10 IoT Security Tips You Can Use to Secure Your IoT Devices

IoT is something of a double-edged sword. While it makes life so much simpler to have a smart home with a smart lock, and a Wi-Fi kettle that boils the water for your morning tea automatically, it comes at a price that may cost you significantly more than what’s on the price tag. In IoT security, there are security trade-offs and, unfortunately, these can do more harm than good, and almost make you miss the days when there was nothing “smart” about your TV!
Let’s take a look at some examples to drive home the importance of security before we welcome this technology into our homes, our industries, and our everyday lives.
Hackers can gain a foothold into your network from the most innocuous devices on your network. Nicole Eagan, CEO of Darktrace, a cybersecurity firm, recounts an incident at an unnamed casino in North America where attackers were able to access the high-roller database of gamblers. They did so by exploiting a low-risk vulnerability in a smart thermometer that was used to monitor the temperature of an aquarium.
But this is just one example. Let’s take a look at a few more examples of IoT security breaches before moving on to pointers on IoT device security.
If you’ve read the reports on how security bugs in Alexa and Google Home smart assistants have been exposed to be phish and eavesdrop on users, let’s just say that you’re right to be worried. Despite countermeasures from both Amazon and Google every time, they continue to be thwarted using newer techniques.
Apart from this, there’s Samsung’s smart refrigerator, whose display is designed to be integrated with its user’s Gmail calendar so they can see what their day looks like before heading out of the house. Except that, however great that sounds, it is not quite as neat. Even though SSL was deployed to secure the Gmail integration, the fridge itself failed to validate the SSL/TLS certificate, leaving the doorway open to hackers for getting on the same network and stealing the login credentials.
To their credit, Samsung fixed the bug in a software update, but it’s quite troubling when credible brands get breached. It sheds light on an almost inescapable fact that, more often than not, functionality takes priority over security, even in companies that should know better. What’s more, in 2015 Samsung also warned us about how they intended to collect and use our data in their smart TV policy:
“Please be aware that if your spoken words include personal or other sensitive information, that information will be among the data captured and transmitted to a third party through your use of Voice Recognition.”
Thank God for Apple, though, right? Let’s hold onto that thought a moment. In February 2019, a severe bug was discovered in Apple’s FaceTime app that allowed attackers access to someone’s iPhone camera and microphone before they accepted or rejected an incoming call.
With attackers finding ingenious ways to evade security controls to steal data, cause damage, or merely be disruptive, it is reasonable to err on the side of safety. Nevertheless, if you still fancy a smart home, umm… good luck?
Mirai is an IoT-centric malware that infects devices with weak credentials, turning them into a network of remotely controlled zombies or bots. Although the original creators of Mirai have been caught, they previously released the malware’s source code (possibly to confuse and distract authorities), and now it has several mutations.
Botnets have been used to launch several DDoS attacks with the attack on Rutgers University and the one on Dyn (the company that provides domain name services to the likes of Netflix, Twitter, etc.).
In technology, nothing is sacred or spared from the clutches of cybercriminals. This includes medical devices.


