How dangerous are IOT devices? | Yuval Elovici | TEDxBGU

Video Statistics and Information

Video
Captions Word Cloud
Reddit Comments
Captions
[Music] did we do this morning I woke up and went to my morning run using my smart watch this watch what is really amazing it collects a lot of information about me about my speed of running about the distance even my heart rate and immediately when I arrived home I can see that all the information is already stored in the cloud and even it can measure my stress level let's see now it's 90 I have another 10 to go with lists while standing next when I finish to make a bathroom I go to my work using my connected car oh how come my car is already connected I'm using Waze in my car and this way it's connected to the Internet in the future every car is going to be connected to the Internet and it's going to be part of the IOT revolution today the cars are connected because of the application that we are having inside our car but in the future cars are going to be fully connected and are going to be even autonomous then when I reach to my office usually I like to play with the latest gadget you know when you are doing a lot of research in the domain of IOT you can play a lot with this IOT devices so you are buying many IOT devices one of them is the Google glass you see even a glass started to become smart and this smart Google glass what we can do with them we can actually navigate the internet and see many things there is a small display and a camera and in the future such glasses will even be able to tell us if somebody in front of us is lying or not and then when I'm coming home I'm going ability to my smart fridge to grab something from the fridge this fridge is smarter why it's smarter it's includes a very very nice display via this display I can order groceries and in addition it has a very nice dashboard where my wife can remain put me all the tasks that to live during this day then I have to play with my letters drawn at home in the evening this drone is really amazing you can take lot of photos with it it's also connected to the Internet via the mobile phone in the futures dawn are going to be completely autonomous and are going to bring us groceries to our house in the late evening I like to go to watch movies in my smart TV this Smart TV is also connected to the Internet and allows me to access to many many content providers and get a lot of free interesting videos and content in the future this our TVs will know automatically what we supposed to watch what really interests us all these things that I described to you are actually part of the Internet of Things revolution these are a loti that are interacting they with them and in the future we are going to do even more so as you saw many devices that we are using today are going to become connected to the Internet and I'm going to provide us much better services why ayat is is so important mainly because in the past for example we had a heart rate monitor the heart rate monitor could collect information about our heart status and then to provide us a prognosis about what is the status of our heart in the future it's going to be a IOT heart rate monitor that is going to collect a lot of information about our heart is going to send it to the cloud and in the cloud the very strong servers are going to make the diagnosis and send it to us back so the revolution is really really profound but let's talk about the privacy risks you know our teeth collect a huge amount of information about us which is stored in the cloud this information is going to be analyzed in order to provide us better services but on the other hand if somebody will manage to get if data you will manage to violate our privacy let's go to one very very sexy example this is a smart vibrator that the company actually developed and this smart vibrator is actually activated via the mobile phone what actually happened is that this company collected a lot of information about the patterns of usage of their customers and eventually their customers went to court and they had to pay $10,000 for every user because they potentially violated the privacy of their customers but to understand really the problem let's go back to my day - my day of interacting with many many types of IOT is let's see what may happen if somebody is going to get the data Oh somebody will manage to compromise my specific coyotes what will happen to my particular privacy first of all let's start with this very interesting Smart Watch try to imagine that I'm sitting in my living room in front of my Smart TV and suddenly the police knocks on my door and they enter into my living room and they tell me that they have a fine for me because I drove while I was intoxicated so I have alcohol in my blood how come the police knows that I have alcohol in my blood well we did a research in Bangor University where we managed to collect information from the Smart Watch and connected to the level of alcohol in our blood in other words the information that this Smart Watch collects can be translated into the amount of alcohol in our blood but how come the police knows that I was driving when I was intoxicated please recall the connected car my car is connected so actually in the cloud provider of these connected cars there is knowledge when I drove so if you correlate the data from the SmartWatch yet over the data from the connected car platform you know that I drove actually when I was intoxicated this is just one example another example if somebody will manage to compromise my SmartWatch I told you before this SmartWatch nodes what is my level of stress at every point in time imagine us at the time in the middle of a poker game somebody can derive immediately conclusion whether I am bluffing or not and these are just examples of what may happen if somebody will manage to compromise either my IOT device all the content of information that was delivered from my IO T's to the cloud next let's go to my connected car every connected car is reporting its location to its cloud service provider so if somebody will manage to hack into the cloud service provider they will know the location of many many cars in a specific country now what is the value of this information first of all you can analyze this data and the right conclusion about where the person is living where he is working and if you are really a very sophisticated safe you can even know to pinpoint every BMW exactly where he is standing at night in order to do a targeted theft not targeted attack target a theft against the particular owner of the car now let's go to these smart glasses smart glasses are connected to the Internet so literally an attacker can compromise a specific piece of Google glass using a malware in addition there are many ways to compromise a personal computer inside the company we managed to develop a very intelligent malware that literally managed to create a very smart blinking on the screen of a PC and by that modulating and sending the data to the smart glasses and from the smart glasses to the internet so actually it is justifiable that many companies do not allow to bring smart glasses into the premises because if the smart lattice is compromised it can be used to leak a lot of information from the organization to the attacker next let's look at this interesting smart fridge imagine you said that you are sitting at your home navigating your notebook and suddenly you get an amazing advertisement for a diet program if it will happen for me probably it's a false positive but think about a general person that receives such an advertisement why it may happen in the future our student discovered that a smart fridge is actually sending information to the cloud each time that we are opening the fridge in other words when you analyze the data in the cloud you can use analytics to derive a conclusion that somebody is actually fat now based on that somebody will send me an advertisement but what could be even worse that somebody will not give me an insurance because they know my eating habits just because I'm using this smart fridge let's go to a drone I describe to you me playing with the drone but me playing with the drone maybe it's not my problem my problem is my neighbor displaying with the drone my neighbor can use a drone above its premises and he may use it to invade my privacy and I will not know that it's actually happening we developed in Bengal University a very destructive research in which what we did and here you can see even my house we use a stimuli on the window such that if somebody is photographing if a drone our window we can intercept on the air the encrypted traffic from the drone to the operator of the drone and since we see that there is a correlation between the physical stimulus on the window that we are creating and the amount of traffic encrypted traffic that we receive we know for sure that actually somebody is photographing us and streaming these data encrypted to his own PC which tell us that actually somebody is invading our privacy what to do if it it's another big story how to stop the drone from flying let's look at our Smart TV you know a Smart TV is connected to the Internet it's a part of the Internet of Things revolution if somebody will be able to compromise my Smart TV you will ever first of all to know what I am watching currently my TV but many many Smart TVs also possess a microphone and a camera and using that and adversary will be able to compromise our bedroom that's very very risky as well to conclude in the future we are going to interact with many many IOT devices this IOT devices are going to collect a lot of information about us this information can be used to provide us better services but on the other hand if this information is going to be leaked to an adversary you will be able to use it to learn many many things about us and to compromise our privacy and it's mandatory that whoever is managing these services will make sure that is using the best security technologies to protect our privacy from any potential violation thank you you
Info
Channel: TEDx Talks
Views: 82,737
Rating: undefined out of 5
Keywords: TEDxTalks, English, Life, Coding, Communication, Community, Development, Smartphone
Id: vgoX_m6Mkko
Channel Id: undefined
Length: 12min 51sec (771 seconds)
Published: Fri Mar 09 2018
Related Videos
Note
Please note that this website is currently a work in progress! Lots of interesting data and statistics to come.