Best buy guide: Galaxy Watch 6 or Galaxy S24+. Woo-hoo join SamMobile on WhatsApp or Telegram!

SamMobile has affiliate and sponsored partnerships. If you buy something through one of these links, we may earn a commission.

Notifications
    News for you

    Samsung’s SmartThings connected home platform seems to have serious security issues

    Latest Samsung news
    By 

    Last updated: May 3rd, 2016 at 11:30 UTC+02:00

    It was evident from the technologies and products that were showcased at the Samsung Developers Conference 2016 that the company is pushing IoT (Internet of Things). However, have you ever considered how secure these products are? Researchers have recently found that Samsung's SmartThings platform has serious security issues.

    Researchers at the University of Michigan have found multiple security flaws in Samsung's SmartThings platform that could allow malicious apps to unlock doors, remotely set access codes to a smart home lock, falsely set off smoke alarms, or put devices on vacation mode. All the attacks showcased in the video require users to install a malicious app from SmartThings app store or click a malicious link.

    It seems that most pressing issues in the SmartThings platform are the privileges given to apps, many of which they don't even need to function. For instance, a smart lock only needs permission to lock itself, but SmartThings bundles a command that allows it to unlock itself, which could then be used by a malicious app to unlock the door. Researchers showcased an overprivileged app that lets hackers program their own PIN code for a smart lock.

    Researchers showcased their findings through a proof of concept app that promises to monitor battery life on various devices. However, it asks permission for a lot of other things apart from a permission to monitor battery level on products and users unknowingly allow the app. The team analyzed 499 SmartApps and found that around 42 percent apps are currently overprivileged.

    Following this report, a SmartThings representative said, “The potential vulnerabilities disclosed in the report are primarily dependent on two scenarios – the installation of a malicious SmartApp or the failure of third-party developers to follow SmartThings guidelines on how to keep their code secure. Following this report, we have updated our documented best practices to provide even better security guidance to developers,” in an email to The Verge.

    Alex Hawkinson, CEO of SmartThings, said the company has issued a number of updates after the findings in the research. The company claims that it conducts app reviews to filter out malicious apps, but the researchers aren't convinced that the company's efforts are enough to stop these attacks. Samsung acquired SmartThings two years ago when the concepts of connected home and IoT were fairly new.

    Via Source Latest Samsung news SmartThings

    You might also like

    Samsung to supply kitchen appliances to the largest US home builder

    Samsung to supply kitchen appliances to the largest US home builder

    Samsung's home appliances division is inking new deals to expand its footprint in the United States, one of the world's most lucrative markets for such products. The company has been forging partnerships with real estate development companies to supply its appliance for their new projects. The Korean giant has now signed a deal with Clayton […]

    • By Adnan Farooqui
    • 2 weeks ago
    Samsung smart home tech chosen for Flow’s new Miami project

    Samsung smart home tech chosen for Flow’s new Miami project

    Most people retrofit their homes with smart home technology and while the implementation can be good enough, it doesn't quite beat the experience you'd get with a new development that's been constructed from the ground up with IoT devices in mind. Flow, a US-based real estate firm, is building a new project in Miami which […]

    • By Adnan Farooqui
    • 3 weeks ago
    Samsung’s Bespoke AI can now do your laundry better than ever

    Samsung’s Bespoke AI can now do your laundry better than ever

    Samsung's latest Bespoke home appliances are chock-full of new and cleverer features powered by AI. But how does it work? How can Samsung's artificial intelligence help the new Bespoke AI Laundry Combo clean and dry your clothes better? In short, Samsung's new washer and dryer All-in-One uses artificial intelligence to sense a variety of parameters […]

    • By Mihai Matei
    • 4 weeks ago
    Samsung could launch advanced version of SmartThings platform

    Samsung could launch advanced version of SmartThings platform

    Samsung's SmartThings is among the world's biggest smart home platforms. Its recent integration with Amazon Alexa and Google Home has made it even more invincible. Now, Samsung could be preparing to launch more advanced features for its platform. SmartThings Pro could be launched soon as the company registers for the term According to a new […]

    • By Asif Iqbal Shaik
    • 4 weeks ago
    Samsung launches Bespoke AI Laundry Combo in a new color

    Samsung launches Bespoke AI Laundry Combo in a new color

    Earlier this year, Samsung launched the Bespoke AI Laundry Combo, a washer and dryer combo, in Korea, which became an instant hit in the country given the cutting-edge features it offers. Like most washing machines and dryers, the product was available in only one color in the region, Dark Silver Steel. While the product looks […]

    • By Abid Iqbal Shaik
    • 4 weeks ago
    Samsung partners with Tide for Bespoke AI washing machine

    Samsung partners with Tide for Bespoke AI washing machine

    Yesterday, Samsung launched the new Bespoke AI Laundry Combo alongside other Bespoke AI products globally. It hasn’t even been twenty-four hours since then and the company is already adding a new feature to the Bespoke AI Laundry Combo. Samsung has announced that it has partnered with Procter & Gamble (P&G) to launch the Tide POD […]

    • By Abid Iqbal Shaik
    • 1 month ago