YoVDO

Smart Nest Thermostat - A Smart Spy in Your Home

Offered By: Black Hat via YouTube

Tags

Black Hat Courses Cybersecurity Courses Ethical Hacking Courses IoT security Courses Data Exfiltration Courses Hardware Vulnerabilities Courses

Course Description

Overview

Explore the security vulnerabilities of the Nest thermostat in this eye-opening Black Hat conference talk. Delve into how researchers Yier Jin, Grant Hernandez, and Daniel Buentello demonstrate the ability to fully control a Nest device using a simple USB connection in just 15 seconds. Learn about the sophisticated hardware of this smart home device, including its dual ARM cores and wireless capabilities. Discover how the team bypassed firmware signing and OS-level security checks through hardware-level attacks, potentially allowing external attackers to backdoor the Nest software. Understand the privacy implications of compromising a device that knows your home occupancy patterns and stores sensitive data like WiFi passwords. Gain insights into ongoing research on exploiting the Nest Weave protocol for stealthy remote control and data exfiltration. This 50-minute presentation highlights the potential risks of smart home devices and emphasizes the need for robust security measures in Internet of Things (IoT) products.

Syllabus

Smart Nest Thermostat: A Smart Spy in Your Home


Taught by

Black Hat

Related Courses

Between Physical and Sofware: Fault Attacks, Side Channels, and Mitigations
Graz University of Technology via edX
POSWorld - Should You Be Afraid of Hands-On Payment Devices
Black Hat via YouTube
Drammer - The Making Of
Hack In The Box Security Conference via YouTube
The Evolving Attack Surface
Kaspersky via YouTube
Blacksmith- Compromising Target Row Refresh by Rowhammering in the Frequency Domain
IEEE via YouTube