{"id":22295,"date":"2012-12-29T18:25:32","date_gmt":"2012-12-29T23:25:32","guid":{"rendered":"http:\/\/rbach.net\/blog\/index.php\/"},"modified":"2021-07-29T12:45:30","modified_gmt":"2021-07-29T16:45:30","slug":"smart-tvs-dumb-security","status":"publish","type":"post","link":"https:\/\/rbach.net\/index.php\/smart-tvs-dumb-security\/","title":{"rendered":"Smart TVs Dumb Security"},"content":{"rendered":"<p><em><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-101482\" title=\"Smart TVs Dumb Security\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/Internet-of-things1-1.jpg?resize=120%2C105&#038;ssl=1\" alt=\"Smart TVs Dumb Security\" width=\"120\" height=\"105\" \/>When a device gets connected to the web <strong>without any security it leaves the users vulnerable<\/strong>. This is a trend as the <a title=\"Internet of Things\" href=\"https:\/\/web.archive.org\/web\/20201205034413\/https:\/\/thenextweb.com\/insider\/2012\/12\/09\/the-future-of-the-internet-of-things\/\" target=\"_blank\" rel=\"homepage noopener noreferrer\"><strong>Internet of Things<\/strong><\/a> evolves. In this case, Samsung Smart TVs seem to have no security, a dumb TV. <\/em><i><a title=\"Dailywireless.org\" href=\"http:\/\/www.dailywireless.org\/\" target=\"_blank\" rel=\"noopener noreferrer\">Dailywireless.org<\/a><\/i> <a title=\"40% Connect TVs to Internet \" href=\"https:\/\/web.archive.org\/web\/20141005165053\/http:\/\/www.dailywireless.org:80\/2012\/12\/20\/40-connect-tvs-to-internet\/\" target=\"_blank\" rel=\"noopener noreferrer\">reports<\/a> that 40% of Americans have connected their TV to the Internet.<\/p>\n<p><a href=\"https:\/\/www.extremetech.com\/extreme\/133528-samsungs-upgradable-tv-doa-unless-the-company-reinvents-itself\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-101484 size-medium\" title=\"Samsung Smart TV\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/Television_samsungsmarttv.jpg?resize=150%2C83&#038;ssl=1\" alt=\"Samsung Smart TV\" width=\"150\" height=\"83\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/Television_samsungsmarttv.jpg?resize=150%2C83&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/Television_samsungsmarttv.jpg?resize=75%2C41&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/Television_samsungsmarttv.jpg?w=640&amp;ssl=1 640w\" sizes=\"auto, (max-width: 150px) 100vw, 150px\" \/><\/a>At the same time, <a title=\"The Security Ledger\" href=\"https:\/\/web.archive.org\/web\/20230414005951\/https:\/\/securityledger.com\/\" target=\"_blank\" rel=\"noopener noreferrer\"><i>The Security Ledger<\/i><\/a> is reporting that a &#8220;<a title=\"Permanent Link to Security Hole in Samsung Smart TVs Could Allow Remote Spying\" href=\"https:\/\/securityledger.com\/security-hole-in-samsung-smart-tvs-could-allow-remote-spying\/\" target=\"_blank\" rel=\"bookmark noopener noreferrer\">Security Hole in Samsung Smart TVs Could Allow Remote Spying<\/a>.&#8221; The Malta-based firm <a title=\"ReVuln\" href=\"http:\/\/revuln.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">ReVuln<\/a>, says it has uncovered a <strong>remotely exploitable security hole<\/strong> in <strong>Samsung Smart TVs<\/strong>. If left unpatched, the vulnerability could allow hackers to make off with owners\u2019 <strong>social media credentials. <\/strong>Attackers could also spy on those watching the TV using compatible video cameras and microphones.<\/p>\n<p>ReVuln is a security research firm that offers information on security holes it discovers only to subscribers. However, it did confirm the previously unknown (\u201c<strong>zero-day<\/strong>\u201d) hole with <i>Security Ledger. <\/i>The zero-day affects\u00a0<a title=\"Samsung Electronics Co.\" href=\"http:\/\/www.samsung.com\/us\/\" target=\"_blank\" rel=\"noopener noreferrer\">Samsung Electronics Co.<\/a> (<a title=\"KS : 005930\" href=\"http:\/\/www.bloomberg.com\/quote\/005930:KS\" target=\"_blank\" rel=\"noopener noreferrer\">005930<\/a>) <a title=\"Samsung Smart TVs\" href=\"http:\/\/web.archive.org\/web\/20140722140102\/http:\/\/www.samsung.com\/us\/2012-smart-tv\/\" target=\"_blank\" rel=\"noopener noreferrer\">Smart TVs <\/a>running the latest version of the company\u2019s <strong>Linux-based<\/strong> firmware. It could give an attacker the ability to get <strong>access to any file<\/strong> on the remote device, As vulnerable are e<strong>xternal devices<\/strong> (such as USB drives) connected to the TV.<\/p>\n<p>In an Orwellian twist, the hole could be used to <strong>use cameras and microphones attached<\/strong> to the Smart TVs. Granting remote attackers the ability to spy on those viewing a compromised set. Luigi Auriemma of ReVuln <a title=\"Samsung TV vulnerability could let a hacker change the channel\" href=\"http:\/\/www.computerworld.com.au\/article\/444399\/samsung_tv_vulnerability_could_let_hacker_change_channel\/\" target=\"_blank\" rel=\"noopener noreferrer\"> told<\/a> <a title=\"ComputerWorld\" href=\"http:\/\/www.computerworld.com.au\/\" target=\"_blank\" rel=\"noopener noreferrer\"><i>ComputerWorld<\/i><\/a> via email, &#8220;<em>If the attacker has full control of the TV &#8230; then he can do everything like stealing accounts to the worst scenario of using the integrated webcam and microphone to &#8216;watch&#8217; the victim.<\/em>&#8221;<\/p>\n<p><i><a href=\"http:\/\/pmerrill.com\/2012\/02\/tastes-good-like-a-cigarette-should\/\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-101486\" title=\"Dumb TV\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/old-tv.jpg?resize=100%2C100&#038;ssl=1\" alt=\"Dumb TV\" width=\"100\" height=\"100\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/old-tv.jpg?resize=150%2C150&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/old-tv.jpg?resize=75%2C75&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/old-tv.jpg?w=320&amp;ssl=1 320w\" sizes=\"auto, (max-width: 100px) 100vw, 100px\" \/><\/a>Security Ledger <\/i>says that the Smart TVs offer <strong>no native security features<\/strong>, such as a firewall, user authentication, or application whitelisting. More critically: there is no <strong>independent\u00a0<\/strong>software update capability, Which means that, <strong>barring a firmware update from Samsung<\/strong>, the exploitable hole can\u2019t be patched without \u201c<em>voiding the device\u2019s warranty and using other exploits,<\/em>\u201d ReVuln said.<\/p>\n<p>The company posted a <a title=\"ReVuln - The TV is watching you\" href=\"https:\/\/vimeo.com\/55174958\" target=\"_blank\" rel=\"noopener noreferrer\">video<\/a> of an attack on a <a title=\"Samsung UN55C7000 55-Inch 1080p 240 Hz 3D LED HDTV (Black)\" href=\"http:\/\/www.amazon.com\/Samsung-UN55C7000-55-Inch-1080p-Black\/dp\/B0036WT4JW\" target=\"_blank\" rel=\"noopener noreferrer\">Samsung TV LED 3D\u00a0Smart TV<\/a> online. It shows an attacker gaining shell access to the TV. Copying the contents of its hard drive to an external device and mounting them on a local drive. This gave them access to photos, documents, and other content. ReVuln said an attacker would also be able to lift credentials from any social networks or other online services accessed from the device.<\/p>\n<p><strong><em>rb-<\/em><\/strong><\/p>\n<p><em><a href=\"https:\/\/web.archive.org\/web\/20140126031634\/http:\/\/www.familyhomesecurity.com:80\/do-it-yourself-home-security\/\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-101488\" title=\"DIY security\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/do-it-yourself-home-security.jpg?resize=150%2C100&#038;ssl=1\" alt=\"DIY security\" width=\"150\" height=\"100\" \/><\/a>There is no patch for people. Until there is, Smart TV users will have to wait for Samsung to fix this huge security hole or fix it for themselves and risk voiding their warranty. Smart TV with a complete lack of security features, Smart TV Dumb Security.<\/em><\/p>\n<h6>Related articles<\/h6>\n<ul>\n<li><a href=\"https:\/\/news.samsung.com\/global\/samsung-developer-conference-showcases-new-smart-tv-tools-and-policies-for-developers\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Samsung Developer Conference Showcases New Smart TV Tools and Policies for Developers<\/a> (news.samsung.com)<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><em><a title=\"Ralph Bach\" href=\"https:\/\/rbach.net\/index.php\/new-resume\/\" target=\"_blank\" rel=\"noopener noreferrer\">Ralph Bach<\/a>\u00a0has been in IT long enough to know better and has blogged from his\u00a0<a title=\"Bach Seat\" href=\"https:\/\/rbach.net\/\" target=\"_blank\" rel=\"noopener noreferrer\">Bach Seat<\/a> about IT, careers, and anything else that catches his attention since 2005. You can follow him on <a class=\"broken_link\" href=\"http:\/\/www.linkedin.com\/in\/rb48334\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">LinkedIn<\/a>,\u00a0<a href=\"https:\/\/www.facebook.com\/ralph.bach.14\" target=\"_blank\" rel=\"noopener noreferrer\">Facebook<\/a>,\u00a0and\u00a0<a href=\"https:\/\/twitter.com\/rbach48334\" target=\"_blank\" rel=\"noopener noreferrer\">Twitter<\/a>. Email the Bach Seat\u00a0<a href=\"mailto:\/\/bach.seat@gmail.com\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Smart TVs have no security as a trend as the IoT evolves where devices get connected to the web with no security leaving users vulnerable<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[2197,832,780,393,4,936,1501],"class_list":["post-22295","post","type-post","status-publish","format-standard","hentry","category-security","tag-2197","tag-internet-of-things","tag-linux","tag-samsung","tag-security","tag-smart-tv","tag-vulnerability"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/22295","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/comments?post=22295"}],"version-history":[{"count":10,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/22295\/revisions"}],"predecessor-version":[{"id":132272,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/22295\/revisions\/132272"}],"wp:attachment":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/media?parent=22295"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/categories?post=22295"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/tags?post=22295"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}