AT&T’s Cybersecurity Insights Report surveyed more than 5,000 companies worldwide, 85% of which were in the process of deploying IoT devices, and only 10% of those surveyed felt confident that they could secure them. Many of these companies are much smaller and do not even have security professionals on their payroll, instead using third-party electronics that may or may not have been tested for security.
Devices considered in the IoT range from washers and dryers to thermostats. Recently the most popular devices are those like Amazon's Alexa-powered Echo in-home speaker. Devices like these are extremely attractive, making virtually everything just one voice command away. It is also devices like these that can be the most vulnerable.
Amazon has around 250 devices that are certified to work with Alexa, and Amazon has encouraged a rapid development of these devices. All companies need to do to get this certification is write code and submit it to Amazon for review. Although they do require physical testing, they allow that testing to happen at third-party locations. Once Amazon reviews the code and the products are physically tested, they give a decision on giving it the "Works with Alexa" stamp of approval within 10 days. Even though devices can go through the process to get this stamp of approval, they do not need to to be able to be used with Alexa; it is more of a certification that helps market their product.
One of Amazon's competitors in this market, Apple, only has around 100 devices that can be used with its HomeKit. In order to be certified for use with HomeKit, devices need to use a special HomeKit chip, and specific WiFi and Bluetooth chips. Their method can be substantially more expensive, can take 3-5 months, and device makers are not allowed to publicly announce they are seeking HomeKit certification. These restrictions tend to be off-putting to developers, however those that do endure the process believe it is well worth it. CEO of Nanoleaf (a smart lighting system), Gimmy Chu, said, "they found issues with our product before we released it that we didn't find in our testing. We know that after we have the certification that it's rock solid."
Amazon acknowledges that unlike Apple, it can't guarantee the security of third-party devices. This strongly backs the aforementioned reason for lack of security being to simply get devices on the market, even if it means security taking a back seat. The good news is now that it is a very well-known issue that many devices are not secure, larger companies like Belkin are starting to respond to and patch these issues. This won't be something that can be fixed overnight, and going forward, hopefully companies will start to put security before profit.
Sources:
Defining the IoT Security
Why IoT Security is So Critical (TechCrunch)
The IoT Threat to Privacy (TechCrunch)









