Monday, February 4, 2019

Nest and Your Peace of Mind

 Here's #10:


Nest and Your Peace of Mind

Nest has been taking a lot of heat lately over reports of their camera systems being hacked. Before we accept that framing at face value, it is worth understanding what actually happened and where the real problem lies.

Here are the facts. Yes, unauthorized people gained access to accounts belonging to two families, and the results were frightening. One family received a false nuclear alert through their home system. Another had a stranger speaking through the camera in their child's room. Nobody should ever experience either of those things. As a parent, the thought of hearing an unknown voice coming from my child's bedroom triggers every protective instinct I have.

But here is the part that tends to get lost in the headlines: Nest was not breached. The accounts were compromised because the owners were reusing passwords that had already been exposed in breaches at other websites. The attackers did not break into Nest. They walked in through a door the users had left unlocked, using credentials that were already floating around on the dark web.

That distinction matters, and it is important to say it clearly without blaming the victims. We have all become far too comfortable in our digital lives. Most people have credentials on dozens of websites and apps, accessed across phones, tablets, computers, and smart devices. Keeping track of unique, strong passwords for all of them feels impossible, and so people fall back on the same email and password combination across multiple sites. That is an understandable habit. It is also a genuinely dangerous one.

Here is the reality: over a three to four year period, there is a very good chance that at least one site you use has been compromised and your credentials exposed. Once that happens, those credentials get tested against other services automatically. If you use the same password on Nest that you used on a site that was breached two years ago, someone will eventually find their way in.

So what can you actually do?

First, stop reusing passwords. Every account should have a unique password. I know that sounds overwhelming, but a good password manager makes it manageable. You only need to remember one strong master password, and the manager handles the rest.

Second, turn on two-factor authentication everywhere it is available, and especially on anything connected to your home. Nest supports it. Use it. Even if someone has your password, they cannot get in without the second verification step.

Third, check whether your credentials have already been exposed. The website haveibeenpwned.com lets you enter your email address and see which known breaches included your information. It is free, it is reputable, and the results are often sobering.

Companies like Nest share some responsibility here too. Making security features more prominent and strongly encouraging two-factor authentication during setup would go a long way. Balancing ease of use with genuine security is not easy, but when the product involves cameras inside someone's home, that balance needs to lean harder toward protection.

Your home should be a place where you feel safe. A few simple habits can go a long way toward making sure it stays that way.

Tuesday, January 29, 2019

Responsible Corporations: My Privacy Does Matter

Yesterday was a big day in the Apple world, and not in a good way.

Around 4 PM on January 28th, MacRumors, my go-to source for Apple news, began reporting on a serious flaw discovered in the Group FaceTime feature of the latest iOS update. The bug was straightforward and alarming: if you initiated a FaceTime call with someone and then added yourself back into the call as a third participant, an audio bridge would open on the other end, whether or not the person you called ever accepted. In plain terms, you could listen in on someone without their knowledge or consent.

By 11 PM, local television news was running the story. That same night, Apple disabled Group FaceTime on their servers entirely, shutting down the vulnerability before it could spread further.

I went to bed feeling reasonably reassured. Apple has spent years positioning itself as a company that genuinely champions user privacy. It is woven into their marketing, their product announcements, and their public messaging. I had just upgraded a Mac, and one of the first things Mojave presented me with was a notice about privacy and Apple's commitment to protecting it. Their entire privacy page exists as a public declaration of values. I believed them. I still want to.

Then I woke up the next morning.

MacRumors had posted a thread showing that a teenager had discovered this exact bug and reported it to Apple on January 21st, a full seven days before it became public. The timestamps on those posts cannot be faked. Apple had been made aware of a significant privacy vulnerability affecting millions of users, and nothing changed until mainstream media picked up the story.

That is the part that concerns me most.

I am not suggesting Apple acted maliciously. What I am suggesting is that somewhere in the chain between a teenager's bug report and a company-wide response, something failed. Either the report did not reach the right people, or it did and the urgency was not recognized, or, in the worst case scenario, someone knew and was quietly working toward a backend fix before the story got out. Any of those outcomes points to a process problem that a company of Apple's size and stated values should not have.

Technology companies, especially those that have built their brand on privacy and trust, have a responsibility that goes beyond good marketing. When a flaw is reported, the response cannot depend on whether a journalist picks up the story first. Users deserve to know when their security is at risk. Transparency, even when it is uncomfortable, is what actually builds trust over time.

Apple has done remarkable things. I remain a believer in a lot of what they stand for. But this was a stumble, and it deserves to be called one clearly.

Put people above the bottom line. Always.

Today, the world feels a little quieter, a little dimmer.

We knew this day would come, but we held onto the hope that there would be more time. John Michael "Ozzy" Osbourne—our beloved Pri...