Home » News » A horror story of reusing passwords, a warning to us all

A horror story of reusing passwords, a warning to us all

A horror story of reusing passwords, a warning to us all

Friday, 15 February, 2019

It is the mantra of our 21st century cyber world, don’t reuse your passwords. It’s dangerous and can be extremely costly. But do we heed the warnings? Well the experience of users of Google’s smart home outfit Nest should be a stark warning to us all.

Recently Nest has urged its customers to stop reusing their passwords they use between their smart home gadgets and other websites and services. The warning comes after bad guys were found using leaked or stolen usernames and passwords to log into Nest accounts and take control of the home gadgets. A form of attack known as ‘credential stuffing.’

Take the story of Arjun Sud. Arjun, from Illinois, USA found to his horror that hackers had got into his family’s account. They used it to change the temperature of his home. And at one point they heard a male voice talking to their child through the baby monitor. And then the voice began shouting obscenities in the living room.

Arjun found his details had been obtained from the dark web and was a victim of speculative hacking after usernames and passwords had been dumped online from other unrelated security breaches.

Or how about the California family who awoke one day to a warning blaring out of their Nest camera, claiming to come from Civil Defence. The warning claimed three ballistic missiles were heading their way and that President Trump had taken to his bunker.

It is expected that by 2021 there will be upwards of 25 billion connected devices in use, but we have no clear idea how many are regularly hacked. And experts believe this is a problem that will only get worse.

Next said it actively seeks out passwords online, and, they said, ‘when compromised accounts are found, we alert you and temporarily disable access. We also prevent the use of passwords that appear on known compromised lists.’

With a smart home involving security cameras, smoke alarms, thermostats, even the front door the possibilities for mischief are extremely high and extremely damaging. And although cybersecurity is rapidly catching up with the Internet of Things and smart home products, they still remain vulnerable to attacks. Nest is one of the few that applies protection measures embedded into its products.

But, in the end, it doesn’t matter how many defence mechanisms are put in place, if the user remains lax in their own security then they and their products will continue to be at risk.

Nest provides, like so many others, tips for better account security. Always use its two-factor authentication, choose a strong password that you only use for Nest. Never share your account login, but if you have to only use the company’s shared access service to allow others on your account.

Finally, always keep your router software up-to-date and be on the look out for phishing emails and suspicious activities.

Image: Santeri Vinamaki

Tim Bamford author picture


Tim is a veteran freelance journalist writing extensively on internet news and cybersecurity.

News What's the story?

Keep up with the latest developments in UK broadband.

The biggest malware threats of 2020…so far

It’s been a year few of us will forget in a hurry, and we're only halfway through.

The biggest malware threats of 2020…so farThe biggest malware threats of 2020…so far Read more

Instagram could become the main news source for young people.

Reuters finds changes in the way younger users consume the news.

Read more

BT launches second line service

BT launches second broadband home line service for the new crop of home workers.

Read more

Best broadband areas for online gaming in the UK.

Read more

Help Learn with us

Make the most of the internet with our broadband library.

How to check if your broadband is down

It might seem obvious that an outage has occurred, but there are easy ways to check if your broadband is down, or whether the problem is more localised

How to check if your broadband is downHow to check if your broadband is down Read more

A guide to Big Tech alternatives.

It seems like we’re reliant on a small group of companies, are there alternatives?

Read more

Quick tips for boosting home broadband speed

Boosting speed can transform activities like streaming, gaming and accessing cloud storage

Read more

What’s the difference between hardware, firmware and software?

Read more