The IoT is hugely diverse: home assistants, fitness trackers, medical devices, home security, kid trackers, smart TVs, industrial equipment, crypto wallets, car alarms and even sex toys. We've seen security and privacy failures in nearly all these systems, some trivial, some serious. In today's IoT, security failures in these systems might seem trivial, but in 10 years, these systems will be ruling our lives.
We suspect that the developers of the products failed to predict which threats they needed to protect against. Unless security is considered during the design of these systems, they will never be truly secure.
We'll look at 4 practical examples where lessons can be learned:
- Crypto-wallets that didn't take into account physical access.
- A telematics unit in a car that allowed us to take control of the corporate network.
- An EV car charger that relied on the security of a Raspberry Pi.
- Police body cameras that place confidentiality above authenticity of data.
Hopefully you'll be able to see the mistakes that were made, alongside the simple solutions to these issues.