WSJ today

Anyone see the Wall Street Journal article today on hacking homes? I was trying to read it over somebody else’s shoulder on a flight today, but MCV was mentioned in it along with Kwickset.

It was a report from the black hat convention.

Can’t we add from the more security experienced guys get some guidance how to make your network as safe as possible, the do’s and don’ts. RTS was mentioning ssh tunneling, but that is way over my head

@guessed raised it here:
http://forum.micasaverde.com/index.php/topic,15887.msg121112.html#msg121112

This is to me a funny one, as the indication are it is not a matter if Harding your network security if they are coming in via a third parties door e.g via MCV.

As @guessed logical put in the other thread the separation of is one way… And the most easily implemented and cost effective.

http://forum.micasaverde.com/index.php/topic,15425.msg120886.html#msg120886

It is hard to give any real advise as there are too many variable from hardware to network configuration to IP exposed device and everyone is different. Even if you fixed the HA security vulnerabilities other may exist.

The likelihood of an attach on an individual to turn on and off lights is probably low but could be critical depending on the functional. If they unlock your door, they need to be at the premise to gain access and if they are there well they would find a way in anyway.

I see this as more a warning to the system providers. This has happened to every Software release for one major brand that their security or lack thereof is exposed publicly and it hurts their brands. There are number threads and posts on the lack of security of the Vera but no action taken to remediate it and therefore, I see the wider exposure and naming elevating this to hopefully making it thought of where the problem actually resided.

The fear factor in securing our HA systems on the internet could lead to a whole new range of Z-Wave products for after someone hacks into your home:

Z-Wave explosive dye packs, smoke screens, tear gas, wall mount Tasers, …still thinking, holographic rabid pit bull or holographic Chuck Norris?

It’s not just WiFi security or security at MiOS, but the Zwave protocol itself seems pretty hackable as well :slight_smile: I was a bit disappointed to find no home automation related stuff at OHM2013, but I expect there to be something in the next edition of this hackerfest, in 4 years time (even if it’s me doing the presentation :stuck_out_tongue: )

Vera has security issues. But, you’re right, Z-Wave itself very hackable. While locks use encryption, the relays(switches) and other Z-Wave devices do not. Then when people, myself included, use relays for garage doors etc. they create an easily “hackable” door opener.

Zensys/Sigma restricts access to Z-Wave sniffers, but it’s unencrypted data on a frequency that’s easily accessible. A $20 receiver and a SDR and some time is all that’s needed to sniff it yourself. And once someone writes a little program to parse it all, the Genie’s out of the bottle and my garage door is opening for someone else.

Z-Wave security is an issue, but everyone is still whistling past the graveyard.

At DefCon 2011 they said they hacked Z-Wave but it turns out they hacked X10. They did have one Z-Wave device that wasn’t encrypting its AES key so it could be intercepted, but they never said what device that was. We talked about it here:

http://forum.micasaverde.com/index.php?topic=7391.0

Z-Wave (locks) employs 128 bit AES encryption and at least a brute force attack would take a while:

No. of Years to crack AES with 128-bit Key = (3.4 x 10^38) / [(10.51 x 10^12) x 31536000]
= (0.323 x 10^26)/31536000
= 1.02 x 10^18
= 1 billion billion years

Much faster to perform a brute force attack on your front door code, but murder on your thumb. ::slight_smile:

[quote=“shady, post:8, topic:176343”]Z-Wave employs 128 bit AES encryption and at least a brute force attack would take a while:

No. of Years to crack AES with 128-bit Key = (3.4 x 10^38) / [(10.51 x 10^12) x 31536000]
= (0.323 x 10^26)/31536000
= 1.02 x 10^18
= 1 billion billion years[/quote]
Z-Wave device manufacturers can use encryption and lock(all that I know of) do use encryption. But, it has been my understanding that non-lock devices on the market are not using encryption, hence my previous post. Am I mistaken, or are you referring to locks?

No, I think you are right (I was referring to locks). The Z-Wave chip has 128-bit AES but it is only used in some devices (locks, and… ?)

“The Sigma Designs ZM4101 is an integrated Z-Wave module for drop-in designs of home monitoring and control functions. It can achieve a data rate of 100 kbits/s and uses AES 128 security.”

Here is more information from the DefCon 2011 hack attempt from the author on HaD: Home Automation Systems Easily Hacked Via The Power Grid | Hackaday

“3. Z-Wave is by almost all means all unencrypted and extremely easy to sniff/intercept/inject into the mesh network. There were only front-door locks that we were able to find leveraging AES. To the gentlemans comments above, they leverage a mesh network so if you use an antenna and can have a transmit strength great enough to encompass one device you can communicate with all of the devices, not just one.”

Link to video: http://vimeo.com/29282237#

He is the corresponding short thread on homeseer. Pretty clear about brand competition.

interestingly enough, ebay has a lagotek zwave sniffer for less than 50$ listed.

Sent from my XT897 using Tapatalk 4 Beta

CNN reported on it here: http://money.cnn.com/news/newsfeeds/gigaom/articles/2013_07_26_breaking_into_the_smart_home_of_the_future.html

ZWave is easily hackable and to date, only locks are using the security features.

Unfortunate too because the 100 series ZWave chips had a built in DES engine (bank level security). Then Zensys in their infinite wisdom dropped it for the 200/300 series.
Fortunately they have stepped up for the 400 series with an AES engine which the lock guys forced Zensys to do.

Then again - the Pink Panther Bandits don’t bother with security or Tech at all. Smash and Grab. Very few thieves have even the slightest knowledge of tech so I’m not too worried (yet).

A good friend of mine has ADT and still was broken into. The thieves knew that had at least 10 min before cops would even be called. They were in and out in less. So all the tech available today is not going to completely prevent theft.

If you are interested:

I’m a security technician, doing alarm systems primarily. I’m using the Vera platform as a training set up to keep me sharp and on top of my game. I’ve also used it to do custom systems for clients. I’m starting to think two things… Firstly that Mr RichardTSchaefer is correct, and that the Vera device ought to be isolated on it’s own VLAN. This will limit the joy of these systems, as it will be harder to get it working the same way, but if Micasaverde is being unwise and ignoring this issue, I can not afford to.

Secondly, this isn’t about physical security, but more information security and identity theft. It’s not likely at all some thief will exploit this system and break in. The vast majority of thieves who target residences are down and out types, not high tech hackers. The real threat comes from Chinese bots, designed to penetrate any network they can find. Once there, to rip whatever they can from the LAN before caught, and compromise one’s bank account or who knows what. You can be guaranteed that the cat is now out of the bag, and scheming individuals are cooking up some evil. If I was Micasaverde, I’d be double checking the cp.mios.com authentication server right about now…

[quote=“Brientim, post:14, topic:176343”]If you are interested:

This article talks about brute forcing the HomeID. But you don’t need to do that. You do need a sniffer but within a couple of minutes you’ll know the HomeID as it is sent unencrypted in every transmission.

Zwave is easily hackable unless everyone uses the Security Command Class which so far only door locks use.

But the articles mentioned above it appears that most of the hacking is actually being done at the internet gateway as that is the weakest point and does not require being phycially near the home being hacked.

Aaron Bergens (MIOS CTO) response does not inspire confidence that MIOS considers security a very important issue.