Passwords in the air: Harvesting wi-fi credentials from smartcfg provisioning

Changyu Li, Hui Liu, Quanpu Cai, Yuanyuan Zhang, Yu Yu, Juanru Li, Dawu Gu

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

16 Scopus citations

Abstract

Smart devices without an interactive UI (e.g., a smart bulb) typically rely on specific provisioning schemes to connect to wireless networks. Among all the provisioning schemes, SmartCfg is a popular technology to configure the connection between smart devices and wireless routers. Although the SmartCfg technology facilitates the Wi-Fi configuration, existing solutions seldom take into serious consideration the protection of credentials and therefore introduce security threats against Wi-Fi credentials. This paper conducts a security analysis against eight SmartCfg based Wi-Fi provisioning solutions designed by different wireless module manufacturers. Our analysis demonstrates that six manufacturers provide flawed SmartCfg implementations that directly lead to the exposure of Wi-Fi credentials: attackers could exploit these flaws to obtain important credentials without any substantial efforts on brute-force password cracking. Furthermore, we keep track of the smart devices that adopt such Wi-Fi provisioning solutions to investigate the influence of the security flaws on real world products. Through reversely analyzing the corresponding apps of those smart devices we conclude that the flawed SmartCfg implementations constitute a wide potential impact on the security of smart home ecosystems.

Original languageEnglish
Title of host publicationWiSec 2018 - Proceedings of the 11th ACM Conference on Security and Privacy in Wireless and Mobile Networks
PublisherAssociation for Computing Machinery, Inc
Pages1-11
Number of pages11
ISBN (Electronic)9781450357319
DOIs
StatePublished - 18 Jun 2018
Externally publishedYes
Event11th ACM Conference on Security and Privacy in Wireless and Mobile Networks, WiSec 2018 - Stockholm, Sweden
Duration: 18 Jun 201820 Jun 2018

Publication series

NameWiSec 2018 - Proceedings of the 11th ACM Conference on Security and Privacy in Wireless and Mobile Networks

Conference

Conference11th ACM Conference on Security and Privacy in Wireless and Mobile Networks, WiSec 2018
Country/TerritorySweden
CityStockholm
Period18/06/1820/06/18

Keywords

  • Smart devices
  • Wi-Fi provisioning

Fingerprint

Dive into the research topics of 'Passwords in the air: Harvesting wi-fi credentials from smartcfg provisioning'. Together they form a unique fingerprint.

Cite this