Can your Smart Switch disclose your physical location?
Internet of Things /Location

Can your Smart Switch disclose your physical location?

I was having a chat with a group of friends who are technical but not from the security domain. We were talking about a variety of things including Internet of Things (IoT) security when an interesting question popped up:

We understand our IoT devices could get hacked but can the attacker ever get to our homes? after all IP address will not disclose the exact location? maybe our City name but not our Street and Address?

Sadly, I had to be the bearer of bad news: your IoT Smart Switch can allow an attacker to physically locate you with the same accuracy as your Uber app or Google Maps does!

How is this possible you ask? Because the same technology is available for purchase to just about anyone online: Google GeoLocation API

The way this works is simple: the Attacker asks your Wi-Fi enabled Smart IoT device to send him the list of Wi-Fi Access Points around it. Your compromised IoT device obliges and sends the Attacker the list with MAC addresses and Signal Strength Info.

The Attacker would then query Google's GeoLocation API with the above data and get back the response: LONGITUDE and LATITUDE of your Home. You are welcome :)

But how did Google manage to gather all this information about you? They used their self-driving cars and your Android devices to build this massive Wi-Fi access point and Cellular tower. You've given your consent when you agreed to one of their Terms of Services or agreed to be part of their "Participate and Make this Service Better" agreement.

So beware! A compromised IoT device can beacon back its physical location! Enough said :)

If you are interested in looking at learning security, pentesting, Red-Blue Teaming etc. check out Pentester Academy!


Anju Dahiya

CyberSecurist | STEM Advocate | Diversity Champion | CISM | ISO27001 Lead Auditor

5 年
John O'Malley CGEIT, CISM, CISA

IT Audit Manager at The Greenbrier Companies, Inc.

6 年

Vivek: Isn't the most common method to hack a WiFi enabled IoT device, is to be within WiFi range, thus you would already roughly know where the location of the IoT device/home would be? Or are you saying that the IoT device was already compromised/backdoored before it was connected to the home WiFi, and thus be able to beacon back to hacker? Once a network is penetrated, a hacker will normally go after assets of value like data, which may reveal the owner of that data. What additionally does the geographical location of the network, or data asset get you I.e. the house or address? I'm trying to understand a real life scenario?

要查看或添加评论,请登录

Vivek Ramachandran的更多文章

  • IoT Rootkits: Should We Worry?

    IoT Rootkits: Should We Worry?

    We've been busy creating videos for our newest course Linux Rootkits for Red-Blue Teams. We posted the first few videos…

  • Bootloader Attacks on IoT Devices: The Basics

    Bootloader Attacks on IoT Devices: The Basics

    One of the key components of the embedded/Internet of Things software stack is the Bootloader. Unfortunately, this is…

    3 条评论

社区洞察

其他会员也浏览了