Thursday, February 19, 2015

Samsung’s Smart TVs don’t just spy, they transmit your speech in unencrypted plaintext


Samsung TV
The TV that David Lodge tested is a 2.5 year-old UE46ES8000, not the latest model. Samsung is now saying that its latest televisions are encrypted and that it’s just older devices that lack the feature. Exactly what qualifies as an “older” device is unclear — the UE46ES8000 was a high-end device at launch, with a price tag of £1500-2000 (review sites vary on this figure), or $2300-$3000.
When news broke that Samsung’s Smart TVs actively monitor what users say and transmit that information to third parties, the company snapped into action with the usual reassurances that it takes user data seriously, follows best practices, and would never, ever, share information with untrusted third parties or individuals. It’s taken a bit over a week for such reassurances to unravel — new research shows that Samsung TVs don’t just transmit what you say, it sends that information in unencrypted plaintext without even bothering to use HTTPS.

According to security researcher David Lodge, the TV communicates with the server over Port 443 (left open in most routers by default) using what he describes as “a mix of XML and some binary data packet.” The real money shot is what the TV transmits to the server, as shown below:
Samsung hack
The code isn’t hard to read. The TV is reporting that it either heard the word “Samsung,” “Samson,” or “Samsong.” It’s not clear if the “confidence” figures are percentages or represent some other data format — if they’re confidence figures, it would mean the TV was virtually certain it heard Samsung, thought it might have heard Samson, and didn’t think Samsong was very likely at all.
Lodge’s research is only just beginning, he notes that Nuance’s network may have leaked one of its own IP addresses, and that there’s definite potential here for a hacked firmware update to capture and transmit more data.

The cost of corporate malfeasance

There was one piece of good news in Lodge’s analysis — the Samsung Smart TV only listens to what you say after you tell it to do so (the default command is “Hi TV!” This is a good thing as far as it goes, though it’s always possible that a third party hack could modify the TV to listen and transmit far more data.
Lodge’s research has exposed a deeper problem in the entire computing industry — one that stretched far beyond Samsung. It was barely a week ago that Samsung told CNET that “Samsung takes consumer privacy very seriously. In all of our Smart TVs we employ industry-standard security safeguards and practices, including data encryption, to secure consumers’ personal information and prevent unauthorized collection or use.” (Emphasis added).
We now know that’s completely untrue. Samsung doesn’t employ industry standard best practices, it doesn’t even connect via HTTPS for its data transmission. It transmits voice commands in plaintext. It doesn’t matter if this was intended behavior or an unintentional bug; the Korean manufacturer has been shipping devices with a significant security flaw for months while marketing connectivity as a major selling point. A great deal of ink has been spilled over the years bemoaning how little emphasis most users place on their personal privacy and security. It’s hard to convince people that securing their own information is critically important when corporations are actively inventing new ways to siphon information, lie about their own security practices, and face virtually no consequences for doing so.
The problem is not that a hapless Samsung spokesperson told CNET the wrong thing. The problem is that corporations have virtually no incentive to actually, meaningfully protect customer data. When data breaches occur, the cost of those breaches are born by banks and credit card companies, not the likes of Samsung or Target.
There are no easy solutions to these problems. When Bill Gates decided to make security a major focus of future Microsoft development, the words “Windows” and “security” were a contradiction in terms. The company made a huge pivot, poured millions into OS development, and delayed its entire OS launch cycle to fix Windows XP. The result? An achingly slow series of improvements. Arguments over which operating system is “most” secure still rage to this day, but there’s no arguing that Microsoft’s long-term commitment to security dramatically improved the state of its operating systems.
Until Samsung and other IT vendors make similar commitments to securing their devices, problems like this will continue to occur. Absent sustained consumer outcry, it’s an open question whether they’ll ever care enough to bother.

No comments:

Post a Comment

Facebook Friends

Labels

Microsoft Nvidia Security Amd Google Android Apple Samsung Windows 10 Autos Science Smartphones Apps Automobiles Cars Encryption Gpu Intel Ios Iphone Nasa Pc Ps4 Software VW Volkswagen Xbox One 3d Printing Gaming Gtx 980 Hardware Internet Maxwell Mobile Operating Systems PC Gaming Privacy Ps3 Tesla Wearables Windows diesel diesel engines pollution space 3d Printers 4g 8K Apple Car Astrophysics BMW Comcast Cpu Developers Directx 12 Displays Google Fiber Graphics Gtx 970 Holograms How-To ICar Lte Malware Medicine Memory Nanoparticles OLED Oculus Rift PCS Piracy Project Morpheus Quantum Entanglement Robotics Smart Tv Spectrum Tablets Torrents Uhd Valve Virtual Reality Wearable Computing Windows 9 Wireless Communications Xbox 360 clean diesels diesels emissions government ipad lcd lg 1080p 2160p 21:9 34UC87C 3D 3d Photography 4K 4KTv A123 Systems ABP ARM AT&T ATS Acura RDX Ads Aero Air Gap Airmont Alienware Amazon American truck simulator App Apple Pay Apple Watch Apu Astronomy Asus Atmosphere Atom Audi Augmented Reality Auto Show Top Cars Auto Shows Avg Bandwidth Batteries Battery Life Bing Bittorrent Blizzard BlueStacks Bonan Brain Brains Branson Braswell Broadwell Business CALL OF DUTY: BLACK OPS 3 CNNIC Cameras Cancer Car Shows Carrington Event Certificate Authority Charging Chevrolet Equinox Chicago Auto Show Chips Chromebook Pixel Chromebook Pixel 2 Chromebooks Climate Change Console DX11 David Irvine Dci Deals Dell Diablo 3 Directx Dota 2 Downloads Dream Dx12 EPA EVs Eighth Generation Electric Vehicles Electromagnetic Electrons Enterprise Enthusiast Et European Union Exoplanets Female Festival Fiber Firefox 41 Fisker Karma Fitness Tracker Ford Explorer Ford Police Interceptor Formula E Fukushima Fukushima Daiichi Future GRIP Digital GTX Game Streaming Gamers Gchq Google Wireless Gorillapod Grid HDTV Health Heat Holographic Displays Holographic Storage Holographic Universe Holography Hololens Honda Pilot Htc Http Huang IETF ISPs Icera Illumiroom Imagination Technologies Imaging Inkjet Printers Internet Of Things IoT Iphone 6 Iphone 6 Plus Itanic Itanium Keller Kinect Kinectic Energy Kittson LED Laptops Lasers Latency Lenovo Lidar Light Liquid Metal Lithium-Ion Low Latency API MCS Holdings MCV MRI Machine Learning Magnetic Field Man In The Middle Mantle Masturbate Medical Medical Imaging Mercedes Microsoft Access Microsoft Excel Microsoft Office 2016 Microsoft Office 365 Microsoft One Microsoft PowerPoint Microsoft Research Microsoft Word Miscrosoft Mobile Computing Model S Modems Modems 0 Comments Mozilla Muon Tomography Mvno NOx NSA Navigation Net Neutrality Networking Neural Networks Neurology Nexus 6 Noaa Nokia Note Nova Nuclear Nuclear Power Nvidia Shield Office 365 Online Ouya Overclocking Paid Paintings Palmer Particles Performance Photography Physics Pirate Bay Plaintext Plasma PornHub Pornhub Wankband Porsche Poulson Power VR Project Tango ProtocolI Qualcomm Quantum Computing Quantum Mechanics Quantum Physics R9 290X RAM RPV Radeon Richard Branson Russia SCS SEC SLS SOEDESCO SSL/TLS Same-Day Delivery Samsung Galaxy Note SanDisk Scanning Sdk Search Seattle Senate Launch System Servers Setup Sharp Shield Silvermont Siri Slideshow Smartphone Smartwatches Snowden Society Soft Robotics Software As A Service Solar Sony Sound Sound Waves Spacetime Spectroscopy. ESO Spying Stars Steam Stellar Dynamics Observatory SDO SunLock Superfish Swarm TDI THQ TPB TSA TSA locks Tegra Terrible Posture Games Titan Titan Black Titan Z Torrentfreak Tower of Guns Toyota Avalon Toyota Camry Toyota Corolla Travel Sentry Uhdtv Ultra VR Verizon Versioning Very Large Telescope Video Games Virgin Virgin Atlantic Virtualbox Virtualization Viruses Voice Wankband Wide Wifi Windows 10 Technical Preview Windows 8 Windows Nt 6.4 Windows Phone WindowsI Wireless Spectrum World Of Warcraft Xbox Xbox Live Xeon Yahoo Yandex Zen ai apollo artificial intelligence artist backdoor biology bitcoin blender block broadband broadcast car sales chain chrome clean diesel corporate fraude court cpus diesel emissions dreamcast edgeadblock plus electric cars etherium ets ets2 euro truck simultor euro truck simultor 2 exploration fifth amendment fingerprint firefox freedom game development game theory games genetic engineering geometry gtx 980m heed Martin high speed cameras iMo iMove ibm internet explorer k12 konami language learning licenses mars math metal gear solid metal gear solid 5 microSD microsoft office missions mobile gaming model e model x moon nano-optics nanotechnology netflix orion os pHTTP/2 pachinko passcode programming robots rock paper scissors scandinavian security theater sega self-incrimination smart contracts space launch system telecommunications terahertz trucks tv waveguides x86