{"id":16602,"date":"2019-10-16T06:30:04","date_gmt":"2019-10-16T14:30:04","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2019\/10\/16\/news-10341\/"},"modified":"2019-10-16T06:30:04","modified_gmt":"2019-10-16T14:30:04","slug":"news-10341","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2019\/10\/16\/news-10341\/","title":{"rendered":"Why we need Apple\u2019s HomeKit-enabled routers"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/article\/2019\/02\/homekit-100788746-large.3x2.jpg\"\/><\/p>\n<p><strong>Credit to Author: Jonny Evans| Date: Wed, 16 Oct 2019 06:47:00 -0700<\/strong><\/p>\n<p>How <a href=\"https:\/\/www.computerworld.com\/article\/2476652\/can-apple-keep-us-safe-in-the-internet-of-things.html\">secure<\/a> are the connected smart devices you keep in your home? How much protection have you put in place, and have you even taken a minute to change your default router password?<\/p>\n<p>The truth is many smart home device users (and those running connected devices in smart offices, enterprises, manufacturing and beyond) may not yet have taken stock of their security.<\/p>\n<p>This is a particular problem when it comes to older smart devices, many of which are still in use even though a large number of them shipped with weak or non-replaceable factory default passcodes.<\/p>\n<p>The proliferation of poorly protected smart devices in conjunction with weak router security is a potential gold mine for hackers, who are eagerly attempting to crack into people\u2019s IoT networks in order to create botnets for future use.<\/p>\n<p>That\u2019s alongside the inevitable threat that criminals will use poorly protected IoT devices as access points to penetrate networks, harvest personal and payment data, and more.<\/p>\n<p>Apple\u2019s <a href=\"https:\/\/www.applemust.com\/where-are-the-homekit-secured-wi-fi-6-routers-for-my-iphone-11\/\" rel=\"noopener nofollow\" target=\"_blank\">promised HomeKit-enabled routers<\/a> may improve protection.<\/p>\n<p>One of the many <a href=\"https:\/\/www.computerworld.com\/article\/3407799\/how-apple-is-improving-icloud-this-year.html\">iCloud enhancements<\/a> Apple is attempting to bring to market in 2019, the idea is that these protect your accessories with a firewall at router level.<\/p>\n<p>You can see some screen shots of how this works <a href=\"https:\/\/twitter.com\/KhaosT\/status\/1135828579931967488?s=20\" rel=\"noopener nofollow\" target=\"_blank\">here<\/a>, while<a href=\"https:\/\/staceyoniot.com\/lets-dig-into-apples-homekit-news\/\" rel=\"noopener nofollow\" target=\"_blank\"> this report explains a little more<\/a> concerning how this protection works.<\/p>\n<p>In use, you\u2019ll be able to assign each of your HomeKit devices security permissions as follows:<\/p>\n<p>You set this preference up individually for each one of your HomeKit devices.<\/p>\n<p>Apple is also introducing a HomeKit Secure Video service, which adds layers of protection around CCTV video.<\/p>\n<p>To help understand the scale of the threat &#8212; and why Apple&#8217;s solution is so important &#8212; reflect on\u00a0new\u00a0<a href=\"https:\/\/www.kaspersky.com\/about\/press-releases\/2019_iot-under-fire-kaspersky-detects-more-than-100-million-attacks-on-smart-devices-in-h1-2019\" rel=\"noopener nofollow\" target=\"_blank\">Kaspersky<\/a>\u00a0research which tells us attacks against smart home devices climbed by around 700% in the last 12 months.<\/p>\n<p>Using a network of decoy devices they found that while 12 million attacks originating from 69,000 IP addresses took place in the first half of 2018, the first half of 2019 saw 105 million attacks from 276,000 IP addresses.<\/p>\n<p>The attacks are not particularly sophisticated, the researchers say. They observe that hackers are trying not to be noticed, which suggests they are building botnets, presumably for future DDoS attacks.<\/p>\n<p>\u201cAs people become more and more surrounded by smart devices, we are witnessing how IoT attacks are intensifying.<\/p>\n<p>Judging by the enlarged number of attacks and criminals\u2019 persistency, we can say that IoT is a fruitful area for attackers that use even the most primitive methods, like guessing password and login combinations,\u201d said Dan Demeter, security researcher at Kaspersky Lab.<\/p>\n<p>While we wait for Apple and router companies to introduce these better protected routers, how can we protect ourselves?<\/p>\n<p>Kaspersky advises us to take the time to check our existing security setups, warning that the most common security combinations in the field are appallingly easy to guess and crack.<\/p>\n<p>\u201cThe most common combinations by far are usually \u201csupport\/support\u201d, followed by \u201cadmin\/admin\u201d, \u201cdefault\/default\u201d,\u201d they said,<\/p>\n<p>Consumer and enterprise users of connected devices should take time to change default password settings to mitigate this.<\/p>\n<p>There are other steps you can (and should) take:<\/p>\n<p>The problem with many of these protections is they are not necessarily trivial or accessible to every user, and that (I think) is how Apple\u2019s HomeKit-approved router scheme will help people protect themselves a little more effectively.<\/p>\n<p>The only problem being that at present <a href=\"https:\/\/www.applemust.com\/linksys-intelligent-mesh-routers-will-add-homekit-compatibility\/\" rel=\"noopener nofollow\" target=\"_blank\">we don\u2019t know when these systems will ship<\/a>.<\/p>\n<p>I suspect there may be some unexpected challenges.<\/p>\n<p>Recently announced delays in delivering some previously announced Catalina and iOS iCloud-related features (such as folder sharing in iCloud Drive) suggests tying together that last few pieces of Apple\u2019s nascent HomeKit security model may have hit turbulent, unless this is being held back by potential <a href=\"https:\/\/www.computerworld.com\/article\/3442944\/9-reasons-there-may-be-an-october-apple-event.html\">plans to introduce<\/a> another product <a href=\"https:\/\/www.computerworld.com\/article\/3435201\/why-apple-s-little-find-my-tile-competitor-is-big-news.html\">designed to work<\/a> within such an ecosystem.<\/p>\n<p>Signing off, no matter what computing platforms you run, you should most certainly take control of your existing smart home security set-up. Change your passwords, update the firmware, and make sure your routers are secure.<\/p>\n<p>Please follow me on<em>\u00a0<a href=\"https:\/\/twitter.com\/jonnyevans_cw\" rel=\"nofollow\">Twitter<\/a>, or join me in the\u00a0<a href=\"https:\/\/mewe.com\/join\/appleholics_bar_and_grill\" rel=\"nofollow\">AppleHolic\u2019s bar &amp; grill<\/a>\u00a0and\u00a0<a href=\"https:\/\/mewe.com\/join\/apple_discussions\" rel=\"nofollow\">Apple Discussions<\/a>\u00a0groups on MeWe.<\/em><\/p>\n<p><a href=\"https:\/\/www.computerworld.com\/article\/3446197\/why-we-need-apples-homekit-enabled-routers.html#tk.rss_security\" target=\"bwo\" >http:\/\/www.computerworld.com\/category\/security\/index.rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/article\/2019\/02\/homekit-100788746-large.3x2.jpg\"\/><\/p>\n<p><strong>Credit to Author: Jonny Evans| Date: Wed, 16 Oct 2019 06:47:00 -0700<\/strong><\/p>\n<article>\n<section class=\"page\">\n<p>How <a href=\"https:\/\/www.computerworld.com\/article\/2476652\/can-apple-keep-us-safe-in-the-internet-of-things.html\">secure<\/a> are the connected smart devices you keep in your home? How much protection have you put in place, and have you even taken a minute to change your default router password?<\/p>\n<h2><strong>Computer says no<\/strong><\/h2>\n<p>The truth is many smart home device users (and those running connected devices in smart offices, enterprises, manufacturing and beyond) may not yet have taken stock of their security.<\/p>\n<p>This is a particular problem when it comes to older smart devices, many of which are still in use even though a large number of them shipped with weak or non-replaceable factory default passcodes.<\/p>\n<p class=\"jumpTag\"><a href=\"\/article\/3446197\/why-we-need-apples-homekit-enabled-routers.html#jump\">To read this article in full, please click here<\/a><\/p>\n<\/section>\n<\/article>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[11062,10643],"tags":[2211,10480,10554,714],"class_list":["post-16602","post","type-post","status-publish","format-standard","hentry","category-computerworld","category-independent","tag-apple","tag-ios","tag-mobile","tag-security"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/16602","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=16602"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/16602\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=16602"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=16602"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=16602"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}