Hacked Light Bulbs Can Reveal Your Wi-Fi Password

Hacked Light Bulbs Can Reveal Your Wi-Fi Password

It’s all the new craze: the connected or smart home, where at the touch of a button on your smartphone you can dim your living room lights, close the garage door, let the housekeeper into your home because she forgot her key and turn off the water should there be a leak, all while keeping a live, virtual eye on your property. But, with sophisticated technology comes risk if you aren’t vigilant in applying the latest security updates to your smart home. In fact, the latest risk involves LED light bulbs that can be hacked to change the lighting and reveal the homeowner’s Wi-Fi Internet password.

Hacked Light Bulbs Can Reveal Your Wi-Fi PasswordResearchers at Context Information Security were intrigued by LIFX light bulb systems because these LED bulbs use new wireless network protocols, operating on the 802.15.4 6 LoWPAN wireless mesh network, built upon the same base standard used by Zigbee. For the homeowner, they work just like regular light bulbs, simply screw them in; but, with LIFX, the homeowner can also control them from a downloadable smartphone app.

Context Information Security found that “LIFX’ mesh network protocol was largely unencrypted, which allowed them to easily crop messages to control the light bulbs and replay arbitrary packet payloads.” By monitoring these packets, researchers found that when new light bulbs are added, messages are transmitted from the master bulb containing Wi-Fi details. All a hacker has to do is request these details from the master bulb because no alarms were raised within the system.  

Ultimately, researchers were able to identify what encryption code there was and inject packets into the network.

LIFX has since released a firmware update in to fix the problem, but non-updated users remain unprotected.

Even though a hacker would have to be within less than 25 yards to make a hack successful, this demonstrates that the need for cyber security is expanding into our homes.

About the Author

Ginger Hill is Group Social Media Manager.

Featured

New Products

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file.

  • Luma x20

    Luma x20

    Snap One has announced its popular Luma x20 family of surveillance products now offers even greater security and privacy for home and business owners across the globe by giving them full control over integrators’ system access to view live and recorded video. According to Snap One Product Manager Derek Webb, the new “customer handoff” feature provides enhanced user control after initial installation, allowing the owners to have total privacy while also making it easy to reinstate integrator access when maintenance or assistance is required. This new feature is now available to all Luma x20 users globally. “The Luma x20 family of surveillance solutions provides excellent image and audio capture, and with the new customer handoff feature, it now offers absolute privacy for camera feeds and recordings,” Webb said. “With notifications and integrator access controlled through the powerful OvrC remote system management platform, it’s easy for integrators to give their clients full control of their footage and then to get temporary access from the client for any troubleshooting needs.”

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area.