{"id":4902,"date":"2011-12-20T21:21:07","date_gmt":"2011-12-21T02:21:07","guid":{"rendered":"http:\/\/rbach.net\/blog\/?p=4902"},"modified":"2022-08-26T16:38:47","modified_gmt":"2022-08-26T20:38:47","slug":"web-connectable-tv-sales-soar-new-source-of-threats","status":"publish","type":"post","link":"https:\/\/rbach.net\/index.php\/web-connectable-tv-sales-soar-new-source-of-threats\/","title":{"rendered":"Web Connected Television New Source of Threats"},"content":{"rendered":"<p><em><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-101409\" title=\"Web Connected Television New Source of Threats\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/Internet-of-things1.jpg?resize=115%2C102&#038;ssl=1\" alt=\"Web Connected Television New Source of Threats\" width=\"115\" height=\"102\" \/>You may want to consider the security of the fancy new 55-inch high-def <a title=\"LCD television\" href=\"https:\/\/en.wikipedia.org\/wiki\/LCD_television\" target=\"_blank\" rel=\"wikipedia noopener noreferrer\">LCD Television<\/a> that Santa Claus brings you. <\/em><em>Surprise,<\/em><em> surprise, <\/em><em>surprise<\/em><em> they may have security holes that could allow hackers to take over your home network.\u00a0<\/em>Consumer appetite for on-demand and online video content will drive sales of <strong>Internet-connectable TV devices<\/strong> to nearly 350 million units worldwide by 2015 reports <a title=\"www.itnewslink.com\" href=\"https:\/\/web.archive.org\/web\/20200928204650\/http:\/\/itnewslink.com\/\" target=\"_blank\" rel=\"noopener noreferrer\"><em>ITnewsLink<\/em><\/a>.<\/p>\n<p><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-101411\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/television_digitAL.jpg?resize=93%2C95&#038;ssl=1\" alt=\"\" width=\"93\" height=\"95\" \/><a title=\"www.parksassociates.com\" href=\"http:\/\/www.parksassociates.com\/index.php\" target=\"_blank\" rel=\"noopener noreferrer\">Parks Associates<\/a>\u2019 <a title=\"www.parksassociates.com\" href=\"https:\/\/web.archive.org\/web\/20220516144136\/https:\/\/parksassociates.com\/report\/connected-living-room--web-enabled-tvs-and-blu-ray-players\" target=\"_blank\" rel=\"noopener noreferrer\">Connected Living Room: Web-enabled TVs and Blu-ray Players<\/a> forecasts worldwide sales of Internet-connectable <a title=\"High-definition television\" href=\"http:\/\/en.wikipedia.org\/wiki\/High-definition_television\" target=\"_blank\" rel=\"wikipedia noopener noreferrer\">HDTVs<\/a>, <a title=\"www.pcworld.com\" href=\"http:\/\/web.archive.org\/web\/20120819051816\/http:\/\/www.pcworld.com:80\/article\/147209\/the_best_bluray_players.html\" target=\"_blank\" rel=\"noopener noreferrer\">Blu-ray players<\/a>, <a title=\"Game consoles\" href=\"https:\/\/secure.wikimedia.org\/wikipedia\/en\/wiki\/Video_game_console\" target=\"_blank\" rel=\"noopener noreferrer\">game consoles<\/a>, and digital video players like <a href=\"http:\/\/www.apple.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Apple<\/a>&#8216;s (<a title=\"NASDAQ : AAPL\" href=\"https:\/\/www.tradingview.com\/symbols\/NASDAQ-AAPL\/\" target=\"_blank\" rel=\"noopener noreferrer\">AAPL<\/a>) <a title=\"www.apple.com\" href=\"https:\/\/www.apple.com\/appletv\/\" target=\"_blank\" rel=\"noopener noreferrer\">Apple TV<\/a> will grow about fourfold from 2010.<\/p>\n<p>Parks Associates says all major manufacturers are debuting new models with innovations in content aggregation, apps development, and user interfaces. Content options are finally catching up to the hardware innovations, and growing libraries of on-demand movies and TV available are starting to unlock the potential of <a title=\"Smart TV\" href=\"http:\/\/en.wikipedia.org\/wiki\/Smart_TV\" target=\"_blank\" rel=\"wikipedia noopener noreferrer\">connected TV<\/a> devices as multifunction <strong>online entertainment and communications platforms<\/strong>.<\/p>\n<p>The growth of these devices will increase opportunities for apps developers &#8211; including third-party developers and giants such as <a title=\"Google\" href=\"https:\/\/www.google.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Google<\/a> (<a title=\"NASDAQ : GOOG\" href=\"https:\/\/www.tradingview.com\/symbols\/NASDAQ-GOOG\/\" target=\"_blank\" rel=\"noopener noreferrer\">GOOG<\/a>), <a title=\"Samsung\" href=\"http:\/\/www.samsung.com\/us\/video\/tvs\" target=\"_blank\" rel=\"noopener noreferrer\">Samsung<\/a>, and <a href=\"http:\/\/www.yahoo.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Yahoo<\/a> (<a href=\"https:\/\/www.tradingview.com\/chart\/YHOO\/EWjh1a3K-The-last-YHOO-chart-for-posterity-hello-AABA\/\" target=\"_blank\" rel=\"noopener noreferrer\">YHOO<\/a>), and one other group, hackers.<\/p>\n<p><a title=\"Mocana\" href=\"https:\/\/www.mocana.com\/\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-11328 size-full\" style=\"border: 0pt none; margin-left: 3px; margin-right: 3px;\" title=\"Mocana_logo\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/2011\/11\/Mocana_logo-e1566514432586.jpg?resize=139%2C64&#038;ssl=1\" alt=\"Mocana logo\" width=\"139\" height=\"64\" \/><\/a> <a title=\"Mocana\" href=\"https:\/\/www.mocana.com\/\" target=\"_blank\" rel=\"homepage noopener noreferrer\">Mocana<\/a>, a company that focuses on securing the \u201c<a title=\"www.cisco.com\" href=\"https:\/\/web.archive.org\/web\/20150215224737\/http:\/\/blogs.cisco.com:80\/news\/the-internet-of-things-infographic\/\" target=\"_blank\" rel=\"nofollow noopener\">Internet of Things<\/a>\u201d, released a study that highlights <strong><a title=\"Digital security\" href=\"http:\/\/en.wikipedia.org\/wiki\/Digital_security\" target=\"_blank\" rel=\"wikipedia noopener noreferrer\">digital security<\/a> flaws in Internet-connected HDTVs<\/strong> reports <a title=\"www.itnewslink.com\" href=\"https:\/\/web.archive.org\/web\/20200928204650\/http:\/\/itnewslink.com\/\" target=\"_blank\" rel=\"noopener noreferrer\"><em>ITnewsLink<\/em><\/a>. The Mocana researchers believe that the security flaws exist in many Internet TVs and recommend that consumers seek out third-party security tests before they purchase and install them in their homes.<\/p>\n<p>Mocana\u2019s CEO <a title=\"Adrian Turner\" href=\"https:\/\/www.crunchbase.com\/person\/adrian-turner\" target=\"_blank\" rel=\"wikipedia noopener noreferrer\">Adrian Turner<\/a> told <em>ITnewsLink<\/em>: \u201c&#8230;manufacturers are <strong>rushing Internet-connected consumer electronics to market without bothering to secure them<\/strong> &#8230; consumer electronics companies that might lack internal security expertise should seek it out, before connecting their portfolio of consumer devices to the Internet.\u201d<\/p>\n<p><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-12034\" style=\"border: 0pt none; margin-left: 3px; margin-right: 3px;\" title=\"security-computer2\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/2011\/12\/security-computer2-e1566514464136-75x64.jpg?resize=100%2C85&#038;ssl=1\" alt=\"Computer security\" width=\"100\" height=\"85\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/2011\/12\/security-computer2-e1566514464136.jpg?resize=75%2C64&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/2011\/12\/security-computer2-e1566514464136.jpg?resize=150%2C127&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/2011\/12\/security-computer2-e1566514464136.jpg?w=333&amp;ssl=1 333w\" sizes=\"auto, (max-width: 100px) 100vw, 100px\" \/>Mocana\u2019s research shows that attackers may be able to leverage Internet-connected TVs to <strong>hack into consumers\u2019 home networks<\/strong>. Researchers found that the Internet interface failed to confirm script integrity before those scripts were run. Mocana was able to show that <strong><a title=\"JavaScript\" href=\"http:\/\/en.wikipedia.org\/wiki\/JavaScript\" target=\"_blank\" rel=\"wikipedia noopener noreferrer\">JavaScript<\/a><\/strong> could then be injected into the normal data stream, allowing attackers to obtain<strong> total control over the device\u2019s Internet functionality<\/strong>. As a result, an attacker could intercept transmissions from the television to the network using common \u201c<a title=\"Rogue DNS\" href=\"https:\/\/secure.wikimedia.org\/wikipedia\/en\/wiki\/DNS_hijacking#Rogue_DNS_server\" target=\"_blank\" rel=\"noopener noreferrer\">rogue DNS<\/a>\u201d, \u201c<a title=\"Rogue DHCP\" href=\"http:\/\/en.wikipedia.org\/wiki\/Rogue_DHCP\" target=\"_blank\" rel=\"wikipedia noopener noreferrer\">rogue DHCP<\/a> server\u201d, or <a title=\"searchsecurity.techtarget.com\" href=\"https:\/\/web.archive.org\/web\/20210119001710\/https:\/\/searchsecurity.techtarget.com\/answer\/How-IP-spoofing-and-session-hijacking-work\" target=\"_blank\" rel=\"noopener noreferrer\">TCP session hijacking<\/a> techniques. The security holes could allow attackers to:<\/p>\n<ul>\n<li>Present <strong>fake credit card forms<\/strong> to fool consumers into giving up their private information.<\/li>\n<li>Create a <strong>man-in-the-middle attack<\/strong> on the HDTV to dupe consumers into thinking that \u201cimposter\u201d banking and commerce websites were legitimate.<\/li>\n<li>Steal the TV manufacturer\u2019s digital \u201ccorporate credentials\u201d to gain special VIP access to backend services from third-party organizations including popular search engines, video streaming, and photo sharing sites.<\/li>\n<li>Monitor and report on consumers\u2019 private Internet usage habits without their knowledge.<\/li>\n<\/ul>\n<p>The flaws Mocana uncovered should raise questions about the security of consumer electronics in general-which manufacturers are scrambling to connect to the Internet, often with <strong>little or no security technology on board<\/strong>.<\/p>\n<p><a href=\"https:\/\/www.madmagazine.com\/\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-101418\" title=\"Alfred E. Newman\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/AlfredENewman.jpg?resize=110%2C135&#038;ssl=1\" alt=\"Alfred E. Newman\" width=\"110\" height=\"135\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/AlfredENewman.jpg?resize=123%2C150&amp;ssl=1 123w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/AlfredENewman.jpg?resize=61%2C75&amp;ssl=1 61w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/AlfredENewman.jpg?w=245&amp;ssl=1 245w\" sizes=\"auto, (max-width: 110px) 100vw, 110px\" \/><\/a>Mocana\u2019s CEO Adrian Turner continued: \u201cWhile much public discussion &#8230; on the recent explosion of smartphones &#8230; the vast majority of new devices coming onto the Internet aren\u2019t phones at all: they are devices like television sets, industrial machines, medical devices, and automobiles &#8211; devices representing every conceivable industry. And the one thing that all these manufacturers have in common is that, unlike the computing industry, they don\u2019t have deep experience in security technology.\u201d<\/p>\n<h6>Related articles<\/h6>\n<ul>\n<li><a href=\"http:\/\/tarpon.wordpress.com\/2011\/12\/13\/microsoft-already-won-the-battle-for-the-living-room-when-nobody-was-looking\/\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Already Won The Battle For The Living Room When Nobody Was Looking<\/a> (tarpon.wordpress.com)<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><em><a title=\"Ralph Bach\" href=\"https:\/\/rbach.net\/index.php\/new-resume\/\" target=\"_blank\" rel=\"noopener noreferrer\">Ralph Bach<\/a>\u00a0has been in IT long enough to know better and has blogged from his\u00a0<a title=\"Bach Seat\" href=\"https:\/\/rbach.net\/\" target=\"_blank\" rel=\"noopener noreferrer\">Bach Seat<\/a> about IT, careers, and anything else that catches his attention since 2005. You can follow him on <a class=\"broken_link\" href=\"http:\/\/www.linkedin.com\/in\/rb48334\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">LinkedIn<\/a>,\u00a0<a href=\"https:\/\/www.facebook.com\/ralph.bach.14\" target=\"_blank\" rel=\"noopener noreferrer\">Facebook<\/a>,\u00a0and\u00a0<a href=\"https:\/\/twitter.com\/rbach48334\" target=\"_blank\" rel=\"noopener noreferrer\">Twitter<\/a>. Email the Bach Seat\u00a0<a href=\"mailto:\/\/bach.seat@gmail.com\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Global sales of Internet-connectable television devices will reach nearly 350 million units by 2015 many with security flaws that can steal credit card info<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[3045,420,101,938,536,92,940,832,935,937,4,936,525],"class_list":["post-4902","post","type-post","status-publish","format-standard","hentry","category-security","tag-3045","tag-aapl","tag-apple","tag-apple-tv","tag-goog","tag-google","tag-hdtv","tag-internet-of-things","tag-mocana","tag-parks-associates","tag-security","tag-smart-tv","tag-yahoo"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/4902","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/comments?post=4902"}],"version-history":[{"count":19,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/4902\/revisions"}],"predecessor-version":[{"id":128509,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/4902\/revisions\/128509"}],"wp:attachment":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/media?parent=4902"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/categories?post=4902"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/tags?post=4902"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}