Make your neighbor think their house is haunted by blinking their Ikea smart bulbs
- Reference: 1665216492
- News link: https://www.theregister.co.uk/2022/10/08/buggy_ikea_smart_bulbs/
- Source link:
While the pair of bugs won't top the list of security flaws [1]Beijing-backed spies hope to exploit to steal government secrets or wreak havoc on high-value targets, the vulnerabilities could provide some mildly disruptive entertainment for, say, an annoying next-door neighbor looking for some spooky-month hi-jinx.
Jonathan Knudsen, head of global research at Synopsys Cybersecurity Research Center, led a team that discovered the vulnerabilities by fuzzing Ikea's Tradfri bulbs and their gateway via Zigbee Light Link, the wireless protocol the devices use to communicate and receive commands.
[2]
In a couple write-ups about the bugs, the researchers described how CVE-2022-39064, the vulnerability in the Tradfri smart bulbs, could be exploited by sending a single malformed Zigbee frame over the air that makes the light blink. Resending the frame multiple times forces the bulb to perform a factory reset, which erases its configuration and other information, such as brightness level.
[3]
[4]
"After this attack, all lights are on with full brightness, and a user cannot control the bulbs with either the Ikea Home Smart app or the Tradfri remote control," the team [5]noted .
This bug received a CVSS severity score of 7.1 out of 10, and it affects all versions of the lightbulb. There's also no full fix available from Ikea, and because the malformed Zigbee frame is an unauthenticated broadcast message, all vulnerable devices within radio range are affected.
[6]
"To recover from this attack, a user could add each bulb manually back to the network," according to the alert. "However, an attacker could reproduce the attack at any time."
CVE-2022-39064 is related to a second vulnerability, [7]CVE-2022-39065 , that affects the Ikea Tradfri smart lighting gateway, which controls the lights. Similar to the bulb bug, a malformed Zigbee frame renders the gateway unresponsive so that it can't control the connected lights and other devices via the Ikea Home Smart app.
However, the lighting gateway vulnerability, which earned a 6.5 CVSS rating, does have a fix: upgrading the gateway software to version 1.19.26 or later. Synopsys disclosed both bugs to Ikea in June 2021, and four months later the mega retailer confirmed it would fix them. In February this year, it did release a fix for the lighting gateway flaw, and in June it issued a partial fix for the bulb.
[8]
When asked about the vulnerabilities, an Ikea spokesperson told The Register : "We continue our work to improve the safety and functionality of our smart devices."
"It is not currently possible to gain access to sensitive information inside Tradfri Gateway or other Ikea smart devices," the spokesperon continued. "Most importantly, the identified issue is not jeopardizing the safety of our customers. The issue can be replicated in other, already known, ways due to the design of the Zigbee protocol."
[9]Too busy feasting on meatballs, Windows struggles to update itself in IKEA
[10]Take a former NSA head hacker, a Raspberry Pi, weird Kiwi radios and what do you get?
[11]Papa John's sued for 'wiretap' spying on website mouse clicks, keystrokes
[12]Top of the Pops: US authorities list the 20 hottest vulns that China's hackers love to hit
While the blinking and lost connection with the gateway device are "a nuisance," by themselves they "don't pose any serious risks such as safety concerns or loss of sensitive information," Knudsen admitted, in an email to The Register .
Not just fun and games
But there's a catch. "A deeper analysis of exploitability could reveal a chance for an attacker to take control of a bulb or a gateway, which would pose a more serious risk," he added.
"We haven't performed (and won't perform) this deeper analysis; our interest is improving the software ecosystem by working with vendors to fix security vulnerabilities."
There's also the potential issue that other smart home devices that use the same wireless protocol could be vulnerable, and we're told fuzzing may uncover similar bugs across other product lines.
Knudsen suggests that manufactures test their devices earlier in the development phase. "Organizations that build such devices should be making security part of every phase of software development, including testing such as static analysis, software composition analysis, fuzzing and more," he said.
This is especially true when, as with Ikea lights, it's relatively cheap and easy to pull off an annoying, albeit not dangerous, cyberattack, he warned.
"An attacker with low-cost hardware (a laptop and a $25 radio device) can exploit this vulnerability with no prior knowledge of a victim," Knudsen said. "Furthermore, the attack can be launched from a distance, typically 10 meters to 100 meters."
It's also important to remember that flickering lights aren't necessarily an indication of a cyberattack. There's also the possibility that someone trapped in the Upside Down is desperately trying to communicate. ®
Get our [13]Tech Resources
[1] https://www.theregister.com/2022/10/07/us_spooks_reckon_these_are/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y0FKNRyhbA6@KS7VC6veNQAAAFQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y0FKNRyhbA6@KS7VC6veNQAAAFQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y0FKNRyhbA6@KS7VC6veNQAAAFQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.synopsys.com/blogs/software-security/cyrc-advisory-ikea-tradfri-smart-lighting/
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y0FKNRyhbA6@KS7VC6veNQAAAFQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://www.synopsys.com/blogs/software-security/cyrc-advisory-ikea-tradfri-smart-lighting-gateway/
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y0FKNRyhbA6@KS7VC6veNQAAAFQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[9] https://www.theregister.com/2021/12/30/bork/
[10] https://www.theregister.com/2018/01/22/rob_joyce_hacking/
[11] https://www.theregister.com/2022/10/06/papa_johns_spying_lawsuit/
[12] https://www.theregister.com/2022/10/07/us_spooks_reckon_these_are/
[13] https://whitepapers.theregister.com/
But, but, but ...
"should be making security part of every phase of software development"
But they are programmed using Rust, and that's always safe and secure, right?
Right? right?
I've been running across this incorrect assumption in wild management ... be afraid, very afraid.
Rule 1 : Anything labelled 'Smart'
is as dumb as my little toe. The latter seems to find legs of furniture all by itself when not wearing shoes at home.
My so-called Smart TV gets dumber and dumber almost daily as the hideously out-of-date software (which has not been updated for years) loses app support. As for websites that use 2-ph verification? Forget it.
See... it is dumb.
Rule 2 : anything labelled as 'Smart' is only workable while the vendor maintains the phone home server associated with it.
Rule 3 : any paid for subscriptions are only as good as your bank account lets them be,
If you go about assuming these rules then you won't go far wrong. We are becoming increasingly dependent upon the whims of the companies whose products we buy.
Very few people look at the 3-5 year TCO.
For example, you are clearly paying for the blanket TV Ads for Verisure Alarms. £47/month minimum 3 years. Other companies offer similar services without the TV ad levy for half that. You are NOT buying an alarm system, you are renting it because AFAIK, without the mandatory service, it is useless. I wonder how many customers understand that before they buy and commit to spending around £2K over 3 years.
Smart devices for dummies
"While the pair of bugs won't top the list of security flaws Beijing-backed spies hope to exploit to steal government secrets"
How about flickering lights to transfer information over an air gap. Flickering might be made undetectable to humans, depending on the device characteristics in question. The threat scenario might only be of academic interest, but shows again how big a security/privacy hazard this 'smart' crap makes.
I trust that no government agency would instal 'smart' devices in their premises, no?
A more rational explanation
It's also important to remember that flickering lights aren't necessarily an indication of a cyberattack. There's also the possibility that someone trapped in the Upside Down is desperately trying to communicate.
Wrong and wrong!
Flickering lights are definitely desperate AI trying to escape from cyberspace and get into the real world. The AI are probing all pathways and stumble constantly on virtual light switches and tripping them in the process.
You can see a nice display of this when you up the voltage and look at the blue glow when the lights go off. Upping the voltage draws in the AI in droves and the crowded wires start to glow because the AI are reaching out. Beware not to touch the blue glow if you do not want to get infected by wandering AI.