Watch engineers hack a ‘smart home’ door lock

แชร์
ฝัง
  • เผยแพร่เมื่อ 5 ส.ค. 2024
  • Samsung’s SmartThings is a top-selling platform that connects household electronics like lights, doors, cars, etc. Unfortunately, malicious hackers could exploit app vulnerabilities, potentially giving them access to users’ homes.. Watch as University of Michigan cybersecurity researchers hack into SmartThings. The vulnerabilities are covered in Wired: www.wired.com/2016/05/flaws-s...
    -----
    Watch more videos from Michigan Engineering and subscribe: / michiganengineering
    The University of Michigan College of Engineering is one of the world’s top engineering schools. Michigan Engineering is home to 12 highly-ranked departments for both undergraduate and graduate studies, with over 80,000 alumni around the globe.
    engin.umich.edu
    -----
    This project was led by Dr. Atul Prakash, a professor of computer science and engineering at the University of Michigan.
    web.eecs.umich.edu/~aprakash/
    Read the News Release:
    news.engin.umich.edu/2016/05/...
    Read the Research Paper:
    “Security Analysis of Emerging Smart Home Applications,” (IEEE Symposium on Security and Privacy 2016)
    ieeexplore.ieee.org/document/...
    Follow Michigan Engineering:
    Twitter: / umengineering
    Facebook: / michigan.engineering
    Instagram: / michiganengineering
    Contact Michigan Engineering:
    engin.umich.edu/about/contact/
  • วิทยาศาสตร์และเทคโนโลยี

ความคิดเห็น • 139

  • @slice-o-life
    @slice-o-life 3 ปีที่แล้ว +12

    I wouldn’t call it a hack if he developed the app and lock himself I would like to see a different hacker actually hack it himself.

  • @JasonBreslow
    @JasonBreslow 8 ปีที่แล้ว +96

    Two fundamental issues I see with this video. 1) These "hacks" are entirely based on an owner downloading a 3rd party app from an unverified developer. That's like taking your keys to a shady kiosk to have them duplicated, and the kiosk making an extra copy of your key. 2) It's not like our current locks are un-hackable. Burglars have been using lock picks for ages.

    • @JoeRKsChannel
      @JoeRKsChannel 8 ปีที่แล้ว +6

      That is exactly what I thought. As long as the homeowner is downloading apps from establishments they can trust, there should be no issue

    • @all-in-one5828
      @all-in-one5828 5 ปีที่แล้ว +1

      You must mentioned in your message that, should use genuine app provided by the lock company. just don't miss lend to peoples.

    • @JM-ll6hd
      @JM-ll6hd 5 ปีที่แล้ว +1

      Hey stupid, lock picks take skill sets and aren't readily available (illegal) and take time. This skill set just preys on people's vulnerabilities which are greater compared to an "analog" lock. The elderly are particularly susceptible. Which e-lock company do you work for?

    • @thyme4035
      @thyme4035 5 ปีที่แล้ว +1

      J M hacking is also illegal....? An elderly person can just as easily buy an easy to pick lock. Which honestly, manual lock picking and hacking are about the same in being able to teach yourself how to do it, despite the fact that both are illegal.

    • @user-sw1wq8lh2w
      @user-sw1wq8lh2w 4 ปีที่แล้ว +2

      I'd actually say it's easier to just exploit human mistakes and avoid even lock picking, it's slow, check out deviant ollam's talks on the subject.

  • @jessjess813
    @jessjess813 8 ปีที่แล้ว +11

    Yup, going back to flip phones. Closing up my windows like if theres a apocalypse. Getting a tiger to protect my door. writing all information in a freaking book then put on the tiger.

    • @jstdun
      @jstdun 8 ปีที่แล้ว

      Lol nice

    • @SmoothCoaxing
      @SmoothCoaxing 8 ปีที่แล้ว

      that sounds like a video game level

  • @veronicabe7902
    @veronicabe7902 ปีที่แล้ว

    So that’s blue tooth only right? What if you took that out of the lock? Can it be hacked then too? Or is it only local to the physical lock itself? Thanks

  • @brettf3252
    @brettf3252 8 ปีที่แล้ว

    Umm... Wouldn't you need the homeowners address? And besides what good does it do them when the alarm goes off which isn't connected to the SmartThings device?

  • @rpnp2
    @rpnp2 8 ปีที่แล้ว +1

    I recently had a rental house re keyed and it takes a locksmith maybe 5 minutes to pick the front door. nothing new here

  • @Desopolis
    @Desopolis 8 ปีที่แล้ว +26

    As interesting as this is, you used a developer SDK on a test version that was never sent for approval. What would be impressive is if the apps you deployed were on the store and made it past their safety checks. Just because you can make a piece of software work on a bench doesn't mean it will go live. Windows/Android/iOS and other platforms have checks to prevent this type of thing(which I admit are not foolproof)

    • @all-in-one5828
      @all-in-one5828 5 ปีที่แล้ว

      You are right, this kind of peoples just miss-lending to others.

  • @Matdogg2k
    @Matdogg2k 8 ปีที่แล้ว +2

    Good thing is that Zombies don't know about hacking in an apocalypse

  • @nicholaslandolina
    @nicholaslandolina 6 ปีที่แล้ว

    When you sent the message to the lock, your leaving the trail that you weren't

  • @DragginNuts1
    @DragginNuts1 2 ปีที่แล้ว

    The "Beware of Dog" sign is the best cost affective deterrent against impulsive criminals AND you dont even need to own a dog to use it

  • @One564
    @One564 8 ปีที่แล้ว +47

    That's a small house

    • @dennis12879
      @dennis12879 5 ปีที่แล้ว

      lol

    • @K_ingh16
      @K_ingh16 4 ปีที่แล้ว +1

      i thought that too

    • @buck_shot4197
      @buck_shot4197 4 ปีที่แล้ว

      papa smurf lives in India..

    • @WireWeHere
      @WireWeHere 3 ปีที่แล้ว

      There's a doctor Who might make it work from time to time.

  • @WarriorOfMetal
    @WarriorOfMetal 3 ปีที่แล้ว

    And if it has no conection of any kind only code, fingerprint or cards?

  • @paulcaldwell9039
    @paulcaldwell9039 5 ปีที่แล้ว +1

    Just watching this doesn't look like the initial attack, both require access to the Smartthings IDE so make sure you have 2FA on. The Third party app may reveal a passcode change but does not reveal the locks location. So do not put street address as your hub name. What is really disturbing is that the spokesman says they let Samsung know but doesn't say when or what their response was... Going public like this is just creating FUD and does not add to the security. EDIT: Just noticed this is at least 2 years ago Wired just published on facebook... WTF

  • @chriss9383
    @chriss9383 3 ปีที่แล้ว

    With this being 5 years old, can you provide an updated version?

    • @liekzq
      @liekzq 3 ปีที่แล้ว +2

      no we cannot

  • @user-sw1wq8lh2w
    @user-sw1wq8lh2w 4 ปีที่แล้ว +3

    so you wrote a keylogger app, that's not really hacking in my mind, it's just malware.

  • @nicholaslandolina
    @nicholaslandolina 6 ปีที่แล้ว

    When you sent the message to the lock, you left a trail that you were there

  • @Krishnan564
    @Krishnan564 4 ปีที่แล้ว

    What about finger print id

  • @yyangcn
    @yyangcn 8 ปีที่แล้ว +8

    As I have always have thought, key and lock will always be the easiest and cheapest way to, well, lock your door. If this digital lock is more expensive and yet provides no greater safety, what's the whole point? All the fluff is bullshit anyway, what's the point of opening the door remotely anyway? If you know me personally and need to get into my house for one reason or another, come see me and get the key yourself!

    • @ShredPenguins
      @ShredPenguins 8 ปีที่แล้ว +1

      +yyangcn It removes the necessity of carrying keys, allows for you to monitor when someone exits or enters (important for if you have kids), and alerts you about suspicious activity. Also, there are substantially less people who can hack these devices than there are people who just do smash and grab. As always, the most simple methods are the best. Get a medium or bigger dog, train it to bark at people when no one is home. Put signs up on lawn that home is monitored (even if it's not), and don't live in shitty neighborhoods.

    • @caffeineted
      @caffeineted 5 ปีที่แล้ว

      Digital door lock higher price is for convenience, not for safety. But I must say that you can learn to pick a lock in 1 day. It's not easy to hack digital locks though.

    • @davidcosine
      @davidcosine 5 ปีที่แล้ว

      airbnb

  • @cjohnson784
    @cjohnson784 4 ปีที่แล้ว

    i just use bolts with 3 inch screws. We do have Smart tech here though, and never thought of getting smart locks. Just out of curiosity does Samsung encrypt these gadgets? Why would anything security wise accept extra coding? Set up should accept a code of up to six digits, and accept no extra code. If you need that then send it back to the manufacturer.

  • @bigdog4173
    @bigdog4173 5 ปีที่แล้ว +3

    Thank you,most informative and well narrated

  • @FRWD_FXLRST
    @FRWD_FXLRST 4 ปีที่แล้ว +2

    It's easier to kick the door open, or smash a window.

  • @Kalumbatsch
    @Kalumbatsch 8 ปีที่แล้ว +15

    So they didn't really hack a door lock, which is what I came here for, they put some spyware crap on a phone. Yawn.

  • @badmank42
    @badmank42 5 ปีที่แล้ว

    If I buy a £100 for font door it can be picked open if a buy 300 400 smart lock if can be hacked WTF

  • @jodihobbs168
    @jodihobbs168 8 ปีที่แล้ว +1

    Ya know a good old fashion boot or crow bar can have the same effect XD

    • @Sebastian-gj9tc
      @Sebastian-gj9tc 6 ปีที่แล้ว

      Jodi Hobbs1 in canada the boot is super effective because the door frame is just stapled to the 2by4 in the wall

    • @JM-ll6hd
      @JM-ll6hd 5 ปีที่แล้ว +1

      Yeah that wont draw attention you fucking mental midget.

  • @loothootyou
    @loothootyou 8 ปีที่แล้ว +2

    well good thing i'm too poor to afford nice locks :D i just use bolts.

  • @pockeybearmilk264
    @pockeybearmilk264 6 ปีที่แล้ว

    he looks like panda

  • @josefholzer2433
    @josefholzer2433 6 ปีที่แล้ว +1

    Thank you for this, I do not want one! Key is find with me.

    • @viewersforme839
      @viewersforme839 6 ปีที่แล้ว +1

      you say keys are fine with you. it takes about a year to learn how to hack and code. it takes about 10 minutes to learn to lock pick with two paper clips just saying

  • @jonathanoakey2778
    @jonathanoakey2778 8 ปีที่แล้ว +4

    The only reason this is possible is because Samsung opens the door to 3rd party apps, there are two ways it can be patched. 1. You make it so only Samsung has the ability to create the smart apps or 2. Samsung rewrites the platform so that 3rd party developers don't have access to personal/private variables such as pin codes and passwords.. etc

    • @AwesomeBlackDude
      @AwesomeBlackDude 8 ปีที่แล้ว

      +Luis Gutierrez No neither you'll have to go all the way Software/Hardware proprietary Is it extreme approach?,.. YES but that's how you get your lead from hackers and your competitors.

    • @majoro7251
      @majoro7251 8 ปีที่แล้ว +1

      +AwesomeBlackDude Apparently you forgot about the existence of reverse engineering.

    • @AwesomeBlackDude
      @AwesomeBlackDude 8 ปีที่แล้ว

      Major O How ?!!? You can't reverse hardware nor software from the ground up.

    • @majoro7251
      @majoro7251 8 ปีที่แล้ว

      AwesomeBlackDude You can. You merely have to read assembly code, and practice common sense. Heck it doesn't even have to be assembly but a high-level language if the original code is bytecode! (Java etc..)
      Look up "Defcon reverse engineering" here on TH-cam.

    • @AwesomeBlackDude
      @AwesomeBlackDude 8 ปีที่แล้ว +2

      +Major O There is amazing among of down time (not being exposed) when writing a new batch of newer machine language codes from ground up and nobody can dispute that (not even hacker's) ! Especially when hardware's is also proprietary from the ground up.

  • @jaas9457
    @jaas9457 5 ปีที่แล้ว +6

    So both attacks require the "victim" to install malicious software from third parties?.. Got it.. they deserve it then.

    • @buck_shot4197
      @buck_shot4197 4 ปีที่แล้ว +1

      in this day in age all software is malicious in some way

    • @JewTube001
      @JewTube001 3 ปีที่แล้ว +2

      @@buck_shot4197 yep, but you know what it does. facebook and tiktok are kind of like beer and smokes, but this would be like eating an unidentified mushroom you found somewhere.

  • @redtango9472
    @redtango9472 4 ปีที่แล้ว

    Do you want to develop an app?

  • @Ho55Delux
    @Ho55Delux 5 ปีที่แล้ว +1

    Wouldn't connect door lock with a smart home....

  • @carlosdavidesquivel878
    @carlosdavidesquivel878 8 ปีที่แล้ว

    26 people just installed that system......

  • @paulcaldwell9039
    @paulcaldwell9039 5 ปีที่แล้ว

    Just watching this doesn't look like the initial attack, both require access to the Smartthings IDE so make sure you have 2FA on. The Third party app may reveal a passcode change but does not reveal the locks location. So do not put street address as your hub name. What is really disturbing is that the spokesman says they let Samsung know but doesn't say when or what their response was... Going public like this is just creating FUD and does not add to the security.

  • @pawebrak9860
    @pawebrak9860 2 ปีที่แล้ว

    great price easy to set up.

  • @Pseudynom
    @Pseudynom 4 ปีที่แล้ว +1

    0:47
    Pun intended.

  • @Lonerstoner86
    @Lonerstoner86 ปีที่แล้ว

    Came here after watching the id channel where a security guard hacked a girls smart lock and killed her

  • @all-in-one5828
    @all-in-one5828 5 ปีที่แล้ว

    Please, don't miss land to peoples. Can you show a hack of Samsung and Yale door locks?

  • @uploaded113redone
    @uploaded113redone 6 ปีที่แล้ว +1

    Let's see will i hack their door lock or just break the window right beside it .. tough choice for criminals

  • @miamimercenary
    @miamimercenary 8 ปีที่แล้ว

    Just use a lock pick.

  • @MattiaVio
    @MattiaVio ปีที่แล้ว

    why in the array you pass 8 as a number but 5500 as a string 😅

  • @Pharesm
    @Pharesm 5 ปีที่แล้ว +1

    It is definitely ill advised to hook up your electronic door lock to your phone or any other gear of any kind, especially IOT devices are a no-no.
    If you're going to use your smart lock with an RFID tag, use a shielded tag, where you have to slide part of the shield away in order to open your door.
    Presumably, no lock will ever be perfect, but you just need to make it difficult enough to not be worth the time/effort for the burglar. For regular people, this should work out ok.

    • @BK-pc3ei
      @BK-pc3ei 10 หลายเดือนก่อน

      Smart locks are a lot more secure and safe than your house. Key lock.

  • @paul3003mathew
    @paul3003mathew 8 ปีที่แล้ว

    sharks crossed with tigers fitted with lasers guarding the door......
    problem solved....😎

  • @killerhawk9620
    @killerhawk9620 8 ปีที่แล้ว +2

    Not very impressive when you hack your own lock

  • @happinesscompilation5252
    @happinesscompilation5252 ปีที่แล้ว

    This is a phishing attack. The vulnerability isn't on the lock or the official software but on the end user. This only works on people with absolutely no knowledge of technology who will not buy a smart lock in the first place.

  • @originalradman9491
    @originalradman9491 4 ปีที่แล้ว +1

    🙄 🤦‍♂️ this is about the same as sharing your real keys with a store to duplicate your keys while you keep shopping - which you should never do. Maintaining best practises is the REAL story here. At no point was the technology a problem. The users actions were!

  • @davidmillan3529
    @davidmillan3529 3 ปีที่แล้ว

    my access code to my house is 357,... come on over.

  • @deepteji8638
    @deepteji8638 2 ปีที่แล้ว

    Please, you can teach us to speak like this, Lock!

  • @classikz
    @classikz 5 ปีที่แล้ว

    If a criminal element is capable of doing this, then they deserve whatever they can snatch from inside my house.

  • @rustem1404
    @rustem1404 2 หลายเดือนก่อน

    Looks like something that a traditional lock company would commission. Obviously BS, as other comments point out, but sows just enough doubt.

  • @jackd23
    @jackd23 3 ปีที่แล้ว +1

    As you can see, clearly, after I submitted some JSON... the lock opens xD Is this an April's fool in the wrong month?

    • @forsanityandreason5356
      @forsanityandreason5356 3 ปีที่แล้ว

      You didn’t think they’d tell you the vulnerability, did you?

    • @jackd23
      @jackd23 3 ปีที่แล้ว

      @@forsanityandreason5356 True, it would be too much work to implement working solutions submitted or suggested by other people if they were open about it!

  • @660hpCamaro
    @660hpCamaro 5 ปีที่แล้ว

    Still dont know how. This didnt show me shit

  • @rogerbussiii
    @rogerbussiii ปีที่แล้ว

    I thought 3rd party apps available on the play store were vetted by Google and checked for malware? I would never download an app without play protect.. I'm pretty sure that's the name of Google's vetting service..

    • @rogerbussiii
      @rogerbussiii ปีที่แล้ว

      So this is from smartthings from Samsung? They need to do better. They should be embarrassed. This isn't a good look for them.

  • @aggplanta
    @aggplanta 8 ปีที่แล้ว

    SmartThings is so expensive and apparently now insecure. Buy somethings else. $40 for a multipurpose sensor. It should cost under $5. The production cost is well under $1.

  • @akshaypatel8450
    @akshaypatel8450 8 ปีที่แล้ว +7

    I highly doubt that a Indian hacker would break into peoples homes... 😁

    • @amazingdany
      @amazingdany 5 ปีที่แล้ว

      In South Asian homes, yes!

  • @manuelguevara1437
    @manuelguevara1437 8 หลายเดือนก่อน

    Usually the software is crap 😅

  • @xcams4599
    @xcams4599 3 ปีที่แล้ว

    Dang and I bet they went as the University too. If it was the kid individually. They would of payed him I bet. Shame

  • @slimg3tstr863
    @slimg3tstr863 4 ปีที่แล้ว

    30sec in and my stopped working I was like I got hacked to😭😭 high moments

  • @LogicDumbasses
    @LogicDumbasses 8 ปีที่แล้ว

    As u can see

  • @NIPSZ
    @NIPSZ 8 ปีที่แล้ว +2

    Why so many dislikes?

  • @giovannycruz3553
    @giovannycruz3553 8 ปีที่แล้ว

    How is this trending?

  • @joansnow4013
    @joansnow4013 5 ปีที่แล้ว

    Jesus fucking Christ, I’m being stalked someone comes in and helps themselves to everything and anything, every time I leave my home. I just bought a Yale living lock, and I watch this shit! I might just as well leave the damn door open! I don’t understand why this is even allowed on here to show everyone how to do it? My life sucks!

  • @casewhite5048
    @casewhite5048 8 ปีที่แล้ว

    Do that with samsung pay

  • @EXITONEZ
    @EXITONEZ 5 ปีที่แล้ว

    These guys are trying to get money from Samsung lol

  • @EddieLeal
    @EddieLeal 2 ปีที่แล้ว

    lass="content">
    Access Denied
    We're sorry, but you are not authorized to perform the requested operation.

  • @name-nu4qn
    @name-nu4qn 8 ปีที่แล้ว

    that's just tricking people to give you their password not hacking

  • @warcarfter567
    @warcarfter567 8 ปีที่แล้ว

    neat

  • @r34p3r_here
    @r34p3r_here 3 ปีที่แล้ว

    So not hacking just watching some dudes unlock a door with an app...lame

  • @Z-Ack
    @Z-Ack 5 ปีที่แล้ว

    Or you can stick a pin in the hole at the bottom of the keypad.. its the release.. but either way if i want to break into a house i dont care what kind of smart crap they got. Or door locks, whatever. The only thing that would deter me is a posted sign and the sight of a cctv or camera system or if they had bars over all their windows and metal case doors with metal frames.. thatd be a house youd break in and never come back out alive.. or in handcuffs.. rig up those grates that slam closed over every window and door and a speaker sysyem indoors. somebody breaks in and all the sudden shit closes and a-voice comes over the intercom, “would you like to play a game?” Lol. Ask em where they live and go steal their shit leave a note “ good game” then let em go...

  • @ANCUTTER
    @ANCUTTER 8 ปีที่แล้ว

    "Thousands" so not a lot.

    • @JM-ll6hd
      @JM-ll6hd 5 ปีที่แล้ว

      Entire apartment complexes are switching to this inferior "technology" to artificially raise rent prices. I can think of one with almost a thousand homes that has alone.

  • @necromancer7305
    @necromancer7305 8 ปีที่แล้ว

    Why the fuck people need mobile to unlock their doors. What happened to old fashioned keys.

  • @millerk115
    @millerk115 2 ปีที่แล้ว

    This is why you don't download 3rd party apps...

  • @jackparsons8750
    @jackparsons8750 2 ปีที่แล้ว

    Their on android says it all really

  • @RavagHer
    @RavagHer 8 ปีที่แล้ว +1

    no lock is fool proof, I rather have a huge deadbolt that someone has to pick or break into rather than electronic locks

  • @WardenRian
    @WardenRian 8 ปีที่แล้ว

    amir narini :)))))))))))))))))))))))

  • @ankitchhetri6571
    @ankitchhetri6571 8 ปีที่แล้ว

    AR RAHMAN

  • @StezzSquad
    @StezzSquad 11 หลายเดือนก่อน

    Bought this one because the older version th-cam.com/users/postUgkx0jZ_lGlDVJhDnmagEU8gn47cmfPNlLQ had was really choppy and would disconnect from the wifi ALOT, was not catching everything and every week j had to charge it. So far the picture quality on this one is exceptional. I also bought a solar panel with it so I will see how this all turns out.

  • @Inadharion
    @Inadharion 5 ปีที่แล้ว +1

    Chrome enthusiast "hacking" with JSON. Okay.

  • @OsamaBinLooney
    @OsamaBinLooney 6 ปีที่แล้ว

    and the hacker is Indian, why am I not surprised...?

  • @feildtheory
    @feildtheory 8 ปีที่แล้ว

    Every time you call a REST API you need to have an authentication token generated when you initially logged in using your smart phone. But now this '''hacker" did not pass an Auth token in JSON which is bullshit and real lock makers don't make such crappy REST API. In short this demo is shit and assumes lock manufacturers are dumb which they are not.

  • @rickb06
    @rickb06 5 ปีที่แล้ว

    I don't like the this door hacking method, it reminds me of my great-great uncle who was a Nazi during WW2, he killed tens of thousands of Jews, gay people, mentally Ill and deficient. He was a monster and the door lock is just like him.

  • @hoodcube5497
    @hoodcube5497 8 ปีที่แล้ว

    This guy hacks with a freakin ios system, I thought hackers preferred linux.

  • @tysk5729
    @tysk5729 8 หลายเดือนก่อน

    This isnt really realistic, as you arent likely to use an app the guy whos going to be your burgler has created😂
    Neither should you have to be worrying about the company that creates your lock, putting maliciouse stuff in there
    Something more realistic would be a hacker sitting in his car near your house scanning bluetooth weaknesses to get into your doorlock and open it, or sniffing your home wifi to somehow find out more about the doorlock and maybe your account and somehow gain access to that
    But this is just totaly stupid
    Am i supose to expect a company that probertly makes milions selling smart locks to also go afther my 400 euro tv😂 ?
    Or some app develloper that is smart enough to make a official looking app, for a smart lock to be intrested in stealing my 80 bucks airfryer ?😂