LAS VEGAS (CNNMoney)

Today's high-end televisions are almost all equipped with "smart" PC-like features, including Internet connectivity, apps, microphones and cameras. But a recently discovered security hole in some Samsung Smart TVs shows that many of those bells and whistles aren't ready for prime time.

The flaws in Samsung Smart TVs, which have now been patched, enabled hackers to remotely turn on the TVs' built-in cameras without leaving any trace of it on the screen. While you're watching TV, a hacker anywhere around the world could have been watching you. Hackers also could have easily rerouted an unsuspecting user to a malicious website to steal bank account information.

Samsung quickly fixed the problem after security researchers at iSEC Partners informed the company about the bugs. Samsung sent a software update to all affected TVs.

But the glitches speak to a larger problem of gadgets that connect to the Internet but have virtually no security to speak of.

Security cameras, lights, heating control systems and even door locks and windows are now increasingly coming with features that allow users to control them remotely. Without proper security controls, there's little to stop hackers from invading users' privacy, stealing personal information or spying on people.

Related story: The scariest search engine on the Internet

In the case of Samsung Smart TVs, iSEC researchers found that they could tap into the TV's Web browser with ease, according to iSEC security analyst Josh Yavor. That gave hackers access to all the functions controlled by the browser, including the TV's built-in camera.

"If there's a vulnerability in any application, there's a vulnerability in the entire TV," said Aaron Grattafiori, also an analyst at iSEC.

Yavor and Grattafiori were also able to hack the browser in such a way that users would be sent to any website of the hacker's choosing. While the hack would have been obvious if the website on the screen didn't match the desired address, Yavor says there could be serious implications if a bad actor sent a user to a lookalike banking page and retrieved a user's credentials.

Related story: NSA chief recruits hackers

The research was conducted on different models of 2012 Samsung Smart TVs and was presented this week at the Black Hat cybersecurity conference in Las Vegas.

In a statement to CNNMoney, Samsung said it takes user safety very seriously. Addressing the camera flaw, a company spokesperson said, "The camera can be turned into a bezel of the TV so that the lens is covered, or disabled by pushing the camera inside the bezel. The TV owner can also unplug the TV from the home network when the Smart TV features are not in use."

Samsung also recommends that customers use encrypted wireless access points.

The iSEC crew said they remain skeptical that the technology is perfectly secure, even after Samsung patched the bugs.

"We know that the way we were able to do this has been fixed; it doesn't mean that there aren't other ways that could be discovered in the future, " Yavor said.

Companies like Samsung pay hackers when they report security vulnerabilities like the ones iSEC found. The researchers are iSEC confident that there are more undetected flaws in these devices that they are running a fund-raiser off of finding bugs in Smart TVs at technology conference Def Con later this week.

Yavor and Grattafiori say users should run regular updates from vendors like they would for anti-virus definitions or system updates on the smartphone.

And when all else fails, users can always put tape over their cameras. 

http://money.cnn.com/2013/08/01/technology/security/tv-hack/index.h...

Views: 163

Reply to This

Replies to This Discussion

I talked to a guy from Nevada last year that swears this is nothing new. He ran through several scenarios that were quite scary. Any web connected device has certain capabilities that could be used to spy.

RSS

"Destroying the New World Order"

TOP CONTENT THIS WEEK

THANK YOU FOR SUPPORTING THE SITE!

mobile page

12160.info/m

12160 Administrators

 

Latest Activity

Doc Vega posted blog posts
14 hours ago
Less Prone favorited cheeki kea's photo
19 hours ago
cheeki kea posted photos
yesterday
Doc Vega posted blog posts
Thursday
tjdavis posted a photo
Tuesday
james will posted blog posts
Tuesday
Less Prone favorited Sandy's video
Tuesday
Doc Vega's 5 blog posts were featured
Tuesday
tjdavis's 4 blog posts were featured
Tuesday
Doc Vega posted a blog post

What was the Significance of the F-94 C and What role in History?

 It’s July 19, 1952 over White House forbidden airspace and Captain William Patterson observes…See More
Dec 21
tjdavis posted a video

FLUORIDEGATE: An American Tragedy. a film by Dr. David Kennedy

FLUORIDEGATE: An American Tragedy, is a feature documentary that reveals the tragedy of how government, industry and trade associations protect and promote a...
Dec 20
Doc Vega posted a blog post

Rendezvous With The Unknown

Rendezvous With the Unknown Chapter I It was about 9:00 am when I received a text on my phone from…See More
Dec 20
cheeki kea replied to cheeki kea's discussion Tartaria
"ah ha - a Tartarian cuisine component lurks inside good old Tartar Sauce. Who would have thought.…"
Dec 20
tjdavis posted a blog post
Dec 19
Doc Vega posted a blog post

Shadows in the Wind

If you think that life is but a game you can winYou’re just a shadow in the windConveniently…See More
Dec 19
Doc Vega posted a blog post
Dec 18
tjdavis posted a photo
Dec 17
james will is now a member of 12160 Social Network
Dec 17
Burbia replied to cheeki kea's discussion Tartaria
Dec 17
Burbia posted a video

Mossad: we create a pretend world, we are a global production company... the world is our stage

60 Minutes interviews alleged Mossad agent"we create a pretend world, we are a global production company......the world is our stage."_______________________...
Dec 17

© 2025   Created by truth.   Powered by

Badges  |  Report an Issue  |  Terms of Service

content and site copyright 12160.info 2007-2019 - all rights reserved. unless otherwise noted