Smart home for dummies. Not everyone needs a smart home

Threats to the development of the "Internet of Things" and modern approaches to cybersecurity were discussed in Moscow

On May 23-24, Moscow hosted a key cybersecurity event - Positive Hack Days, organized by Positive Tecnologies. It was attended by about 5 thousand experts who discussed the main trends and problems of data protection. This year, analysts call the development of IoT - the "Internet of Things" one of the main problems. The correspondent of Realnoe Vremya also attended the event.

Analysts predict that by 2025, smart devices will become the main “users” of the World Wide Web. For example, smart TVs and multicooker with Wi-Fi control, surveillance cameras and “smart home” elements. Positive Technologies experts have compiled the top 5 most dangerous devices for the user with access to the Internet.

First of all, this is the heart of the entire home network - a Wi-Fi or 3G-4G router. Experts find up to 10 vulnerabilities in these devices every month. The developers, in turn, are in no hurry to eliminate them - in the pursuit of cheap devices, the firmware of the router may not be updated, and manufacturers save on testing and security.

True, the user remains the most vulnerable element of the router. As Positive Technologies experts found out, out of 100 devices, 15 passwords have never been changed from the factory ones. This means that anyone can get into his "brain" and program him for any action.

Analysts predict that by 2025 the main "users" of the world wide web will not be people, but smart devices

CCTV cameras are no less vulnerable. These devices pose a greater threat to business: about 90% of those used by small and medium-sized enterprises have critical vulnerabilities. A hacker can spy on the office through CCTV cameras with little or no effort.

Navigation and wireless control have also proven to be good targets for hackers. To demonstrate this, Positive Technologies experts decided to play magicians - they translated watches on cell phones right in the pockets of viewers and set fake GPS coordinates, confusing phone navigation. And if now the failure of the navigator, by and large, only threatens unmanned aerial vehicles, then on unmanned vehicles a hacker can do a lot of misfortunes. Resetting the time and date in turn invalidates site security certificates, opening the door for cyberattacks.

Continuing the trick, security experts intercepted the wireless keyboard signal. At one time, hackers used keylogging programs that recorded all keystrokes and sent them to the owner. With the development of wireless keyboards, this can be done by an operator sitting at a distance of up to several hundred meters. And the low cost of equipment - about 300 rubles - threatens massive espionage.

“Generals are always preparing for the previous war. Internet things are just a consequence of the problem. The main problem is the technological debt accumulated by IT companies. The first victim of the price race is safety, and in an attempt to create a competitive price, companies sacrifice it, ”says Artem Gavrichenkov, chief engineer of QRator Labs.

Artem Gavrichenkov: “Generals are always preparing for the previous war. Internet things are just a consequence of the problem. The main problem is technological debt accumulated by IT companies "

Experts suggest patching the hole in the security perimeter starting from the head. No measures will save the user who will not change the router password himself and will open suspicious links. Also, experts say, the state should develop certification standards for devices on the market, which would include the requirements for the required level of protection.

WannaCry: how many times have the world been told

Alexey Novikov, head of the cybercrime investigation department of Positive Technologies, made a presentation with this title. WannaCry ransomware is just one of hundreds of such programs known to mankind. A virus that encrypts data or places permanent banners on the screen and demands money for “curing” a computer is almost the same age as the Internet.

WannaCry became known only due to its wide geography and the scale of the attack. Interestingly, the beneficiaries of the program did not even write it, but simply found it on the Internet and made a "seeding". The vulnerability exploited by the virus was known back in March. The distribution includes those users who do not properly update their computers.

“Basically, the initial propagation vector using a vulnerable port at the perimeter is a very simple, very easy path. Nothing prevented the attacker from complicating the exploit and ... infecting even those organizations whose perimeter was protected, ”noted Alexey Novikov.

Alexey Novikov: “To be honest, I doubt that an attacker will cash out this money. It seems to me that the goal was not money, otherwise he would have come up with a more sophisticated delivery and receipt mechanism. "

For the same reason, the expert doubts that the purpose of distributing the ransomware was money. Answering the question whether it would be difficult to cash out the funds received by the hacker, Alexey Novikov suggested that, oddly enough, hardly anyone would do this:

“To be honest, I doubt that an attacker will cash out this money. It seems to me that the goal was not money, otherwise he would have come up with a more sophisticated delivery and receipt mechanism. Earlier, we saw precedents when attackers exploited this vulnerability, but their activity was limited to using the computing power of servers. The cybercriminals earned much more from this than from WannaCry and even withdrawn money. In principle, this can be monetized, but in the case of WannaCry, "I doubt it," concluded the speaker.

During the forum, the thesis "No patch from human oversight" was repeatedly sounded. Acronis, which offers users cloud-based solutions for data protection, took on the denial. Their essence is that the company's product periodically makes backups, with the help of which you can restore data on your computer and smartphone until the moment of infection, up to icons on the desktop. In addition, the program has a built-in function that detects RansomWare at the time of infection and blocks its spread.

“The WannaCry infection statistics itself showed that companies are rather negligent about software updates. The patch was urgently released back in March, quite a long time has passed since March. Those companies suffered that did not have time or did not want to update for some reason ... The main problem is precisely in the way of thinking, in responding to news, leaks, trends, in organizing the work of internal IT services and information security services, ”the department manager is convinced standardization and risk management at Acronis Yulia Omelyanenko.

Yulia Omelyanenko: "The statistics of WannaCry infection in itself showed that companies are rather negligent about software updates"

In general, experts call social engineering one of the main tools for distributing malicious software. This is the use of standard patterns of human behavior, with the help of which attackers convince a user to voluntarily download malware onto their computer. How many times in the last month have you received letters where a non-existent grandmother left you an inheritance of a million dollars, which you can get by clicking on the link? Or they tried to download a book “for free, without registration and SMS” from a suspicious site. And an SMS with a proposal to see your photos using a suspicious link?

You can fight social engineering by increasing the technical literacy of employees, Yulia Omelyanenko is sure:

A person who is less tech-savvy and will be the target of attacks.

Stalingrad-online

While the speakers talked about cybersecurity, a real battle for the city was going on in a separate room between representatives of the hacker elite and the IT security services. The hackers were given a cardboard-plastic settlement with hundreds of virtual residents, transport, factories, traffic lights, a shopping center, a thermal power station, banks and a railroad for looting. The city was governed by the same systems that can be found in a metropolis, the layout was needed only for clarity.

The goal of the hackers was to make as much play money as possible. For example, one of the teams intercepted the mayor's SMS containing incriminating evidence, which earned 150 thousand "publis". The Hack.ERS team was able to steal money from SIP telephony users: by hacking accounts, hackers received money using paid calls to short numbers.

A cardboard-plastic settlement with hundreds of virtual residents, transport, factories, traffic lights, a shopping center, a thermal power plant, banks and a railway was given to hackers for looting

The "intruders" managed to stop the thermal power plant and the oil refinery - by hacking into the corporate network, the hackers revealed the controllers used by the organization and were able to stop the work of the enterprises. This is due to the "oversight" of the administrators of the organizations, which was discussed at the IoT meeting: the Wi-Fi router was protected by a default password that was not removed by the administrators. The vulnerability, which would have taken a sysadmin a minute to fix, knocked out the entire industrial complex of the city. The hackers turned off the power supply to the CHP, which stopped supplying steam to the oil refinery, which made him stand up.

Under cover of night, the hackers committed a grandiose theft: almost 4 million "publis" were stolen from the bank. To do this, they previously stole user data, which made it possible to hack the remote banking system. Another team of hackers took advantage of the compromised data of bank cards, removing 10 "publics" from each. In reality, such an attack would go unnoticed, but would bring the cybercriminals income. A large theft led to an economic crisis, forcing the organizers of the competition to conduct an additional issue of "public".

The organizers of PHDays made the reservation that the city model is an ideal system for hackers. In reality, attackers have fewer resources, and security specialists have more options. However, even such a model is enough to make it clear that a modern hacker can do a lot of trouble by hacking into the banking system, de-energizing an entire city, or creating chaos in transport.

A new threat is posed by the "Internet of Things", when the "smart home" can turn against its owner. Take a look around - perhaps your refrigerator and coffee maker are already plotting against you?

In the first quarter of this year, our company marks a 30% growth in demand for its products, and most market players, including distributors and system integrators, predict that over the next five years the Russian systems market will grow at an average rate of 25% per year.

Who needs a smart home?

The growing interest of Russians in smart home is obvious, but not everyone understands what it is. Half of the customers who come to us need an explanation of exactly how automation technology can solve their daily problems. They have a need to manage housing, to optimize their life, but they still have no idea how this can be done.

As part of a smart home, they see an intercom with video surveillance and a security and fire system, but this, of course, is not the case. These are just scattered engineering elements, and a smart home is the connection of all subsystems, centralized control of lighting and air conditioning, heating, access control, video surveillance, gas leakage and water leakage control, automatic watering and curtains control. And all this is done using a smartphone. The number of subsystems that can be included in a smart home is practically unlimited.

This complexity of modern housing creates the need for a smart home. There are too many electronics and daily processes around us that need to be rationally built, connected with each other, and controlled.

Smart home is a natural stage of progress, evolution of housing, it is a direct consequence of all technical innovations that surround us in modern houses and apartments.

Let's imagine a large country house in which a family lives with children, there are 7-10 rooms in it. When going to sleep, you need to make sure that the lights and air conditioners are turned off everywhere - can you imagine how much energy will be wasted if this is not done? This is where smart home scenarios come in handy - automatic timed shutdown, for example. And there is no need to walk around the house and turn off everything manually. Or the “everyone is gone” function: the owners leave the house and all electrical appliances are safely turned off.

That is, the larger the area of \u200b\u200bhousing, the more systems inside it, the more obvious the advantages of a smart home. And another important argument is economy. On average, "smart" systems reduce the cost of energy consumption by 20-30%, and the experience of our projects says that a smart home begins to "work" in full force on an area of \u200b\u200b100 square meters or more.

Professional equipment for a smart home lives for about 10 years, and then requires replacement due to obsolescence. The average cost of equipment is one thousand rubles per square meter. In a house or apartment with an area of \u200b\u200b100 square meters, a smart home will cost from 100 thousand rubles. And now you can imagine how much on average it will pay for itself, saving 20-30% of the cost of heat and energy resources monthly. According to our calculations, the full payback period for a smart home on such an area is from 3 to 5 years.

Who doesn't need it?

Most likely, you don't need a smart home if:

  • You have a small apartment with a small number of functional areas (one bathroom, one kitchen, and so on).
  • All switches are within walking distance, it is not difficult for you to monitor the consumption of energy resources: turn off the lights and turn off electrical appliances yourself.
  • You do not need to provide remote access to the apartment for children, relatives, workers.

Not a very smart home

Most Russians live in small apartments, so the value of a smart home is not obvious to them. Recently this has been actively used by suppliers of "kits in a box". They are sold at retail by telecom operators, Russian startups and Chinese electronics manufacturers.

"Kits in a box" are simple devices for controlling individual functions in an apartment: temperature, turning on / off a light bulb, turning off water, and so on. The owner of the house sends sms or activates the function in the app, and the radio signal transmits a message to the device.

We call such kits "smart home probe": they solve individual problems in apartments and, in general, can simplify specific household processes. You can install these kits by yourself, you do not need professional engineers for this. Those who buy them have no real need for a smart home. And the owners of large houses and apartments will never buy "kits in a box", because "probes" cannot solve complex problems of a smart home.

Smart home market in Russia

The Russian smart home market looks like this. According to our calculations, approximately 50% are suppliers of foreign brands (USA, Germany, Austria). In most cases, their equipment complies with the KNX or EIB / KNX standard. This is high quality but expensive equipment for the premium segment of real estate.

20% of the market is occupied by Russian brands, some of which, in our opinion, are only disguised as independent manufacturers and developers. In fact, their equipment is taken from an assortment of various Chinese manufacturers and passed off as their own.

Only a few are engaged in the real development and production of complex integrated systems "smart home" in Russia. It is quite easy to distinguish real manufacturers by the presence of patents and development departments.

The remaining 30% are the same "kits in a box", inexpensive, uncomplicated and with a service life of 1-2 years.

The cost of Russian smart home technologies is several times different from the cost of foreign equipment, they are much cheaper. The cost of Russian equipment does not include excise taxes and import duties, transportation, markups of several wholesalers, foreign development costs, salaries of foreign engineers - and they are quite high, it is worth admitting this. This explains the difference in value, which, judging by the latest fluctuations in the ruble exchange rate, will only increase.

Residential real estate will "grow wiser"

A typical smart home buyer is a man over 30, usually working in IT, or in some other way connected with this area. He has a higher technical education and hence the habit of trusting modern technologies, integrating them into his life.

The Russian guild of realtors has recently published a study of the market for new buildings. They note that the share of comfort-class housing is growing throughout Russia, and projects for the integrated development of territories - the construction of economy housing on the outskirts of cities -, on the contrary, are being phased out. With this factor, we can associate the further growth of demand for smart home technologies.

Higher-end homeowners are more interested in centralizing the management of all life support systems in their apartment.

It is also important that developers have "matured" to a smart home. Many of them are ready to integrate basic versions of “smart” systems into apartment buildings under construction: automated lighting groups, access control, automatic data collection from meters, heating control, water leakage control, security and fire alarms.

Such "smart" filling of apartments allows developers to stand out from competitors, increase their status by working with innovative technologies and stimulate the stagnating real estate market.

What "smart House"? They repeat about him at every step, but only a few saw him. Accessory manufacturers aggressively use this label, and we, ordinary consumers, dutifully "peck" at it. Editorial staff website decided to clearly distinguish between two technology segments, deriving from there two completely different trends. Stop being deceived!

Recently, we began to actively follow the topic of the "smart home" and receive requests for device reviews that are often attributed to it. In this regard, we decided to prepare a small but capacious article on this topic.

What is "smart home" and why it is not yet available

Let's close our eyes for a moment and say this old marketer's overused phrase. "Smart House"! What do you imagine at this moment? Ten or fifteen years ago, you would have remembered a futuristic movie: where the windows shut off by themselves, where the light and climate are supported by an autonomous system with artificial intelligence, where coffee is prepared in the morning in advance without your participation, and so on.

This is the “smart home”. Today he is not at all futuristic - but real one hundred percent. But it won't appear on its own. You should initially think over such a project at the stage of laying the foundation of your future home. Or do it in an apartment before a major overhaul. You will also need a very significant amount of money, because such solutions require the involvement of professionals, the installation and deployment of specific equipment.

In short, a "smart home" is when everything is cool and beautiful, like in a movie, but for big money and a lot of time. In the next five years, little will change in terms of time and money in Russia. While the real "smart home" is just trying to break through to the masses, marketers of all stripes are building effective advertising campaigns on this immense word. As a result, the consumer himself sits and does not understand anything.

Thanks to the efforts of the media, in the minds of modern geeks, a smart home is a light bulb Philips HUE, sockets with Wi-Fi module, weather sensors Netatmo, sensor sets Lapka and so on. But in reality, these are devices of a completely different format, keeping up with the trend called "Internet of Things" IoT.

What is IoT and why is it trending now?

IN IoT includes a special class of purely consumer devices, which by themselves cannot become the basis of a "smart home", but profess similar ideas. The very phrase "Internet of Things" implies two key elements of this trend: ordinary objects that can connect to the Web. In an ideal world, these items should also exchange data with each other.

Roughly speaking, IoT Is a coffee maker that has an iPhone application and prepares coffee at the same time as the alarm goes off. IoT is a set of bulbs Philips HUEthat change the color and brightness of light at the request of the owner. This is the same set of sensors Lapkameasuring the ecological situation around. And many, many other existing and future gadgets that connect to our iPhones - for the sake of displaying data or controlling functions.

It becomes necessary to separate “smart objects” of the IoT format and “smart home” for a simple reason. The largest companies in the world in the coming years will be furiously researching and releasing products that meet exactly the challenges of the IoT. Advances in technology have made smart refrigerators and Wi-Fi toasters a reality. Each of them is interesting in a vacuum of its possibilities, but their installation in the house will never make the latter truly "smart".

This is the difference. You can buy a basket of smart accessories, but none of them - whether together or separately - will be part of a true smart home.

What a smart home really looks like

First of all, a “smart home” is not a set of “smart bulbs”, but a central “brain” that monitors and controls all communications in an apartment, climate and electricity. The key element of a real "smart home" that everyone dreams of is its software and technical platform... It is this "base" that connects at the lowest level to your pipes, electrical panel and heating system in order to control it.

There are many such low-level control systems. For example, there are promising software solutions - for example, the environment Apple HomeKit, which in the long term will unite all "smart coffee makers" into a single and truly efficient network that exchanges data with each other. But without a central control system, these conversations won't get beyond meaningless marketing.

Control systems for "smart homes" are not nearly as much publicized as "sockets" and "light bulbs", but they have existed, flourished and developed for many decades. Many of them are very expensive, as they include fine-tuning software and specific computer components, plus various sensors, communication equipment and much more.

Lost in thought, the editors website I tried to look for such companies in Russia that offer really working systems for creating a “smart home”. We were especially interested in those who approach the issue from a purely Russian, impenetrable side. So that you can deliver easily, quickly and forever. And preferably for a penny.

A primordially Russian "smart home"

The company responded to our request Ektostroyoffering a special solution for our country: "Smart home" in Russian, impenetrable and adapted to our harsh realities. Their system does not depend on the availability of electricity in the house. She doesn't need internet. It works with the highest reliability and does not require further investment, and is able to make life easier and prevent a local man-made disaster.

: behind the temperature in pipes, behind boilers, behind the supply of electricity, behind heating devices and much more. And not only tracking, but also management... The entire system operates via a GSM network, does not require any form of Internet and processes commands via SMS messages.

Example. You are sitting at work, 50 kilometers from your country house. We haven't been there for two months. What if he was robbed? What if he had a problem with the heating system? Suddenly the electricity was turned off, and you are going to go there tomorrow with guests? The idea behind Ectocontrol is to notify user immediately about the situations described above. This is what allows a person to take the necessary measures on time: arrive on time and eliminate the problem before it causes critical consequences.

Or another example. You are going to the dacha. Even when you leave the house, you send a technical message to your Ectocontrol station, which starts the heating system in the house. Come to warmth and comfort. We rested, went out, closed the gate - sent a message about turning off the system or working at a low temperature. The pipes remain warm, the house does not freeze through to the end, and you always know what the temperature is in it.

Ektostroy and his team attracted us with their enthusiasm and the fact that their product differs from the existing ones on the market in a number of interesting, sometimes unique qualities. Instead of briefly describing the capabilities of the system, we decided to go further - and go to the filming of the installation process of the Ectocontrol system.

In the coming days, we will tell you how one of the most promising systems of the Russian "smart home" works. Until then, don't be fooled. "Smart home" may end with a "smart lamp", but it does not start with it;)

A free retelling of the humorous work of Mat Honan, published by him in the American magazine Wired, in which he humorously recreates a picture of the life of a "happy" owner of a Smart Home. And if you believe the forecasts of scientists and analysts, then in five or ten years every wealthy consumer will have such a house. According to Honan, such a life cannot be called especially joyful and calm.

The author of the story offers the reader a scenario of an ordinary day in a smart mansion. It begins with the fact that a resident of a "smart" house wakes up early in the morning, hearing the sounds made by pillows, which play invigorating rhythms and wink with built-in light and music. The alarm clock also starts playing something of its own at this time, which does not quite coincide on the theme with the pieces performed by the pillows. It is with this cacophony of sounds that a new day begins for the protagonist.

The owner of the house already half asleep begins to suspect that it is possible that the attackers have installed a malware virus in the control program to ensure the operation of the smart home. And all this is due to the fact that he did not install the appropriate patch, which has not yet been released. As a result, the entire street on which the smart homes of its neighbors are located plays the most incomprehensible music and flashes with all the colors of the rainbow. It is good that the owner of the house managed to add some of his musical compositions to the “black list” of the Pandora service.

True, it turned out that the virus began to take photographs when the owner leaves the shower room, and began to post them on Facebook. Although this is just a trifle compared to other deviations in the functioning of the "smart" home, which have already appeared before. So, in 2022, some virus turned off water all over the street in all smart houses just for Christmas and at the same time turned on all irrigation systems at the same time - it really was sad, although the creator of the malware obviously planned to amuse everyone with this.

After waking up so early with pillows and alarm clocks, the resident of the "smart" home decides to make himself coffee and goes to the kitchen. He had to make coffee the old fashioned way, since the smart coffee maker had to be turned off a long time ago. Some failures began in her, she began to periodically go online to participate in DDOS attacks on a game server located in Singapore. And all due to the fact that a virus got into the operating system of the house, thanks to which now smart housing is sometimes used by unknown hackers as a botnet.

In 2020, the home owner installed a home operating system compatible with Android, as various interesting applications and accessories were sold for it at that time, and the design itself was the best in its segment. But then it turned out that the new corporate smartphone is incompatible with the current operating system for the home. Now you have to constantly carry around a tablet from Google, which is not currently supported by new firmware and software. And then the doors themselves began to open whenever they wanted, so the owner began to think about inserting a regular English lock instead of a smart key.

It also found that many of these devices in the Nexus Home system use patented proprietary connectors, as well as chargers, and this is also not very convenient. And recently, for some reason, drones from Amazon stopped parking correctly and, as a result, broke a clothes dryer.

When it all started with a simple Nest thermostat and automatic climate control, it seemed to many that the future was bright and cloudless. Each company produced a gadget for managing smart apartments or mansions, striving to surpass everyone else in this. True, it turned out that everything was determined by the company that first began to control the "smart" home.

Then, to manage and ensure compatibility, they also released the SmartWall infrastructure, connecting to it all the sockets and climate control, refrigerator control systems, watering flowers, and counting dishes. And also various biosensors, filtration systems, stereos, drug control, car parking, exercise equipment. There are many other things - you can't remember everything. And who then thought that the new agreement between Samsung and Microsoft would lead to unpredictable consequences in ten years?

«좋은 아침 입니», - welcomes the host in korean electric ovenwhile he warms up his dinner on an induction cooker, and the owner sleepily mutters "조용히" back to her.

Over the past ten years, a number of devices have failed (it turned out that things tend to break even in a smart home), and now the house is served by a strange company of devices on different operating systems. It is not possible to achieve normal work, but what to do is to adapt: \u200b\u200bafter all, reinstalling all the software, and even changing most of the gadgets is too expensive.

On the way from the kitchen in the direction of the room, the house suddenly "pleases" the owner with flashes of LED-indicators and greets with an exclamation: "Congratulations, you have completed the daily norm of steps." Recently, the house so often began to remind of this rate of distance traveled that it had to be set at twenty steps a day, so as not to listen to constant reminders from the sofa, chair and TV about the need to jog or walk, even in the middle of the night, to ensure the required rate, which guarantees good health and long life.

With a cup of coffee, the sleepy owner of the smart home sits down at the table. He turns on the stereo projector, reads the news. There is nothing interesting in them, and out of boredom he leafs through the heading of advertisements for the sale of houses that cannot be renewed. They don't even have a simple electric car charger, no smart tech inside. But a person, while drinking coffee, continues to dream of buying some completely senseless and completely "unreasonable" house.

Day is breaking. The automatic blinds open themselves. The smart toaster and shower in the bathroom turn on by itself, welcoming the owner. A new morning is coming in the smart home on the smart street.