Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - There’s a Cuckoo in my Nest. Time to Talk About Security for the Internet of Things
Articles

There’s a Cuckoo in my Nest. Time to Talk About Security for the Internet of Things

ISBuzz TeamBy ISBuzz TeamMay 14, 2015Updated:July 30, 20246 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
security for the Internet of Things
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

As the Internet of Things rapidly becomes mainstream, I often wonder whether or not security is a primary concern for the product designers and developers. Time to market is a priority, and “quick and dirty” development leads to technical debt and vulnerabilities in the code. In addition, design of a successful product is top of mind.

Global internet deviceWhile this is certainly an important consideration, I worry that no one is looking out for consumers when it comes to security. Gartner predict that there will be more than 26 billion IoT devices by 2020. This niggling concern led me to research the topic and write this blog. As I dove into the subject, April 1st brought the announcement of the Amazon Dash button. Was this for a fool or for real? Either way, I hope the developers had security up there with the design and ease of use as a priority.

Like most people who work in the technology world, and this covers many different disciplines today, I could not resist deliberately introducing IoT into my life by purchasing and installing a couple of Nest thermostats in my home. As I live in the UK, this was not as easy as it should be, but that is a topic of discussion for a different time. As I was physically installing the Nest (and I say physically because we are so used to technology requiring hardly any physical intervention, apart from the odd USB cable), I had to discover how my central heating system had been wired 20 years ago, and literally hack into it by cutting, splicing and reconnecting cables.

This made me think about the technology embedded in the Nest, and about hacking into it. Working in the security industry, I could not help but start to think about how I could subvert its behavior and I started to sketch out the network architecture evolving in my home. To help me, I installed AlienVault and very quickly I had at my disposal an inventory of all the network assets in my home.

Would it surprise you to know that I found more than thirty assets? As far as I knew we only have a handful of laptops, so where are these thirty network assets and more importantly what are they doing and who are they chatting with? I discovered I had two unidentified Linux devices, and after some investigation, they turned out to be the two Nest thermostats that I had just installed.

As I thought more about the rapid evolution of the Internet of Things, it concerned me that there is a wave of highly sophisticated technology being unleashed on an unsuspecting public, without adequate concern or planning for the security consequences. I see washing machines now that include an Internet connection and I even found a toaster!

If you saw the brilliant Bourne Supremacy film (watch it here), you may remember the scene when Jason Bourne puts a phone directory in the toaster, turns on the gas and quickly leaves the building. Imagine how much easier it would have been if he had been able to hack into the smart meter, gas oven and toaster, all connected to his iPhone? Would this be possible, either by design or by accident? This is a great article that wonders whether or not a connected toaster may over time develop feelings.

Stephen Hawking warns that AI could spell the end of mankind, and it is only a matter of time before Hollywood produces a blockbuster depicting our worst nightmare. More than 100,000 Nests are being sold per month. Could this be one of the largest potential botnets in existence today?

This past weekend the UK switched to summer time, and the evening before I idly wondered whether or not the Nest thermostats would correctly change the time, given that they have access to the Internet. When I woke the next day up I was surprised to find the heating on at the wrong time, despite the correct time being displayed on the Nest. I quickly surmised that there must be a bug in the scheduling software, and not surprisingly there are many online references now to the issue. You can read all about it here.

Yet several days later Nest had not yet issued a patch. As a conscientious energy user, I find this to be a problem, and some people quickly discovered that by changing their location to somewhere in Europe (Belgium seemed to be a popular choice), normal service has been resumed. But if a simple scheduling conflict was overlooked, what does that say for security?

Security researchers from the University of Central Florida have already shown how a Nest can be compromised, and this presentation given at Black Hat 2014 is worth reading. Surprisingly there are a number of basic security concerns highlighted, including the use of HTTP for downloading updates to the Nest and there is a nice video here. No doubt Nest are hard at work resolving these security concerns.

So where does this leave us? As with most security matters, we now know that protection alone is not sufficient and that monitoring must become the cornerstone of any security strategy. This is even more poignant with respect to the deployment of the Internet of Things, because the users will be us and our friends and family. We will be reliant on, and to some extent at the mercy of, the companies selling us the Things. Nest is a good example, but who knows how long it will be before it’s a lorry full of soap powder delivered to your doorstep?

About AlienVault

AlienVault’s mission is to enable organizations with limited resources to accelerate and simplify their ability to detect and respond to the growing landscape of cyber threats. Our Unified Security Management (USM) platform provides all of the essential security controls required for complete security visibility, and is designed to enable any IT or security practitioner to benefit from results on day one. Powered by threat intelligence from AlienVault Labs and the AlienVault Open Threat Exchange—the world’s largest crowd-sourced threat intelligence network — AlienVault USM delivers a unified, simple and affordable solution for threat detection, incident response and compliance management. AlienVault is a privately held company headquartered in Silicon Valley and backed by Trident Capital, Kleiner Perkins Caufield& Byers, GGV Capital, Intel Capital, Sigma West, Adara Venture Partners, Top Tier Capital and Correlation Ventures.

AlienVault, Open Threat Exchange and Unified Security Management are trademarks of AlienVault. All other company and product names mentioned are used only for identification purposes and may be trademarks or registered trademarks of their respective companies.For more information visit www.AlienVault.com

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}