Skip to main content

Installing Osram Lightify smart bulbs could gift wrap your Wi-Fi password to hackers

osram smart bulbs vulnerable to hacks osram2
Osram
Like a setting out of a horror movie, a recent discovery of potential security flaws in Osram’s Lightify smart light bulbs may give hackers the ability to remotely operate a user’s lights, and even control their network, without asking for approval. Perhaps even more critical, the vulnerabilities — of which nine were found by a security researcher at Rapid7 — could also give unwanted visitors access to a home’s Wi-Fi network. Deral Heiland, the researcher who happened upon the cracks in Osram’s armor, has reportedly informed the manufacturer of the flaws, and has stated that a simple software update coming out in August should fix the problem.

Of the nine vulnerabilities found by Heiland, the one likely responsible for the bulk of the problem lies with the smart bulb’s companion application, which stores unencrypted copies of an owner’s Wi-Fi password. Because of this, hackers could easily obtain this information via the app, which would grant them access to anything connected to the Wi-Fi network. In other words, this is bad.

“This is not just about being able to manipulate the light bulbs,” said University College London cybersecurity expert, Professor Angela Sasse. “The vulnerabilities here could give somebody access to control the network itself and that’s a very serious issue. In this day and age, you would regard that as an unacceptable security flaw. It’s a well known thing that you don’t store passwords like that — it’s really elementary.”

Currently, the company says it continues to analyze potential issues with its products and that most of the flaws will likely be resolved come August. For the remaining risks — which reportedly surround the companion ZigBee Hub — the company says it’s working to find a way to develop yet another patch, though it’s uncertain what the patch would actually target.

As smart home technology continues to grow, one of the most important aspects consumers look for is a device’s built-in security. Unfortunately for Osram, until it fixes its issue of unencrypted Wi-Fi passwords, it’s likely few people will be knocking down its door to install a Lightify system.

Editors' Recommendations

Rick Stella
Former Digital Trends Contributor
Rick became enamored with technology the moment his parents got him an original NES for Christmas in 1991. And as they say…
Nanoleaf reveals new Matter-enabled smart lights at CES 2023
The Nanoleaf 4D TV syncing lights to the colors on TV.

Nanoleaf, a manufacturer of smart lights, introduced several new products to its lineup during CES 2023. The most exciting addition is the Nanoleaf Skylight, which mounts onto your ceiling to provide an impressive array of light shows. It’s also completely modular and can be arranged into a variety of shapes to fit every space in your home.

The Skylight connects to your smart ecosystem through Wi-Fi and works with Matter -- meaning you shouldn’t run into any compatibility issues with your current setup. The modular ceiling fixture can produce more than 16 million colors, its brightness can be adjusted through the accompanying smartphone app, and you can even set schedules to automatically adjust its settings throughout the day. The only downside? It won’t be launching for quite a while, with an expected release date in the third quarter of 2023.

Read more
TP Link launches budget-friendly smart light strips
TP-Link lights glowing pink behind a computer monitor.

TP-Link, a company known for producing affordable smart home gadgets, has announced a new lineup of smart LED light strips and light bulbs. This includes the Tapo L900, Tapo L920, Tapo L930, and Tapo L530E. Pricing for the products ranges from $25 to $50, making these some of the most affordable lighting options on the market.

The Tapo L930 is considered the flagship LED strip of the family, offering advanced features such as music sync mode, 16 million colors, up to 1000 lumens of white light, and an IP44 waterproof rating. You can also set up a personalized lighting schedule using the accompanying smartphone app. Amazon Alexa, Google Assistant, and Apple HomeKit are all supported by the L930. A 16.4-foot roll costs $50, making it a cheap way to get surprisingly versatile smart lights into your home.

Read more
How to use smart ambient lighting
The Govee Immersion Kit enhances on-screen content.

Ambient lighting is most simply thought of as "indirect lighting." It’s lighting that isn’t focused directly on an object and is used to add to the available amount of light in a room. You can use ambient lighting as part of ceiling-mounted fixtures or floor lamps to brighten or even out the light in a room. Ambient lighting can also be placed behind an object and used to bounce light off a wall or the ceiling. Think of it as the lighting that takes your room from plain to warm and inviting.
Benefits of smart ambient lights
While adding ambient lighting to a room can help transform it from simple to extraordinary, smart ambient lighting is definitely the way to go. The main reason is that smart lighting can be programmed to look precisely how you want it and turn on when you want. Not only can you control the brightness and intensity of the light, but also the color.

You can light up the back of your TV set and have it change color depending on your programming. You can also take things a step further by combining the system with a voice assistant and have several pre-set routines that change the lighting in the room with a single command. “Turn on horror movie lighting,” is just one example of how it could accent movie night.
Setting up ambient lighting

Read more