• On mySimon: Hanky Panky thong underwear
July 16, 2008 2:18 PM PDT

Adding risk to our homes

Posted by Robert Vamosi
  • Font size
  • Print

Gaining the ability to remotely control your HVAC might seem like an energy-responsible thing to do, but it might also pose hidden security risks.

In a recent blog titled Security implications in HVAC equipment SANS handler Swa Frantzen wrote of his concerns regarding one energy-saving program in Texas. The utility, TXU, uses what's called an iThermostat, which allows you to program your thermostat remotely over the Internet from any laptop or desktop.

In California, PG&E offers a similar program, SmartAC. PG&E also uses an Internet addressable, programmable thermostat, however, the user guide (PDF) mentions only remote access from the utility, not from the end user.

Frantzen makes it clear that's he's not intentionally picking on the iThermostat system; he's only using it for educational purposes. Nor am I necessarily saying the SmartAC program is flawed either. I do, however, think his academic questions are quite valid because they go beyond just HVAC systems.

Recently there was a security hole identified within an Internet-connected coffee maker. I think the first question here should be: do we really need to access our coffee machine remotely?

It might be argued that these systems (the HVAC and coffee machine) both terminate--they don't necessarily allow a remote attacker access to a home computer network. But that's for right now. Jump ahead a few years when these systems start talking each other, when you'll be able to create a warm and comfy home environment from your desktop at work.

Until then, what if someone remotely views your schedule of when the AC turns on and off? It could tip a potential burglar to when you're likely to be home and when not. And what if, asks Frantzen, the remote lockout on the thermostat fails and some remote hacker cranks the heat or air conditioning setting to its maximum setting while you're on vacation?

Is anyone even thinking about these issues? If not, shouldn't someone be?

Recent posts from Defense in Depth
How to handle ID fraud's youngest victims
Is white listing going mainstream?
How Live OneCare changed the antivirus landscape
Express Scripts clients threatened with extortion
Study: DDoS attacks threaten ISP infrastructure
Security expert talks Russian gangs, botnets
Extortion used in Express Scripts database breach
WPA wireless encryption cracked
Add a Comment (Log in or register) 5 comments
by Penguinisto July 16, 2008 3:06 PM PDT
This isn't really new news... Sun had a project called Jini out in 1999/2000 that promised to wire everything from your refrigerator to your television to its own network, and make it all internet-capable. The presentation (and movie that accompanied it) was really nice, but one question during Q&A stopped the presenters cold: "What about security? Someone can turn off the heat in winter, make your food spoil or burn (fridge or stove, respectively), turn the TV to a 24/7 pr0n channel, etc..."

Jini died as a major marketing effort pretty shortly after that. It still exists (sorta), and can be seen here: http://www.sun.com/software/jini/
Reply to this comment
by cporpheus July 16, 2008 3:19 PM PDT
I think the environmental and financial benefit of remotely controlling your home energy use outweighs the risk of somebody who might try to mess with those systems. I doubt hackers are trying to do this when they could spam a couple million people and make a profit from it.
Reply to this comment
by Dalkorian July 16, 2008 5:16 PM PDT
It's not hackers or spammers you should be worried about. What about that ex? Or that neighbor that no one gets along with? Or a child's jilted boyfriend/girlfriend? Or that jerk who thinks it would be funny if you came home from a two week vacation only to find out you have a $4000 heating bill because your furnace had mysteriously turned on full blast the day you left? Or that person you got into a fight with last weekend? Or ...

The possibilities for mischief are endless. THAT is why this is a bad idea. Besides, in case you haven't heard we now have programmable thermostats that you can tell to run at certain times of the day and even what temperature to run at. I have a cheap one in my house that's set to 55 between 11:45PM and 6:15AM, then 68 until 9:00AM, then 55 again until 5:00PM, then back to 68 (during winter, otherwise I keep it in the "off" mode). Never even have to think about it and no internet access required. People with brains can set these up *BEFORE* leaving on vacation, it's really not hard (since you're on vacation, I'd recommend the "off" setting because it's the simplest and least expensive option). There's even more, I have a coffee machine that also has a timer on it. It makes coffee in the morning, whether or not I've slept in. It's also perfectly unhackable (no internet connection = absolute internet security).
by CyR00k July 16, 2008 7:10 PM PDT
Though it may be interesting to control the home remotely. Isn't it slightly more sensible to utilize the tech that exists presently to control the systems from your home desktop? Not to mention the fact that it should be more secure.
Reply to this comment
by Get_Bent July 17, 2008 12:29 PM PDT
My thermostat needs Internet access about as badly as my refrigerator does.... Just because you *can* give a device Internet access doesn't mean that it *needs* it.
Reply to this comment
advertisement

In the news now

Slowing expectations at a green-tech start-up

Six months ago, biofuels start-up Mascoma had the wind in its sails, as did the rest of the clean-tech sector. Now, the company is treading carefully and scaling back.


With JavaFX, Sun seeks new coders, new revenue

With the launch of JavaFX 1.0, Sun is trying to reclaim Java's strength as a foundation for rich Internet applications. But it's no longer the incumbent.


Tim Lincecum, motion capture star

San Francisco Giants pitcher, who won the Cy Young award last month, dons a motion capture suit for 2K Sports' Major League Baseball 2K9 video game.


About Defense in Depth

Covering computer viruses and computer crime, Robert Vamosi goes beyond the hype to provide you with expert interviews of the top security researchers, as well as offering the hands-on, nontechnical advice you'll need to stay safe online.

Add this feed to your online news reader

Defense in Depth topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right