"Hackers" Take Over Moving Vehicle a.k.a. Secure Your Home!

Posted on
Thu Jul 23, 2015 12:23 pm
RogueProeliator offline
User avatar
Posts: 2501
Joined: Nov 13, 2012
Location: Baton Rouge, LA

"Hackers" Take Over Moving Vehicle a.k.a. Secure Your Home!

This is just a gentle reminder to everyone that you really need to be security conscious with your home automation setup -- there is a reason that many of us "preach" not to use basic authentication and open up ports and run your own security protocols... particularly the mistake of "security by obscurity" (thinking that just because you don't tell anyone, say, what port you are using that you are safe.)

This article is one example -- here hackers (in the good sense of the word - really security researchers) demonstrate a real-time exploit that allowed them to control a Jeep on the highway 10 miles away; don't worry the driver was a willing participant - the author of the story.
http://www.wired.com/2015/07/hackers-remotely-kill-jeep-highway/

I realize this is a car, yes, but it does show that researchers, and likely malicious hackers, are broadening their scope of attacks. Vulnerabilities like this will likely become more and more common, though in the real world I doubt a hacker goes after a car as there is little profit there. A house, however, could be an inviting target.

Far from an exhaustive list, here are some of the home-automation-specific suggestions that I've had along with those from other forum members that have been mentioned before. Might behoove everyone to do a quick check of their system's security every so often...

  • Physical Security - make sure your door locks are reliable; best case is that they have feedback though for many this will need to wait until Indigo supports door locks
  • Security System - ideally your security system should be a known vendor and will work independently of the Indigo server running (even with reduced functionality you want something to happen!)
  • Security System - alerts should work with power out ideally, though there are certainly situations that you can't control. Some users use a backup notification system so that it can send a notification via cellular, phone and network
  • Camera Systems - make sure you can record all the time or on motion, but just most importantly that it works! Some prefer standalone systems here, some integrated to Indigo and some a hybrid approach. All have advantages and disadvantages, but all are better than none!
  • Network - secure your wireless with WPA2 and a decent passphrase; if you enable a guest network ensure it cannot get to internal network devices
  • Indigo System - enable digest authentication, don't use basic or none
  • Indigo System - disable remote access if not using it, use reflector service if you are. If you REALLY know what you are doing then a reverse proxy in Apache can enable secure access. If you need to access Indigo remotely via Mac Client, consider a good network router that supports VPN connections instead of opening additional ports to the world
  • Indigo System - some users place a screensaver and password requirement, some secure physical access to the device. nothing is perfect here, but at LEAST hide the server from plain sight!
  • Indigo System - use a good password for both the Mac and Indigo... in general a longer password that is not made up of standard words/phrases is stronger than a shorter password with more diverse characters. Even better, use a password manager with a very secure password and utilize the random password generator feature.
  • Indigo's Computer - really applies to any, but turn off any services you are not using. If you aren't using File Sharing or Back to My Mac, turn them off
  • Attached Network Devices - use a good password; it can be inconvenient but is really a small thing. Don't allow unauthenticated access to anything (e.g. file shares)!
  • Control Pages -- obvious but overlooked... don't put a "Disarm Alarm" button on a wall-mount iPad next to the door. Stop laughing, you would be surprised at how many don't think about that.
  • All Passwords - change your passwords on a schedule & enable two factor authentication anywhere it is supported

I'm SURE I've missed some other suggestions from the forums; if you have any more please feel free to add them!

Adam

Posted on
Fri Jul 24, 2015 5:44 am
durosity offline
User avatar
Posts: 4320
Joined: May 10, 2012
Location: Newcastle Upon Tyne, Ye Ol' England.

Re: "Hackers" Take Over Moving Vehicle a.k.a. Secure Your Ho

Brilliant post Adam, much of which I've been thinking of more and mor lately but some good things there I hadn't thought of. Ideally I'd love to see Indigo implement secure connections when not using reflector.. Unfortunately I just find it too slow for daily use (and also my work block access to it so I'm constantly having to turn off wifi to access).


Sent from my iPad using Tapatalk

Computer says no.

Posted on
Sun Jul 26, 2015 9:35 am
howartp offline
Posts: 4559
Joined: Jan 09, 2014
Location: West Yorkshire, UK

Re: "Hackers" Take Over Moving Vehicle a.k.a. Secure Your Ho

Yeah, I read/watched that story about the jeep this week and immediately thought about Indigo.

Time to lock down my own systems a bit more, methinks.


Sent from my iPhone using Tapatalk

Posted on
Tue Jul 19, 2016 10:22 am
T-Power offline
User avatar
Posts: 220
Joined: May 10, 2010

Re: "Hackers" Take Over Moving Vehicle a.k.a. Secure Your Ho

Hello All,
Just saw this post, great feedback Adam !
As always, thanks for sharing.

MacMini 2.3 GHz Intel Core i7 16GB DDR3
Indigo Pro 2022.1 macOS Mojave 10.14.6

Page 1 of 1

Who is online

Users browsing this forum: No registered users and 10 guests