Researchers have found that security gaps in smart bulbs can expose consumers to hacks.
Oct. 22, 2019 — Smart bulbs are expected to be a popular purchase this holiday season. But could lighting your home open up your personal information to hackers?
Earlier this year Amazon’s Echo made global headlines when it was reported that consumers’ conversations were recorded and heard by thousands of employees.
Now researchers at UTSA have conducted a review of the security holes that exist in popular smart-light brands. According to the analysis, the next prime target could be that smart bulb that shoppers buy this coming holiday season.
“Your smart bulb could come equipped with infrared capabilities, and most users don’t know that the invisible wave spectrum can be controlled. You can misuse those lights,” said Murtuza Jadliwala, professor and director of the Security, Privacy, Trust and Ethics in Computing Research Lab in UTSA’s Department of Computer Science. “Any data can be stolen: texts or images. Anything that is stored in a computer.”
Some smart bulbs connect to a home network without needing a smart home hub, a centralized hardware or software device where other internet of things products communicate with each other. Smart home hubs, which connect either locally or to the cloud, are useful for IoT devices that use the Zigbee or Z-Wave protocols or Bluetooth, rather than Wi-Fi.
If these same bulbs are also infrared-enabled, hackers can send commands via the infrared invisible light emanated from the bulbs to either steal data or spoof other connected IoT devices on the home network. The owner might not know about the hack because the hacking commands are communicated within the owner’s home Wi-Fi network, without using the internet.
This study, titled “Light Ears: Information Leakage via Smart Lights,” was coauthored by Anindya Maiti and published in the September 2019 issue of the journal Proceedings of the ACM on Interactive, Mobile, Wearable and Ubiquitous Technologies.
Smart bulbs have moved beyond novelty to a lucrative mature market. Last year consumers spent close to $8 billion, and that amount is expected to more than triple to $28 billion in less than a decade.
“Think of the bulb as another computer,” adds Jadliwala. “These bulbs are now poised to become a much more attractive target for exploitation even though they have very simple chips.”
Jadliwala recommends that consumers opt for bulbs that come with a smart home hub rather than those that connect directly to other devices. He also recommends that manufacturers do a better job in developing security measures to limit the level of access that these bulbs have to other smart home appliances or electronics within a home.
Learn more about the Security, Privacy, Trust and Ethics in Computing Research Lab.
Celebrate UTSA’s 50th anniversary year and share social media posts about the 50th using the hashtag #UTSA50.
Connect with UTSA online at Facebook, Twitter, YouTube, Instagram and LinkedIn.
UTSA Today is produced by University Communications and Marketing, the official news source of The University of Texas at San Antonio. Send your feedback to news@utsa.edu. Keep up-to-date on UTSA news by visiting UTSA Today. Connect with UTSA online at Facebook, Twitter, Youtube and Instagram.
Día en la Sombrilla, formerly Fiesta UTSA, is a festival hosted each spring as a part of Fiesta® San Antonio events. Sponsored by Roadrunner Productions, the event features music, food, confetti, games, event t-shirts, and more.
Sombrilla Plaza, Main CampusCovidence is a systematic & scoping review tool used to streamline the process of screening and reviewing articles. Using this software, research teams can easily import studies, perform automatic deduplication, and extract data using templates. This workshop will show attendees how to start a review in Covidence, add collaborators, and get started on screening.
Virtual (Zoom)In this workshop, attendees will be introduced to Pandas, a Python tool for working with data easily. It makes it simple to organize and analyze information when data is organized and categorized, like spreadsheets or tables.
Group Spot B, John Peace LibraryEach fall and spring semester, students convene at the Main Campus at UTSA with booths, ideas and prototypes. A crowd of judges, local organizations, students, faculty and sponsors walk around and talk to the students about their projects and ask questions. Students get the real-life experience of "pitching" their project with hopes of getting funding or support to move to the next level.
UTSA Convocation Center, Main CampusJoin the doctoral candidates for the Doctoral Conferreal Ceremony and celebrate their accomplishments.
Arts Building Recital Hall, Main CampusCelebrate the graduates from the Carlos Alvarez College of Business, College of Education and Human Development, Margie and Bill Klesse College of Engineering and Integrated Design and University College.
AlamodomeCelebrate the graduates from the College for Health, Community and Policy, College of Liberal and Fine Arts and College of Sciences.
AlamodomeThe University of Texas at San Antonio is dedicated to the advancement of knowledge through research and discovery, teaching and learning, community engagement and public service. As an institution of access and excellence, UTSA embraces multicultural traditions and serves as a center for intellectual and creative resources as well as a catalyst for socioeconomic development and the commercialization of intellectual property - for Texas, the nation and the world.
To be a premier public research university, providing access to educational excellence and preparing citizen leaders for the global environment.
We encourage an environment of dialogue and discovery, where integrity, excellence, respect, collaboration and innovation are fostered.