Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Casino Gets Hacked Through Its Internet-Connected Fish Tank Thermometer
The Hacker News ^ | April 16, 2018 | Wang Wei

Posted on 12/25/2020 7:23:35 PM PST by TigerLikesRoosterNew

---snip---

We have another great example that showcases how one innocent looking insecure IoT device connected to your network can cause security nightmares.

Nicole Eagan, the CEO of cybersecurity company Darktrace, told attendees at an event in London on Thursday how cybercriminals hacked an unnamed casino through its Internet-connected thermometer in an aquarium in the lobby of the casino.

According to what Eagan claimed, the hackers exploited a vulnerability in the thermostat to get a foothold in the network. Once there, they managed to access the high-roller database of gamblers and "then pulled it back across the network, out the thermostat, and up to the cloud."

Although Eagan did not disclose the identity of the casino, the incident she was sharing could be of last year, when Darktrace published a report [PDF], referencing to a thermometer hack of this sort on an unnamed casino based in North America.

---snip---

(Excerpt) Read more at thehackernews.com ...


TOPICS: Chit/Chat; Computers/Internet
KEYWORDS: 2018; casino; clickbait; hacking; iot; oldnews; puttheyearintitle
Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-80 ... 101-107 next last
To: JohnBrowdie
Apparently, this is not a new type of hacking people have never known before. It is pretty much a public knowledge in cybersecurity circle.

Hackers exploit casino's smart thermometer to steal database info

BY KELLEN BECK

APR 16, 2018

"The attackers used that to get a foothold in the network," Eagan said at a Wall Street Journal panel. "They then found the high-roller database and then pulled that back across the network, out the thermostat, and up to the cloud."

21 posted on 12/25/2020 7:52:20 PM PST by TigerLikesRoosterNew
[ Post Reply | Private Reply | To 5 | View Replies]

To: minnesota_bound

Reminds me of the old fax days.


22 posted on 12/25/2020 7:52:39 PM PST by RushIsMyTeddyBear
[ Post Reply | Private Reply | To 12 | View Replies]

To: TexasFreeper2009

Judging by his hysterically tragic story, those lights apparently need a smart *owner*, as well.

:D


23 posted on 12/25/2020 7:52:52 PM PST by Salamander (There's Nothing For It But To Sit And Wait For The Hard Men To Get Me Out....)
[ Post Reply | Private Reply | To 13 | View Replies]

To: Orosius

Every time I hear of the term “smart”...I think “stupid”.


24 posted on 12/25/2020 7:54:10 PM PST by RushIsMyTeddyBear
[ Post Reply | Private Reply | To 15 | View Replies]

To: BipolarBob

2001: A Space Odyssey was the first warning for this stuff and then in 1977, there was this horrifying movie.

https://www.imdb.com/title/tt0075931/

Everything in this house relies upon me flicking a switch.

My house is happily stupid.

;)


25 posted on 12/25/2020 7:55:27 PM PST by Salamander (There's Nothing For It But To Sit And Wait For The Hard Men To Get Me Out....)
[ Post Reply | Private Reply | To 16 | View Replies]

To: Jotmo

There was a story a few days back that one of the Dominion machines was connected to the internet via a thermostat.


26 posted on 12/25/2020 7:58:06 PM PST by Stormy_MS1
[ Post Reply | Private Reply | To 20 | View Replies]

To: TigerLikesRoosterNew; All

Thanks for posting, New. Go to a casino. Look at all the Chinese-themed machines. Don’t use your card. Notice the companies that make these “games”. Who are they partnered with?

CCP = CNP Comprehensive National Power includes Comprehensive Data Collection.

Kai-Fu Lee at edge.org likes the data collectors to “Chinese Gladiators”. Go figure.

https://www.learnchinesehistory.com/history-chinese-emperors/

https://www.edge.org/response-detail/23838


27 posted on 12/25/2020 7:59:13 PM PST by PGalt (Past Peak Civilization?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: TigerLikesRoosterNew

28 posted on 12/25/2020 7:59:28 PM PST by Svartalfiar
[ Post Reply | Private Reply | To 1 | View Replies]

To: Orosius

One of my neighbors has a DIL who is in CyberSecurity and she doesn’t have anything ‘smart’ in her home. This lady’s daughter’s office is like a real tight drum, security-wise.

We’re going to be hold-outs on any ‘smart’ TV or appliance.

I freaked out one day because we were discussing something and my damn IPad repeated something I had just said. I was 4 feet away from it and had not pressed the sound tab, or anything like it. My husband and I *both* damn near had strokes. It hasn’t done it since then.... so we have no clear idea what happened... it had never done anything like that in the years I have had the IPad... only that one time....

...still, it spooked us enough! We’d already made the decision never to have a ‘smart’ TV; this just reinforced that decision.

What I don’t understand is why people were shocked when their ‘smart’ homes locked them out. There have been movies made about bad guys doing that to homes and businesses!!!

Give me a key and lock any day of the week.

And a strong, reinforced door, as well! :)


29 posted on 12/25/2020 7:59:53 PM PST by Notthereyet (May the Lord God Find 10 Good Men In America. Amen. )
[ Post Reply | Private Reply | To 15 | View Replies]

To: Jotmo
They didn't say what was the thermostat in question. However, the following article might be useful for you:

Can A Nest Thermostat Be Hacked?

30 posted on 12/25/2020 8:02:20 PM PST by TigerLikesRoosterNew
[ Post Reply | Private Reply | To 20 | View Replies]

To: TigerLikesRoosterNew

Do you get it yet!?!


31 posted on 12/25/2020 8:13:18 PM PST by Mr. Blond
[ Post Reply | Private Reply | To 1 | View Replies]

To: Orosius

I’m with them. However, every phone or home computer or router can probably be hacked by those who know how. Paper and pen in my line of work is all I trust to keep things private.


32 posted on 12/25/2020 8:18:21 PM PST by The Westerner (Protect the most vulnerable: get the gov out of medicine, education and forests!)
[ Post Reply | Private Reply | To 15 | View Replies]

To: Signalman

So does the Mirage

33 posted on 12/25/2020 8:20:59 PM PST by martin_fierro (< |:)~)
[ Post Reply | Private Reply | To 8 | View Replies]

To: minnesota_bound

Wouldn’t a VPN solve this problem?


34 posted on 12/25/2020 8:24:46 PM PST by SuperLuminal (Where is Sam Adams now that we desperately need him)
[ Post Reply | Private Reply | To 12 | View Replies]

To: Ken H

Oh fer cod’s sake


35 posted on 12/25/2020 8:25:09 PM PST by martin_fierro (< |:)~)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Ken H

Right out of the gate, you win the thread!


36 posted on 12/25/2020 8:30:31 PM PST by Flick Lives (#resist)
[ Post Reply | Private Reply | To 2 | View Replies]

To: TigerLikesRoosterNew
Reportedly, it is contained in https://www.darktrace.com/resources/wp-global-threat-report-2017.pdf

The link to the report is no longer available.

However, I dug up the relevant section of the report from somebody's blog(https://seedvc.blog/2017/08/01/hacking-the-fish-tank/). For some reason, there are spelling problems. Here it is:


Read #6:

Technological innovations keep businesses dynamic and pro table, their employees productive and creative, and their premises exciting and modern. A North American casino recently installed a high-tech sh tank as a new attraction, with advanced sensors that automatically regulate temperature, salinity, and feeding schedules.

To ensure these communications remained separate from the commercial network, the casino con gured the tank to use an individual VPN to isolate the tank's data. However, as soon as Darktrace was installed, it identi ed anomalous data transfers from the sh tank to a rare external destination.

Anomalous activity detected:

Transfer of 10GB outside the network

No other company device had communicated with this external location

No other company device was sending a comparable amount of outbound data

Communications took place on a protocol normally associated with audio and video

The tank's communication patterns included sporadic communications with company devices, but that activity was in line with similarly con gured IoT devices. The external data transfers, however, were deemed highly unusual by Darktrace’s AI algorithms.

The data was being transferred to a device in Finland where an attacker had managed to gain control over the tank. This was a clear case of data ex ltration, but far more subtle than typical attempts at data theft.

By targeting an unconventional device that had recently been introduced into the network, the attack managed to evade the casino's traditional security tools. Darktrace’s Enterprise Immune System detected the threat because the technology does not make assumptions about where threats will arise. It detected a subtle anomaly that indicated a much larger threat, and it aided the casino in remediating the vulnerability. The incident demonstrates the need to have complete visibility of every user and device – including internet-connected sh tanks.

37 posted on 12/25/2020 8:33:31 PM PST by TigerLikesRoosterNew
[ Post Reply | Private Reply | To 1 | View Replies]

To: TigerLikesRoosterNew

I will never connect an appliance to the Interwebs.

Or one of those “smart speakers” that relay everything you say to the NSA.


38 posted on 12/25/2020 8:38:30 PM PST by E. Pluribus Unum (You are in far more danger from an authoritarian government than you are from a seasonal virus.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: TigerLikesRoosterNew

Just the octopus.


39 posted on 12/25/2020 8:45:35 PM PST by headsonpikes (Mass murder and cannibalism are the twin sacraments of socialism - "Who-whom?"-Lenin)
[ Post Reply | Private Reply | To 7 | View Replies]

To: Ken H

“Cleary a fishing scam.”

One that people will be carping on for some time.


40 posted on 12/25/2020 8:50:49 PM PST by LeoTDB69
[ Post Reply | Private Reply | To 2 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-80 ... 101-107 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson