{"id":5785,"date":"2018-12-25T00:43:17","date_gmt":"2018-12-25T00:43:17","guid":{"rendered":"http:\/\/www.styledeals.co.uk\/blog\/hot-tub-hack-reveals-washed-up-security-protection\/"},"modified":"2018-12-25T00:43:17","modified_gmt":"2018-12-25T00:43:17","slug":"hot-tub-hack-reveals-washed-up-security-protection","status":"publish","type":"post","link":"https:\/\/www.styledeals.co.uk\/blog\/hot-tub-hack-reveals-washed-up-security-protection\/","title":{"rendered":"Hot tub hack reveals washed-up security protection"},"content":{"rendered":"\n<div property=\"articleBody\">\n<figure class=\"media-landscape has-caption full-width lead\"><span class=\"image-and-copyright-container\"><\/p>\n<p>                <img loading=\"lazy\" decoding=\"async\" class=\"js-image-replace\" alt=\"Hot tub\" src=\"https:\/\/ichef.bbci.co.uk\/news\/320\/cpsprodpb\/3BC8\/production\/_104940351_7e57e25a-254a-4609-a37f-010df5d9c0e5.jpg\" width=\"976\" height=\"549\"\/><\/span><figcaption class=\"media-caption\"><span class=\"off-screen\">Image caption<\/span><br \/>\n                <span class=\"media-caption__text\"><br \/>\n                    Ken Munro demonstrated the hack to the BBC on a recent episode of Click<br \/>\n                <\/span><br \/>\n            <\/figcaption><\/figure>\n<p class=\"story-body__introduction\">Thousands of hot tubs can be hacked and controlled remotely because of a hole in their online security, BBC Click has revealed. <\/p>\n<p>Researchers showed the TV programme how an attacker could make the tubs hotter or colder, or control the pumps and lights via a laptop or smartphone.<\/p>\n<p>Vulnerable tubs are designed to let their owners control them with an app. <\/p>\n<p>But third-party wi-fi databases mean hackers can home in on specific tubs by using their GPS location data.<\/p>\n<p>Balboa Water Group (BWG), which runs the affected system, has now pledged to introduce a more robust security system for owners and said the problem would be fixed by the end of February.<\/p>\n<h2 class=\"story-body__crosshead\">Christmas alert<\/h2>\n<p>Pen Test Partners &#8211; the UK security company that carried out the research &#8211; warned that hot tubs were not the only household items at risk.<\/p>\n<p>Founder Ken Munro said that many Christmas gifts people would receive this year would connect to the internet and offer remote control through apps.<\/p>\n<p>&#8220;Manufacturers still are not taking security seriously enough, and until they do consumers have to be very vigilant,&#8221; he said.<\/p>\n<p>&#8220;We recommend users reset any default passwords the device has immediately with a unique one of their own.&#8221;     <\/p>\n<h2 class=\"story-body__crosshead\">&#8220;Next to no security&#8221;<\/h2>\n<p>In the case of the hot tubs, the researchers found that information found on public resources, known as &#8220;wardriving databases&#8221;, could be used to hijack the equipment without the need for any other kind of authentication.<\/p>\n<figure class=\"media-landscape has-caption full-width\"><span class=\"image-and-copyright-container\"><\/p>\n<p>            <\/span><figcaption class=\"media-caption\"><span class=\"off-screen\">Image caption<\/span><br \/>\n                <span class=\"media-caption__text\"><br \/>\n                    Public databases contain enough details to carry out the hack (this image has been edited to remove some information)<br \/>\n                <\/span><br \/>\n            <\/figcaption><\/figure>\n<p>BWG told the BBC that it had been &#8220;surprised&#8221; to learn of the flaw as its app had been available for five years during which users had not reported any problems.<\/p>\n<p>It said it was working with more than 1,000 owners in the UK and others globally to set up a system of individual usernames and passwords to secure the online controls.<\/p>\n<p>It said it had previously opted not to do so because it had wanted to &#8220;allow for simple and easy use and activation&#8221; by homeowners.<\/p>\n<p>Mr Munro said this had been &#8220;irresponsible&#8221;.<\/p>\n<p>&#8220;It takes away consumer choice and it takes away users&#8217; right to privacy and security,&#8221; he explained.<\/p>\n<p>The researcher acknowledged that it was not the most serious internet-of-things vulnerability in the world, but said it was still worth bringing to the public&#8217;s attention.<\/p>\n<p>&#8220;Blowers are only turned on when someone is in the tub, so a hacker could figure out if you&#8217;re in the tub at the time, which is creepy,&#8221; he explained.<\/p>\n<p>&#8220;Consumer IoT security is not in a good place. These findings underline that.&#8221;<\/p>\n<\/p><\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/www.bbc.co.uk\/news\/technology-46674706\">Source<\/a> by <a href=\"\">[author_name]<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Image caption Ken Munro demonstrated the hack to the BBC on a recent episode of Click Thousands of hot tubs can be hacked and controlled remotely because of a hole in their online security, BBC Click has revealed. Researchers showed the TV programme how an attacker could make the tubs hotter or colder, or control &hellip; <\/p>\n","protected":false},"author":0,"featured_media":5786,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-5785","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-general"],"_links":{"self":[{"href":"https:\/\/www.styledeals.co.uk\/blog\/wp-json\/wp\/v2\/posts\/5785","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.styledeals.co.uk\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.styledeals.co.uk\/blog\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/www.styledeals.co.uk\/blog\/wp-json\/wp\/v2\/comments?post=5785"}],"version-history":[{"count":0,"href":"https:\/\/www.styledeals.co.uk\/blog\/wp-json\/wp\/v2\/posts\/5785\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.styledeals.co.uk\/blog\/wp-json\/wp\/v2\/media\/5786"}],"wp:attachment":[{"href":"https:\/\/www.styledeals.co.uk\/blog\/wp-json\/wp\/v2\/media?parent=5785"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.styledeals.co.uk\/blog\/wp-json\/wp\/v2\/categories?post=5785"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.styledeals.co.uk\/blog\/wp-json\/wp\/v2\/tags?post=5785"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}