Sensors can be fooled without hacking software
You can attack a physical system by lying to its senses rather than to its computer.
Heat the sensor, spoof the signal, put a printed image in front of the camera. Nothing in the software has been compromised and the system is behaving correctly on the information it has. In cyber-physical systems the measurement is an input like any other, and it is one that can be manipulated from outside the network entirely.
More on IoT and embedded
- A default password scales into a fleet vulnerabilityOne word, printed a million times
- Physical access changes the embedded threat modelThe lid was the threat model
- Firmware updates are a long-term security promiseYou sold the box, you signed up for the years
- Secure boot protects the startup chainEach link checks the next
- Device identity should be uniqueAll answering to one name
- Cloud shutdown can strand smart devicesThe strings came from elsewhere
