Skip to Content

Smart Lightbulbs Could Plunge the Internet Into Darkness

A new study shows how connected devices could be hijacked to perform ferocious digital attacks.
November 3, 2016

Commandeering Internet-connected devices is an increasingly popular pastime for hackers. Now researchers have shown that it’s not just aged devices that can be corralled by criminals.

A new study shows that it is possible to remotely hack modern smart-home hardware. The technique, demonstrated on Philips Hue smart lamps, injects a software worm that allows the researchers to control the device.

The compromised hardware uses a low-power wireless system called ZigBee to create its own networks. The researchers say that it’s possible for the worm to propagate from one device to another via these connections, causing it to “catastrophically spread everywhere within minutes,” in a kind of chain reaction.

The researchers explain that the approach can be used to turn devices “on or off, permanently brick them, or exploit them in a massive DDoS [distributed denial of service] attack.” To demonstrate the hack, the team flew a drone alongside a building and controlled a series of smart bulbs remotely.

These flickering lights are being controlled by a drone flying alongside the building.

It’s a discomforting view of the future. If enough devices are brought together in this way, they could be used to cause serious damage to the Internet.

Indeed, the threat of applying such a hack to enable a DDoS attack, where devices are appropriated by hackers and used to overwhelm servers with data requests, is timely. There have been several recent instances of Internet-connected devices being used as slaves to take down Internet services using the approach.

The most serious of those saw a widespread Internet outage hit the East Coast of the U.S. While those attacks were blamed on the Internet of things, it has been suggested that it was older devices that were used to carry out the attacks. This research demonstrates that it may be possible to add more modern devices to the ranks of zombie hardware used by hackers.

As we’ve pointed out before, some security experts, such as Bruce Schneier, are concerned that hackers are developing ever-more sophisticated DDoS attacks that could take down the Internet more severely than ever before. It looks like there could be more tools available to achieve that than we might like.

(Read more: IoT Goes Nuclear, New York Times, “The Internet of Things Goes Rogue,” “Massive Internet Outage Could Be a Sign of Things to Come,” “How the Internet of Things Took Down the Internet”)

Keep Reading

Most Popular

Large language models can do jaw-dropping things. But nobody knows exactly why.

And that's a problem. Figuring it out is one of the biggest scientific puzzles of our time and a crucial step towards controlling more powerful future models.

OpenAI teases an amazing new generative video model called Sora

The firm is sharing Sora with a small group of safety testers but the rest of us will have to wait to learn more.

Google’s Gemini is now in everything. Here’s how you can try it out.

Gmail, Docs, and more will now come with Gemini baked in. But Europeans will have to wait before they can download the app.

This baby with a head camera helped teach an AI how kids learn language

A neural network trained on the experiences of a single young child managed to learn one of the core components of language: how to match words to the objects they represent.

Stay connected

Illustration by Rose Wong

Get the latest updates from
MIT Technology Review

Discover special offers, top stories, upcoming events, and more.

Thank you for submitting your email!

Explore more newsletters

It looks like something went wrong.

We’re having trouble saving your preferences. Try refreshing this page and updating them one more time. If you continue to get this message, reach out to us at customer-service@technologyreview.com with a list of newsletters you’d like to receive.