A horror story of reusing passwords, a warning to us all

A horror story of reusing passwords, a warning to us all

Friday, 15 February, 2019

It is the mantra of our 21st century cyber world, don’t reuse your passwords. It’s dangerous and can be extremely costly. But do we heed the warnings? Well the experience of users of Google’s smart home outfit Nest should be a stark warning to us all.

Recently Nest has urged its customers to stop reusing their passwords they use between their smart home gadgets and other websites and services. The warning comes after bad guys were found using leaked or stolen usernames and passwords to log into Nest accounts and take control of the home gadgets. A form of attack known as ‘credential stuffing.’

Take the story of Arjun Sud. Arjun, from Illinois, USA found to his horror that hackers had got into his family’s account. They used it to change the temperature of his home. And at one point they heard a male voice talking to their child through the baby monitor. And then the voice began shouting obscenities in the living room.

Arjun found his details had been obtained from the dark web and was a victim of speculative hacking after usernames and passwords had been dumped online from other unrelated security breaches.

Or how about the California family who awoke one day to a warning blaring out of their Nest camera, claiming to come from Civil Defence. The warning claimed three ballistic missiles were heading their way and that President Trump had taken to his bunker.

It is expected that by 2021 there will be upwards of 25 billion connected devices in use, but we have no clear idea how many are regularly hacked. And experts believe this is a problem that will only get worse.

Next said it actively seeks out passwords online, and, they said, ‘when compromised accounts are found, we alert you and temporarily disable access. We also prevent the use of passwords that appear on known compromised lists.’

With a smart home involving security cameras, smoke alarms, thermostats, even the front door the possibilities for mischief are extremely high and extremely damaging. And although cybersecurity is rapidly catching up with the Internet of Things and smart home products, they still remain vulnerable to attacks. Nest is one of the few that applies protection measures embedded into its products.

But, in the end, it doesn’t matter how many defence mechanisms are put in place, if the user remains lax in their own security then they and their products will continue to be at risk.

Nest provides, like so many others, tips for better account security. Always use its two-factor authentication, choose a strong password that you only use for Nest. Never share your account login, but if you have to only use the company’s shared access service to allow others on your account.

Finally, always keep your router software up-to-date and be on the look out for phishing emails and suspicious activities.

Image: Santeri Vinamaki

Tim Bamford author picture


Tim is a veteran freelance journalist writing extensively on internet news and cybersecurity.

News What's the story?

Keep up with the latest developments in UK broadband.

Why is the UK worried about Huawei and what does this mean for 5G?

The Huawei controversy continues as Boris Johnson says we ‘will not risk British security”.

Why is the UK worried about Huawei and what does this mean for 5G?Why is the UK worried about Huawei and what does this mean for 5G? Read more

Unmissable streaming TV shows for 2020

Telly has moved online - let's dive in to the most bingeworthy releases due this year!

Read more

The most complained about home broadband services

Who's failing to live up to expectations?

Read more

Brits spend up to 4.9 hours surfing the web at work!

Read more

Help Learn with us

Make the most of the internet with our broadband library.

What are the differences between HD, UHD, 4K and 8K?

What are the differences between HD, UHD, 4K and 8K?What are the differences between HD, UHD, 4K and 8K? Read more

How far can augmented reality take us?

Read more

Keeping the Internet of Things secure

Read more

The best broadband routers for 2020

Read more