Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - 3 Security Problems the IoT will Create — and how to Solve them
Articles

3 Security Problems the IoT will Create — and how to Solve them

ISBuzz TeamBy ISBuzz TeamMay 21, 2015Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Security problems the IoT will create
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The connected world is coming sooner than you think. App developers and mobile service providers are already taking advantage of the new era of connected cars, wearable devices, and entire smart homes — all fitting into the notion of the Internet of Things (IoT).

According to Gartner, there are currently 4.9 billion connected devices in use, with that number projected to soar to 25 billion by 2020.

This sudden expansion will boost the economic impact of the IoT as consumers, businesses, city authorities, hospitals, and many other entities find new ways in which to exploit the technology. Yet, they won’t be alone. Hackers will increasingly target this technology and exploit it in a very different way.

This begs the question, what about IoT makes it such a vulnerable target for cyberattacks? Here are three security problems that IoT will create:

  1. Increasingly Poor Security Design. From a security perspective, IoT devices share some common features with their mobile brethren. Both store, transmit, and process highly sensitive consumer information within potentially hostile environments that manufacturers have no control over. However, mobile software manufacturers can avoid security incidents by moving the processing of sensitive information assets into a more controllable environment like a centralised server that they can reliably connect to.

IoT device manufacturers do not have the same luxury as their mobile counterparts because IoT devices are typically gathering very sensitive information within a physical world and doing some minimal amount of processing of that information within that device before sending that information to a backend server. At the same time, consumers demand highly responsive IoT devices. Hence, IoT manufacturers cannot completely shift the processing of sensitive information to a centralised server. Hackers will have much more reliable opportunity to access and steal information from an IoT device compared to a mobile device due to inherent design flaws.

  1. Increasingly Unaware Environments. IoT devices have substantially less computing power than other devices like PCs and phones. Hence, IoT devices cannot afford to spend precious computing power on additional functionality beyond their core service. Serious malware detection capability within an affordable IoT device is not currently feasible. Hackers will have more opportunity to infect IoT devices and go undetected by the victim compared to infections that occur on mobile of PC devices. There have already been instances where routers, multimedia cents, televisions and at least one refrigerator participated in a spam botnet blast that sent 750,000 emails to unsuspecting victims.
  2. Increasingly Outdated Environments. Many hospitals and doctor’s offices are still running Windows XP, even though that OS is long out of date and subject to serious security flaws. Many industrial controllers are also still running XP, making them potential targets. XP has a notorious history of making security patches difficult to apply.

History has taught us that, when security patches are not automatically downloaded and easy to apply by consumers, consumers are less likely to enforce them. There are several different key technical challenges (limited online availability; restrictions on computer power; limited graphical user interface) that will discourage consumers from enforcing security patches on IoT devices. Hackers will be more likely to exploit known vulnerabilities in these IoT devices because consumers will not apply established security patches.

Beyond a shadow of a doubt, hackers will take advantage of these weaknesses in security, given the opportunity. That leaves a lot of cars, alarm systems, locks and so on open to compromise.

The best and only answer is insisting that designers behind IoT software build security into their systems as a core design requirement. Requirements should include adding new security capabilities that prevent a hacker from conducting static/dynamic analysis of IoT software. Furthermore, IoT software should have runtime modification detection capabilities.

It’s also crucial to involve and educate end users about security and build mechanisms into the device that will help them make the right decisions regarding privacy and security. That means including instructions for secure usage — in layman’s terms.

And, this is where end users need to do their part as well. Hackers count on consumers to make their job easy for them by engaging in insecure online behaviour. Everyone always thinks: “Who would want to hack me?” But today, hacking is more business than personal. If an end user chooses to use an IoT device that collects information, they should quiz the vendor on security certifications and policies, pay close attention for firmware upgrades and carefully inspect any email sent by the vendor with a link in it or asking them to download something.

By  Jonathan Carter, Technical Director, Arxan Technologies (www.arxan.com)

Jonathan CarterBio : Jonathan Carter is an application security professional with more than 15 years of security expertise within Canada, United States, Australia, and England. As a software engineer, Carter produced software for online gaming systems, payment gateways, SMS messaging gateways, and other solutions requiring a high degree of application security. His technical background in artificial intelligence and static code analysis has led him to a diverse number of security roles: Enterprise Security Architect, Web Application Penetration Tester, Fortify Security Researcher, and Security Governance lead.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

AppSec is dead, long live AI security

April 29, 20265 Mins Read

Managing App Access on Frontline Devices in an Always-On World

March 9, 20264 Mins Read

OWASP Top 10 2025: New Enemies, Old Foes, and an Approach to Vulnerability Remediation That Must Evolve

January 22, 20265 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}