The Newest IoT Threat: Child Predators

The Newest IoT Threat: Child Predators

Connected devices at home can record the voices, movements, weight and eating habits of those who live there. They are, in effect, very sophisticated sensors installed in the home environment. As such, they can be utilized by all sorts of people with various motivations and intentions of harming us.

One very common belief about cybersecurity is that the main risks involve criminals stealing something we have -- be it money, information, or identity. Unfortunately, there is even more at stake. We need to be aware that “going online” carries risks even when we are attentive to our digital engagement (ex. securing our passwords, avoiding strangers). Recently, these risks have expanded beyond the security of our online possessions to threaten our personal safety as well.

We know we’re not supposed to post on social media that we are leaving our homes for a long vacation, and we teach our kids about the perils that lurk online, from predators to bullies. However, this understanding (which took years to be acknowledged properly) is limited to the “online” domain, meaning that we know what to do and what not to do when we access the web via our computers or mobile phones.

The problem is that many more connected devices have recently entered our lives, posing new risks to our safety and privacy. Connected devices at home can record the voices, movements, weight and eating habits of those who live there. They are, in effect, very sophisticated sensors installed in the home environment. As such, they can be utilized by all sorts of people with various motivations and intentions of harming us.

Voyeurism

Voyeurs can now remotely tap into connected camera feeds and record imagery of our private homes and lives. Since these images are essentially a live feed filmed without the victims’ awareness, they can be very intimate.  At this point, most parents know that webcams are risky, and either monitor their kids’ behavior around laptops or cover up the webcams altogether.  However, people still seem oblivious to the dangers of connected security cameras, most of which are installed using default passwords that allow even novice hackers to connect to them and view the feed. Some cameras even have built-in vulnerabilities and “backdoors” that enable remote access even if properly configured.  The ability to hack into a camera enables perverts to record, store, sell and distribute sensitive materials, all without the victims’ knowledge.  How is a consumer supposed to know which cameras are the most secure?

Physical harm

The ability to hack into smart, connected devices also means that more motivated predators can stalk their potential victims with the aim of hurting them in real life.  For example, they might use data from video cameras, smart speakers, and smart doors/locks to identify the best time to visit a victim (i.e. when the parents aren’t home).  Moreover, the ability to control a physical actuator means that a hacker can theoretically unlock their victims’ doors and simply wander inside the home. Being in control of the home security system also means that intruders can erase their traces after breaking and entering.  

Child porn storage

A sex offender could also use our devices to store illicit materials, secretly making us liable in assisting a felony.

A recent Demos report states that IoT is creating new opportunities for sex offenders, and the risk is set to grow in the coming years. One of the methods described in the report is the ability of perpetrators to remotely store indecent images of children on connected devices. According to the report:” Unsecured ‘Internet of Things’ devices (such as a ‘smart’ TV) act as ‘safe’ repositories of images, without the knowledge of the device owner.” This reduces the chances of the perpetrators being identified by law enforcement agencies, because the indecent photographs are not, legally speaking, in their possession.

Conclusion

Smarter homes and devices provide comfort and efficiency. On the other hand, they expose us to threats we have never encountered before. We have learned how to stay safe online, and now need to the same for our connected homes. However, we need the help of IoT service providers.  We need them to monitor the behavior of our devices and determine if suspicious behavior is taking place.  Otherwise, we have no way of knowing if, for example, a pervert is uploading files to our smart devices for storage purposes, or a hacker is trying to penetrate a device without authorization.

It is the responsibility of the IoT service provider to flag such activity, notify the device owner and, if need be, mitigate by blocking the device’s access to certain IP addresses. Failing to do so could expose device owners and their families to risks they can’t even imagine.

Featured

  • 91 Percent of Security Leaders Believe AI Set to Outpace Security Teams

    Bugcrowd recently released its “Inside the Mind of a CISO” report, which surveyed hundreds of security leaders around the globe to uncover their perception on AI threats, their top priorities and evolving roles, and common myths directed towards the CISO. Among the findings, 1 in 3 respondents (33%) believed that at least half of companies are willing to sacrifice their customers’ long-term privacy or security to save money. Read Now

  • Milestone Announces Merger With Arcules

    Global video technology company Milestone Systems is pleased to announce that effective July 1, 2024, it will merge with the cloud-based video surveillance solutions provider, Arcules. Read Now

  • Organizations Struggle with Outdated Security Approaches, While Online Threats Increase

    Cloudflare Inc, recently published its State of Application Security 2024 Report. Findings from this year's report reveal that security teams are struggling to keep pace with the risks posed by organizations’ dependency on modern applications—the technology that underpins all of today’s most used sites. The report underscores that the volume of threats stemming from issues in the software supply chain, increasing number of distributed denial of service (DDoS) attacks and malicious bots, often exceed the resources of dedicated application security teams. Read Now

  • Cloud Resources Have Become Biggest Targets for Cyberattacks According to New Research

    Thales recently announced the release of the 2024 Thales Cloud Security Study, its annual assessment on the latest cloud security threats, trends and emerging risks based on a survey of nearly 3000 IT and security professionals across 18 countries in 37 industries. As the use of the cloud continues to be strategically vital to many organizations, cloud resources have become the biggest targets for cyber-attacks, with SaaS applications (31%), Cloud Storage (30%) and Cloud Management Infrastructure (26%) cited as the leading categories of attack. As a result, protecting cloud environments has risen as the top security priority ahead of all other security disciplines. Read Now

Featured Cybersecurity

Webinars

Whitepapers

New Products

  • 4K Video Decoder

    3xLOGIC’s VH-DECODER-4K is perfect for use in organizations of all sizes in diverse vertical sectors such as retail, leisure and hospitality, education and commercial premises. 3

  • HD2055 Modular Barricade

    Delta Scientific’s electric HD2055 modular shallow foundation barricade is tested to ASTM M50/P1 with negative penetration from the vehicle upon impact. With a shallow foundation of only 24 inches, the HD2055 can be installed without worrying about buried power lines and other below grade obstructions. The modular make-up of the barrier also allows you to cover wider roadways by adding additional modules to the system. The HD2055 boasts an Emergency Fast Operation of 1.5 seconds giving the guard ample time to deploy under a high threat situation. 3

  • Luma x20

    Luma x20

    Snap One has announced its popular Luma x20 family of surveillance products now offers even greater security and privacy for home and business owners across the globe by giving them full control over integrators’ system access to view live and recorded video. According to Snap One Product Manager Derek Webb, the new “customer handoff” feature provides enhanced user control after initial installation, allowing the owners to have total privacy while also making it easy to reinstate integrator access when maintenance or assistance is required. This new feature is now available to all Luma x20 users globally. “The Luma x20 family of surveillance solutions provides excellent image and audio capture, and with the new customer handoff feature, it now offers absolute privacy for camera feeds and recordings,” Webb said. “With notifications and integrator access controlled through the powerful OvrC remote system management platform, it’s easy for integrators to give their clients full control of their footage and then to get temporary access from the client for any troubleshooting needs.” 3