Editor at Dark Reading,  10/19/2018
The Browser Is the New Endpoint
Rajesh Ranganathan, Product Manager at ManageEngine,  10/23/2018
Good Times in Security Come When You Least Expect Them
Joshua Goldfarb, Co-founder & Chief Product Officer, IDRRA ,  10/23/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
The Risk Management Struggle
The Risk Management Struggle
The majority of organizations are struggling to implement a risk-based approach to security even though risk reduction has become the primary metric for measuring the effectiveness of enterprise security strategies. Read the report and get more details today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-10839
PUBLISHED: 2018-10-16
Qemu emulator <= 3.0.0 built with the NE2000 NIC emulation support is vulnerable to an integer overflow, which could lead to buffer overflow issue. It could occur when receiving packets over the network. A user inside guest could use this flaw to crash the Qemu process resulting in DoS.
CVE-2018-13399
PUBLISHED: 2018-10-16
The Microsoft Windows Installer for Atlassian Fisheye and Crucible before version 4.6.1 allows local attackers to escalate privileges because of weak permissions on the installation directory.
CVE-2018-18381
PUBLISHED: 2018-10-16
Z-BlogPHP 1.5.2.1935 (Zero) has a stored XSS Vulnerability in zb_system/function/c_system_admin.php via the Content-Type header during the uploading of image attachments.
CVE-2018-18382
PUBLISHED: 2018-10-16
Advanced HRM 1.6 allows Remote Code Execution via PHP code in a .php file to the user/update-user-avatar URI, which can be accessed through an "Update Profile" "Change Picture" (aka user/edit-profile) action.
CVE-2018-18374
PUBLISHED: 2018-10-16
XSS exists in the MetInfo 6.1.2 admin/index.php page via the anyid parameter.