Infrared-enabled 'smart' light bulbs may be used by hackers to either steal data or spoof other connected devices on the home Wi-Fi network, according to Indian-origin scientists in the US.
The researchers at The University of Texas at San Antonio (UTSA) conducted a review of the security holes that exist in popular smart-light brands.
Smart lighting technology involves high efficiency fixtures and automated controls that make adjustments based on conditions such as occupancy or daylight availability.
"Your smart bulb could come equipped with infrared capabilities, and most users don't know that the invisible wave spectrum can be controlled," said Murtuza Jadliwala, a professor at UTSA.
"You can misuse those lights. Any data can be stolen: texts or images. Anything that is stored in a computer," said Jadliwala.
Some smart bulbs connect to a home network without needing a smart home hub, a centralised hardware or software device where other internet of things (IoT) products communicate with each other.
Smart home hubs, which connect either locally or to the cloud, are useful for IoT devices that use the Zigbee or Z-Wave protocols or Bluetooth, rather than Wi-Fi, said Anindya Maiti from UTSA, co-author of the study published in the journal Proceedings of the ACM on Interactive, Mobile, Wearable and Ubiquitous Technologies.
If these same bulbs are also infrared-enabled, hackers can send commands via the infrared invisible light emanated from the bulbs to either steal data or spoof other connected IoT devices on the home network, according to the researchers.
The owner might not know about the hack because the hacking commands are communicated within the owner's home Wi-Fi network, without using the internet, they said.
"Think of the bulb as another computer. These bulbs are now poised to become a much more attractive target for exploitation even though they have very simple chips," said Jadliwala.
Jadliwala recommends that consumers opt for bulbs that come with a smart home hub rather than those that connect directly to other devices.
He also recommends that manufacturers do a better job in developing security measures to limit the level of access that these bulbs have to other smart home appliances or electronics within a home.
Disclaimer: No Business Standard Journalist was involved in creation of this content
You’ve reached your limit of {{free_limit}} free articles this month.
Subscribe now for unlimited access.
Already subscribed? Log in
Subscribe to read the full story →
Smart Quarterly
₹900
3 Months
₹300/Month
Smart Essential
₹2,700
1 Year
₹225/Month
Super Saver
₹3,900
2 Years
₹162/Month
Renews automatically, cancel anytime
Here’s what’s included in our digital subscription plans
Exclusive premium stories online
Over 30 premium stories daily, handpicked by our editors


Complimentary Access to The New York Times
News, Games, Cooking, Audio, Wirecutter & The Athletic
Business Standard Epaper
Digital replica of our daily newspaper — with options to read, save, and share


Curated Newsletters
Insights on markets, finance, politics, tech, and more delivered to your inbox
Market Analysis & Investment Insights
In-depth market analysis & insights with access to The Smart Investor


Archives
Repository of articles and publications dating back to 1997
Ad-free Reading
Uninterrupted reading experience with no advertisements


Seamless Access Across All Devices
Access Business Standard across devices — mobile, tablet, or PC, via web or app
