A small sex toy with big problems
#1
Information 
[Image: 35c3-insecure-sex-toy.jpg]
Quote:Werner Schober is a researcher at SEC Consult and a student at the Austrian University of Applied Sciences. In his fifth year, he faced a problem many of us are quite familiar with: He had to choose a thesis topic.

He began by making a tag cloud with words from topics selected by his course mates. All of the standard IT buzzwords were there: bitcoin, GDPR, cloud, etc. But for some reason, there was no Internet of Things (IoT), a hot topic these days. It was a no-brainer, especially with Werner’s work at SEC Consult giving him a fair bit of pentest experience (i.e., hacking devices and networks and finding vulnerabilities in them) that could be applied in his research.

However, the IoT is a very broad concept, covering just about everything from traffic lights and heart pacemakers to smart teapots. The focus had to be narrowed. But the critical infrastructure side of the IoT — such as the aforementioned traffic lights and pacemakers — had already been researched to death. As for the smart home with its brainy kettles and light bulbs, that too had been covered in depth — with no really critical vulnerabilities to speak of. So what if your smart lawnmower’s been DDoSed? Just cut the grass yourself for one day.

Werner opted for a IoT subcategory that hadn’t been widely researched (although studies do exist, since hackers love the forbidden) and where vulnerabilities can lead to real consequences: smart sex toys.

Werner tested three devices: two Chinese and one German. Guess which contained more vulnerabilities? Spoiler alert: It was the latter. And how! The vulnerabilities turned out to be so critical and so numerous that Werner abandoned the Chinese devices altogether and devoted his entire thesis to the German one. He reported his findings at the 35th Chaos Communication Congress (35C3).
Full reading: https://www.kaspersky.com/blog/35c3-inse...toy/25357/
[-] The following 1 user says Thank You to harlan4096 for this post:
  • silversurfer
Reply


Forum Jump:


Users browsing this thread:
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
QOwnNotes 19.1.6
25.6.1 A segmen...Kool — 15:34
Privazer 4.0.19
PrivaZer version v...Kool — 08:36
AMD announces Ryzen AI Z2 Extreme and Ry...
AMD is announcing ...harlan4096 — 08:12
AMD expands FSR4 game list to 65 titles,...
AMD adds more FSR4...harlan4096 — 08:10
GFYI [Official] Master PDF Editor Mothe...
We are pleased to an...jasonX — 05:45

[-]
Birthdays
Today's Birthdays
avatar (47)vadimTob
avatar (37)leannauu4
Upcoming Birthdays
avatar (38)Tedscolo
avatar (45)brakasig
avatar (44)JamesReshy
avatar (46)Francisemefe
avatar (39)leoniDup
avatar (38)Patrizaancem
avatar (38)biobdam
avatar (41)zacforat
avatar (46)NemrokReks
avatar (37)Barrackleve
avatar (39)Julioagopy
avatar (49)aolaupitt2558
avatar (39)storoBox
avatar (47)kinotHeemn
avatar (38)Ceballos1976
avatar (39)efynu
avatar (31)horancos

[-]
Online Staff
There are no staff members currently online.

>