{"id":6072,"date":"2016-10-24T13:40:31","date_gmt":"2016-10-24T17:40:31","guid":{"rendered":"http:\/\/avtech.com\/articles\/?p=6072"},"modified":"2025-10-24T09:31:47","modified_gmt":"2025-10-24T13:31:47","slug":"room-alert-iot-device-security","status":"publish","type":"post","link":"https:\/\/avtech.com\/articles\/6072\/room-alert-iot-device-security\/","title":{"rendered":"Room Alert and IoT Device Security"},"content":{"rendered":"<p>On Friday, October 21<sup>st <\/sup>2016, an <a href=\"http:\/\/arstechnica.com\/security\/2016\/10\/double-dip-internet-of-things-botnet-attack-felt-across-the-internet\/\" target=\"_blank\" rel=\"noopener\">unprecedented attack was made on Dyn<\/a>, a DNS provider that helps Internet traffic across the globe make its way to many of the world\u2019s popular websites.<\/p>\n<p>A significant number of heavily -trafficked sites were down for a good part of the day, including Twitter, The Wall Street Journal, Spotify, PayPal, and Netflix among many others.<\/p>\n<p>What makes this particular internet attack interesting is the fact that it used Internet of Things (IoT) devices to <a href=\"http:\/\/www.networkworld.com\/article\/3134093\/security\/iot-botnets-used-in-unprecedented-ddos-against-dyn-dns-fbi-dhs-investigating.html#tk.twt_nww\" target=\"_blank\" rel=\"noopener\">launch the denial of service traffic against Dyn<\/a>. In years past, these attacks were usually the result of servers and desktop computers that were infected by malware, and unknowingly used to launch the flood of traffic that brought down targeted servers or websites. This most recent attack used IoT devices such as routers, IP cameras, DVRs, thermostats \u2013 basically any device that connects to the internet to send updates to users, or allows itself to be controlled remotely by its owner.<\/p>\n<h3><strong>IoT Device Security<\/strong><\/h3>\n<p><a href=\"http:\/\/avtech.com\/articles\/wp-content\/uploads\/2016\/05\/room-alert-ui2-manual.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignleft wp-image-4484\" src=\"http:\/\/avtech.com\/articles\/wp-content\/uploads\/2016\/05\/room-alert-ui2-manual-300x234.png\" alt=\"room-alert-ui2-manual\" width=\"280\" height=\"219\" srcset=\"https:\/\/avtech.com\/articles\/wp-content\/uploads\/2016\/05\/room-alert-ui2-manual-300x234.png 300w, https:\/\/avtech.com\/articles\/wp-content\/uploads\/2016\/05\/room-alert-ui2-manual.png 572w\" sizes=\"(max-width: 280px) 100vw, 280px\" \/><\/a>IoT device security has been in the news a lot recently due to the publicizing of some major <a href=\"http:\/\/www.komando.com\/happening-now\/376451\/top-story-security-cameras-could-let-criminals-watch-you-instead?utm_content=buffer3a478&amp;utm_medium=social&amp;utm_source=twitter.com&amp;utm_campaign=buffer\" target=\"_blank\" rel=\"noopener\">IoT device security flaws<\/a> manufactured by a company in Taiwan. Soon after that information was made public, and source code was released for a larger exploit that impacted a number of other types of devices, IoT devices were used to send the traffic that brought down Dyn\u2019s servers. This followed earlier smaller attacks and <a href=\"https:\/\/krebsonsecurity.com\/2016\/10\/source-code-for-iot-botnet-mirai-released\/\" target=\"_blank\" rel=\"noopener\">warnings from security experts<\/a>&nbsp;that a larger attack was likely very soon.<\/p>\n<p><a href=\"http:\/\/avtech.com\/Products\/Environment_Monitors\/\" target=\"_blank\" rel=\"noopener\">Room Alert <\/a>is firmly within the IoT sphere, as it\u2019s designed to send alerts and notifications to users based on the environment factors it\u2019s monitoring. Room Alert can also take automatic corrective action based on those alerts, such as turning on a water pump or fan if certain environment triggers are set up.<\/p>\n<p>It\u2019s important to note that although Room Alert is considered an IoT device, we\u2019ve taken a good number of steps to help protect the security of our devices and our customers.<\/p>\n<h3><strong>Purpose Built Firmware in Room Alert<\/strong><\/h3>\n<p>One major security flaw with some IoT devices is tied into the firmware and software the devices run. When IoT devices run common embedded Linux operating system versions, and specifically the Busybox software that provides stripped down versions of common Unix tools in a single executable, it\u2019s easier to find ways to manipulate those devices from the outside.<\/p>\n<p>Room Alert\u2019s firmware is purpose built, which means that it\u2019s specifically designed for Room Alert devices. Room Alert runs very specifically designed firmware that\u2019s set up to only provide the functions the devices need to monitor, alert and report \u2013 that\u2019s it. Room Alert does not leverage the common Busybox Unix tools.<\/p>\n<h3><strong>Secure Monitoring with GoToMyDevices<\/strong><\/h3>\n<p>Our <a href=\"https:\/\/gotomydevices.com\/\" target=\"_blank\" rel=\"noopener\">GoToMyDevices portal<\/a> offers our customers an easy and secure way to monitor and manage Room Alert. Users can see their devices, reports, alerts, and data directly within the GoToMyDevices portal from any internet-connected device. Sensor data is pushed directly to GoToMyDevices from Room Alert; GoToMyDevices does not require a connection back to Room Alert.<\/p>\n<p>Since traffic is only one way, from Room Alert on the customer\u2019s network to GoToMyDevices, there\u2019s no need for users to open up ports on their local firewalls. Traffic doesn\u2019t need to get in when customers use GoToMyDevices, and users don\u2019t need to worry about those additional open firewall ports adding additional potential points of entry for malicious traffic.<\/p>\n<h3><strong>Room Alert Doesn\u2019t Use Universal Plug and Play<\/strong><\/h3>\n<p>Universal Plug and Play, commonly referred to as UPnP, is a protocol that\u2019s widely used in internet-connected devices to make them easy to set up, and also allows them to discover other devices on their local networks to \u201ctalk to\u201d. This protocol has been identified as a <a href=\"http:\/\/arstechnica.com\/security\/2013\/01\/to-prevent-hacking-disable-universal-plug-and-play-now\/\" target=\"_blank\" rel=\"noopener\">major vulnerability when it comes to outside malicious traffic<\/a>, and has been recommended to be disabled in many instances.<\/p>\n<p>Room Alert does not use UPnP to connect itself to other local network devices or GoToMyDevices for remote monitoring. Again, as we noted above Room Alert uses custom firmware and is designed to provide one-way traffic to our GoToMyDevices platform, the preferred way to monitor your Room Alert. By not using UPnP, we\u2019ve removed one major way IoT devices can be exploited by malicious users and traffic.<\/p>\n<p><strong>UPDATE<\/strong>&nbsp;&#8211; Our Support Team has <a href=\"http:\/\/avtech.com\/articles\/6078\/how-to-maximize-room-alert-security\/\" target=\"_blank\" rel=\"noopener\">published an FAQ <\/a>on how to further increase security on a Room Alert, which includes instructions on disabling unwanted or unused features.<\/p>\n<h3><strong>Heightened&nbsp;IoT Device Security<\/strong><\/h3>\n<p>Going forward, it\u2019s expected that more Denial of Service attacks such as the one suffered by Dyn will occur. With so many devices connected to the internet it\u2019s inevitable that these types of attacks will last longer, and potentially cause more damage. We always keep those security issues in mind here at AVTECH, which is why Room Alert is designed to run its own purpose-built firmware, offering very little in the way of potential security holes. We know that our business is protecting our customers\u2019 most important assets. Our customers can trust that AVTECH takes security very seriously and is continuously evaluating our products against current and future threats.<\/p>\n<p>If any of our users or partners worldwide have any questions about Room Alert, GoToMyDevices, or our products in general as it relates to their security, we welcome you to <a href=\"http:\/\/avtech.com\/Contact\/\" target=\"_blank\" rel=\"noopener\">contact us at any time<\/a>. We fully stand behind our products here at AVTECH and are glad to know our users in over 180 countries stand behind them as well.<\/p>\n<p><em>Note: The former GoToMyDevices online monitoring and management platform was migrated into RoomAlert.com in December 2017. For more information, please see our <a href=\"http:\/\/avtech.com\/articles\/9567\/gotomydevices-is-now-roomalert-com\/\" target=\"_blank\" rel=\"noopener\">announcement article and FAQ<\/a>.&nbsp;<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>On Friday, October 21st 2016, an unprecedented attack was made on Dyn, a DNS provider that helps Internet traffic across the globe make its way to many of the world\u2019s popular websites. A significant number of heavily -trafficked sites were down for a good part of the day, including Twitter, The Wall Street Journal, Spotify, [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0},"categories":[20],"tags":[36,37,41,42,47],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v15.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<meta name=\"description\" content=\"Recent denial of service attacks have raised questions about IoT device security. Room Alert monitors from AVTECH are built with user security in mind.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/avtech.com\/articles\/6072\/room-alert-iot-device-security\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Room Alert and IoT Device Security - AVTECH\" \/>\n<meta property=\"og:description\" content=\"Recent denial of service attacks have raised questions about IoT device security. Room Alert monitors from AVTECH are built with user security in mind.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/avtech.com\/articles\/6072\/room-alert-iot-device-security\/\" \/>\n<meta property=\"og:site_name\" content=\"AVTECH\" \/>\n<meta property=\"article:published_time\" content=\"2016-10-24T17:40:31+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-10-24T13:31:47+00:00\" \/>\n<meta property=\"og:image\" content=\"http:\/\/avtech.com\/articles\/wp-content\/uploads\/2016\/05\/room-alert-ui2-manual-300x234.png\" \/>\n<meta name=\"twitter:card\" content=\"summary\" \/>\n<meta name=\"twitter:creator\" content=\"@RussBenoit\" \/>\n<meta name=\"twitter:site\" content=\"@AVTECHSoftware\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\">\n\t<meta name=\"twitter:data1\" content=\"Russell Benoit\">\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\">\n\t<meta name=\"twitter:data2\" content=\"4 minutes\">\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebSite\",\"@id\":\"https:\/\/avtech.com\/articles\/#website\",\"url\":\"https:\/\/avtech.com\/articles\/\",\"name\":\"AVTECH\",\"description\":\"Frequently Asked Questions\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":\"https:\/\/avtech.com\/articles\/?s={search_term_string}\",\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/avtech.com\/articles\/6072\/room-alert-iot-device-security\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"http:\/\/avtech.com\/articles\/wp-content\/uploads\/2016\/05\/room-alert-ui2-manual-300x234.png\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/avtech.com\/articles\/6072\/room-alert-iot-device-security\/#webpage\",\"url\":\"https:\/\/avtech.com\/articles\/6072\/room-alert-iot-device-security\/\",\"name\":\"Room Alert and IoT Device Security - AVTECH\",\"isPartOf\":{\"@id\":\"https:\/\/avtech.com\/articles\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/avtech.com\/articles\/6072\/room-alert-iot-device-security\/#primaryimage\"},\"datePublished\":\"2016-10-24T17:40:31+00:00\",\"dateModified\":\"2025-10-24T13:31:47+00:00\",\"author\":{\"@id\":\"https:\/\/avtech.com\/articles\/#\/schema\/person\/a69a6dcca44758552972ea0f504d3ea6\"},\"description\":\"Recent denial of service attacks have raised questions about IoT device security. Room Alert monitors from AVTECH are built with user security in mind.\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/avtech.com\/articles\/6072\/room-alert-iot-device-security\/\"]}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/avtech.com\/articles\/#\/schema\/person\/a69a6dcca44758552972ea0f504d3ea6\",\"name\":\"Russell Benoit\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/avtech.com\/articles\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/4e35ce8839348e1ba5f28f9123e3a8fb?s=96&d=mm&r=g\",\"caption\":\"Russell Benoit\"},\"sameAs\":[\"https:\/\/twitter.com\/RussBenoit\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","_links":{"self":[{"href":"https:\/\/avtech.com\/articles\/wp-json\/wp\/v2\/posts\/6072"}],"collection":[{"href":"https:\/\/avtech.com\/articles\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/avtech.com\/articles\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/avtech.com\/articles\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/avtech.com\/articles\/wp-json\/wp\/v2\/comments?post=6072"}],"version-history":[{"count":13,"href":"https:\/\/avtech.com\/articles\/wp-json\/wp\/v2\/posts\/6072\/revisions"}],"predecessor-version":[{"id":29616,"href":"https:\/\/avtech.com\/articles\/wp-json\/wp\/v2\/posts\/6072\/revisions\/29616"}],"wp:attachment":[{"href":"https:\/\/avtech.com\/articles\/wp-json\/wp\/v2\/media?parent=6072"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/avtech.com\/articles\/wp-json\/wp\/v2\/categories?post=6072"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/avtech.com\/articles\/wp-json\/wp\/v2\/tags?post=6072"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}