Slashdot Mirror


Hackers Make the First-Ever Ransomware For Smart Thermostats (vice.com)

Lorenzo Franceschi-Bicchierai, writing for Motherboard: One day, your thermostat will get hacked by some cybercriminal hundreds of miles away who will lock it with malware and demand a ransom to get it back to normal, leaving you literally in the cold until you pay up a few hundred dollars. This has been a scenario that security experts have touted as one of the theoretical dangers of the rise of the Internet of Things, internet-connected devices that are often insecure. On Saturday, what sounds like a Mr. Robot plot line came one step closer to being reality, when two white hat hackers showed off the first-ever ransomware that works against a "smart" device, in this case, a thermostat. Luckily, Andrew Tierney and Ken Munro, the two security researchers who created the ransomware, actually have no ill intention. They just wanted to make a point: some Internet of Things devices fail to take simple security precautions, leaving users in danger. "We don't have any control over our devices, and don't really know what they're doing and how they're doing it," Tierney told Motherboard. "And if they start doing something you don't understand, you don't really have a way of dealing with it." Tierney and Munro, who both work UK-based security firm Pen Test Partners, demonstrated their thermostat ransomware proof-of-concept at the hacking conference Def Con on Saturday, fulfilling the pessimistic predictions of some people in security world.

213 comments

  1. Bitcoin by Anonymous Coward · · Score: 0

    Of course they demand bitcoin.

    Everything involving the words 'tor' or 'bitcoin' are frauds.

    1. Re:Bitcoin by sirber · · Score: 4, Funny

      You can send me 1 bitcoin to get a +1 score

      --
      Be or ben't
    2. Re: Bitcoin by fyngyrz · · Score: 2

      You forgot "cloud."

      --
      I've fallen off your lawn, and I can't get up.
    3. Re: Bitcoin by slashrio · · Score: 2

      No he didn't. Bitcoin and tor work against vested interests and therefore 'need' to be outlawed. The Cloud doesn't.

      --
      "Trump!!", the new Godwin.
    4. Re: Bitcoin by gtall · · Score: 2

      Errr....Tor was (and still is) supported by the U.S. Naval Research Laboratory which, last we checked, was under the Office of Naval Research of the U.S. Navy. So Tor is being developed to work against which vested interest exactly? Maybe if you took a fixed point in the right space, you'd get the answer you want to believe, but I doubt it.

    5. Re:Bitcoin by fluffernutter · · Score: 1

      And if I give you a +1 score? Oh shoot I've commented now, never mind.

      --
      Laws are rules for the court, but merely a bottom bar to hit for life. Think beyond laws in your actions always.
    6. Re: Bitcoin by fyngyrz · · Score: 2

      Yeah, he did. The cloud is the perfect petri dish for fraud, and that's exactly how it's used most of the time, to suck money and/or information out of bewildered users.

      "We'll just keep "your" music and "your" video in the cloud for you"

      uh-huh...

      --
      I've fallen off your lawn, and I can't get up.
  2. Yes, because it would be by The+Cisco+Kid · · Score: 5, Insightful

    COMPLETELY impossible to unscrew the smart thermostat from the wall, unwire it, and (temporarily) install a traditional non-networked thermostat so you could operate your heat (or AC) while you contact the vendor or manufacturer of the smart thermostat for help.

    1. Re:Yes, because it would be by Anonymous Coward · · Score: 1

      Do you really assume every person who owns one is capable of that?

    2. Re:Yes, because it would be by Anonymous Coward · · Score: 5, Informative

      Actually on my furnace you cannot connect a conventional thermostat. The thermostat talks to the furnace over RS-485 with a proprietary protocol. Now lucky for me it's not a 'smart' internet connected device. But depending on the installation the option of putting in a dumb thermostat may not exist.

    3. Re:Yes, because it would be by Anonymous Coward · · Score: 2, Insightful

      Yes, i'm sure the smart thermostat vendor has a line dedicated for hacked thermostats. And if they don't, I'm sure their technical support folks will have no problem getting past the "is your thermostat connected? No? Then you must connect it for us to help you" part of their script.

      3 days later, you might get to someone in engineering who will say, yup, we raised this at our management meeting. Them marketing folks didnt care. Can't help you.https://it.slashdot.org/story/16/08/08/1449221/hackers-make-the-first-ever-ransomware-for-smart-thermostats#

    4. Re:Yes, because it would be by Anonymous Coward · · Score: 4, Insightful

      Why the fuck did you buy that?

    5. Re:Yes, because it would be by tripleevenfall · · Score: 3, Insightful

      Probably capable of calling a person to install a $25 thermostat and paying them one hour of labor to do so.

    6. Re:Yes, because it would be by Anonymous Coward · · Score: 1

      If you can install a thermostat (or have proper backups), ransomware won't seriously effect you. For the other 95% of people, it's a choice between paying for someone else to come and fix it, or paying the ransom.

      I've been asked to deal with ransomware on computers a few times; it's generally priced such that it's cheaper to pay the ransom than get me out to look at it, and mostly there's nothing that can be done (strongly encrypted files + no backups, or only one set of now-encrypted backups).

      With compromised hardware, there is at least something can be done, but best case scenario is that you spend money on a replacement whilst your expensive IOT device pulls duty as a paperweight. If you wait for the manufacturer to sort it out/send a replacement, then you'll have to put up with extreme hot/cold for at least a couple of days and - unless that manufacturer has got it's shit together since it sold you the piece of crap - as soon as you set it back up you're vulnerable again. In any case, you're probably out more dollars than they were asking for the ransom.

      It sucks, but so long as people will pay them, I don't see it going away any time soon.

    7. Re:Yes, because it would be by cfalcon · · Score: 2

      > calling a person to install a $25 thermostat

      Because HVAC guys are able to gear up to handle a newly enabled assault on the infrastructure they provide ("Thanks, Computer Science! For bringing all your problems everywhere, from hearth to hospital!"), show up, and have a whole ton of old school thermostats just laying around in case.

      Way worse if the attack is distributed top down.

      And remember: this specific attack is just about a thermostat. Other "smart" things (read: "will remotely obey your enemies in time of need") will or do include the refrigerator with grandma's insulin, the lock on the front door, and opened or closed status of the garage door, and in some cases, pieces of the plumbing. I can't wait for some smart toilet to yield some kind of resonant attack on the pipes by clever timing of valves.

      All this tech, brought to you by a few semi-professionals buying the cheapest commodity chips from gods-know-where. I'm sure they will succeed where security professionals routinely fail.

    8. Re:Yes, because it would be by Anonymous Coward · · Score: 1

      Where do you live that every piece of tech in your home was made to your exacting specifications? Libertopia? Satoshi's comet? Are you John Galt? Come on man, he probably lives in his house for the same reason as everyone- its close enough to work, and he was able to afford it. Replacing a furnace is a pretty goddamned big deal.

    9. Re:Yes, because it would be by swb · · Score: 1

      Harder to do when you're in Florida and its -20F at home.

      Pay the ransom or run the risk of burst pipes and destroyed interiors from water damage.

      During the mortgage meltdown, there were at least a couple of "frozen waterfall" houses that turned up in the news when the heating failed. Basements flooded, ceilings collapsed and pretty ice sculptures where you'd normally expect drywall.

    10. Re:Yes, because it would be by Anonymous Coward · · Score: 0

      The last time my thermostat broke I took it off the wall and just shorted the wires when I needed to turn on the furnace.

      It got me through the day until I had a chance to get to the hardware store.

    11. Re:Yes, because it would be by Anonymous Coward · · Score: 0

      Not GP, but I made compromises on what I wanted when I had my house built. There are even more compromises when you buy a house. You can't presume that everyone even the best informed people will make every choice optimally. Well it is everything we wanted at lower than market value but the thermostat had a proprietary protocol for talking with the furnace so we just decided to pass...

    12. Re:Yes, because it would be by Archangel+Michael · · Score: 1

      I am beginning to believe that "smart" devices = "dumb" humans.

      --
      Agent K: A *person* is smart. People are dumb, stupid, panicky animals, and you know it.
    13. Re:Yes, because it would be by slashrio · · Score: 1

      Doesn't the manual mention the possibility of 'hard reset', or 'factory restore'?

      --
      "Trump!!", the new Godwin.
    14. Re:Yes, because it would be by Opportunist · · Score: 1

      If you're renting, it could well be.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    15. Re:Yes, because it would be by Anonymous Coward · · Score: 1

      It's a geothermal system which with a more advanced thermostat can do zoned heating. Have a RS-485 protocol allows you to get away with only 2 wires to the furnace and still be able to have more advanced features. For instance I can see at a glance on the thermostat how much energy the furnace is consuming right now. It also supports staged heating / cooling to conserve energy it can run the compressor at reduced speed when only a little bit of heat is required making the system more efficient. You can also hook up outdoor temperature sensor and have the heat/cool change automatically. It tracks the furnace run time and tells me when to clean the filter, etc. All these 'features' would not be available on a dumb thermostat. It also comes with a 10 year warranty so I'm not particularly worried.

      My whole point though was that not all systems are capable of simply replacing the thermostat with a dumb one.

    16. Re:Yes, because it would be by cfalcon · · Score: 2

      I mean, look at how many compromises we make with our computers and computer programs. And many of us are computer professionals. Even if you do go through hoops to have your computer be pretty much perfect, that's because of a passion about that. I don't think anyone has everything set up perfectly, and the mere existence of these things in the market place means that many people are going to end up with them, unless they are passionate haters.

      For my part, I actually got a new furnace and AC recently, and I brought up that I didn't want any networking technology, and that an analog ("mechanical") thermostat would be ideal. He was easily able to accommodate the first, but the "mechanical" thermostats were a pain- they were rare and way more expensive because there's not much market for them. What will that conversation sound like in twenty years?

      And of course- I was able to accomplish this because I was having just the HVAC work done anyway, and all had to be replaced regardless.

    17. Re:Yes, because it would be by Anonymous Coward · · Score: 0

      If you are renting, it's even easier because you call the owner and inform them of the broken thermostat and they have to come fix it... And, in most localities since it's a problem that could make the dwelling uninhabitable they have no choice but to fix it and fix it fast.

    18. Re:Yes, because it would be by fustakrakich · · Score: 1

      Are you sure your "smart" furnace will work with a regular thermostat?

      --
      “He’s not deformed, he’s just drunk!”
    19. Re:Yes, because it would be by pla · · Score: 1

      If you're renting, it could well be.

      If I'm renting, I don't care about the cost of getting someone out on a Sunday morning in a blizzard to fix it, because appliances like a furnace count as 100% the problem of the landlord.

      That said, if the landlord drags his feet - A screwdriver still works just fine. Let him try to take me to court for a problem directly resulting from his own negligence.

    20. Re:Yes, because it would be by Anonymous Coward · · Score: 0

      COMPLETELY impossible to unscrew the smart thermostat from the wall, unwire it, and (temporarily) install a traditional non-networked thermostat so you could operate your heat (or AC) while you contact the vendor or manufacturer of the smart thermostat for help.

      For a Slashdotter, no. For the average consumer, yes. Particularly if they're in Boston or Maine and they're buried under some blizzard and can't make it out to Home Depot to buy a replacement. And if your counter is then to have a $20 thermostat on hand on the shelf as a backup in case of ransomware, then why have the smart thermostat at all?

      There are cases where this ransomware could be really bad.

      Disclaimer: I think smart thermostats are stupid. I still use an old $20 one that has a 90's era digital readout and my home always stays at the perfect temperature.

    21. Re:Yes, because it would be by JackieBrown · · Score: 1

      Do you really assume every person who owns one is capable of that?

      I am sure everyone is able to switch off the power breaker to their AC/Heater unit.

    22. Re:Yes, because it would be by kheldan · · Score: 1

      You, I, and any number of other Slashdot readers could handle installing a thermostat for their HVAC system, even if they've never done it before; not so much for the average person, who needs to whip out a calculator for basic math, needs a YouTube video to help them change a lightbulb, and (back in the day, at least) always had "12:00" flashing on their VCR. You know, the same ones who never thought twice that their computer, one day, suddenly had Windows 10 on it? That's who these assholes will be targeting, the people who can't defend themselves to start with. The rest of us will either not fall for the 'IoT' troll/meme in the first place (like me), or will choose IoT devices that can be on an isolated network or that can otherwise be protected.

      --
      Are YOU using the TOOL, or is the TOOL using YOU? Think about it!
    23. Re:Yes, because it would be by Anonymous Coward · · Score: 0

      I think it's a mistake to assume that Slashdot readers are smarter than the general population. That was true years ago, long before Slashdot turned into a panicky reactionary blog, but those days are gone.

    24. Re:Yes, because it would be by c · · Score: 1

      Most of these "smart" thermometers have some sort of presence sensing. If you target devices where someone hasn't been home for 2-3 days (say, Monday-Wednesday) you might catch people on vacation. In colder climates, killing the furnace during a cold snap while the owners are away for a couple weeks might be an effective threat.

      --
      Log in or piss off.
    25. Re:Yes, because it would be by Anonymous Coward · · Score: 0

      As only a dumb person will opt for a smart thermostat the answer is yes, it would be impossible.

    26. Re:Yes, because it would be by Anonymous Coward · · Score: 0

      Not possible because they also hacked your smart phone and took over control of your router causing your voip "land line" phone to not function correctly either. All outgoing calls on both devices just go to the hackers call center and demand bitcoins to fix your stuff. Of course it is only in the hell holes of piles of snow land that this works; otherwise you could ask your neighbor to call for you.

    27. Re:Yes, because it would be by Gravis+Zero · · Score: 1

      which part of "theoretical dangers" do you not understand? the fact that you can take control of it remotely and have it do your bidding is the point being made.

      --
      Anons need not reply. Questions end with a question mark.
    28. Re:Yes, because it would be by Anonymous Coward · · Score: 0

      Well.... yes. You're just moving the "intelligence" from the human being to the device. For example, a fully programmable thermostat hosts $80-$100 and will take all of 5 minutes to program correctly (I did mine and my parent's, in the past). A "smart" thermostat costs $200+ and will slowly learn what you would have programmed manually. So instead of the human having to think about their usage and updating the thermostat accordingly, the smart thermostat tries to guess it. That is why I say the intelligence moves to the device, you no longer have to think about what you do in order to use it effectively.

    29. Re:Yes, because it would be by geekmux · · Score: 2

      COMPLETELY impossible to unscrew the smart thermostat from the wall, unwire it, and (temporarily) install a traditional non-networked thermostat so you could operate your heat (or AC) while you contact the vendor or manufacturer of the smart thermostat for help.

      Quite often there is an inverse correlation between the "smart" device and the owner, and you ARE talking about a human that needs an app to operate their thermostat so, good luck with that theory.

    30. Re:Yes, because it would be by Anonymous Coward · · Score: 0

      Who the fuck even designs a furnace that needs a proprietary protocol to talk to the thermostat?

      What's next, light bulbs that need a proprietary protocol to talk to the light switch? (Oh, wait....)

      Coming soon to a bathroom near you...toilets which use a proprietary protocol to communicate with the flush handle.

      Seriously, more engineers need to ask themselves not "can it be done?" but "should it be done?".

    31. Re:Yes, because it would be by Anonymous Coward · · Score: 0

      Turn off the water whenever you're leaving for more than a couple of days. Don't forget to set the water heater to pilot (or off if it's electric).

      The pipes might freeze, but they won't completely destroy the house. The cost of replumbing a house is high, but compare that with replacing the entire thing!

      Of course, you could also go all the way and drain the pipes + add plumbing antifreeze where necessary, however, that is too complicated for most people. But nobody should own a home where they don't know how to turn the water off. It's no harder than turning off a faucet!

    32. Re:Yes, because it would be by DRJlaw · · Score: 1

      For my part, I actually got a new furnace and AC recently, and I brought up that I didn't want any networking technology, and that an analog ("mechanical") thermostat would be ideal. He was easily able to accommodate the first, but the "mechanical" thermostats were a pain- they were rare and way more expensive because there's not much market for them. What will that conversation sound like in twenty years?

      The first requirement is understandable. The second, I just don't get. I installed a bog-standard Honeywell programmable electronic thermostat. Programmable in the sense that I can set four temperature/time targets per day (manually); but it doesn't network to anything, doesn't learn anything, and the only input it cares about from outside the house is the temperature of an air-source heat pump as a run/not-run threshold (where not-run simply burns natural gas). A mechanical thermostat would remove most of that functionality in favor of -- surviving an EMP? I'd have bigger problems.

      Anyone who can mess with mine can mess with yours -- once you're inside the house and getting your grubby mitts on it, you can change the settings on either one.

    33. Re:Yes, because it would be by Archangel+Michael · · Score: 1

      Smart Thermostats only learn if you're predictable, you still have to figure out how to override them when they don't figure you out correctly, which can be quite annoying. "Hey, I'm not home you stupid thermostat, don't turn on the air/heat automatically" to "Hey, I stayed home today, I still have to turn the air/heat one manually" ...J

      Just now, I can do it remotely, just like the hackers!

      --
      Agent K: A *person* is smart. People are dumb, stupid, panicky animals, and you know it.
    34. Re:Yes, because it would be by tlhIngan · · Score: 1

      For my part, I actually got a new furnace and AC recently, and I brought up that I didn't want any networking technology, and that an analog ("mechanical") thermostat would be ideal. He was easily able to accommodate the first, but the "mechanical" thermostats were a pain- they were rare and way more expensive because there's not much market for them. What will that conversation sound like in twenty years?

      That's because "dumb" programmable thermostats have basically become the norm - the old analog ones worked but were clunky and had lots of workarounds like setbacks, hysteresis and high-end-start-lockouts. In the end it made for a complex mess of workarounds. (high end start is if the AC has been running and the high pressure line is still pressurized - you should not engage the compressor because it puts on a lot of stress and wear - you have to wait a few minutes for the high pressure line to depressurize before kicking in the compressor)

      One thing is, a smart thermostat is way more expensive than a dumb programmable digital one - all the ioT ones cost around $200, while the fanciest of dumb ones still are under $100. And a basic one is often only $30 on sale.

    35. Re:Yes, because it would be by barc0001 · · Score: 1

      /.ers tend to forget that they are generally far more comfortable doing things like that than the average person. Would your grandmother, or sister be comfortable doing that? Or your wants-nothing-to-do-with-wiring-stuff son?

      But that sidesteps the bigger point in that this shouldn't even be a concern. It's a thermostat, this feature creep crap is getting out of hand and we'll be lucky to live through it.

    36. Re: Yes, because it would be by Anonymous Coward · · Score: 0

      That same argument applies to people just backing up their data properly, but look how successful ransomware continues to be.

    37. Re:Yes, because it would be by Bob+the+Super+Hamste · · Score: 1

      needs a YouTube video to help them change a lightbulb

      Hey I've done that, granted it was for a light on the interior of my car and I didn't want to destroy anything as the little friction clips used provided a lot more friction than I thought they would have. So given that I wanted to see if there was some dumb little thing I was missing, like slip a slotted screw drive in to press a tab in or something, so that I would only be putting in a $2 bulb instead of putting a whole new light enclosure that would cost $150.

      --
      Time to offend someone
    38. Re:Yes, because it would be by Anonymous Coward · · Score: 0

      >capable of that

      Capable of minor electronic handy-man work? No, not everyone is capable of that.
      But capable of remaining calm, not-panicking, and thinking outside the box? They darn well should be capable of that at least.

      As someone once said, "I don't know how to do it but I know someone who can". This is very helpful to remember because it allow one to humbly ask for help.

    39. Re:Yes, because it would be by Bob+the+Super+Hamste · · Score: 1

      Do not underestimate grandmothers, granted some of the younger ones now days maybe, but those who grew up in the depression actually have skills. My grandmother plays the sweet old grandma who is into sewing, knitting, house plants, and cooking most of the time but over the years you find out that she can handle herself just fine around tools, machines, firearms, and wild animals as well.

      --
      Time to offend someone
    40. Re:Yes, because it would be by Megane · · Score: 1

      It is also completely impossible to make a smart thermostat that doesn't expose itself to inbound connections from everywhere. I have one that connects out to the cloud service every 3-5 minutes. (It also doesn't have a fancy color display for those l33t pwnz0r screens.) So when you make a change from their web page it may take a few minutes before it happens, but it it's not being a port slut to every kiddie scan out there.

      --
      #naabhaprzrag, #sverubfr-000, #agi-fcbafberq, negvpyr[pynff*=' negvpyr-ary-'] { qvfcynl: abar !vzcbegnag; }
    41. Re:Yes, because it would be by Megane · · Score: 1

      He's not talking about "exacting specifications", he's talking about the standard fucking 4- or 5-wire connection that most normal thermostats have been using for decades. (The one that somehow operates relays off of 24VAC.) It's a weird spec, but it's a well known one. Even then, there are still home HVAC manufacturers out there that insist on their own special snowflake wiring.

      --
      #naabhaprzrag, #sverubfr-000, #agi-fcbafberq, negvpyr[pynff*=' negvpyr-ary-'] { qvfcynl: abar !vzcbegnag; }
    42. Re:Yes, because it would be by judoguy · · Score: 1

      COMPLETELY impossible to unscrew the smart thermostat from the wall, unwire it, and (temporarily) install a traditional non-networked thermostat so you could operate your heat (or AC) while you contact the vendor or manufacturer of the smart thermostat for help.

      Yes, it can be. I have a 10 year old system with a thermostat that talks to the controller via some fucking proprietary scheme over cat-5 that simply can't be replaced with a simple switch. It isn't IP addressable, so no problem there, (although, that might be preferable now that I think about it) but when it goes tits up, I'm in a world of hurt. Or around $700 of hurt at current Ebay prices.

      So, no, sometimes you can't just wire in a cheap replacement.

      --
      Peace is easy to achieve, just surrender. Liberty is much harder get/keep.
    43. Re:Yes, because it would be by Anonymous Coward · · Score: 0

      Why the fuck did you buy that?

      Obviously I will know now to ask such an odd question, and so do you, but don't act fucking stupid and assume that's an automatic question to ask when buying hardware like this.

    44. Re:Yes, because it would be by russotto · · Score: 1

      Honeywell CT87N. $42 at Big Orange (this is the classic round one). Honeywell CT31A, $20 at Big Orange.

    45. Re:Yes, because it would be by BronsCon · · Score: 1

      And if your counter is then to have a $20 thermostat on hand on the shelf as a backup in case of ransomware, then why have the smart thermostat at all?

      Actually, you can find my counter in bold.

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
    46. Re:Yes, because it would be by Anonymous Coward · · Score: 0

      You, sir, have the crappiest possible furnace.

      The thermostat is fine, do whatever with it. Make it fancy. No big deal. But the furnace should be a standard 4- or 6-wire system.

      Black = ground
      Green = fan
      Red = heat stage 1
      White = cooling stage 1
      Yellow = heat stage 2
      Blue = cooling stage 2

      If you need some kind of fancy serial connection to the thermostat, there had better be a controller that translates that serial connection into BGRW(YBl) at the other end. The furnace should know neither jack nor squat about serial connections or protocols.

      Worst case, you can use the serial cable as a pull-cord to bring some 18/4 up to the t-stat location.

    47. Re:Yes, because it would be by type40 · · Score: 1

      For 95% of snowbirds this is how that'll go: Hi Kate, it's Jeff ,how are you? Oh thats good to hear. Well, I was wondering if you could get Hank to do me a favor when he gets back from bowling. Some little jerk off in Croatia or somewhere just hacked the thermostat in our house and whats $500 to turn the heat back on. I know, right! For Christ's sake get a job! Ha ha no, I'm sure Hellen isn't behind it but don't go giving her any ideas! Yeah so if Hank could run over to Murphy's and grab a cheepo thermostat to install that'd be awesome. Really, the Henderson's? Well, at least we're not the only ones. You don't say?! If Jenny has time by all means let her take a crack at it. If she can unlock it and keep it from happening again I'll gladly pay her the $500. No, No I insist. She's going to school and'll put it to better use than that little Yugoslavian prick. Well that sounds great then. Yup, just give me a call later. Bye.

      --
      "You can see I know very little about pimp policy." George McGovern.
    48. Re:Yes, because it would be by guruevi · · Score: 1

      Completely impossible for these thermostats or hell, even newish furnaces to have a freeze sensor that mechanically triggers the heat regardless of it's internal setting?

      Or you could place your old thermostat at a low temperature in parallel and hang it in your basement.

      --
      Custom electronics and digital signage for your business: www.evcircuits.com
    49. Re:Yes, because it would be by Anonymous Coward · · Score: 0

      Why not? So long as it's not connected to anything external I don't see the problem. And believe me: I've helped install far, far worse, on both commercial and residential sites.

    50. Re:Yes, because it would be by fluffernutter · · Score: 1

      I certainly hope you mention it if you sell your home. I'd be pretty pissed off if I bought a house and found out I could only replace with 0.001% of the thermostats available on the market. Not something I or any agent I've used has thought to ask about that. Good reason for getting a home inspection I guess, but do most of those even discover a non-standard furnace connection?

      --
      Laws are rules for the court, but merely a bottom bar to hit for life. Think beyond laws in your actions always.
    51. Re:Yes, because it would be by coofercat · · Score: 1

      Actually, I have a 'smart' thermostat. I asked a bunch of companies what would happen to their device if their servers stopped working. Nest does almost nothing without the 'cloud'. Hive (via British Gas) never gave me a straight answer. I asked repeatedly, but all they'd say is that I needn't worry, they're not going anywhere and so the servers would always be there. AFAIK, it turns into an ordinary bi-metalic strip type thermostat if there's no cloud.

      I ended up with a Heat Genius system because it carries on working (albeit without remote access). It's got a 'cloud' connection, but it's optional. I can either use uPNP, or else I have to open up firewall ports to let the cloud (and support) in. If I don't do so, then it all just works LAN-only.

      The system is a hub (with a raspberry pi in it, I believe), and some z-wave radiator valves, UFH valve switches and a few other bits. In theory they're all hackable, although I seriously doubt you could do much that way - the comms between hub and device isn't really up to it. If the actual hub box got p0wned, it'd be a pain in the arse (about £200 to replace, although I'd probably argue enough to get one for free). In the interim period, it's possible to turn it off and let each of the radiator valves work manually (they have some little buttons that set the target temperature). I don't think our underfloor would work at all though.

      So... why bother with any of this? Well, when it's working properly, it's actually very good at controlling the temperature in the house. It uses some fancy logic to just about heat the room to the target temperature without over-shooting it. It also maintains temperature very well. My memory of physics suggests this should be cheaper to run than more traditional setups (although I don't have any decent facts either way). If I'm honest, it's got quite a few rough edges, and some annoying bugs. Having said that, I can't fault their support, so getting to the bottom of what's going on pretty quickly.

    52. Re:Yes, because it would be by mcswell · · Score: 1

      Probably as many people choose their house for the furnace it has, as choose their car for the cupholders it has.

    53. Re:Yes, because it would be by mcswell · · Score: 1

      "What's next, light bulbs that need a proprietary protocol to talk to the light switch?": I have a box of incandescent light bulbs stored in my basement for that day.

    54. Re:Yes, because it would be by Anonymous Coward · · Score: 0

      Hey, I'd say management is to blame. Engineers aren't asking "can" instead of "should", they're asking "how can I avoid getting fired for pushing back on these asinine ioT designs?"

  3. Who the f*** would pay this? by BronsCon · · Score: 5, Insightful

    Hmm... Pay you hundreds of dollars, or replace the damn thing with a $20 model you can't hack remotely. Seems an easy choice for me.

    --
    APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
    1. Re:Who the f*** would pay this? by Anonymous Coward · · Score: 0

      A 20 dollar Thermostat? What do you think this is, 1982?

      The cheapest you can buy in a store is probably going to run you 40 bucks.

    2. Re:Who the f*** would pay this? by NotInHere · · Score: 1

      A thermostat is probably a bad example, but take e.g. an oven that may be able to cause a fire or a car that may kill you on the road. Also, larger deployments will be more inclined to pay, e.g. for a company a $5000 ransom may be cheaper than having to replace all 200 thermostats in its various rooms.

    3. Re:Who the f*** would pay this? by Anonymous Coward · · Score: 1

      wrong. (not an endorsement, just the first result):

      $18.88.

      http://www.homedepot.com/p/Lux-7-Day-Manual-or-Programmable-Thermostat-TX100E-006/206605731

    4. Re:Who the f*** would pay this? by Overzeetop · · Score: 1

      How much would you pay to get back into your house at 11:30pm on a Saturday night when it's 20 below zero outside and your smart locks have all been hacked? No need for a $5k ransom - it needs only be a couple hundred dollars, repeated many times, to be profitable.

      Or in the case of a thermostat, a remote override that switches a heater on full blast on a hot summer day or - better yet - begins switching between heating and cooling on a heat pump, which will burn out the compressor in under an hour and cost a couple thousand dollars to replace. How many people will think of cutting the breaker in time? Not too many.

      --
      Is it just my observation, or are there way too many stupid people in the world?
    5. Re:Who the f*** would pay this? by Anonymous Coward · · Score: 0

      Right...

      Thats a huge jump in price, $20 to $40.

      It will break the bank!

    6. Re:Who the f*** would pay this? by Anonymous Coward · · Score: 0

      Really, you couldn't take 10 seconds to hit amazon before making a retarted remark like that????

      https://www.amazon.com/Honeywell-RTH221B1021-Week-Programmable-Thermostat/dp/B0088A5X5G/ref=dp_ob_title_hi

    7. Re:Who the f*** would pay this? by Anonymous Coward · · Score: 0

      If someone is threatening to make my car kill me, I'm not going to pay the ransom and keep using the car. I'm going to get the damn computer taken out before anything! I might even sell the whole car because I'm so mad about these hackers.

    8. Re:Who the f*** would pay this? by BronsCon · · Score: 1

      $5000 one time might be cheaper, but you're still vulnerable ant it'll happen again next week. $5000 + the cost of replacing thermostats when you learn this fact is still more than the cost of replacing the thermostats in the first place.

      But, you did answer my question. Idiots will pay it.

      It's not like your irreplaceable (because who has proper backups) files on your computer, which is how they're able to demand $5000 to unlock a $600 computer. Your favorite recipes won't be lost when your oven gets hacked, you just replace the $2000 oven with a cheaper model that isn't vulnerable, rather than paying the $5000, and you're protected in the future and you've saved a few grand over paying off the criminals.

      Likewise with a car. They want $5000? A used model that isn't vulnerable can be had for less.

      It works on computers because you can't get your kid's birthday party photos back if you don't pay. It doesn't work with an oven or a car -- or a thermostat -- that you can replace without losing anything more than (maybe) a couple of features; and you can remove power in the interim in order to prevent the disasters you mention.

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
    9. Re:Who the f*** would pay this? by MyLongNickName · · Score: 1

      Untrue. A quick search finds I can go lower than $20 for a simple model. This one is $15, and several other models were under $20.

      http://www.homedepot.com/p/Lux...

      --
      See my journal for slashdot ID's by year. Mine created in 2005. http://slashdot.org/journal/289875/slashdot-ids-by-year
    10. Re:Who the f*** would pay this? by pr0fessor · · Score: 1

      You have never been to homedepot they start around $10 for a non-digital thermostat and go up...

    11. Re:Who the f*** would pay this? by pla · · Score: 5, Insightful

      Not sure how an oven - Or a refrigerator - Or anything else, for that matter, involves a substantially different solution:

      The IoT is a bad idea, period. I don't need any appliance in my house to have internet access, and will actively go out of my way to make damned sure they don't.

      And before someone says "eventually you won't have any choice" - Of course we will. We might pay a bit a bit extra for the "marine" or "remote cabin" version, but as long as someone has a use case requiring offline use, that will remain an option.

    12. Re:Who the f*** would pay this? by Anonymous Coward · · Score: 0

      Utility companies give some significant discounts for you to install this. Probably paid by you through taxes. Is it still an easy choice?

    13. Re:Who the f*** would pay this? by Anonymous Coward · · Score: 0

      I just bought a wal mart special for a house I am selling for $19.99. Sure, it's a complete piece of shit that doesn't even accept a 'C' wire, but it's better than a hacked one....

    14. Re:Who the f*** would pay this? by cfalcon · · Score: 1

      Ok, but repeat this physical replacement drama for pieces of the stove, the fridge, the internals of the AC once some jackass decides it needs to be firmware updatable from factory, the TV, the front and back doors, the garage door, the stereo, the toilets, and the shower.

      There's always a way to fix a problem. This article *should* make you ask the question- do you want to inject more problem-vectors into everyone's life?

    15. Re:Who the f*** would pay this? by jeffmflanagan · · Score: 1

      >Also, larger deployments will be more inclined to pay, e.g. for a company a $5000 ransom may be cheaper than having to replace all 200 thermostats in its various rooms.

      Only of they're short-sighted fools. The insecure devices have to be updated or replaced. Paying the ransom will not secure the thermostats against tomorrow's attack. They need the manufacturer to replace the firmware to fix the lockout and secure against future attacks, or to replace them with a better brand.

    16. Re:Who the f*** would pay this? by Anonymous Coward · · Score: 0

      IoT isn't good or bad, but its going to be implemented by companies for which:

      - Priority 1 is profit.
      - Priority 2 is more profit.
      - Priority 3 is not your safety.

      With these constraints we'll tend to build it quick, sell it hard and support it "not at all". The end result is going to be a chain of broken and badly supported devices acting as bad agents, injection points, exfiltration points. and they'll destabilize networks all over the place. At the least these things will become yet more easy zombies driving DDOS attacks and causing misery for everyone worldwide.

      The software behind these devices can be weaponized on a public internet and we seem to forget that.

    17. Re:Who the f*** would pay this? by drinkypoo · · Score: 1

      And before someone says "eventually you won't have any choice" - Of course we will. We might pay a bit a bit extra for the "marine" or "remote cabin" version, but as long as someone has a use case requiring offline use, that will remain an option.

      Eventually, the power company will want the right to turn your appliances on and off remotely to handle demand whether you like it or not, and there might well be legislation to make it illegal to hook equipment without remote control up to the grid.

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    18. Re:Who the f*** would pay this? by pla · · Score: 1

      Oh, make no mistake, I "get" the benefit of having my home HVAC controllable remotely - Why should I need to wait fifteen minutes after getting home for the house to reach a comfortable temperature when I could remotely tell it when I leave work, and it will know exactly when to turn on for my maximum comfort?

      That said, until someone can convince me otherwise, I consider the risks as massively outweighing any potential benefits.

    19. Re:Who the f*** would pay this? by pla · · Score: 1

      Eventually, the power company will want the right to turn your appliances on and off remotely to handle demand whether you like it or not, and there might well be legislation to make it illegal to hook equipment without remote control up to the grid.

      Oddly, I agree with you to the extent that I see exactly that as a much more unavoidable risk than random hackers.

      Fortunately, the utility companies have less than 20 years left before solar (or more accurately, storage, since PV itself has already gotten "good enough") makes them about as relevant as buggy whips.

      Sure, I'd rather have a grid tie to fall back on - But the day they start telling me how I can use the power I pay for, I won't hesitate to cut that last cord.

    20. Re:Who the f*** would pay this? by Anonymous Coward · · Score: 0

      Lowes, 2 years ago, bought a 5+2 programmable thermostat for about $25. Had it installed that afternoon, the provided documentation made it excessively easy. It was harder to set the drywall screws than to wire the thermostat.

    21. Re:Who the f*** would pay this? by Bob+the+Super+Hamste · · Score: 1

      Looks like no more than about $70 because other wise I will just pound a slotted screw drive into the lock and attach a pair of vice grips to the screw drive and shear the pins in the tumbler. Then again I wouldn't buy a smart lock either.

      --
      Time to offend someone
    22. Re:Who the f*** would pay this? by naughtynaughty · · Score: 1

      Paying a ransom without fixing the vulnerability is not going to be cheaper.

      So you pay to fix the problem and ignore the hacker's demands.

    23. Re:Who the f*** would pay this? by BronsCon · · Score: 1

      This article *should* make you ask the question- do you want to inject more problem-vectors into everyone's life?

      Okay, so we're in agreement and you just don't see it.

      The whole premise of my comment was to replace the hacked item with one which could not be hacked (e.g. a "dumb" model). Or, more to the point, don't install the hackable "smart" version in the first place.

      Do you see it now?

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
    24. Re:Who the f*** would pay this? by Anonymous Coward · · Score: 0

      How much would you pay to get back into your house at 11:30pm on a Saturday night when it's 20 below zero outside and your smart locks have all been hacked? No need for a $5k ransom - it needs only be a couple hundred dollars, repeated many times, to be profitable.

      Or in the case of a thermostat, a remote override that switches a heater on full blast on a hot summer day or - better yet - begins switching between heating and cooling on a heat pump, which will burn out the compressor in under an hour and cost a couple thousand dollars to replace. How many people will think of cutting the breaker in time? Not too many.

      Switching a heat pump between heat and cool simply energizes and de-energizes a reversing valve. The discharge line and suction line of the compressor will never change flow direction. How will that burn out a compressor? Also, most furnaces built in the last 100 years have a high limit switch. Turning on the heat in the middle of summer might work, but not for very long. Its not like you'll get the house much over 100 degees.

    25. Re:Who the f*** would pay this? by naughtynaughty · · Score: 1

      I would pay the $75 it costs to get a locksmith to come over and spend 5 minutes opening my lock. Plus the cost of the locksmith removing the smart locks and putting some locks that aren't going to cost me future calls to the locksmith.

      After all, I'm going to have to have the locks replaced anyway so no sense paying a ransom AND paying a locksmith vs just paying the locksmith.

      I can sit in my car with the heater running while I'm waiting in the cold weather for the locksmith to show up.

      Or worst case, I'll bust a $100 pane of glass to get it and pay for a locksmith and the cost of repairing the window.

      Pay me a ransom because you'll die if you don't get in your house and I'll just keep bleeding you for more payments until you either freeze to death or you run out of money or run out of stupid.

    26. Re:Who the f*** would pay this? by sjames · · Score: 1

      It's the dead of winter at home, but you are vacationing on the sunny beach of some Island nation somewhere for the next 2 weeks. You get the ransom notice, do you cancel the vacation and eat all the pre-paid costs as well as pay for the expensive I need to fly NOW flight home to install that $20 thermostat from Home Depot, or do you pay the ransom?

    27. Re:Who the f*** would pay this? by BronsCon · · Score: 1

      I suppose I'd ask my trusted friend, who has a key to my home and has agreed to keep an eye on things for me while I'm gone, pop in and replace the thermostat for me. Don't you have friends?

      Of course, that assumes they'd have my email address and not just display the ransom notice on the thermostat itself. Know what's funny about your hypothetical situation? They display the ransom notice on the device itself. I guess I'd just come home to find... well, I live in California, so I'd find that everything was fine, no burst pipes or such, and I need to replace my thermostat. Someone living elsewhere might find that they have a bit more damage done to their home, but it's not like they could have done anything about it in the first place, the ransom notice was displayed on their thermostat, not sent to their email, so they didn't see it until they got back.

      Sometimes it's worthwhile to actually read the article before posting.

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
    28. Re:Who the f*** would pay this? by HiThere · · Score: 1

      It *could* be done in a reasonably safe manner. It just isn't being done that way. Ideally the devices would only communicate over 192.0.0.n, and any communication relaying would be done over your computer...and if you turned off your computer, it would only be local. And any messages going out should be encrypted, as should the responses, with a key that is shared between your device (by serial number) and the company that it needs to communicate with (which adds another chunk of numbers). You don't need strong security, just one that is unique to each device, and only allows two failed attempts before it starts requiring increased delays between logon attempts.

      All that is purely standard security. That it isn't being should make the manufacturers liable for negligence. And, unfortunately, it should make anyone knowledgeable refuse to use them. Of course, they don't reveal the information before you buy the device, and probably not afterwards, either. Certainly I haven't gotten any warnings about my monitor (which might not be IoT) or my printer (which, unfortunately, is...I didn't find out until after I'd purchased it that it required access to more than my local net).

      If anyone has recommendations for multi-function networkable printers that work with Linux and don't require access to anything beyond 198.0.0.n I'd like to hear them.

      --

      I think we've pushed this "anyone can grow up to be president" thing too far.
    29. Re:Who the f*** would pay this? by BronsCon · · Score: 1

      No, utility companies give some significant discounts for you to install heat/AC cutoff devices they control, completely separate from your thermostat. If you consider a one-time payment of $50 to be significant. Yes, it's an easy choice.

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
    30. Re:Who the f*** would pay this? by Ungrounded+Lightning · · Score: 1

      And before someone says "eventually you won't have any choice" - Of course we will. We might pay a bit a bit extra for the "marine" or "remote cabin" version, ...

      In some parts of California you no longer have a choice to not have a computer in your water heater, and will have to put in a computerized one when your current one fails. (Probably within a decade if you don't replace the sacrificial anode(s) every six years or less.)
        - You can only put in an extremely energy-efficient model.
        - These models achieve energy efficiency by using a spark, rather than a pilot light, igniter, and by closing an exhaust vent valve to block convection when the burner is off. They also have sensors to prevent ignition in the presence of flammable fumes (so you don't blow up your garage if you have gasoline fumes or a gas leak).
        - Controlling and interlocking these features is complex enough, and automation chips are cheap enough, that it's cheaper to use a computer than special-purpose logic. So ALL the available ultra-efficiency models have computers.
        - (Fortunately, as of this spring, the radio network interface on the brand I wanted (Rheem) was still an extra-cost optional board, rather than being built into the system-on-a-chip.)

      --
      Bantam Dominique roosters crow a four-note song. Once you've heard it as "Happy BIRTHday" you can't NOT hear it that way
    31. Re:Who the f*** would pay this? by bluegutang · · Score: 1

      Even if you can't buy the offline version at Best Buy, it will be on Amazon and AliExpress.

  4. Governments will love this by operagost · · Score: 1

    They'll be the first in line to use this kind of software-- forget the scammers. I can definitely picture places like Venezuela claiming they need to control your HVAC for the common good, when the problem is that there is an artificial scarcity due to their own incompetence. The Western Europeans will be next, and the USA not far behind.

    I was going to say HK would be the first, but I honestly don't know if they have the technical knowledge to do this, and their people all live in government-owned housing already anyway.

    --

    Gamingmuseum.com: Give your 3D accelerator a rest.
    1. Re:Governments will love this by tripleevenfall · · Score: 3, Interesting

      It's not difficult to imagine California deciding they need the ability to throttle your AC to combat brownouts/global warming/whatever

    2. Re:Governments will love this by Anonymous Coward · · Score: 0

      I think this is actually already a real thing (opt-in though?). I remember either reading about it or getting a mailer asking me to opt in.

    3. Re:Governments will love this by pr0fessor · · Score: 2

      It's an opt in and it supposed to help costs and availability during peak hours... They even have those programs in the mid-west.

    4. Re:Governments will love this by Opportunist · · Score: 2

      Governments will love this for a completely different reason. When "hackers" start to bother normal people, normal people will ask for laws that stop this. And they'll get the laws. Not that they stop anything, but you know how it is, once a law is passed, it stays.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    5. Re:Governments will love this by Anonymous Coward · · Score: 0

      It's in North Carolina!.

      You thought the bathrooms were the first step, but it's already too late, they're in your house, in your house!

    6. Re:Governments will love this by Anonymous Coward · · Score: 0

      You have a mental health issue. Avoid foolish Libertarians and Reactionaries (they call themselves Conservatives but conserve nothing of value). Swap an actual tech blog in for whatever time you spend at this conspiracy blog. Good luck in your recovery!

    7. Re:Governments will love this by Cro+Magnon · · Score: 1

      Yup! I live in the Midwest. On one of the blazing hot days we had, I had to take off early to deal with something, and came home to a hot house and a thermostat blinking "Saving".

      --
      Slow down, cowboy! It has been 4 hours since you last posted. You must wait another few hours.
    8. Re:Governments will love this by pr0fessor · · Score: 1

      My retired neighbor opted in and opted out as soon as he realized it was supposed to save by turning it off when they thought most people would be at work.

  5. IoT strikes again by smooth+wombat · · Score: 1

    The more IoT crap gets thrown out there the more we'll hear about this nonsense. In our mad rush to digitize everything, to make it "convenient", to show how 1337 we can be we've forgotten the virtue of simplicity.

    You know why light switches are still analog? Because they work. Every time. No having to look at an app and muck about, no trying to get a signal, no being dependent upon someone else to provide connectivity. Finger. Switch. It's that simple.

    --
    We will bankrupt ourselves in the vain search for absolute security. -- Dwight D. Eisenhower
    1. Re: IoT strikes again by fyngyrz · · Score: 1

      Most light switches are digital. On or off. The correct term is "mechanical."

      --
      I've fallen off your lawn, and I can't get up.
    2. Re: IoT strikes again by Anonymous Coward · · Score: 0

      You know, I hear that around, but I sort of think the correct term is "electrical", versus "electronic". Something is mechanical if it uses potential and kinetic energy of the mechanical system. I think "mechanical" got used in marketing parts to avoid the similarity, so you aren't wrong or anything, it just seems odd.

    3. Re: IoT strikes again by drinkypoo · · Score: 1

      Something is mechanical if it uses potential and kinetic energy of the mechanical system.

      It's not electrical, because electricity doesn't power the switch. You do. Hence, it's mechanical. It's not electromechanical, because that's the opposite; a switch is a mechanical device which controls electricity, whereas electromechanical means using electricity to control mechanics.

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    4. Re: IoT strikes again by Bob+the+Super+Hamste · · Score: 1
      --
      Time to offend someone
    5. Re: IoT strikes again by fyngyrz · · Score: 1

      ...I didn't say they were. :)

      --
      I've fallen off your lawn, and I can't get up.
  6. From consumers to products by wcrowe · · Score: 4, Insightful

    This is why I don't understand the rush to have all these IOT devices in the house. I have a couple, but they are isolated, and if they were hacked I could still function without them. There seems to be a rush to have everything, from the washing machine, to the microwave, to the toaster hooked to the internet, and there seems to be even a push to build these devices so that they do not function without an internet connection. I used to be baffled as to why consumers would even want such things. But, of course, it is not the consumers who want all this IOT, but the vendors who sell the devices and the services, trying to turn us into the product.

    --
    Proverbs 21:19
    1. Re:From consumers to products by Anonymous Coward · · Score: 1

      It is also marketing, marketing, marketing. People see a commercial about how convenient it would be to activate XYZ remotely and then they buy it, just like every other unnecessary kitchen gadget that replaces a knife and cutting board. Its only $20 more with IOT features, she says, lets buy the "best". Little does the customer know its a cheaper $20 toaster with WiFi being sold for $60, next to the actual $40 toaster. IOT is a way to sell inferior products for massively more money than they are worth because the IOT feature is being bought and not the core function. It is ingenious marketing and has little to do with data harveting (for now). It is a symptom of people with "too much money" (or people not saving money as they should) and that do too little research.

      AFTER the purchase they realize that between setting up the device, trouble shooting, and using it one time, that it is actually not any easier to use your smart phone to turn on your toaster. And that amazing use-case they showed on TV only occurs once every six months and, then you forgot about it because you use it so infrequently. Then the app stops working 2 years later and the adapter/hub/etc. is no longer supported and it is worthless for IOT features unless you want to run a second/third set of IOT hubs and devices.

    2. Re:From consumers to products by Opportunist · · Score: 1

      Because there's not really any other selling angle to household appliances. Those damn things last way too long. It's not like with your TV where you want to get a new one every other year so you can see the wrinkles in your favorite porn star's face or ass in higher resolution or the constant format change in content carrying media that keeps you buying a new player. A fridge pretty much lasts, well, nearly forever. And you don't replace it until it is simply and plainly broken.

      We need something to make you want the new gadget! And that's why you need the IoT. Ok, you don't. The vendor does. But you're supposed to buy it!

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    3. Re:From consumers to products by Anonymous Coward · · Score: 0

      Most of this comes from Silicon Valley companies. A key chapter in the Silicon Valley playbook is to own as much data about your customer as possible in order to maximize monetization of that customer. As such there is always a drive to have everything networked and ideally (from the company's perspective) running through the company's servers so they can mine that for opportunities to sell you more stuff or sell that data to someone else to mine for opportunities to sell you stuff.

      I don't feel that anything in my home outside of my computer should be connected to the internet; I don't think it's to the consumers' advantage. But it is to the company's advantage.

    4. Re:From consumers to products by Anonymous Coward · · Score: 4, Interesting

      A lot of people are glossing over that the newer models with IoT thermostats have much more complicated control systems because the compressor and fan have different power settings. Thus, the signal-to-activation connection is no longer a binary controller that can be hot wired.

      We live near but not in Washington D.C. When we installed new HVAC units we had the option of taking a wireless or regular thermostat, to which I elected "very strongly" to have the regular one or else I would cut the antennas out. The HVAC guy looked up with any amount of shock and said that the last two installs he did the people said the same thing. One was at the CIA and the other at the FBI (according to the HVAC guy. I'm in the DoD).

      Most people just see the functionality, not the risk. No one understands the risk until it becomes a reality. I have tried multiple times to get people to understand this and they refuse. Setting up a computer is no different for the layman---they fiddle with it until it works and stop as soon as it does. Doesn't matter that the firewall is fully open now and sharing is on. It works, and that's all that counts. I'd wager the same goes with IoT. It's about what can be done, not what might happen that you didn't expect.

    5. Re:From consumers to products by AthanasiusKircher · · Score: 1

      I used to be baffled as to why consumers would even want such things. But, of course, it is not the consumers who want all this IOT, but the vendors who sell the devices and the services, trying to turn us into the product.

      I agree that I can't understand the desire for many IoT devices, but internet control for a thermostat does make a certain amount of sense, particularly for those who are frequently out of town or take long vacations. In those cases, getting an alert that your thermostat is no longer responding correctly could make the difference between realizing your heat or A/C is busted immediately vs. dealing with potentially tens of thousands of dollars in water damage (from frozen pipes in winter), mold damage, or whatever when you get home a week or more later. And there are lots of less dire situations where someone who takes frequent trips might benefit from being able to make adjustments remotely. (And even if you don't travel, if you set back your thermostat during the day, this could be a convenient feature to have if you plan to come home a little earlier than expected and want your house warmer or cooler when you get there, etc.)

      Anyhow, obviously such things need adequate security, and they should never REQUIRE an internet connection to function correctly. But at least in the case of thermostats, I can imagine quite a few cases where consumers might actually like the connectivity as an option.

    6. Re:From consumers to products by sjames · · Score: 1

      It is all marketing crap. I can't think of a reason I want any of my appliances talkking to anything outside of my LAN, ever.

      In the unlikely event I might want to talk to my appliances when I'm not right there, I would rather talk to a well updated server over the net and let it talk to the appliances. Sadly, that is what they make impossible by insisting on proprietary protocols and certs signed by them. So, that leaves the default of no networked anything.

      At least I won't get hacked by the Cylons :-)

    7. Re:From consumers to products by skam240 · · Score: 1

      Who watches porn on their TV nowadays? What is this, the 80's?

      --
      I ignore Anonymous Coward posts. If you want to discuss something, that's awesome. Log in.
  7. I actually prefer it hackable by omnichad · · Score: 3, Interesting

    Sure, there are malicious cases for this. But most IoT devices like smart thermostats are a bit too dumbed down and don't even operate correctly without an external Internet connection. Their broken security is about the only way to get a proper level of functionality.

    1. Re:I actually prefer it hackable by Anonymous Coward · · Score: 0

      Yep, this is why I like the Filtrete "Radio Thermostat" unit that I bought. It's default mode of operation is to contact the company servers to get programming/setting updates from your smart phone app or web page, but the company is a decent company and has an exposed and documented API that I used to build my own application to control the thing and integrate it with my other custom smart home work. I have full control of the device and can secure it properly.

      As much as I love the smart thermostat capabilities, I would forgo them if my only choice was a device I could not ensure the security of.

    2. Re:I actually prefer it hackable by Anonymous Coward · · Score: 0

      I'll second that. I'm still using the official app and cloud server in my case, but I bought this one specifically because if they ever kill their service, or I find the time to tie the custom API into other home automation software, I have options.

      The Radio Thermostat also gets bonus points because the WiFi module is removable, and can also be replaced (or supplemented) with a Z-Wave radio if desired.

    3. Re:I actually prefer it hackable by samwichse · · Score: 1

      Nest will work just fine with no internet connection.

    4. Re:I actually prefer it hackable by Megane · · Score: 1

      I've got two in different houses. I'm moving out of one of those houses, and the thermostat will come with me, even if I don't have a place for it right away. They also support a JSON local control protocol, so they won't be bricks if/when the cloud service dies.

      --
      #naabhaprzrag, #sverubfr-000, #agi-fcbafberq, negvpyr[pynff*=' negvpyr-ary-'] { qvfcynl: abar !vzcbegnag; }
  8. Yes, you can unscrew, but ... by Anonymous Coward · · Score: 0

    Yes, you can unscrew, but this only shows incompetence on your side regarding the ransom business.

    What about if the crackers wait for the thermostat to be set to holiday mode and nobody is home and only then start with changing the settings and sending the ransom note? Your choice now becomes to pay or to find someone very fast to go to the home and remove the thermostat, e.g. to prevent bursting pipes in the winter or wasting tons of energy in the summer and killing the indoor plants.

    1. Re:Yes, you can unscrew, but ... by Anonymous Coward · · Score: 1

      or wait for the thermostat to be in holiday mode and then go rob the place.

    2. Re:Yes, you can unscrew, but ... by BronsCon · · Score: 1

      Send the ransom note... where? RTFA, they display the ransom note on the thermostat itself because, well, they don't have your email address.

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
  9. Emergency service call costs by Overzeetop · · Score: 3, Insightful

    Do you have any idea what a licensed installer charges for an emergency visit on a Sunday morning? That $25 thermostat is $50 because you don't get to buy the one that's on sale at Home Depot, and the cost to knock on your door is going to be close to $150, and then the rate ticks forward at $100/hr. And at the end of your $300 emergency service call, you'll be left with a dumb thermostat and a $200 paperweight.

    --
    Is it just my observation, or are there way too many stupid people in the world?
    1. Re:Emergency service call costs by Waffle+Iron · · Score: 3, Insightful

      In the worst case, they could just unscrew the wires from the thermostat and clip the bare ends together with a clothespin to turn on the furnace. That would at least keep the pipes from freezing and cost $0.

    2. Re:Emergency service call costs by Anonymous Coward · · Score: 0

      really? five wires and a tick-tick tester, youtube will walk you through it.

    3. Re:Emergency service call costs by Frosty+Piss · · Score: 1

      In the worst case, they could just unscrew the wires from the thermostat and clip the bare ends together with a clothespin to turn on the furnace. That would at least keep the pipes from freezing and cost $0.

      "Smart" thermostats ofter communicate with the furnace / cooling via a cat-6 or some other type of communications cable, they are rarly just a switch. On the other hand, you can often buy them at Home Depot / Lowes, and just install a new one yourself and then maybe reset the old one to factory.

      --
      If you want news from today, you have to come back tomorrow.
    4. Re:Emergency service call costs by Lord+Apathy · · Score: 1

      I doubt that most people could do that. To a lot of people something as simple as thermostat might as well be magic to them.

      --

      Supporting World Peace Through Nuclear Pacification

    5. Re:Emergency service call costs by Anonymous Coward · · Score: 3, Insightful

      >"Smart" thermostats ofter communicate with the furnace / cooling via a cat-6 or some other type of communications cable

      No, these smart thermostats are simple replacements, not something requiring a computerized furnace.

    6. Re:Emergency service call costs by Anonymous Coward · · Score: 0

      Every home thermostat is just a switch. Consumer HVAC systems are not intelligent. They use CAT5/6 cable in the wall because they have it, but they are often wired with old fashioned 'bell' wire.

    7. Re:Emergency service call costs by Frosty+Piss · · Score: 1

      Consumer HVAC systems are not intelligent.

      Modern as in :new" ones certainly are, and the communications between the "switch" is today more often than not just a little tiny bit more than On/Off ...

      --
      If you want news from today, you have to come back tomorrow.
    8. Re:Emergency service call costs by Anonymous Coward · · Score: 0

      And at the end of your $300 emergency service call, you'll be left with a dumb thermostat and a $200 paperweight.

      Don't forget a lesson learned.

    9. Re: Emergency service call costs by WarJolt · · Score: 5, Insightful

      Somehow I feel like in order to graduate from high school one requirement should be to realize thermostats aren't magic. Too bad we can't revoke HS diplomas. Many Americans don't know cell phones work using radios. It's a bit troubling that a 30 minute electricity experiment performed at an elementary school level can provide the necessary insight into the operations of a thermostat and yet most Americans can't figure this shit out.

    10. Re:Emergency service call costs by Anonymous Coward · · Score: 1

      "Smart" thermostats ofter communicate with the furnace / cooling via a cat-6 or some other type of communications cable, they are rarly just a switch.

      They are almost always just a switch.

      Actually a bunch of switches. For example, in my house, I have one for turning on the furnace blower, one for turning on the AC, and one for turning on the heat. There's a 24V common (or multiple 24V lines), which comes in, and is routed to the blower, AC or heat to turn them on.

      Practically, it's either blower + heat or blower + AC for most things, depending on if I'm heating or cooling.

      The only reason why CAT5 is used is because it's cheap and it gives multiple wires to play with. Practically, most systems are probably using only 4 or 5 of the wires. Telephone wiring (2 pairs) is also used in older systems.

      Your smart thermostat does not know what the HVAC system is doing. It can only tell a system to turn on or off, and monitor its environment.

    11. Re: Emergency service call costs by UnknownSoldier · · Score: 2

      Part of problem is that people have more money then time.

      They would rather remain ignorant and pay someone else to solve the problem.

    12. Re:Emergency service call costs by guruevi · · Score: 1

      Never seen one like that and I own and have researched many 'smart' thermostats. Mine and most IoT devices also doesn't just sit exposed to the Internet, not sure why anyone would spend a public IP (because those things sure as hell don't do IPv6) on a thermostat.

      --
      Custom electronics and digital signage for your business: www.evcircuits.com
    13. Re: Emergency service call costs by AthanasiusKircher · · Score: 1

      Somehow I feel like in order to graduate from high school one requirement should be to realize thermostats aren't magic. Too bad we can't revoke HS diplomas.

      I still remember the reactions I got when I told people I replaced the basic thermostat model I had in a house when I moved in with a basic programmable model that I could setback during the day or at night for energy savings, etc.

      Many people I know -- a lot of them with graduate degrees -- looked at me like I had told them I just built my own car after smelting and processing the metal from raw ore I had dug out of a mine myself. I'm frankly astounded at how few people have ANY knowledge of basic electrical stuff. Swapping out a bad switch or an old ceiling fan or whatever is really basic stuff (as long as you follow truly basic safety measures), but for some reason everyone acts like this is rocket science... or at least way too difficult and dangerous for anyone except a "licensed electrician" to attempt.

      Anyhow, whenever I think of thermostats and the public, I always remember my grandmother, who had grown up in the days before air conditioning was at all widespread. But she had central air installed when she was older and to the day she died, she could not comprehend that turning the dial to a LOWER number meant that the air conditioning effect would increase. She was stuck on this idea that a thermostat was just some sort of arbitrary numbers where higher meant "more" or something. And, frankly, she was a pretty smart person otherwise... she just couldn't get that.

      I don't know what it is about thermostats that people just are incapable of understanding. Most people seem to think that by turning the numbers much higher or lower that the system will "work harder" (even though that's only true in a minority of setups, and only under certain conditions). Even fewer people understand the impact of humidity on comfort perception and realize how to make thermostat adjustments accordingly.

      I agree -- this should be taught in schools.

    14. Re: Emergency service call costs by HiThere · · Score: 1

      Yes, that should be taught in schools.

      Unfortunately, knowing that doesn't really solve the problem. Different control systems take different voltages. (In the discussion above I've seen explicit mention of 9 V and 24 V. Presumably both were DC, but that's not guaranteed.) And different devices have different control signals.

      If your thermostat was retrofitted onto an old system, you've got a simple job. If you're using some system a manufacturer put together to work as a system, he's got a positive incentive to make it unable to take a simple replacement. So expect that it won't. And there's no requirement that he should make the internal communications documentation available to you, so you can't count on being able to hack together a replacement.

      Now if you're knowledgeable, you might be able to figure it out (they aren't really obfuscating things yet), but if you're knowledgeable, why in the world would you buy into such a thing in the first place? Were I doing it (I'm not going to. I see no real benefit in IOT thermostats.) I'd probably use a raspberry pi or some such and hack together a system attached to a real computer (i.e., one with a keyboard and monitor) and allow THAT access to the internet over a protocol that I wrote. But I don't like fiddling around with hardware, and I see no real benefit in the IoT devices. I intend to avoid them as long as I can. (But I do already have a printer that I can't block off from internet access without disabling an automatic ink purchase program. I think this was a bad idea, but my wife like not needing to go out to buy ink.)

      --

      I think we've pushed this "anyone can grow up to be president" thing too far.
    15. Re:Emergency service call costs by BronsCon · · Score: 1

      And you're still ahead. A single bitcoin is nearly double that at the moment.

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
    16. Re: Emergency service call costs by BlytheBowman · · Score: 1

      I would rather have a "dumb" furnace I could connect just about any kind of thermostat to, whether it's a 1950s era entirely mechanical unit, or an 80s/90s era digital thermostat, or even a "smart" thermostat which electricaly operates as a regular thermostat and does not use proprietary bullshit to try and lock you in to any one product. If it does get hacked, and is doing something real dangerous, I could break it off the wall if I have to in a pinch, do some minor repair to the dry wall, and reinstall the old thermostat.

    17. Re:Emergency service call costs by Anonymous Coward · · Score: 0

      Not a good idea. Touch the wrong ones together and best case scenario you fry the 3 or 5 amp fuse on the control board. Worst case is blow the transformer and/or the control board and now you're really fucked.

    18. Re: Emergency service call costs by mcswell · · Score: 1

      We should trade. You can have my old thermostat, and I'll take yours. Except it's too late:I got tired of setting the smart (but not networked) thermostat: every day of the week was at least four (IIRC) separate settings (morning/ evening, summer/ winter), and half the time when I got through all of them, the setting didn't "stick." So I took the smart thermostats (one upstairs, one down) off the wall and replaced them with dumb thermostats from Home Box (name changed to protect the guilty). Two settings each (summer/ winter) and I'm done.

    19. Re:Emergency service call costs by mcswell · · Score: 1

      Three to five amps? For what? This is a relay controller, not a motor starter. Low voltage, and afaik low amperage. I don't think those itty bitty wires that the thermostat is wired to would handle that many watts (24 volts * 3-5 amps).

    20. Re:Emergency service call costs by arglebargle_xiv · · Score: 1

      Actually a bunch of switches. For example, in my house, I have one for turning on the furnace blower, one for turning on the AC, and one for turning on the heat. There's a 24V common (or multiple 24V lines), which comes in, and is routed to the blower, AC or heat to turn them on.

      Sounds horribly complicated. I just have a cord pull to summon the boy to deal with the fire, and another to summon the girl to top up the drinks. They connect to a bell that rings in their quarters or something. Not really sure how it all works, they just come when we need them.

    21. Re: Emergency service call costs by Anonymous Coward · · Score: 0

      Makes me think of my daughters face when I told her computers were actually "dumb" and that they are only capable of what humans program them to do. (We'll discuss SkyNet later...)

      I started teaching her Python and we setup various electronic projects on a Raspberry Pi. She's actually gaining a good understanding of circuits, switches, and resistors so far. I don't think she'l;l go into electrical engineering, but at least she will have a basic idea of electronics and computers in general. You're not going to get that in public education these days.

    22. Re: Emergency service call costs by Anonymous Coward · · Score: 0

      It's nonsense to expect people to fix even simple things, like thermostats, by themselves. It would be nice if they did, but saying that they should be able or willing to do it is not a way to go.

      First of all, you probably like tinkering with devices and this is why you do it, and ignoring that, you suggest that you do it because it's easy and everyone should do it. Most people don't find it pleasant and that is the main reason why they don't want to spend their free time doing that. This is the same reason I don't do many things, even though I could in theory. I don't have that much free time, I go home tired from work and don't want to engage into activities I don't like if I don't have to. This is why I could pay someone to clean my house even though I know how to clean myself.

      Secondly, you ignore the fact that in order to start fixing things, you really need to dedicate more time than you think when you do this for the first time. If you're just starting, you need to get interested like which tools you need, which spare part, which possibly includes spending some time reading about how similar parts differ from each other, which are suitable for you, which company to avoid cause they make garbage etc. Then you need to find out if a particular manufacturer didn't do anything to prevent DIY repairs and how to bypass that. Then you are cautious, because you are not used to it and you don't have manual skills, so you do everything extremely slowly not to break anything. Finally, if you do break something out of your clumsiness, you go berserk because you hate doing that anyway and any failed attempt means more time spent on doing things you don't like.

      Apart from that, many DIY repairs are going to void your warranty.

      Everything seems so quick and simple to you because you like it and you either have already forgotten how much time it took before you became experienced and self-confident about repairs or you started at the very young age, when you had much free time and you've never realised how much time you've put into this.

      That said, no excuse for any people looking at you as if you've just built a rocket yourself, because even though they don't repair stuff themselves, they should know it's not rocket science.

  10. IoT is nothing without user control by HBI · · Score: 1

    I shove anything like this on a DMZ with limited access. If it doesn't work without unfettered access to the Internet, I return it. Then again, I consider all devices untrusted unless I have complete control, including the ability to flash them to an arbitrary firmware.

    The IoT isn't going to make much progress with me.

    --
    HBI's Law: Frequency of calling others Nazis is directly correlated with the likelihood of the accuser being Communist.
    1. Re:IoT is nothing without user control by stabiesoft · · Score: 1

      Except in this case, the hack requires you to insert an SD card into the thermostat. So DMZ or no, you could be hacked. Although given you have a DMZ, I seriously doubt you'd be tricked into sticking some unknown SD card into the unit. Basically the article is hype. It is not an exploit if I have to load something into my thermostat. Who would even bother? A phone sure, but a thermostat????

    2. Re:IoT is nothing without user control by naughtynaughty · · Score: 1

      I don't think DMZ means what you think it means.

      You want it behind a firewall that tightly controls what can talk to it and what can talk to it.

    3. Re:IoT is nothing without user control by HBI · · Score: 1

      I think you made a "who" a "what". And I understand entirely what a DMZ is. It's exactly where a device like this belongs, with carefully defined ability to communicate with particular hosts - and assuredly with no inbound access to the internal network. If you can't clearly define what communications it needs, it's getting removed from the network.

      --
      HBI's Law: Frequency of calling others Nazis is directly correlated with the likelihood of the accuser being Communist.
  11. Hackers chatge Alphaben I.O.T. = FUcking Nightmare by burni2 · · Score: 1

    I F
    O U
    T N

  12. Won't Work by Anonymous Coward · · Score: 0

    Ask me for $300 to get my thermostat back, and my response would be to go buy another $30-50 thermostat and have it taken care of in 5 minutes.

    That said, they are absolutely right about IoT being idiotic. My personal favorite is the new fridges with orwellian spycams. THOSE getting hacked would indeed be a workable ransomware.

  13. Woo, can't wait for the Internet of Things by Anonymous Coward · · Score: 0

    Pay us 10$ daily or we'll run your toaster, turn your heater on in the summer, and turn off your refridgerator.

  14. Add a switch.. by Anonymous Coward · · Score: 0

    Why can't these vendors and a $1 switch to lock the firmware from being written to.
    Old PC BIOS used to have a jumper you have have to move to be able to update the BIOS.
    Problem solved. Flip the switch, update firmware, flip the switch back. Hard hard is that?

    1. Re:Add a switch.. by JustAnotherOldGuy · · Score: 1

      Why can't these vendors and a $1 switch

      Because it would cost a dollar, a whole fucking dollar, that's why.

      (Actually a switch to enable/disable firmware updates would only cost a few cents, but even that's too much to spend on security.)

      --
      Just cruising through this digital world at 33 1/3 rpm...
    2. Re:Add a switch.. by naughtynaughty · · Score: 1

      8 smoke alarms, 1 smart thermostat, 4 smart locks, 48 smart lightbulbs and someone needs to go flip a switch on each of them every time a firmware update is needed? No thanks.

    3. Re:Add a switch.. by JustAnotherOldGuy · · Score: 1

      8 smoke alarms, 1 smart thermostat, 4 smart locks, 48 smart lightbulbs and someone needs to go flip a switch on each of them every time a firmware update is needed? No thanks.

      I would be glad to flip a switch on each of them every time a firmware update is needed if it kept them from being hacked.

      What's more important, a few minutes of your time once in a while or some fairly bulletproof security?

      --
      Just cruising through this digital world at 33 1/3 rpm...
  15. Can't spell IDIOT without IOT.. by Anonymous Coward · · Score: 0

    What could be simpler than a thermostat? Even a digital thermostat with scheduled temperature changes should still at a basic level, be temperature controlled switch. What's next? Make sure to like my temperature settings on Facebook?

    I think my beard may be starting to turn grey.

  16. Bullshit, never going to happen by kheldan · · Score: 3, Insightful

    One day, your thermostat will get hacked by some cybercriminal

    No, it won't: I'm not falling for the 'Internet of Things' troll/meme. You won't be hacking my thermostat, lightbulbs, dishwasher, microwave oven, clothes washer, clothes dryer, television, or any other household appliance because there's not a single damned good reason why these NEED to be connected to the Internet.

    --
    Are YOU using the TOOL, or is the TOOL using YOU? Think about it!
    1. Re:Bullshit, never going to happen by geekmux · · Score: 1

      One day, your thermostat will get hacked by some cybercriminal

      No, it won't: I'm not falling for the 'Internet of Things' troll/meme. You won't be hacking my thermostat, lightbulbs, dishwasher, microwave oven, clothes washer, clothes dryer, television, or any other household appliance because there's not a single damned good reason why these NEED to be connected to the Internet.

      Vendor Marketeers: "There's not a single good reason our products should be offline!"

      Good luck fighting it.

    2. Re:Bullshit, never going to happen by kheldan · · Score: 1

      There will ALWAYS be a market for simple, functional, inexpensive products. If not, I'll fucking build it myself. A thermostat is not complicated. Now quit with the retarded trolling.

      --
      Are YOU using the TOOL, or is the TOOL using YOU? Think about it!
    3. Re:Bullshit, never going to happen by b0bby · · Score: 1

      there's not a single damned good reason why these NEED to be connected to the Internet.

      Need is a stretch, but there are some compelling uses for an internet connected thermostat. I'm thinking second home, where you want to be able to adjust the thermostat remotely, after your short term renters leave. Sure, it's not imperative, but the positives outweigh the (so far) theoretical negatives. I have an ecobee, and being able to set it to vacation when I'm already an hour away is pretty nice. If it gets hacked, I'll unplug it. Meantime, it has a remote temp sensor so my upstairs temperature is much better than my old thermostat, which was the real reason I got it.

    4. Re:Bullshit, never going to happen by Anonymous Coward · · Score: 0

      I own an XBox 360. I've never seen fit to give it my wifi password.
      Why would I give it to any of these products that don't even provide any useful online functionality?

    5. Re:Bullshit, never going to happen by naughtynaughty · · Score: 1

      One day, your thermostat will get hacked by some cybercriminal

      No, it won't: I'm not falling for the 'Internet of Things' troll/meme. You won't be hacking my thermostat, lightbulbs, dishwasher, microwave oven, clothes washer, clothes dryer, television, or any other household appliance because there's not a single damned good reason why these NEED to be connected to the Internet.

      Unless the only things you have hooked to your TV are an antenna and a DVD player the chances are it already is connected to the Internet or whatever you are using to view videos is connected. There are great reasons to connect a TV to the internet, watching all the content you can get from the internet.

      A smart dishwasher might be sending sensor information to the manufacturer where early signs of failure can be identified and you alerted prior to the dishwasher failing.

      A microwave oven might have a voice interactive control system and the voice recognition is done in the cloud.

      Your dryer might communicate with the power company who gives you a discounted rate if they are allowed to shut it off for short intervals to minimize peak power draw.

      Your washing machine might get updated with new, better washing algorithms or send information about how well wash cycles are working back to the manufacturer so they can get your clothes cleaner or as clean in less time.

      I suppose there isn't a single damn reason why you need to connect to Slashdot and leave comments. But you enjoy it so have at it. Other people might enjoy talking to their microwave while you want to turn a dial and press start. Different strokes for different folks.

    6. Re:Bullshit, never going to happen by Anonymous Coward · · Score: 0

      second home...short term renters

      So it's just for you one-percenters with more dollars than sense. Got it.

    7. Re:Bullshit, never going to happen by Megane · · Score: 1

      It can also let you know when a house in another city is having HVAC trouble. But there's still no need for it to be exposed to the live internet, when it can simply poll a cloud service every few minutes for updates.

      --
      #naabhaprzrag, #sverubfr-000, #agi-fcbafberq, negvpyr[pynff*=' negvpyr-ary-'] { qvfcynl: abar !vzcbegnag; }
    8. Re:Bullshit, never going to happen by naughtynaughty · · Score: 1

      A simple thermostat certainly isn't complicated. But is it very expensive to have a simple thermostat in many areas of the country.

      Add a tiny bit of smarts like changing the setpoints based on the time of day and day of the week and you can save thousands of dollars a year in areas of the country where time of day electric rates make off peak electricity 1/4th the cost of on peak electricity.

      Even smarter thermostats let me tells my thermostat remotely at a vacation home that I'm coming for the weekend and to please switch from away mode to present mode.

      Much smarter thermostats let utilities even out peak demand by keeping everyone's AC from running at the same time.

      But you are always free to buy the $10 model at Home Depot if it meets your needs or build your own.

    9. Re:Bullshit, never going to happen by Anonymous Coward · · Score: 0

      There will ALWAYS be a market for simple, functional, inexpensive products. If not, I'll fucking build it myself. A thermostat is not complicated. Now quit with the retarded trolling.

      No, a thermostat is not complicated.

      Getting the proper certs and UL rating on hardware that controls the environment in your $200,000+ investment is what is complicated, and when your home insurance company uses your DIY bullshit against you the next time you try and make a claim, you'll remember a troll reminded you of just how legally fucked this world is.

      There will always be a market for common sense too, but if common sense were the one prevailing here, we wouldn't be having a fucking conversation about pointless IoT shit taking over.

    10. Re:Bullshit, never going to happen by knorthern+knight · · Score: 1

      > Add a tiny bit of smarts like changing the setpoints based on the time of day and day of
      > the week and you can save thousands of dollars a year in areas of the country where
      > time of day electric rates make off peak electricity 1/4th the cost of on peak electricity.

      *A PROGRAMMABLE DIGITAL THERMOSTAT DOES NOT NEED TO BE INTERNET CONNECTED*

      > Even smarter thermostats let me tells my thermostat remotely at a vacation home that
      > I'm coming for the weekend and to please switch from away mode to present mode.

      If you can connect over the internet, so can the bad guys. If you want to risk a major security breach at your place for the convenience of not having to wait 2 hours for the temperature to get comfortable, your priorities are ass backwards.

      --

      I'm not repeating myself
      I'm an X window user; I'm an ex-Windows user
    11. Re:Bullshit, never going to happen by knorthern+knight · · Score: 1

      > Unless the only things you have hooked to your TV are an antenna and a
      > DVD player the chances are it already is connected to the Internet or
      > whatever you are using to view videos is connected. There are great reasons to
      > connect a TV to the internet, watching all the content you can get from the internet.

      I prefer to connect an HDMI cable from my computer, which I know is updated/firewalled properly. BTW, a 30-foot HDMI cable is only 30 dollars Canadian at Home Depot http://www.primecables.com/p-3...

      > A smart dishwasher might be sending sensor information to the manufacturer where
      > early signs of failure can be identified and you alerted prior to the dishwasher failing.

      Beyond stupid. Howsabout a "trouble light" like in your car? Again, it's absolutely unnecessary for packets to traverse the internet for that to happen.

      >A microwave oven might have a voice interactive control
      > system and the voice recognition is done in the cloud.

      Beyond beyond stupid.

      > Your dryer might communicate with the power company who gives you a discounted
      > rate if they are allowed to shut it off for short intervals to minimize peak power draw.

      Or like, you know, do your laundry, etc, on weekends or after 7:00 PM weekdays to take advantage of "Time-of-Use Pricing" http://www.ontario-hydro.com/c...

      --

      I'm not repeating myself
      I'm an X window user; I'm an ex-Windows user
    12. Re:Bullshit, never going to happen by Anonymous Coward · · Score: 0

      No, it won't: I'm not falling for the 'Internet of Things' troll/meme. You won't be hacking my thermostat, lightbulbs, dishwasher, microwave oven, clothes washer, clothes dryer, television, or any other household appliance because there's not a single damned good reason why these NEED to be connected to the Internet.

      Of course there is no reason to connect a device to the internet today, but I'll bet in ten years you won't be able to buy a device that is not.

    13. Re:Bullshit, never going to happen by wyHunter · · Score: 1

      Indeed, it means you have to buy the highest quality, most reliable things you can find NOW and plan never to replace them if you possibly can. It isn't easy. But I'm with you.

    14. Re:Bullshit, never going to happen by wyHunter · · Score: 1

      I hear what you are saying but... 1. I don't have a television. 2. I'd rather have my dishwasher output a code to its panel. 3. I can't imagine not just hitting '1 minute' or 'dinner plate' button on my microwave BUT I can see a use for this if the individual is handicapped. 4. The dryer has a point but on the other hand, I'd just as soon not dry clothes during peak times, leaving them to dry at night or something. This is truly my preference, but I live quite a nice life WITHOUT IoT stuff and, frankly, can't imagine ever wanting IoT things.

    15. Re:Bullshit, never going to happen by Anonymous Coward · · Score: 0

      Regarding the updates: you have that option on smartphones, and yet most vendors release several updates at best and then abandon your phone and you have to flash it with custom ROM if you want fresh soft. It will be the same with home appliances - it's easier to make you buy new devices if they keep the ones you have outdated. So your washing machine is not going to receive many updates - they'll rather build a new model based on the data you send them and release an update that will make your current washing machine work worse so that you are forced to buy a new one.

      Regarding voice control features: I don't think voice control is that useful, especially that in many languages it's still extremely buggy (and will be - only several languages are going to get good support because you have to have a lot of users to make it feasible). Besides, installing some privacy-intrusive device just to have it voice controlled is not an option for me - is it really so much more convenient to say 'MICROWAVE START' rather than just pressing a button? Takes about the same amount of time. Especially given that the microwave may be turned on easily by accident if voice controlled?

      Your smart dishwasher may as well just report these early signs of failure directly to you, without reporting it back to the manufacturer. Many devices today are crippled on purpose so that they break down after warranty period expires. Given that, I don't believe that most companies will use this feature to make your device more reliable and last longer since they've already shown that reliability is not their priority - they will rather use IoT as a mean to inform you to have it serviced for additional charge after warranty expires even if you don't necessarily need it.

      I also don't believe in discounts from your friendly power plant for managing your power consumption in a smart way - they'd rather raise prices for people not using IoT and not raise them for people that do.

      Even if all the things you say turn out to be true (which I doubt), it's still not worth having all the devices at home hackable - and they WILL get hacked. If you expose something to the internet, it's only a matter of time, and guys at home appliances industry have no experience with internet security. If all the companies go IoT, most of them will always have crappy security since IT security is quite complex and costly and there are far too few IT security experts in the wild to support all these companies. Besides, security is always viewed as an additional cost and most companies cut their spendings on that. When your device breaks down, then you can return it. In case of your device getting hacked, there will be NO WARRANTY clause in the terms of use as well as statements like 'while we do everthing we can to protect you from internet attacks, we cannot guarantee full security". You are also giving huge amount of power and control over people to companies and governments.

      I don't mind if IoT is going to remain an option, but I'm afraid that at some point you won't be able not to use it.

  17. Lol, oh my by JustAnotherOldGuy · · Score: 1

    Oh, Internet-of-Endlessly-Exploitable-Things, ah love yew! (heart emoji x 1000)

    Every day a new exploit, it's like an all-you-can-eat buffet of terrible shit, served fresh and piping hot.

    --
    Just cruising through this digital world at 33 1/3 rpm...
  18. embedded need to have os updates that are on there by Joe_Dragon · · Score: 2

    embedded stuff needed to have os updates that are on there own that come out faster then the app update.

    At least some embedded stuff is ARM with cut down linux based os's. But others are full pc's running a big linux install or even windows with a custom app on top of it. And if them alot for the time you need to wait from the app part to be updated before the under lining os get's fixed even for just os security fixes. As the updates just come as full install images.

    Some embedded systems have sd cards that can have there os hacked and the hack can stay on the system even after power off. Unlike others where it's flashed with a small nvram area that just holds settings / logs.

  19. So you can put bad code on things that run on code by Anonymous Coward · · Score: 0

    Wow this is amazing news after all.

    How ever will we figure this one out? Any day now, ninjas drop in from Apache helicopters and hack all of your thermostats.

    Or.. US Gov false flag, say Russia or Iran did it, disrupt domestic power grid systems.

    Lying is what taxes pay spies to do. What makes you think this story is not a bait for responses story since Slashdot is FBI? They use what you say to play their bullshit. eg. 9/11 was false flag but did you just learn this today?

  20. simple override switch? by Anonymous Coward · · Score: 0

    and why not a simple built-in external override switch on the outside that returns the device to manual? Seems like a selling feature.

  21. Come on America. Think Lawyers ! by Anonymous Coward · · Score: 1

    Well if you're home is put at risk or damaged due to poor security on a "Smart" thermostat surely the first thing a real American will do is call a lawyer. And sue the Thermostat company for marketing defective goods !

    All this talk of fixing it yourself is wholly un American.

    Sue the bastards. That will get them to take security seriously.

    1. Re:Come on America. Think Lawyers ! by Megane · · Score: 1

      It's the "smart" TVs that worry me more. There are a lot more of those out there.

      --
      #naabhaprzrag, #sverubfr-000, #agi-fcbafberq, negvpyr[pynff*=' negvpyr-ary-'] { qvfcynl: abar !vzcbegnag; }
  22. capital offense? by Anonymous Coward · · Score: 0

    Is it just me, or do others thing that developing and deploying ransomware should be a capital offense? To me this is just seems like another form of terrorism. If someone were to hold your house for ransom in most jurisdictions you would be allowed to use deadly force to secure your property. At the very least this type of stuff should be a class A felony.

    1. Re: capital offense? by Anonymous Coward · · Score: 0

      You're right on the terrorism aspect, but there's also the Darwinism aspect: If someone is stupid enough to have important infrastructure in their house connected to the internet...

  23. Communication protocol by sjbe · · Score: 4, Informative

    "Smart" thermostats ofter communicate with the furnace / cooling via a cat-6 or some other type of communications cable, they are rarly just a switch.

    No they do not. Retrofitting a cat6 (overkill) cable to run to the HVAC in an existing house would be prohibitively expensive and/or time consuming. They communicate with the HVAC via the same set of wires a "dumb" thermostat would use and gets power over the same cables. They generally communicate with the network via wifi. Nest even kindly color codes everything so that someone who isn't a a licensed technician can do the job.

    1. Re:Communication protocol by stabiesoft · · Score: 1

      The carrier infinity line uses a derivative of RS-485 to allow two wire communications. How do I know? Because I have a carrier unit right now that communicates with the outside condenser unit over the original dumb pair of unshielded standard thermostat wires. The outdoor unit is a 2 speed unit, and reports such things as coil temperature and fault codes to the thermostat. A somewhat negative side effect of this is the outdoor unit now needs a power supply which runs all the time to power the interface. If I had 4 wires to the outdoor unit, 2 would have been used for power/gnd and the outdoor unit would not have the separate power supply. The thermostat does not need wifi for operations. If I want it to talk to my phone, I would need to enable the wifi, but I don't have a need for that so I did not enable it.

  24. Consequences by DidgetMaster · · Score: 1

    Until we start treating hackers who maliciously destroy people's lives like we do kidnappers or people who throw rocks through your window, this kind of thing is going to keep getting worse. People treat hacking like a hobby where you can cause thousands or millions of dollars in damage with almost no chance of getting caught and with lackluster penalties if you do.

    1. Re:Consequences by HiThere · · Score: 1

      I hope the outrage makes you feel better, because it serves no other purpose. People tend to discount future rewards and threats. What would make people less likely to do this is more the certainty of getting caught than a severe punishment.

      So how are you willing to improve their "certainty of getting caught"? Are you willing to make all internet communication traceable? Even that wouldn't work, as those who do this will often be in other countries. So even just making all methods of payment traceable wouldn't suffice, but you'll notice that these people usually want to be paid in bitcoins. Son if you eliminated untraceable currency, you'd reduce it a lot. Is the game worth the candle to you?

      In London one of the favorite places for pickpockets to work used to be the place where they hanged people for, among other things, being a pickpocket. Threat of punishment doesn't deter people well unless there's a high likelihood of being caught. And if there's a high likelihood you don't need severe punishment. Restitution + damages + a small fine should suffice. Restitution and damages should be generously calculated to benefit the person injured. Fines should be moderate, say twice the court cost + the bill for police services needed. And the perpetrator (i.e., the person/persons found guilty of committing the act) should have the right to challenge the bill for any of the costs involved, though then they would need to pay for the independent auditor unless the bill was found to be in error.

      --

      I think we've pushed this "anyone can grow up to be president" thing too far.
  25. Online everything? by Lumby · · Score: 1

    Doubt i'd ever connect my thermostat to the internet anyways. If it's really smart it won't need the internet to help it =P Nor will it need my input.

  26. Little benefit to IoT by Shadow+IT+Ninja · · Score: 1

    I've said this before but it needs to be said again. The benefits of a thermostat being an Internet of things device as opposed to a LAN-only device is minimal. The main benefit to these smarter thermostats is just that you can configure them from a web page. This is easier than the older ones with a tiny LCD screen and a small number of buttons. The thing is that many devices such as printers and broadband routers have embedded web pages that demonstrate how you can handle configuration web pages internally. There is no need to connect outside your LAN for this. Really, the only thing that an IoT design allows on top of this is the ability to change settings from anywhere without having to set up a method to get into your local network such as a VPN server (many broadband routers today include one), a service like GoToMyPC or SSH tunneling. I really doubt that this ability to change thermostat settings from anywhere in the world is that useful to most people. You loose security and privacy. The real point of the IoT design is to allow the external site to collect data about you. They can probably infer when you are home or away and when you are awake or asleep from the thermostat data. Are those costs really worth the benefits?

    1. Re:Little benefit to IoT by Anonymous Coward · · Score: 0

      I disagree. I use the ability to change my thermostat remotely all the time.

      * When I leave town and forget to set my thermostat to away
      * When I leave work early or late and want to change when my system kicks on
      * Any other time when the rigid schedule of a thermostat program doesn't match my actual life schedule.

  27. Just because we can, doesn't mean we should by whitroth · · Score: 1

    My power company called, last year, to offer me one. I told them not under any circumstances.

                mark, who remembers when the 'Net was civilized

  28. honeywell? by mangamaster03 · · Score: 1

    Rabble rabble rabble... Honeywell round thermostat. Twenty bucks, no internet connection, and simple enough even my grandparents can operate it.

  29. Sounds short-sighted to me by damn_registrars · · Score: 1

    If they hold your thermostat ransom for $300, why not just use the $300 to buy a new thermostat and tell the hackers to get lost? I can pick up the Nest Thermostat at my local big box home improvement store today for $249.99; why would I pay more to the hackers?

    Granted, my thermostat cost a lot less than that - and doesn't have the fancy features of the nest - but if I was someone inclined to purchase a thermostat for $300 I don't see why I would pay the same amount to get it back from hackers if I could replace it instead and tell them to take a hike.

    --
    Damn_registrars has no butt-hole. Damn_registrars has no use for a butt-hole.
    1. Re:Sounds short-sighted to me by DidgetMaster · · Score: 1

      Not only that, when you pay ransom you have no guarantee at all that they will fulfill their promises. They might just take your money and leave you hanging with a dead thermostat. Since they are already the scum of the Earth, why think they would ever give you control back?

    2. Re:Sounds short-sighted to me by samwichse · · Score: 1

      What makes more sense is:

      1) Write an automated hack for some company's thermostats (I'm sure most of these companies have some report home feature that means you could get them all in one once you scoop up their list)
      2) Wait till terrible weather time (January in the US)
      3) Pwn all 500k of the units in people's houses
      4) Set the ransom somewhere low like $5-10
      5) Profit

    3. Re:Sounds short-sighted to me by sjames · · Score: 1

      Most will do just that, and the bad guy loses nothing. A few are away and it would cost them considerably more than $300 to get back and replace the thermostat before the pipes freeze. That's where they get the money.

  30. IOT *only* makes some sense.... by mark-t · · Score: 1

    ... when you are in control of the device's internet connectivity, and can put it behind a firewall and a private-only IP that will permit outgoing access only, similar to a NAT. If that causes the device to behave badly, then the device is already broken and useless. If you want to control the device from outside of your firewall, you can still do so via a secured system that is behind the firewall that *can* accept incoming connections, where any incoming connection to the other system can go through authorization procedures that are otherwise necessary to remotely connect to that system (such as what you might use for ssh, etc).

  31. Kids today... by Anonymous Coward · · Score: 1

    You call yourself Frosty Piss, and you can't send binary down the line using a 9V battery, some paper clips, and a resistor (to get it down to 5V)? Whatever happened to Slashdot?!

  32. IOT water sensor by Anonymous Coward · · Score: 0

    I'm working on a plan to have an IOT shower head. It has a camera built into it that watches the steam coming from the shower to judge if it is hot enough or not- the shower head will then automatically adjust the temperature. Internet connectivity will ensure firmware updates.

    Any backers for my device? Camera is for watching steam only.

  33. A few hundred dollars? by naughtynaughty · · Score: 1

    Anyone who responds would go on a hacker sucker list.

    What's next, someone is going to hack a lightbulb and demand $100 or threaten to leave it on 24/7?

  34. A few hundred dollars? by EmagGeek · · Score: 1

    A decent new programmable thermostat is $40 at home depot. If I had a so-called "smart" thermostat and it got hacked, you can bet I'm neither going to pay the ransom nor replace it with another so-called "smart" thermostat.

  35. I remember this by Anonymous Coward · · Score: 0

    I played this when it was called Megaman Battle Network. It didn't end too well IIRC.

  36. More of a simple, generic demo, I think by Anonymous Coward · · Score: 0

    Initially, I thought the same as many other comments - just replace the thermostat with a basic contact closure type not connected to the net. I think that probably misses the main point of the exercise, though, which is to demonstrate how simple taking over IoT devices can be. Some devices are mission critical and taking them offline or losing reliable control could be detrimental. I think the real point of the exercise might be that mission critical devices need to be designed so that they can be unplugged from the net without consequence, and there must also be design considerations to keep unwanted attackers from gaining any sort of control. Seems obvious, but proof of need seems to be necessary, especially when people can't see the forest for the trees. Just sayin.

  37. IoS by GrumpyNope · · Score: 1

    Internet of Shit

  38. All your base by npslider · · Score: 1

    All your baseboard are belong to us!

  39. It is uneconomical for most people to know by Anonymous Coward · · Score: 0

    Well, said human can expend time and mental energy to figure out something, which will have little benefit to him/herself, or call someone whom deals with said problem frequently. That someone could be a bottom third high school graduate whom took a one year course on said problem, and knows the details, but does not know the science behind said problem: sort of like cable TV installers.

  40. Dumb themorstat by Anonymous Coward · · Score: 0

    A dumb thermostat isn't always an option. My pellet stove for example uses a proprietary thermostat. The thermostat is the actual brains for the pellet stove.

  41. Ran into something similar with water heaters. by Ungrounded+Lightning · · Score: 1

    Actually on my furnace you cannot connect a conventional thermostat. The thermostat talks to the furnace over RS-485 with a proprietary protocol. Now lucky for me it's not a 'smart' internet connected device. But depending on the installation the option of putting in a dumb thermostat may not exist.

    I ran into something like that when I had to replace a water heater - in Silicon Valley.

    In some areas of California, environmental regulations require you to install an extremely energy-efficient water heater. Part of the way this efficiency is obtained, with gas water heaters, is by not using a pilot light, which burns substantial gas all the time. (The pilot-light in my Nevada place's water heater puts out enough heat that, even with the heater set to "vacation" in the dead of winter, the tank's water is only about 10 degrees F below the normal setpoint when I arrive after weeks away.)

    Instead, they have a furnace-style spark igniter - and a computerized thermostat to control it.

    One downside is that, in a power failure, the tank won't heat. (After a couple showers I need to start the emergency genny and make sure the water heater is on the backed-up circuit.)

    But another downside is that the heater is able to hook up to your home network via WiFi - for convenient monitoring and remote control.

    (Fortunately, as of this spring, the WiFi hookup is an add-on board, which I presume contains the radio. So I just didn't buy the board. But with radio-capable systems-on-a-chip becoming so cheap, due to the IoT, I expect that the next models will have the radio built-in and always-on. That will let the bad guys track whether, and when, the building is occupied by looking at the water heating load, or just screw around with the settings.)

    --
    Bantam Dominique roosters crow a four-note song. Once you've heard it as "Happy BIRTHday" you can't NOT hear it that way
  42. until you pay up a few hundred dollars by Anonymous Coward · · Score: 0

    Or buy a new one for few hundred dollars, because that is what they cost new?
    It also assumes the if no way to force a factory Bootload.
    It also assume the Targeted House would not just call for service since the heat is broken.

  43. It's not a bug. It's a feature. by RogueWarrior65 · · Score: 1

    How else are we going to save the planet unless the government has control over your thermostat?

  44. I don't understand smart thermostats by Anonymous Coward · · Score: 0

    how hard is it to walk over to the thermostat, do you really need to control it with your phone - and why do you need to turn the heat on when you aren't home? just to waste energy? It's like remote start on a car - just start the damned car when you get in it - it seems like tech for tech's sake and not for problem solving.