“Smart used to be a word that described intelligence and quick mental capabilities. Now, it’s used to describe things that wouldn’t have existed without that very same smartness”
We live in a world where we love to slap the word “smart” in front of everyday household items. We have smart thermostats, smart doorbells, smart locks, smart speakers, and even smart refrigerators (WHY?).
In fact, if you look up the definition of smart, you may be met with the “Technical Definition” that specifically refers to a smart device: “Using a built-in microprocessor for automatic operation, for processing of data, or for achieving greater versatility“
However, as a cyber embedded software engineer, I feel obligated to let you in on a little secret: when it comes to cybersecurity, chances are there is absolutely nothing “smart” about these devices. In fact, they are often the greatest vulnerability sitting inside your home right now.
The Internet of (Vulnerable) Things
A few years ago, I recorded a video breaking down the reality of the Internet of Things (IoT) and how the push for “Smart Cities” is rushing us toward a security nightmare.
(Check out the video! -> Smart Cities Are Coming Sooner Than We Think)
In the video, I defined IoT as follows: A massive network of devices with embedded processors and sensors that communicate with the internet, and each other, without requiring human interaction. Once you complete the initial configuration, they’re designed to run with little to no assistance.
I know I sound like a broken record at this point, but again, that convenience is where the danger lies.
The “Watch Dogs” Reality
To avoid the same mistakes in the future, we must often times look to the past.
Even if that past happens to be a video game that was released in 2014. Humor me for a bit.
If you’re a gamer, you might remember the game of Watch Dogs, where the entire city of Chicago was connected to a central operating system [08:18]. The main character hacks into this system and essentially gains access to multiple backdoors that allows him to control traffic lights, pipelines and various infrastructure throughout the city.
It sounds like a far-fetched sci-fi plot (well at least back in 2014, but in 2026? not so much), but the underlying concept is alarmingly real. When you connect physical hardware to the internet, you introduce remote vulnerabilities to physical spaces that otherwise wouldn’t have existed.
Now I asked for you to bear with me through the video game example, because in that video I also mentioned a terrifying, real-world example of hackers compromising baby monitors connected to home networks and screaming at the infant sleeping in the room [10:06] [https://www.nbcnews.com/tech/security/man-hacks-monitor-screams-baby-girl-n91546].
Now consider the rest of the smart devices in your home. Imagine sitting inside on a warm day, and all of a sudden, your smart thermostat gets breached and they’re cranking it up to 90 degrees in your home. When you take into account the consumers bill it would take cooling your house back down, and any damage to your furnace, that’s easily hundreds of dollars, maybe upwards of four figures. Or, what happens when that same lack of security is applied to say smart locks on your front door?
What Actually Makes Them So Insecure?
I realize up to this point I’ve discussed what types of breaches that can happen, but not why they’re likely to. Thus, naturally, you may now be wondering why these tech companies can’t secure something as simple as a doorbell. The answer unfortunately comes down to manufacturing priorities.
When a company builds a generic, off brand smart camera, their goal is to get it to market as quickly and cheaply as possible. They aren’t thinking about long-term firmware integrity or patching a zero-day vulnerability. They’re more concerned with being able to produce a product that can be created cheaply and sold at a profitable margin.
As a result, devices get shipped with outdated software, hardcoded default passwords (we already know how big of a no-no those are), and generally no real way for the user to easily update the security protocols. In fact, a lot of smart devices on the market probably reach their end of support dates only after a few years, which means the company isn’t even looking to secure the device once it reaches the markets. If there was no long-term security support plan in the development of the device, chances are there wasn’t a short term one either.
Alas, security, if at all a thought, is nothihng but an afterthought.
But Joseph! I Love My Smart Device!
Okay listen, I understand its 2026 and as I stated before we’ve created such a technological ecosystem that it may be hard to try and strip everything down to a “dumb” version. It would be TOTALLY worth it, I mean seriously why do you need a smart refrigerator? I even saw a smart toaster for crying out loud. Not everything needs to be connected to the internet guys. Please. Stop.
I said it in my video three years ago, and it remains true today: nothing is ever truly 100% secure. But there is a way to drastically reduce your attack surface, and that’s by treating these smart devices with the skepticism they deserve.
If you are (still) going to use IoT devices in your home or your business, you need to isolate them.
- The Guest Network: Never put your smart TV, doorbell, or thermostat on the same Wi-Fi network as your personal laptop or your company’s work servers. Create a dedicated “Guest” or even “IoT” network on your router. If your smart fridge gets compromised, you want to ensure the attacker is trapped on a network with no access to your sensitive data.
- This is probably by far the best thing you can do if you insist on keeping your devices connected to the internet. If an attacker does get access to one of these devices, make sure the only thing they can do is ring your doorbell at will.
- Change the Defaults: If the device allows you to change the password, do it immediately.
- Question the Connection: Ask yourself: Does my toaster actually need to be connected to the internet? If the answer is no, leave it offline.
- And trust me, 9/10 for all of these devices, the asnwer will be no.
Since when did we start blindly trusting hardware just because it has a touchscreen? If anything, we should be raising our eyebrows at least a little bit. Trust me on this one: The smartest thing you can do with a smart device, is assume it’s already been compromised.
