• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

Social Security's 2032 deadline puts a 22% cut on the table — but Washington has way less room to negotiate than 1983

2

CEO of $20 billion AI firm Perplexity says the secret to success is ‘sleeping with that fear’ that your competitor will steal your idea

3

Boomers actually do hold most of the wealth and power. So why do they call it 'whiny' to point that out?

1

Social Security's 2032 deadline puts a 22% cut on the table — but Washington has way less room to negotiate than 1983

2

CEO of $20 billion AI firm Perplexity says the secret to success is ‘sleeping with that fear’ that your competitor will steal your idea

3

Boomers actually do hold most of the wealth and power. So why do they call it 'whiny' to point that out?
TechSamsung

Samsung’s smart fridge could be used to steal your Gmail login

By
Stacey Higginbotham
Stacey Higginbotham
Down Arrow Button Icon
By
Stacey Higginbotham
Stacey Higginbotham
Down Arrow Button Icon
August 24, 2015, 1:10 PM ET
Image courtesy of Samsung.

In yet another example of a manufacturer of a connected product failing to secure said product, Samsung’s connected fridge allows malicious people to steal a consumer’s Gmail login credentials provided they can get on the user’s Wi-Fi network. The exploit, known as a man-in-the-middle attack, is made possible because the Samsung smart fridge lets people link their Gmail calendars to a screen in the fridge’s door so they can see their day’s events.

It’s a handy feature, except when a person logs in, the fridge says it provides SSL encryption, but fails to actually verify that the server on the Google end has the right certificate to actually get the encrypted data. It just hands it over. This is akin to a club saying it checks IDs only to let people get in without actually looking at the date on those IDs. Thus anyone on the consumer’s Wi-Fi network could pretend to be Google’s calendar service and snag the consumer’s Gmail login credentials. From there the hacker could wreak all kinds of havoc. Fortune has reached out to Samsung to see what it has to say about the vulnerability.

The vulnerability was discovered during a hackathon at the Defcon event earlier this month and covered by The Register Monday morning. Pen Test Partners discovered the weakness and blogged about both the vulnerability and how it systematically tried to attack the fridge.

 

The best part about the blog post is how clearly it shows off the mindset of someone trying to break the security of a connected product. Failure was only a temporary setback brought about because they hadn’t tried the right passwords or had enough time in this particular setting. For example, check out the confidence in this section (emphasis mine)

We pulled apart the mobile app and found what we believe is the certificate inside a keystore. We “believe” we did because it is has a name that suggests this. However, it is correctly passworded and we are yet to extract the password that opens the key store. We think we’ve found the password to the certificate in the client side code, but it’s obfuscated and we haven’t got round to reversing it, yet.

The challenge here is that connected products are being put out in the market by manufacturers who aren’t necessarily familiar with the importance of security. In some cases, they are legitimately unaware of the threats, but in others they are taking what they feel is a more cost-effective route, believing that they can just add security later. They cannot: Security must be designed in these products from the ground up. A second challenge is that many vendors are relying on consumers to be far more savvy about security than they are.

The Internet connected device industry needs to grow up and do so quickly, before consumers lose trust and regulators decide to get involved. Today it’s a security firm demonstrating a vulnerability, but tomorrow it may very well be a team of blackmailing moralists or a group trying to bring down a company.

About the Author
By Stacey Higginbotham
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

Dario Amodei, Anthropic CEO
AIAnthropic
A warning from Amazon led the White House to shut down Anthropic’s Mythos model
By Beatrice NolanJune 14, 2026
8 hours ago
Canadian Prime Minister Mark Carney warns U.S. restrictions on new Anthropic AI models show danger of relying too much on American providers
AICanada
Canadian Prime Minister Mark Carney warns U.S. restrictions on new Anthropic AI models show danger of relying too much on American providers
By Rob Gillies, Jason Ma and The Associated PressJune 14, 2026
10 hours ago
SpaceX surge further boosts Saudi billionaire prince’s fortune
InvestingSaudi Arabia
SpaceX surge further boosts Saudi billionaire prince’s fortune
By Adveith Nair and BloombergJune 14, 2026
14 hours ago
Wall Street is gaining access to new catastrophe models to help predict wars
BankingWar
Wall Street is gaining access to new catastrophe models to help predict wars
By Gautam Naik and BloombergJune 14, 2026
14 hours ago
People wait outside a building
AIJobs
AI job disruption is here. The problem may be compounded because nearly 75% of people don’t apply for unemployment benefits
By Jacqueline MunisJune 14, 2026
14 hours ago
Just months after Trump warned states not to regulate AI, Republican and Democratic lawmakers are doing it anyway
Politicsregulation
Just months after Trump warned states not to regulate AI, Republican and Democratic lawmakers are doing it anyway
By Marc Levy and The Associated PressJune 14, 2026
14 hours ago

Most Popular

Social Security's 2032 deadline puts a 22% cut on the table — but Washington has way less room to negotiate than 1983
Personal Finance
Social Security's 2032 deadline puts a 22% cut on the table — but Washington has way less room to negotiate than 1983
By John W. Diamond and The ConversationJune 12, 2026
2 days ago
CEO of $20 billion AI firm Perplexity says the secret to success is ‘sleeping with that fear’ that your competitor will steal your idea
Success
CEO of $20 billion AI firm Perplexity says the secret to success is ‘sleeping with that fear’ that your competitor will steal your idea
By Preston ForeJune 13, 2026
2 days ago
Boomers actually do hold most of the wealth and power. So why do they call it 'whiny' to point that out?
Economy
Boomers actually do hold most of the wealth and power. So why do they call it 'whiny' to point that out?
By Nick LichtenbergJune 14, 2026
18 hours ago
Iran proved it can close the Strait of Hormuz, but the U.S. is advertising very loudly that the world's top superpower can at least punch open a hole
Energy
Iran proved it can close the Strait of Hormuz, but the U.S. is advertising very loudly that the world's top superpower can at least punch open a hole
By Jason MaJune 14, 2026
11 hours ago
The Gen Z cofounder of $1.6 billion Whop says his platform has minted over 650 millionaires—he wants to make work fun and money worries obsolete
Success
The Gen Z cofounder of $1.6 billion Whop says his platform has minted over 650 millionaires—he wants to make work fun and money worries obsolete
By Emma BurleighJune 14, 2026
19 hours ago
Gen Z fled San Francisco for Texas and Florida. Now they’re turning ‘welcomer cities’ into the next big tech towns
Real Estate
Gen Z fled San Francisco for Texas and Florida. Now they’re turning ‘welcomer cities’ into the next big tech towns
By Sydney LakeJune 13, 2026
2 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.