What’s the Case for Home IoT?

Goneywell LyricSome of the biggest names in tech have invested heavily into the Internet of Things for the home. But when I look around the marketplace and among people I know, almost nobody is yet using any of this technology. In fact, several recent polls have shown that over half of the people in the country haven’t yet even heard of IoT. This leads me to ask if there is yet a business case for home IoT.

The initial promise of home IoT is that it will make our life easier. The picture painted by the industry is one of having scores of smart devices in the home that all act in harmony to make daily life easier. I’m a huge fan of Star Trek and I look at their future with automatic doors and lights, background music, holodecks, and food replicators and I get it – and I want it.

But the IoT devices on the market today are still a long way away from that Star Trek future. The reality of the situation is that this is an industry that so far only caters to geeks and hobbyists. Today the technology involves buying some sort of central console and then connecting all of your devices to the hub. That alone looks like a lot of work. There are also no standards in the industry and each of the many hubs is proprietary, so you have to worry if a new device you buy will even work with the hub you selected.

Samsung has taken perhaps the first step to pull this all together. They bought a startup called SmartThings that has developed a hub that is controlled entirely by smartphone. Samsung is then developing their whole suite of products to work with this hub.

But I don’t think even the Samsung solution is going to make much of a difference. Just consider smart lights as an example. My house easily has fifty light bulbs, maybe more. Upgrading them all to smart lights sounds extravagantly expensive. And then I am imagining trying to use the smartphone to control my lights. In the time I could fish through a menu and find the right lights to adjust I could have just changed them manually and gone on to do what I was doing. The smartphone idea certainly provides a central way to control everything, but has it really made life easier than today? Unless this works a whole lot easier than I imagine it, what I’ve done is to create a new chore for myself whenever I want to do something simple like dim a light. Unless I’m bedridden, the manual way still requires less effort than a smartphone.

And that is the big catch right now for the industry. They are coming out with devices that do all sorts of neat things, but they have not made life easier. Consider energy management. Programmable thermostats have been around for years and it’s been relatively easy to lower the heat while you sleep or to tone back the air conditioning when you are away at work. The newer smart thermostats go a step farther and help you understand your electric usage in detail so that you can save even more money than with a programmable thermostat. But in doing so they have not made life easier, they have instead created a new monthly chore, which is to interpret the data coming out of the energy monitoring system and then make changes in the way you use electricity. My electric bill is pretty affordable, and so I might be doing all of this new effort to save $20–40 dollars per month. That is certainly a good thing, and it’s probably the right social thing to do, but it is not compelling enough for me to add a new task into my already busy life.

I am guessing that home IoT isn’t going to really go very far until the whole system is smart, like in Star Trek. When I can sit in a room and say, “Dim lights” and it happens, then we are starting to get somewhere. When I can tell my house to play a certain piece of music and then have that music follow me around from room to room, then we are getting somewhere. That sounds like something that almost everybody is going to want, assuming it’s affordable, and assuming it doesn’t take too much effort to set it up and to make work.

That day will come. It’s going to require both better language interfaces that always understand me (something that is improving rapidly) as well as a computer assistant that is smart enough to know what I want and to be able to turn my wishes into real world events. And that is going to take smarter and more powerful computers, something that is also coming soon.

But until then I can’t make a case for home IoT in my own home. I’ve considered a smart security system and video monitoring, and that is likely to be the first thing I might buy. But most of the other things on the market seem to be more work than the satisfaction they will produce. Until that equation flips I am not yet sold, and I don’t think I am unusual in this.

Security and the IoT

One of my regular readers, Zora Lopez, created the document below that lists a lot of interesting facts about the current state of security and the Internet of Things. Her diagram stands pretty well on its own and so I won’t describe it, but there are a few facts on the diagram that I find very interesting:

  • Looking out to 2020 is shows that consumer IoT is only a small slice of the total market. I’ve seen comments asking if the IoT industry can be successful by selling smart thermostats. The answer is that they don’t have to, and the industry is much larger than that and mostly driven by businesses.
  • There are already almost 5 billion IoT devices connected across the world, nearly one for every person on the planet.
  • One scary thing on the list is the black market value from stealing personal data. An older credit card number is worth $5 on the black market while a newly issued one is worth $32. Bank accounts and Paypal account info is worth $27. These numbers show why it pays to be a hacker.

Security and the Internet of Things
Source: ComputerScienceZone.org

Barriers to Home IoT

HouseThe early IoT industry has been busy making smart thermostats and monitors of all kinds for homes, but the industry so far has not done as well as some industry analysts predicted. I think there are a number of barriers that have to be overcome for this to become a widespread technology.

Ease of Installation. Ideally you could buy an IoT device, take it out of the box, push a button, and it would work. But there are almost no devices yet like that, and many devices will never work like that. Hooking up a thermostat and many other smart devices means electrical wiring work and most people aren’t comfortable doing this on their own and are not always ready to pay an electrician to do this for an IoT device. Putting in smart door lock means changing out the old one, and anybody who ever changed a door lock knows that it is never as easy as it ought to be.

Ease of Connection. Even after you install most current IoT devices you aren’t done; you next have to connect them to your home network. We are not yet at a time when a device can self-configure, and perhaps we never want it to be that easy since a device that can do that can also be easily hacked to reconfigure. But if you think people are uncomfortable wiring a thermostat, there are just as many people who are uncomfortable messing with the settings on their home WiFi networks.

Fear of Hacking. It doesn’t take very much web research about home IoT devices to run into articles about the lack of security in these devices today. People don’t want an outsider to be able to hack into their surveillance cameras to watch them or to be able to maliciously tinker with the settings on any of their devices. Until the industry gets serious about security this fear factor is very rightfully going to a barrier to entry for a lot of people.

Ease of Using the Information Generated. When I read the literature on a home energy system it goes into great length to describe the great graphs and charts it will generate for me about my energy usage. But I don’t think most people want data – they want solutions. They don’t want to have to interpret data on hourly usage and then decide how to tinker with the settings to get the results they want. People want solutions and they are going to want IoT devices that understands what they want and takes care of the details. If you have to constantly monitor the data out of your IoT devices and then fiddle to achieve your goals, then what you’ve really gained is a new chore – and none of us want that. I think what we are waiting for is the smart house that can take care of all of the IoT devices for us.

Solving One Problem and Creating Another. I took a look at getting smart door locks. But as I thought through how they work I could see they were not for me. They work by interfacing with your cellphone and also have a manual override. But I am the prototypical absent-minded professor-type and I rarely have my phone with me when I leave the house, even when I should. I picture myself locked out of my house and not able to remember the manual code. And who the heck do you call – a locksmith or an IT guy? And oh crap, my phone is locked inside the house.

Value Proposition. In many cases I just don’t see the value proposition that some of the early IoT devices deliver. For instance, do smart locks really make my home any safer from a guy with a crowbar? Do I really need to pay extra for a smart refrigerator or dryer? It might be that the value propositions are there, but the manufacturers need to do a better job of convincing me why any device is indispensable in my life.

Only for Do-it-Yourselfers. All of these issues to me tell me that everybody who is not a do-it-yourselfer is going to want and need help with IoT, either in setting it up, configuring it or deciding how to use it. Today one a certain rather small percentage of the population is willing to tackle all of those tasks, and that is probably the limiting factor for most people.

But there is an upside to any business that can devise a business plan to help people with IoT devices. Cable companies, telcos and ISPs are certainly in an ideal spot to be that vendor for many homes. All that is really needed is that your customers like you and trust you. And trust is the key word. When you want to have a home security system installed you must trust the company and the people doing the work. I remember back when I lived in Maryland that Comcast once sent a tech to my house who was driving a dilapidated 25-year old pickup and dressed poorly. This guy was clearly a contractor and I would not have let this guy install a Comcast burglar alarm in my house. But the Comcast technician in Florida showed up in a Comcast truck and seemed very knowledgeable and professional and is somebody I would be more likely to trust.

There are a large percentage of people who are never going to want to fiddle with IoT devices, no matter how easy this becomes. I can’t ever foresee the day until maybe when we all have smart robots that a smart home is going to be easy enough for the average person. There are too many components of a smart house that are going to be beyond the comfort level of most people. And that sounds like a permanent new service business to me.

The FTC to Monitor the Internet of Things

federal-trade-commission-ftc-logo_jpgLast week the Federal Trade Commission Chairwoman Edith Ramirez announced that the FTC’s latest initiative was to watch the Internet of things for privacy violations. They are already concerned that IoT devices are subject to easy hacking, and also that they are being used to gather data on us.

In a report issued last week the FTC Staff, and approved by 4 to 1 by the Commissioners, the FTC made specific recommendations in the areas of privacy, data collection and customer notification and choice. They also discussed the need for federal legislation to give them more power to police the IoT.

The FTC broadly defined the Internet of Things to include any device, other than computers and smartphones, which transmits information about the owner of the device over an internet connection.

The report makes specific recommendations about security and recommended that manufacturers of IoT devices should:

  • Assess the security risk for every device they make;
  • Minimize the data they collect and retain;
  • Test security before they ship product;
  • Implement measures to keep unauthorized users from accessing a device or data stored on their own networks;
  • Monitor devices throughout the product life cycle and provide patches to cover known risks;
  • Develop a defense to be ready to react to security breaches.

It’s good to see the government espousing these kinds of concerns. You might recall that HP tested ten popular IoT devices last year and found an average of ten security flaws on each device. My fear is that if the industry doesn’t self-police itself (or get prodded by regulators to do so) then someday we are headed for a perfect storm where hackers will do something terrible, like hack and kill hundreds of people with pacemakers. If something really dreadful happens because the industry doesn’t care about security then the world could quickly turn against the IoT. The IoT industry has the potential for huge growth, but one really terrible security breach on devices could badly sour people on the devices.

The report also made recommendations about storing and misusing customer data. The FTC has already been engaged in monitoring company’s use of data. For example, late last year the FTC reached an agreement with SnapChat to stop misrepresenting that data on their network was completely private. SnapChat has changed their advertising and also agreed to hire an independent privacy monitor for the next twenty years.

For now the report recommends that companies limit the data they collect, and absent legislation that is probably as strong of a warning as the FTC can issue. The report is specifically very concerned about customers not knowing what data is being collected about them from an IoT device. They think it is fundamental that customers be informed about the data they are giving up in order to make an informed decision about using any specific device. While any IoT device will have this concern, the sharing of data from things like health monitors is more troubling than the data gathered from a smart refrigerator or smart washing machine.

The report also voice a concern that the IoT device manufacturers would become the target of hackers and that the kind of information that could be stolen, such as detailed health records, are more troubling than stealing things like credit card numbers.

There is some industry concern, echoed by the dissenting Commissioner in adopting the report that the FTC needs to balance the desires to monitor the industry against too much regulation that might stifle innovation and investment in the field. But as a customer I would already vote in favor of what the FTC has started here. The risks to the industry are far greater from allowing companies to be lax with security and play free with customer data. I am going to be a lot more likely to use a device from a company that I think is being truthful with me and careful on both counts.

Who Will Own the Internet of Things?

Tribrid_CarYesterday’s blog talked about the current Internet that is falling under the control of a handful of large corporations – Apple, Amazon, Facebook, Google and Microsoft. This leads me to ask if the upcoming Internet of Things is also going to be owned by a handful of companies

This is not an idle question because it has become clear lately that you don’t necessarily own a connected device even though you might pay for it. As an example, there was recently an article in the New York Times that reported that a car company was able to disable cars for which the owners were late in making payments. The idea of Ford or General Motors still having access to the brains of your vehicle even after you buy it is unsettling. It’s even more unsettling to think access is in the hands of somebody at your local car dealer. Imagine them turning off your car when you are far away from home or when you have a car full of kids. But even far worse to me is that if somebody can turn off your car then somebody else can hack it

The car companies are able to do this because they maintain access to the root directory of your car’s computer system. Whether you financed the car with them or paid cash, they still maintain a backdoor that lets them get remotely into your car’s computer. They might use this backdoor to disable the vehicle as in this example or to download software upgrades. But the fact is, as long as they have that ability, then to some degree they still have some control over your car and you. You have to ask if you truly own your own car. As an aside, most people don’t realize that almost all cars today also contain a black box, much like the recorder in airplanes that records a lot of data about your car and your specific driving habits. It records data on how fast you drive or if you are wearing your seatbelt – and this data is available to the car companies

Perhaps the car is an extreme example because car is probably the most complicated device that you own. But it’s likely that every IoT device is going to have the same backdoor access to the root directory. This means that the company that made an IoT device is going to have a way to gain access. This means every smartphone, appliance, thermostat, door lock, burglar alarm and security camera can be controlled to some degree by somebody else. It makes you seriously ask the question if you entirely own any smart device

Over time it is likely that the IoT industry will consolidate and that there will be a handful of companies that control the vast majority of IoT devices just like the big five companies control a lot of the Internet. And it might even be the same companies. Certainly Apple, Google and Microsoft are all making a big play for the IoT

I’ve written before about the lack of security in a most IoT devices. My prediction is that it’s going to take a few spectacular failures and security breaches of IoT devices before the companies that make them pay real attention to security. But even should they tighten up every security breach, if Google or Apple maintains backdoor access to your devices, then they are not truly secure

I think that eventually there will be a market for devices that a buyer con control and that don’t keep backdoor access. It certainly would be possible to set up an IoT network that doesn’t communicate outside the home but where devices all report to a master controller within the home. But it’s going to take people asking for such devices to create the market for them

If people are happy to have Apple or Google spy on them in their homes then those companies will be glad to do it. One of the first things that crossed my mind when Google bought Nest was that Google was going to be able to start tracking a lot of behavior about people inside their homes. They will know when you wake and sleep and how you move around the home. That may not sound important to you, but every smart device you add to your house will report something else about you. With the way that the big companies mine big data, the more they know about you the better they can profile you and the easier it is for them to sell to you. I don’t really want Google to know my sleep habits and when I go to the bathroom. To be truthful, it sounds creepy.

Latest on the Internet of Things – Part 2, The Market

Goneywell LyricYesterday I wrote about the security issues that are present in the first generation of devices that can be classified as part of the Internet of Things. Clearly the manufacturers of such devices need to address security issues before some widespread hacking disaster sets the whole industry on its ear.

Today I want to talk about the public’s perception of the IoT. Last week eMarketer released the results of a survey that looked at how the public perceives the Internet of Things. Here are some of the key results:

  • Only 15% of homes currently own a smart home device.
  • And half of those who don’t own a smart device say they are not interested in doing so.
  • 73% of respondents were not familiar with the phrase “Internet of Things”.
  • 19% of households are very interested in smart devices and 28% are somewhat interested.
  • There were only a handful of types of devices that were of interest to more than 20% of households: smart cars – 39%; smart home appliances – 34%; heart monitors – 23%; pet monitors – 22%; fitness devices – 22%; and child monitors 20%.

The survey highlights the short-term issues for any carrier that thinks they are going to make a fortune with the IoT. Like many new technology trends, this one is likely to take a while to take hold in the average house. Industry experts think the long-term trend of the IOT has great promise. In a Pew Research Center survey that I discussed a few weeks ago, 83% of industry technology experts thought that the IoT would have “widespread and beneficial effects on the everyday lives of the public by 2025”.

I know that carriers are all hoping for that one new great product that will sweep through their customer base and get the same kind of penetrations that they enjoyed with the triple play services. But this survey result, and the early forays by cable companies and others into the home automation and related product lines show that IoT is not going to be that product, at least not for now.

This is not to say that carriers shouldn’t consider getting into the IoT business. Let’s face it, the average homeowner is going to be totally intimidated by having more than a couple of smart devices in their home. What they will want is for them to all work together seamlessly so that they don’t have to log in and out of different systems just to make the house ready when they want to take a trip. And eMarketer warned that one thing that concerned households was the prospect of having to ‘reboot’ their entire home when things aren’t working right, or of getting a virus that would goof up their home.

And as I mentioned yesterday, households are going to want to feel safe with smart devices, so if you are going to get into the business it is mandatory for you to find smart products that don’t have the kinds of security flaws that I discussed yesterday.

The eMarketer report predicts that more homes will embrace IoT as more name brand vendors like “Apple, Google . . . The Home Depot, Best Buy and Staples” get into the business. And this may be so, but one is going to expect most such platforms to be somewhat generic by definition. If a carrier wants to find a permanent niche in the IoT market they are going to need to distinguish themselves from the pack by providing integration and customization to give each customer what they most want from the IoT experience. Anybody will be able to buy a box full of monitors from one of those big companies, but a lot of people are going to want somebody they trust to come to their home and make it all work.

But the cautionary tale from this survey is that IoT as a product line is going to grow slowly over time. It’s a product today where getting a 10% customer penetration would be a huge success. So I caution carriers to have realistic expectations. There is going to be a lot of market competition from those big companies named above and to be successful you are going to have to stress service and security as reasons to use you instead of the big names.

Securing the IoT

MLGW_Substation_Whitehaven_Memphis_TN_2013-01-06_006I read this week that a security company was able to hack into somebody’s WiFi network through a smart LED light bulb. This obviously points out a flaw in that particular brand of lights, but it highlights a much larger issue. How are we going to secure the Internet of Things?

Estimates vary widely, but by 2020 there is expected to be many billions of internet connected devices. Many of these devices will have been designed for a given purpose, but many will just be things to which we have added a cheap sensor. The vast majority of the IoT devices will have little or no protection against online attacks. So the IoT is going to create billions of unsecure endpoints in all of our networks.

Many of these devices will have very tiny and primitive processors incapable of any of the kinds of security protection we use today such as anti-virus anti-malware software. The devices are going to be built by a multitude of different companies and have a wide array of capabilities and vulnerabilities. And unless some standard is developed, the devices will use a multitude of different protocols such as Zigbee, WebHooks and IoT6. And perhaps we don’t even want one standard because that could make the whole world susceptible to an effective virus.

Unlike today’s viruses which can cause computer and network problems, an IoT an attack will be able to inflict real world damage. The obvious examples always used include attacks against insulin pumps or pacemakers. But damage can come from anywhere when hackers can address cars, heating and air conditioning systems, water systems and door locks.

There haven’t been many advertised hacks against IoT devices today, mostly because hackers have so many other lucrative places to attack us. But I just read this month how hackers gained access to some electric company grids through their smart metering systems. It won’t take a lot of playing inside an electric network to cause real harm to generators, substations or transformers.

There are some proposed solutions to some of these problems. For example, smartphones and tablets today have elements like SIM or Trusted Execution Environment (TEE) that are secure cores out of the reach of hackers. In those devices we can load credentials into those safe environments which allows us to create a true identity for the device that can be validated by the rest of the network. The more sophisticated IoT devices could deploy the same sort of technology.

We can do something similar for ‘dumber’ devices using something akin to the chip and pin systems that are used in Europe to protect credit cards. Those technologies allow banks to establish the identity of the person trying to complete a transaction.

But to get protection into the IoT is going to require both standards and compliance by manufacturers. Consider the American banking system which is not implementing the same safety standards as Europe, even while tens of millions of credit card numbers and PINs have been stolen multiple times. Just having security is only going to work if the people making the IoT devices spend the money to implement the technology. There will plenty of manufacturers who will cut corners on security to save money.

Further, many of the IoT technologies being contemplated involve swarms of very small sensors connected in clouds and used to monitor our environment. Whether these be deployed in our blood stream to look for signs of illness, or deployed in nature to watch endangered species, these devices will be of such a tiny nature that it will be impossible to add sophisticated software security.

Obviously solutions will be developed because the public will demand it. But before that happens I envision some dramatic and very public cases where hacking kills people or causes other real damage. This doesn’t have to be anything sophisticated. Turning toasters on to full heat overnight might burn down houses. Locking everybody in a town out of their houses by hacking into smart door locks would wake up the public to the dangers of the IoT. I fear we are in for some bumpy roads before we figure out how to do this right.

Keep People in the Equation

Tribrid_CarAs I keep reading about the coming Internet of Things I keep running into ideas that make me a bit uneasy. And since I am a tech head, I imagine that things that make me a little uneasy might make many people a whole lot uneasy.

For instance, I read about the impending introduction of driverless cars. I have to admit that when I am making a long drive on the Interstate that having the ability to just hand the driving off to a computer sounds very appealing. I would think that the challenge of driving on wide-open highways at a consistent speed is something that is quite achievable.

But it makes me uneasy to think about all cars everywhere becoming driverless. I sit here wondering if I really want to trust my personal safety to traveling in a car in which software is making all of the decisions. I know how easily software systems crash, get into loops and otherwise stutter and I can’t help but picturing being in a vehicle when a software glitch raises its ugly head.

I know that a road accident can happen to anybody, but when I drive myself I have a sense of control, however misplaced. I feel like I have the ability to avoid problems a lot better than software might when it comes down to a bad situation.

I am probably wrong, but it makes me uneasy to think about climbing into a cab in a crowded City and trusting my life to an automated vehicle. And I really get nervous thinking about sharing the road with robot tractor-trailers. The human-driven ones are scary enough.

I am probably somewhat irrational in this fear because I would guess that if all vehicles were computer-controlled there would be a lot fewer accidents, and we certainly would be protected from drunk drivers. Yet a nagging part of my brain still resists the idea.

I also worry about hacking. Perhaps one of the easiest ways to bump somebody off would be to hack their car and make it have an accident at a fast speed. You know it’s going to happen and that will make people not trust the automated systems. Hacking can break our faith in a whole lot of the IoT since there will be ample opportunities to hurt people by interfering with their car or their medicine or other technology that can harm as easily as it can help.

I can’t think I am untypical in this kind of fear. I think somehow as we make these big changes that somehow people have to be part of the equation. I don’t have an answer to this and frankly this blog just voices the concern. But it’s something we need to consider and talk about as a society.

The people issue is going to spring up around a lot of the aspects of IoT. It has already surfaced with Google Glass and many people have made it clear that they don’t want to be recorded by somebody else surreptitiously. As the IoT grows past its current infancy there are bound to be numerous clashes coming where tech confronts human fears, feelings and emotions.

There are certainly many of the aspects of the IoT that excite me, but as I think about them I would bet these same changes will frighten others. For instance, I love the idea of nanobots in my bloodstream that will tell me days early if I am getting sick or that will be able to kill pre-cancerous cells before they get a foothold in my body. But I am sure that same concept scares the living hell out of other people, the idea of having technology in our blood.

I don’t know how it’s going to happen, but the human equation must become part of the IoT. It has to. If nothing else, people will boycott the technology if it doesn’t make us feel safe.

Where Will We Draw the Privacy Line?

Monitor_padlockThe efficiencies, convenience and societal cost savings that will be realized from the IoT are so enormous that it is inevitable that the future will eventually become just what the IoT developers imagine – a seamlessly networked world that brings a lot of Star Trek into our lives. But we are not just going to magically pop to that great future and my gut tells me that there is going to be some gigantic growing pains for the technology and some major setbacks on the way to the inevitable future.

One only has to peek behind the curtain at some of the early attempts at developing IoT devices to understand where some of the snafus and problems are going to come from. One area where I foresee the possibility for a lot of backlash is privacy. In order for the IoT to work people are going to have to sacrifice some privacy. The question that I don’t see being asked is how much privacy the average person is going to be willing to give up to gain the convenience of using numerous IoT devices.

Already today we can see a little of the how social sharing interfaces with privacy. For example, when running monitors first hit the market my Facebook got filled with maps showing how far and how fast my various runner friends had run each day. But over a few months these all disappeared and I haven’t seen one in a while. This is not because they have ditched the monitors, but rather that after the novelty wore off people realized they didn’t want to share. They didn’t want their friends to notice that they took a day off from running or that they ran slowly or only did a short route on a given day. It turns out that people don’t want to automatically share things that might reflect negatively on them.

And if people quickly edited their sharing over something like a jogging monitor I can’t help but wonder how people are going to react when they realize that one of the biggest aspects of the IoT is that we will be constantly watched and monitored.

I heard this concern when it was announced that Google was buying Nest, the maker of smoke detectors and other security devices. The promise is being made that IoT devices are going to be smart (or at least that the network that controls them will be smart). And this means that our every movement will be tracked. It doesn’t sound particularly threatening if Google finds out what time of day we turn various lights on and off or when we enter certain rooms. But the technology is at the bare beginning and the fact is that eventually our devices will let companies like Google know more about us that we often know about ourselves.

The whole point of big data analytics is to look for patterns. Knowing how and when a certain person moves around the house is data that can be used to see a pattern. Google can compare the way you move to the way other people move and can see that there are 10,000 other people just like you in the US and that you also have a lot of other traits in common.

I know this sounds simplistic and that would be a big stretch to understand you from just being monitored by a few devices in your home. But it’s not going to eventually going to be just a few devices. It’s likely that there will be enough monitors in the average home where an outside company like Google could understand your sleep patterns, your eating habits, what you watch and read, who you talk to, how you exercise – basically everything about you.

And I just wonder if at some point if there will not be a big rebellion against that kind of invasion of privacy. I foresee a huge pushback coming against IoT until they can solve the privacy issue and give control to each person over how their own data is shared with the world. This is contrary to the goals of Google and others and it will be very interesting to see where society draws the line.

Security for the Internet of Things

Monitor_(medical)We are quickly headed towards the Internet of thing where billions of devices will be connected to the Web. The biggest challenge in making this a reality is figuring out how to make the IoT secure. The world today is full of hackers. There are those that hack to find financial gain. There are cyberwars where government-sponsored hackers launch major attacks. And there are just general hackers who do it for the fun of creating mischief.

Today web security is a cat and mouse game between the hackers and security experts. Our PCs need almost daily updates to fight against newly discovered viruses which look to get around the virus checking programs.

The biggest challenge we face is that most of the devices that will be connected are not going to have large computing power like laptops and tablets. Instead we will have thermostats and smoke detectors and security cameras and medical monitors all connected to our home networks. And these devices have very rudimentary computing power, meaning that our current methods of security can’t be used to protect them.

But protect them we must because causing harm to these devices can cause real world damage. Imagine during the latest artic vortex is some hacker had turned off millions of thermostats and furnaces. This could have caused widespread problems, large dollar damages and even deaths. I don’t even want to think what might happen is somebody can hack into people’s medical devices. Perhaps murder by hacking? As we tie more and more of our daily life into devices that are connected to the web need to find solutions for protecting them.

And hackers are already starting to take notice of the weaknesses in our devices. In Brazil over 4.5 million DSL routers were hacked by people looking for credit card and banking information. There is a computer virus called DNS Changer that is attacking home routers in the US. There are already worms that are attacking things like security cameras and other embedded devices.

Security experts are working on the problem and there are several thoughts on the best way to keep our devices safe.

Safer Firmware. Most devices are operated with software called firmware. The security idea is to put this software onto a part of the chip that cannot be addressed from externally. Basically code the chip and throw away the key.

Cloud Security. Another idea is to limit each device to only being able to communicate with one source. This might be a specific cloud. This feels like a big company idea for a fix and it’s a bit scary, because if somebody can break into the cloud they have access to all of the machines that talk to it.

Government Fines. Today there is nearly zero security even considered for companies building IoT devices. They use old versions of open source Linux and out zero effort into making their devices safe. The thought is to impose big fines on manufacturers of IoT devices that get hacked as an incentive for them to do better.

We have to fix this or else there is going to be some really huge examples of hacking into devices that are going to scare the public off IoT. As we tie more and more of our life into our networks we all need to know that we are safe from being hacked by those with malicious intent.