Endpoint

1/11/2018
02:00 PM
Ryan Barrett
Ryan Barrett
Commentary
Connect Directly
Twitter
LinkedIn
RSS
E-Mail vvv
100%
0%

Privacy: The Dark Side of the Internet of Things

Before letting an IoT device into your business or home, consider what data is being collected and where it is going.

There's a lot of buzz about the Internet of Things (IoT), but people aren't quite sure what to think of it. Back in fall 2016, there was a big attack on an Internet service provider in which a bunch of IoT devices became a botnet and made much of the Internet unavailable. It was a big moment that made people question the security of IoT. And although security risks are getting the headlines right now, and should certainly be considered, the bigger risk with IoT is privacy.

It is going to be so cheap and so easy for manufacturers to put Wi-Fi-connected chips into practically every device we use in our homes and businesses that IoT will become hard to avoid. Combine low costs with the incentives that companies have to collect data on user behavior, and things start to feel creepy. For example, imagine your oven, your refrigerator, or your microwave has data-collecting chips in it, purporting to provide a benefit to you if the device is connected to the Internet (your incentive). The cost is next to nothing for the manufacturer to collect the usage data, from the time of day you use it to how long you use it or what's being prepared, and combine it with information you may have voluntarily provided when you signed up, such as what city you live in and your household income. People aren't going to take notice of this until something bad happens — and I predict that it will.

While these connected devices are collecting all this data without you knowing it, or how it's being used, most people are thinking about features and colors. People aren't thinking about the privacy component, and that's a problem.

The Risk to Business
The potential risk is even greater for businesses that bring IoT devices into their companies. Consumers might get creeped out to think about their personal devices monitoring them and listening to their conversations, but businesses aren't really thinking about the risks from this perspective. Before deploying connected devices within your organization, pause and think about what kind of data is being collected and where it is going. For businesses that value their privacy, this can be a real liability. 

The owners of the corner coffee shop are purchasing home-security-grade devices to better monitor and protect their business. Almost instantly, the system is connected to their Wi-Fi network. But the business owners aren't thinking about the potential ramifications should they lose control over that device, if it isn't secure. If the device is hacked, cybercriminals can monitor customer traffic and flow, and even zoom in on credit card numbers if the camera is near the cash register.

The risk doesn't end with small businesses. From the midsize perspective, these businesses are utilizing things such as smart TVs. Often smart TVs are connected to a Wi-Fi network to display analytics and statistics, but you'd be surprised at how often those TVs are connecting back to their manufacturers to gather advertising information and your usage statistics. Some of the new TVs have webcams on them with incorporated microphones. And then there are cameras in the lobby. All this private business data about when and where people are coming and going and what they are doing is being recorded in the cloud, protected only by a password.

Think First
I am not saying that you shouldn't let IoT devices into your home or business. I'm point is that people need to think about a few things first before they invite these devices into their lives, and make a conscious, risk-aware decision.

Weigh the benefits against the risks when it comes to purchasing Internet-connected devices. Is the risk worth it if the data got into the wrong hands? If the data is stored in the cloud, make sure you are using long and strong passphrases and enable two-factor authentication everywhere you can. Keep the devices secure, keep their software updated, and protect the data they produce (if you can).

Lastly, be aware of what information you are giving away, by reading the privacy policies of the manufacturers of the IoT device. If they are collecting your data, they legally have to disclose it.

The prospects of IoT are undeniably vast. No one knows where the industry is going to go or what is going to happen. My advice? Venture into this exciting new world with eyes wide open.

Related Content:

Ryan Barrett, VP of Security and Privacy at Intermedia, has more than a decade of experience in data security and IT leadership. Prior to Intermedia, Barrett has been integral in security with enterprises such as Qualys and WebEx, where he helped build out the original ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
ArlenWilliams
50%
50%
ArlenWilliams,
User Rank: Apprentice
1/12/2018 | 12:55:58 PM
What if?
What if violating our privacy were one of the primary reasons for the IOT in the first place?

Whose technology was the Internet in the first place?

Why would we think they ever let go of it?

"#DOD #USIC #NSA #DIA #CIA #DOJ #MashUp"

 
Microsoft President: Governments Must Cooperate on Cybersecurity
Kelly Sheridan, Staff Editor, Dark Reading,  11/8/2018
To Click or Not to Click: The Answer Is Easy
Kowsik Guruswamy, Chief Technology Officer at Menlo Security,  11/14/2018
Veterans Find New Roles in Enterprise Cybersecurity
Kelly Sheridan, Staff Editor, Dark Reading,  11/12/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Online Malware and Threats: A Profile of Today's Security Posture
Online Malware and Threats: A Profile of Today's Security Posture
This report offers insight on how security professionals plan to invest in cybersecurity, and how they are prioritizing their resources. Find out what your peers have planned today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-19279
PUBLISHED: 2018-11-14
PRIMX ZoneCentral before 6.1.2236 on Windows sometimes leaks the plaintext of NTFS files. On non-SSD devices, this is limited to a 5-second window and file sizes less than 600 bytes. The effect on SSD devices may be greater.
CVE-2018-19280
PUBLISHED: 2018-11-14
Centreon 3.4.x has XSS via the resource name or macro expression of a poller macro.
CVE-2018-19281
PUBLISHED: 2018-11-14
Centreon 3.4.x allows SNMP trap SQL Injection.
CVE-2018-17960
PUBLISHED: 2018-11-14
CKEditor 4.x before 4.11.0 allows user-assisted XSS involving a source-mode paste.
CVE-2018-19278
PUBLISHED: 2018-11-14
Buffer overflow in DNS SRV and NAPTR lookups in Digium Asterisk 15.x before 15.6.2 and 16.x before 16.0.1 allows remote attackers to crash Asterisk via a specially crafted DNS SRV or NAPTR response, because a buffer size is supposed to match an expanded length but actually matches a compressed lengt...