• On MovieTome: See the TRAILER for TERMINATOR 4!
July 16, 2008 2:18 PM PDT

Adding risk to our homes

Gaining the ability to remotely control your HVAC might seem like an energy-responsible thing to do, but it might also pose hidden security risks.

In a recent blog titled Security implications in HVAC equipment SANS handler Swa Frantzen wrote of his concerns regarding one energy-saving program in Texas. The utility, TXU, uses what's called an iThermostat, which allows you to program your thermostat remotely over the Internet from any laptop or desktop.

In California, PG&E offers a similar program, SmartAC. PG&E also uses an Internet addressable, programmable thermostat, however, the user guide (PDF) mentions only remote access from the utility, not from the end user.

Frantzen makes it clear that's he's not intentionally picking on the iThermostat system; he's only using it for educational purposes. Nor am I necessarily saying the SmartAC program is flawed either. I do, however, think his academic questions are quite valid because they go beyond just HVAC systems.

Recently there was a security hole identified within an Internet-connected coffee maker. I think the first question here should be: do we really need to access our coffee machine remotely?

It might be argued that these systems (the HVAC and coffee machine) both terminate--they don't necessarily allow a remote attacker access to a home computer network. But that's for right now. Jump ahead a few years when these systems start talking each other, when you'll be able to create a warm and comfy home environment from your desktop at work.

Until then, what if someone remotely views your schedule of when the AC turns on and off? It could tip a potential burglar to when you're likely to be home and when not. And what if, asks Frantzen, the remote lockout on the thermostat fails and some remote hacker cranks the heat or air conditioning setting to its maximum setting while you're on vacation?

Is anyone even thinking about these issues? If not, shouldn't someone be?

Recent posts from Defense in Depth
High-tech bank robbers phone it in
How 'carders' trade your stolen personal info
Anatomy of a botnet
Column: Raising Cain at Black Hat
Black Hat 2008: Notes from the field
Add a Comment (Log in or register) 5 comments
by Penguinisto July 16, 2008 3:06 PM PDT
This isn't really new news... Sun had a project called Jini out in 1999/2000 that promised to wire everything from your refrigerator to your television to its own network, and make it all internet-capable. The presentation (and movie that accompanied it) was really nice, but one question during Q&A stopped the presenters cold: "What about security? Someone can turn off the heat in winter, make your food spoil or burn (fridge or stove, respectively), turn the TV to a 24/7 pr0n channel, etc..."

Jini died as a major marketing effort pretty shortly after that. It still exists (sorta), and can be seen here: http://www.sun.com/software/jini/
Reply to this comment
by cporpheus July 16, 2008 3:19 PM PDT
I think the environmental and financial benefit of remotely controlling your home energy use outweighs the risk of somebody who might try to mess with those systems. I doubt hackers are trying to do this when they could spam a couple million people and make a profit from it.
Reply to this comment View reply
by CyR00k July 16, 2008 7:10 PM PDT
Though it may be interesting to control the home remotely. Isn't it slightly more sensible to utilize the tech that exists presently to control the systems from your home desktop? Not to mention the fact that it should be more secure.
Reply to this comment
by Get_Bent July 17, 2008 12:29 PM PDT
My thermostat needs Internet access about as badly as my refrigerator does.... Just because you *can* give a device Internet access doesn't mean that it *needs* it.
Reply to this comment
Powered by Jive Software
advertisement
Resource center from News.com sponsors
You Need The Speed of Norton 2009
Introducing Norton Internet Security™2009

Click Here!
With one-click, one-minute install, under 8MB of memory usage and fewer, shorter scans, it's the fastest security suite anywhere. Norton. Smart Security, Engineered for Speed. Get a FREE trial today!

Click Here!
The Fastest Security Suite Anywhere

Experience the revolutionary Norton Internet Security™ 2009. With Norton™ Insight, a new feature, you get precision security that targets only at risk files for fewer, faster, shorter scans

Win a Trip to Space!*

Enter the Blast Off with Norton Sweepstakes for your shot at a trip to space. You could experience being fast and weightless, just like the new Norton 2009. *No purchase necessary; click for full details.

FREE Trial!

Act now to get your FREE trial of Norton Internet Security 2009. Try it for the protection. Love it for the speed

Norton Safe Web NEW!

A community-based system that rates web site safety

Norton Labs NEW!

Users can download new security technologies and share input directly with developers. Help us shape our future products!

About Defense in Depth

Covering computer viruses and computer crime, Robert Vamosi goes beyond the hype to provide you with expert interviews of the top security researchers, as well as offering the hands-on, nontechnical advice you'll need to stay safe online.

Add this feed to your online news reader

Defense in Depth topics

Featured blogs

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right