• Welcome back Guest!

    MARSH is a private reefing group. Comments and suggestions are encouraged, but please keep them positive and constructive. Negative threads, posts, or attacks will be removed from view and reviewed by the staff. Continually disruptive, argumentative, or flagrant rule breakers may be suspended or banned.

Casino Gets Hacked Through Its Internet-Connected Fish Tank Thermometer (1 Viewer)

Users who are viewing this thread

Joined
Apr 24, 2018
Messages
41
Reaction score
0
Location
S.E. Texas
This is pretty wild. The article doesn't mention which thermometer was hacked, but I found two on the market with just a quick search, Fishbit and ApexFusion, although I image there are others. Does anyone use internet connected aquarium devices?

From The Hacker News. Sunday, April 15, 2018. Wang Wei. There is a link at the bottom to the original article.

"Internet-connected technology, also known as the Internet of Things (IoT), is now part of daily life, with smart assistants like Siri and Alexa to cars, watches, toasters, fridges, thermostats, lights, and the list goes on and on.
But of much greater concern, enterprises are unable to secure each and every device on their network, giving cybercriminals hold on their network hostage with just one insecure device.
Since IoT is a double-edged sword, it not only poses huge risks to enterprises worldwide but also has the potential to severely disrupt other organisations, or the Internet itself.
There's no better example than Mirai, the botnet malware that knocked the world's biggest and most popular websites offline for few hours over a year ago.

We have another great example that showcases how one innocent looking insecure IoT device connected to your network can cause security nightmares.
Nicole Eagan, the CEO of cybersecurity company Darktrace, told attendees at an event in London on Thursday how cybercriminals hacked an unnamed casino through its Internet-connected thermometer in an aquarium in the lobby of the casino.
According to what Eagan claimed, the hackers exploited a vulnerability in the thermostat to get a foothold in the network. Once there, they managed to access the high-roller database of gamblers and "then pulled it back across the network, out the thermostat, and up to the cloud."Although Eagan did not disclose the identity of the casino, the incident she was sharing could be of last year, when Darktrace published a report [PDF], referencing to a thermometer hack of this sort on an unnamed casino based in North America. The adoption of IoT technology raises concerns over new and more imaginative cybersecurity threats, and this incident is a compelling reminder that the IoT devices are theoretically vulnerable to being hacked or compromised.
"There's a lot of internet of things devices, everything from thermostats, refrigeration systems, HVAC [air conditioning] systems, to people who bring in their Alexa devices into the offices," said Eagan. "There's just a lot of IoT. It expands the attack surface and most of this isn't covered by traditional defenses."

Manufacturers majorly focus on performance and usability of IoT devices but ignore security measures and encryption mechanisms, which is why they are routinely being hacked.
Therefore, people can hardly do anything to protect themselves against these kinds of threats, until IoT device manufacturers timely secure and patch every security flaws or loopholes that might be present in their devices.
The best way you can protect is to connect only necessary devices to the network and place them behind a firewall.
Also, keep your operating systems and software up-to-date, make use of a good security product that protects all your devices within the network, and most importantly, educate yourself about IoT products."

https://thehackernews.com/2018/04/iot-hacking-thermometer.html?m=1
 

Cody

Vice President
Staff member
Administrator
Moderator
Content Moderator
Board Member
Supporting Member
Joined
Jul 23, 2014
Messages
7,304
Reaction score
4,253
Location
Spring, TX
This is nuts! I have some general outlet controllers that I play with that run off of wifi, and I thought about how hard it would be to hack into them. I kinda like my old school digital timers for a lot of things. No bells and whistles and you also know exactly what they'll do everytime.
 

Bigfishy

Supporting Member
Joined
Mar 7, 2014
Messages
586
Reaction score
131
This is nuts! I have some general outlet controllers that I play with that run off of wifi, and I thought about how hard it would be to hack into them. I kinda like my old school digital timers for a lot of things. No bells and whistles and you also know exactly what they'll do everytime.

Yep- if you can get on a device that is on the network that is half the battle. Given enough time there is lots of things a hacker can do.


Sent from my iPhone using Tapatalk
 

frankc

Supporting Member
Member Spotlight Contest Winner
Build Thread Contributor
Joined
Jun 11, 2012
Messages
1,360
Reaction score
1,330
Location
The Woodlands
I don't have any internet-enabled aquarium devices, but we just had our a/c replaced and they came with thermostats that can be controlled from an iPhone, and the company that installed them can get performance and diagnostics data without having to come to the house. Pretty cool, but a bit scary too, especially after reading this.

It makes me think of the James Bond movie "Skyfall", where pretty much everything in the government had been hacked and the only safe transportation was the 1964 Aston Martin because it had no electronics to allow tracking or hacking.
 
Top