Skip to main content

Installing Osram Lightify smart bulbs could gift wrap your Wi-Fi password to hackers

osram smart bulbs vulnerable to hacks osram2
Osram
Like a setting out of a horror movie, a recent discovery of potential security flaws in Osram’s Lightify smart light bulbs may give hackers the ability to remotely operate a user’s lights, and even control their network, without asking for approval. Perhaps even more critical, the vulnerabilities — of which nine were found by a security researcher at Rapid7 — could also give unwanted visitors access to a home’s Wi-Fi network. Deral Heiland, the researcher who happened upon the cracks in Osram’s armor, has reportedly informed the manufacturer of the flaws, and has stated that a simple software update coming out in August should fix the problem.

Of the nine vulnerabilities found by Heiland, the one likely responsible for the bulk of the problem lies with the smart bulb’s companion application, which stores unencrypted copies of an owner’s Wi-Fi password. Because of this, hackers could easily obtain this information via the app, which would grant them access to anything connected to the Wi-Fi network. In other words, this is bad.

“This is not just about being able to manipulate the light bulbs,” said University College London cybersecurity expert, Professor Angela Sasse. “The vulnerabilities here could give somebody access to control the network itself and that’s a very serious issue. In this day and age, you would regard that as an unacceptable security flaw. It’s a well known thing that you don’t store passwords like that — it’s really elementary.”

Currently, the company says it continues to analyze potential issues with its products and that most of the flaws will likely be resolved come August. For the remaining risks — which reportedly surround the companion ZigBee Hub — the company says it’s working to find a way to develop yet another patch, though it’s uncertain what the patch would actually target.

As smart home technology continues to grow, one of the most important aspects consumers look for is a device’s built-in security. Unfortunately for Osram, until it fixes its issue of unencrypted Wi-Fi passwords, it’s likely few people will be knocking down its door to install a Lightify system.

Rick Stella
Former Digital Trends Contributor
Rick became enamored with technology the moment his parents got him an original NES for Christmas in 1991. And as they say…
Save money on your utility bills with these smart home gadgets
The Google Nest Learning Thermostat in stainless steel.

Smart home gadgets can do more than respond to voice commands or automate your household -- they can also save you money. It might require a hefty initial investment, but once your smart home is up and running, it’s not uncommon to see big reductions across most of your utility bills. If you’re looking to save a few extra bucks every month, here are some easy ways to save money with smart home devices.
Upgrade to a smart thermostat

Arguably the best way to save money on your energy bills is by switching to a smart thermostat. These come in all shapes and sizes, but your best bet is to spring for a premium model that offers advanced learning capabilities -- such as the Nest Learning Thermostat. Products in this category give you the best control of your HVAC system, as they’ll actively monitor your usage and suggest ways to be more efficient.

Read more
8 things you didn’t know smart lights could do

Smart lights are among the simplest products to add to your smart home. After removing your old bulbs and screwing in the new ones, you’ll instantly be able to adjust their brightness or tweak their color. And while those features alone are a good reason to bring them into your home, there’s a lot more to most smart lights than you’d imagine.

Of course, each smart light comes with its own set of caveats, and not all of them can perform the same task. Philips, Wyze, Sengled, Nanoleaf, and dozens of other manufacturers are churning out smart lights nowadays -- and you can even find unique products such as LED strips or smart lamps that bring their own twist to the category. This variety has led to an explosion of innovation, with smart lights now able to perform tasks well beyond simple illumination.

Read more
Adorable smart home robot unveiled at CES 2023 could be a great addition to your family
A child playing with the EBO X.

Every January, CES brings us a laundry list of innovative, intriguing products that’ll probably never see the light of day. Enabot, an under-the-radar robot company, seems to be bucking that trend at CES 2023, with its impressive EBO X smart home robot offering up dozens of futuristic features and a release date planned for the second quarter of this year.

EBO X is an adorable smart home robot that serves multiple purposes in your household. After mapping its surroundings, the self-balancing, two-wheeled companion can follow you around your home, provide two-way communication through its 4K camera, pump out music via its Harman speakers, sync with other Alexa devices, and provide security alerts while you’re away.

Read more