IoT — Why Smart Devices Are a Hole in Your Home
A smart bulb. A smart plug. A smart TV. A smart fridge. Each of them is a potential entry point into your home network.
The scale of the problem — the figures
By 2025 more than 15 billion IoT devices are connected worldwide. By 2030, 30 billion are forecast. Each of them is a computer. Small, cheap, with minimal protection. Connected to your home network. Working 24 hours a day. Often — forgotten and never updated. IoT stands for the Internet of Things. But it would be more accurate to call it the internet of vulnerabilities.
Why IoT devices are so vulnerable
Manufacturers of IoT devices compete on price. The cheaper — the better it sells. Security costs money, so it is cut. Factory passwords. Most IoT devices ship with the same factory password — admin/admin, admin/12345, or no password at all. These passwords are publicly known. Hackers use them in automated brute-force attacks. Lack of updates. The manufacturer released the device — and forgot about it. Security updates do not come out for years. Vulnerabilities accumulate. The device remains on the network with holes that have long been known to attackers. Weak encryption. Many IoT devices transmit data unencrypted — or use outdated encryption protocols that are easy to break. Excessive permissions. A smart bulb requests access to your geolocation. A smart plug connects to a cloud server in China. A smart TV collects data about what you watch. Why? Because data is money. Lack of isolation. By default all devices in your home network see each other. A hacked bulb sees your laptop. A hacked TV sees your smartphone.
How an attack works — the mechanics
Attacks via IoT work by several scenarios. Let us examine each.
Scenario 1 — Direct hacking via the internet
Most home routers have the UPnP (Universal Plug and Play) function, which automatically opens ports for IoT devices. This means the device is accessible from the internet directly. There exist search engines — Shodan, Censys — that scan the whole internet and find connected devices. A hacker enters the query «camera with a factory password» — and gets a list of thousands of devices accessible right now. Then — an automatic brute force of standard passwords. If the password is not changed — the device is hacked in seconds.
Scenario 2 — An attack from inside the network
A hacker gains access to one IoT device — for example through a vulnerability in the firmware. Now they are inside your home network.
From there they can
Scan other devices on the network
Intercept traffic between devices
- Attack the computer or smartphone that are on the same network
Gain access to network storage (NAS)
Use your internet channel for attacks on others
Scenario 3 — A device as a spy
Smart speakers (Amazon Echo, Google Home) constantly listen to the sound in the room. This is their function. But it also means that by hacking the speaker — an attacker gets a permanent microphone in your home. Smart TVs with built-in cameras — the same thing with video. Smart doorbells with a camera — your schedule. When you leave. When you arrive. When no one is home.
Scenario 4 — A botnet
Hacked IoT devices are combined into botnets — networks of infected devices under an attacker’s control. Used for:
DDoS attacks on sites and services
Cryptocurrency mining at the expense of your electricity
Sending spam
Proxying traffic
Your smart bulb mines bitcoin for someone in another country — and you do not know about it.
Real cases — not theory
- The Mirai botnet, 2016. The Mirai virus infected hundreds of thousands of IoT devices around the world — surveillance cameras, DVR recorders, routers. It used standard factory passwords. The botnet it created carried out the largest DDoS attack in history — took down the DNS provider Dyn. As a result, for several hours Twitter, Netflix, Reddit, Spotify and dozens of other large services did not work. The source of the attack was ordinary people’s household devices, which did not even suspect it.
- Casino via an aquarium, 2017. A casino in the US was hacked through a thermometer in a fish tank. The smart thermometer was connected to the casino’s network to monitor the water temperature. Through it the hackers penetrated the internal network and gained access to the database of major players. Through a fish thermometer. Surveillance cameras, constantly. There exist sites that broadcast live streams from thousands of unprotected cameras around the world — home, office, from shops, from children’s rooms. All that is needed — a camera with a factory password connected to the internet. No hacking at all. Just a standard password.
- Smart locks. In 2019 researchers discovered a vulnerability in a popular smart lock that allowed it to be opened without a password via Bluetooth. The manufacturer released an update — but most users did not install it.
- Baby monitors. Dozens of cases are documented where hackers gained access to baby monitors with a camera and talked to children or watched a family. In all cases — the factory password was not changed.
What your devices collect
- This is not paranoia — it is written in the privacy policies. Smart TV: which channels you watch, when you turn it on and off, how long you watch each piece of content. Samsung and LG were fined in the US for collecting viewing data without users’ consent.
- Smart speaker: all voice queries are recorded and stored on servers. Amazon admitted that employees listen to recordings to «improve quality». Google similarly.
- Smart vacuum cleaner: builds a map of your home during cleaning. iRobot (Roomba) was acquired by Amazon in 2022. The maps of your home — with Amazon.
- Fitness band: your pulse, sleep, activity, geolocation every minute of the day. All on the company’s servers. Often — sold to insurance companies.
- Smart doorbell: Ring (owned by Amazon) transmitted doorbell video recordings to the police without the owners’ knowledge and consent. This became public in 2022.
How to protect yourself — concrete steps
Step 1 — A guest network for all IoT devices
This is the most important. Create a separate guest network in the router settings. Connect all IoT devices there — the TV, speakers, vacuum cleaner, bulbs, plugs. The main devices — computer, phone — leave on the main network. Now if an IoT device is hacked — the attacker is in an isolated network and does not see your computer and smartphone. This is done in the settings of any modern router in 10 minutes.
Step 2 — Change the factory passwords
On each IoT device — go into the settings and change the administrator password. At least 12 characters, digits and letters. On the router — change both the Wi-Fi password and the login password for the router settings (these are different passwords).
Step 3 — Turn off UPnP on the router
UPnP automatically opens ports for devices — making them accessible from the internet. Turn off this function in the router settings. Most home devices do not need UPnP.
Step 4 — Update firmware
Regularly check for updates for all IoT devices. Most do this through an app on the phone. Updates close known vulnerabilities. If the manufacturer has stopped releasing updates for a device — that is a signal that the device is time to change or isolate.
Step 5 — Minimise app permissions
The app for a smart bulb requests geolocation? Refuse. The app for a plug wants access to contacts? No. Settings → Apps → select the app → Permissions → turn off everything unnecessary.
Step 6 — Physical isolation of cameras and microphones
A smart speaker in the bedroom is a permanent microphone in the most private space of the home. Consider whether it is needed. A webcam on the TV — cover it when not in use. This is not paranoia — it is hygiene.
Step 7 — Check what is connected to your network
Go into the router settings — the «connected devices» section. Look at the list. Do you know every device in this list? If there are unfamiliar ones — that is a reason to investigate.
GDPR and IoT — your rights
Smart devices collect personal data. GDPR applies. Article 13 — when selling a device the manufacturer is obliged to communicate what data is collected and to whom it is transferred. If there is no such information in the box — a violation. Article 17 — you have the right to demand the deletion of all data that the device sent to the manufacturer’s servers. Article 20 — the right to portability. Your fitness band’s data — is your data. You have the right to receive it in a machine-readable format. Article 25 — devices must be designed with minimal data collection by default. A smart bulb collecting geolocation — a direct violation.
The bottom line
A smart home is convenient. But every «smart» device you add to your home — is a new entry point. A new camera. A new microphone. A new computer you do not control. Manufacturers earn on the data your devices collect. Security is not their priority.
- Your priority — isolation. A guest network. Changing passwords. Minimal permissions. Regular updates. A smart home begins not with smart devices. It begins with a smart owner.
The first step right now
Go into your router settings. Find the «guest network» section. Turn it on. Reconnect the TV, speakers and all the other «smart» devices there. This will take 15 minutes. After this, even if one of your IoT devices is hacked — your computer and phone will remain safe. 15 minutes — and the hole in your network is closed.