Title
Not so Smart: On Smart TV Apps.
Abstract
One of the main characteristics of Smart TVs are apps. Apps extend the Smart TV behavior with various functionalities, ranging from usage of social networks or payed streaming services, to buying articles on Ebay. These actions demand usage of critical data like authentication tokens and passwords, and thus raise a question on new attack scenarios and general security of Smart TV apps. In this paper, we investigate attack models for Smart TVs and their apps, and systematically analyze security of Smart TV devices. We point out that some popular apps, including Facebook, Ebay or Watchever, send login data over unencrypted channels. Even worse, we show that an arbitrary app installed on devices of the market share leader Samsung can gain access to the credentials of a Samsung Single Sign-On account. Therefore, such an app can hijack a complete user account including all his devices like smartphones and tablets connected with it. Based on our findings, we provide recommendations that are of general importance and applicable to areas beyond Smart TVs.
Year
DOI
Venue
2015
10.1109/SIOT.2015.13
SIoT
Keywords
Field
DocType
Internet of Things, Smart TV, App, Single Sign-On, OAuth, TLS, File System, XXE, XHR, Privacy, Samsung
Internet privacy,Attack model,Social network,Computer science,Computer security,Login,Password,Security token,Market share
Conference
Citations 
PageRank 
References 
2
0.39
7
Authors
4
Name
Order
Citations
PageRank
Marcus Niemietz1172.80
Juraj Somorovsky226319.92
christian mainka36610.80
Jörg Schwenk489988.54