Smart Lights Might Become Data Security Gaps

Connected lighting with smart light bulbs that can be controlled via mobile phone or tablets help to improve life convenience. However, a new study by researchers at the University of Texas, San Antonio (UTSA) warns that personal data and information could be hacked via smart light bulbs.

Researchers at UTSA have conducted a review of the security holes that exist in popular smart-light brands. According to the analysis, the next prime target could be that smart bulb that shoppers buy for the coming holiday season.

"Your smart bulb could come equipped with infrared capabilities, and most users don't know that the invisible wave spectrum can be controlled. You can misuse those lights," said Murtuza Jadliwala, professor and director of the Security, Privacy, Trust and Ethics in Computing Research Lab in UTSA's Department of Computer Science. "Any data can be stolen: texts or images. Anything that is stored in a computer."

Some smart bulbs connect to a home network without needing a smart home hub, a centralized hardware or software device where other internet of things products communicate with each other. Smart home hubs, which connect either locally or to the cloud, are useful for IoT devices that use the Zigbee or Z-Wave protocols or Bluetooth, rather than Wi-Fi.


(Image: UTSA)

If these same bulbs are also infrared-enabled, hackers can send commands via the infrared invisible light emanated from the bulbs to either steal data or spoof other connected IoT devices on the home network. The owner might not know about the hack because the hacking commands are communicated within the owner's home Wi-Fi network, without using the internet.

This study, titled "Light Ears: Information Leakage via Smart Lights," was coauthored by Anindya Maiti and published in the September 2019 issue of the journal Proceedings of the ACM on Interactive, Mobile, Wearable and Ubiquitous Technologies.

"Think of the bulb as another computer," added Jadliwala. "These bulbs are now poised to become a much more attractive target for exploitation even though they have very simple chips." Jadliwala recommends that consumers opt for bulbs that come with a smart home hub rather than those that connect directly to other devices. He also recommends that manufacturers do a better job in developing security measures to limit the level of access that these bulbs have to other smart home appliances or electronics within a home.

Disclaimers of Warranties
1. The website does not warrant the following:
1.1 The services from the website meets your requirement;
1.2 The accuracy, completeness, or timeliness of the service;
1.3 The accuracy, reliability of conclusions drawn from using the service;
1.4 The accuracy, completeness, or timeliness, or security of any information that you download from the website
2. The services provided by the website is intended for your reference only. The website shall be not be responsible for investment decisions, damages, or other losses resulting from use of the website or the information contained therein<
Proprietary Rights
You may not reproduce, modify, create derivative works from, display, perform, publish, distribute, disseminate, broadcast or circulate to any third party, any materials contained on the services without the express prior written consent of the website or its legal owner.

Violumas, provider of high-power UV LED solutions and inventor of 3-PAD LED technology, is proud to launch the release of new 275nm and 265nm LEDs in mid-power, high-power, and high-density packages. The radiant flux of the new 275nm and 265nm... READ MORE

DURHAM, NC – November 12, 2024 –– Cree LED, a Penguin Solutions brand (Nasdaq: PENG), today announced the launch of its new CV28D LEDs with FusionBeam™ Technology, a groundbreaking advancement for the LED signage market... READ MORE