iHelp Innovate

Twitter Linkedin Google+

Pages

  • Home
  • Reviews
  • About
  • Posts
  • Services
  • Contact
Chances are, if you’ve started to hear or read about “The Smart Home”, you’ve learned something about controlling your thermostat or unlocking your house from a smartphone. But what you probably haven’t been exposed to, is the idea that you can interact with your entire home. The technology already exists to enable your smart home devices to react based on which occupant has arrived home or an input received from sensors and detectors. Actions such as opening a gate or garage door, unlocking the entry door, turning on the lights to a pre-set level, playing their favorite music and setting the temperature to their preference are trivial when compared with what is possible today.

One problem; Only hobbyist and the manufacturers for luxury markets have expertise to bring all this together at the moment. The standards needed to help foster smart market growth don’t exist yet, but that’s truly an over-simplification of the complex barriers the so-called “Internet of Things” industry is trying to solve. 

Today, consumers exploring smart home products in their local Best Buy, Home Depot, Lowes or on Amazon are presented with a confusing range of devices that often do not play well together, if at all. Strangely, industry members are addressing this issue by creating consortiums, formed of members holding patents for opposing connected-device communications technologies. At first glance, someone looking to make their home “smart” may not realize they need to choose a team.

Let's say you shell out $249 for a WiFi connected Nest thermostat. Not only is it great for family members with Android phones, it works with iPhones and a host of other products, all thanks to the “Works with Nest” developer program. Great! Now the iPhone users in the house may have also heard about Apple’s HomeKit project, where Apple will attempt to work with several companies to bring this fractured industry of smart home startups and established manufacturers together. 

Works with Nest right? NO

With Google having purchased Nest in 2014, it is of no surprise they are not invited to hang with HomeKit. So if you want to crash this house party, you're going to need to bring someone who knows and gets along with both of them.

Enter the “Hub”

A hub is a box that connects to your WiFi network and bridges the gap between the various technologies. Increasingly, it also connects to the cloud so you can more securely access your smart hub from anywhere. To date there is only one company capable of merging Apple’s vision of the smart home with Google. At the 2015 Consumer Electronics Show, Insteon, a 10 year veteran in the smart home industry announced their $149 Hub Pro that supports Apple HomeKit. Since the current Insteon Hub already supports control of the Nest Learning Thermostat, it's a reasonable assumption that the Apple HomeKit version will too, however Insteon declined to comment on the capabilities of their yet to be released Hub Pro, beyond the official press release.

With the soon to be available Apple Watch, Apple also has a new
tool that adds interesting possibilities for owners of HomeKit compatible iOS devices and a HomeKit compatible Insteon Pro Hub.  From your wrist, you could use voice activation, geo-fencing location services, and touch control to interact with your smart home from a single, secure interface. This could potentially simplify and secure two-way interaction with door locks, lights, thermostats, gate and garage openers, cameras, sensors and alarm systems from anywhere in the world.

Apple is not the only company trying to bridge the divide. Samsung also purchased smart home startup SmartThings, a hub manufacture that tries to bridge several communication types. Staples, though a partnership with D-Link, has the Connect hub which, similar to SmartThings, connects multiple device types. Google also purchased the intellectual property from startup Revolv under the Nest brand, which until they closed down operations, had one of the most intriguing hubs around, promising control of multiple vendor smart devices with no less than eight different communications types from a single box.

Security

Unfortunately, when technology is built as quickly as possible, for the lowest price possible, security is not at the forefront. Good security is hard to get right, and many vendors try to patch it in after the fact. According to sources, security has been a cornerstone of Apple HomeKit from the start, which is good news if you’re an iOS user. Devices compatible with Apple HomeKit require special silicon chips to make them compliant with Apple's security requirements. But what if you have an Android phone, is the secure smart home possible? Turns out there’s both good news and no news.

Next time I’ll go into more detail about the security issues, the current progress, what’s still missing and steps you should take to protect your privacy as the Internet of Everything starts to enter your home.

Interested in joining the discussion? Leave me a comment or send me a tweet @dougkrug. I'd love to hear your perspective about what you think this smart future should look like.
Tweet
Share
Share
No comments
Had a great time presenting "Computer Security at Home and Online" seminar to a sold-out crowd for Ontario Association of Social Workers!

If you missed the event, we discussed -
• How to mitigate the risk if you can't switch from Windows XP before the April 8, 2014 deadline
• Myths and recommendations surrounding secure passwords
• Secure password management - i.e. LastPass and 1Password
• Tips on WiFi security
• Cryptography basics and what you really need to know now
• How to easily encrypt your files before upload to cloud providers
• Guarding against Social Engineering attacks
• Smartphone and tablet security recommendations
A PDF of the presentation is available from this secure link

Please leave me a comment or send me a tweet - I'd love to hear from you and help you with your security questions and concerns.


Image courtesy of ddpavumba/FreeDigitalPhotos.net
Tweet
Share
Share
No comments
Strong passwords are critical to preventing identity theft, loss of assets and damage to personal privacy. Almost a year ago, I wrote about how our online security is under attack. Things have gotten worse since then and we're currently losing the battle, in part due to weak passwords or duplication on multiple websites. One site gets hacked and the gates are open everywhere.

Don't think for even a second that because you used your kid's name and a few numbers, you've somehow fooled the bad guys or made it difficult, because you haven't. Just as dangerous is the use of the same passwords everywhere, making them all rememberable or writing all of them down on paper; Big mistakes in our complex online world.

Read my latest post on Solo Traveler and learn a simple, free and very secure method for endless strong passwords, automatically generated and stored for you.

Trusted by security experts who really understand cryptography and how to safeguard your privacy, these solutions are a must-have. Don't make identity theft easy for the ever increasing number of attackers out there. Take this simple step and protect yourself!
Tweet
Share
Share
No comments
Advances in solid state memory read/write speed and lower manufacturing costs are making Solid State Drives attractive options in new computers. Not to mention that your smartphone, tablet, and USB flash drives all use this technology.

One problem - 

Flash memory cannot actually be erased

A study by researchers at University of California San Diego revealed that between 4% to 75% of a files contents remain completely intact when an attempt is made to erase flash memory. USB flash drives fared worse, were researchers could recover between 0.57% to 84.9% percent of file contents remaining on a USB flash drive after an overwrite attempt was made.

Testing 12 Solid State Drives, UCSD researchers found that none of the available software techniques for erasing individual files proved effective. Erasing entire SSDs with native sanitize commands was most effective, but only when performed correctly. The software techniques were found to work most, but not all of the time. Of the twelve solid state drives they tested using the native "Erase Unit" command, only four were actually erased. One SSD had reported itself to be sanitized, yet the data was recoverable by the researchers.

Additionally, the methods used by the researchers to determine if the data has been truly wiped from flash memory is not available to the average consumer. Without a way for consumers to verify data has actually been completely removed from flash memory, there is no way to know if so called "data sanitation" is truly effective.

The key issues stem from the way that flash memory differs vs a conventional magnetic hard drive. Flash memory works by pushing electrons from one side to another of a barrier. This change of position is monitored and registered as either a 1 or 0, the binary code that is the basis of all modern computing.

Problem is, this pushing of electrons back and forth, causes the material to fatigue rapidly. To combat this, solid state memory manufactures use a method called "Wear Leveling". This moves data around so read/write is not constantly occurring in the same physical spot on the memory.

Wear Leveling creates a security issue

Flash memory doesn't actually erase data at the time new data is written, it just marks it for deletion. Then comes Wear Leveling, duplicating chunks of data and moving it around between the time it's first written and then overwritten. Data marked for deletion is duplicated and moved by wear leveling and the so called "garbage collection" algorithm that was supposed to go back later and erase data marked for deletion, knows nothing about the data that was duplicated by wear leveling.

Since mobile smartphones, tablets and computers with solid state memory are purchased, sold and discarded at an ever increasing rate, it's important going forward that you are aware that your personal information and data cannot simply be permanently "sanitized" from these devices and could be recovered at a later time by someone who should not have it.

One workaround that researchers suggest for manufacturers to employ is called "Crypto-Erasure". But this method requires that the data is encrypted at the time it's first written. The idea is to encrypt all data on the device, so even if it can be recovered later, it will be useless to anyone who does not have the encryption key to access it. For the majority of devices, this is not the case and unsecured data has already been written to flash memory. This means any data already written to the device cannot necessarily ever be made secure.

Why not just use degaussing to erase flash memory?

Degaussing is a method used to render conventional magnetic media unreadable by exposing it to a very powerful magnetic field. For magnetic media, it is very effective, but flash memory is not affected by magnetic fields. In their research document, the method was evaluated and found to be completely ineffective on flash memory.

So what's the answer? How do you protect yourself?

Anyone with a Windows desktop or laptop can use TruCrypt or PGPDisk to protect their data on an SSD or USB flash drive. Mac users can take advantage of the built in FileVault function found in the Security & Privacy settings. Using these methods, the data will be useless without the encryption key, leaving the device or storage media to be erased and securely re-written to again.

For smartphones and tablets, end user privacy and security is largely in the hands of the manufacturer. While some data could be encrypted before storing on the device, native applications on the phone like note pad, address book, etc would not necessarily encrypt the data and protect your privacy when the device is end of life, and no longer in your possession.

Thankfully there are highly affordable, secure solutions such as LastPass and 1Password that can store your passwords, notes, credit card and other personal information securely so they cannot be accessed without a secure master password.

Hopefully these issues will come to the forefront of mainstream media, forcing all manufactures to provide verifiable encryption on all devices that use flash memory, which for now will increasingly be the storage media of choice until the day when data storage using nanostructures, in so called "Superman Memory Crystals" makes the leap from laboratory to commercially viable and affordable.

With all the news over the NSA's intrusion into privacy, the latest poll shows that 50% of users don't care. Where do you stand on the subject?

Do you care if your personal data can be retrieved after you no longer own a device or storage disk?

Please leave me a comment or send me a Tweet @dougkrug


Image courtesy of thanunkorn/Freedigitalphotos.net






Tweet
Share
Share
No comments

Curious about what this so called "Cloud" this is and what it means to you in the future?


Explore Cloud 101 - The ever changing cloud, your privacy and security on boomerbizbuilder.com in Trudy's latest news letter written by your's truly.
Tweet
Share
Share
No comments
Older Posts

About Us

“douglas

Integrity is a specialty.

Your satisfaction is our passion.

Follow Us

  • Twitter
  • Linkedin
  • Google+

Completely Simple Guides

 Available on Amazon


AVAILABLE ON Amazon

recent posts

Previous Posts

  • ▼  2017 (3)
    • ▼  October (1)
      • Your KRACK is showing!
    • ►  May (1)
    • ►  March (1)
  • ►  2016 (2)
    • ►  February (1)
    • ►  January (1)
  • ►  2015 (2)
    • ►  March (1)
    • ►  January (1)
  • ►  2014 (3)
    • ►  August (1)
    • ►  April (1)
    • ►  February (1)
  • ►  2013 (10)
    • ►  November (1)
    • ►  September (3)
    • ►  July (3)
    • ►  June (1)
    • ►  May (2)
HOME

© iHelp Innovate 2017 - All Rights Reserved