SDMmag logo
search
Go to Ask SDM AI
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
SDMmag logo
  • NEWS
  • PRODUCTS
  • TOPICS
    • Access Control & Identification
    • Integration & Network Solutions
    • Life Safety & Fire Alarm
    • Monitoring
    • Smart Home
    • Trends & Industry Issues
    • Video Solutions
  • COLUMNS
    • Digital Shuffle
    • Editor's Angle
    • Insider News & Business
    • Integration Spotlight
    • Marketing Madmen
    • Security & the Law
    • Security Comings & Goings
    • Security Networkings
    • Technology @ Work
    • Technology Solutions & Skills
    • SIA Waypoints
    • Cybersecurity Chronicle
  • EXCLUSIVES
    • Annual Industry Forecast
    • Dealer of the Year
    • Project of the Year
    • SDM 100
    • State of the Market Series
    • Systems Integrator of the Year
    • Top Systems Integrator Report
    • TMA Excellence Awards
  • BLOG
  • MEDIA
    • Videos
    • Podcasts
    • Polls
    • White Papers
  • EVENTS
    • Industry Calendar
    • Webinars
  • MORE
    • Classified Ads
    • Newsletters
    • SDM Store
    • State of Security eBook
    • Sponsored Insights
  • BUYERS GUIDE
    • Buyers Guide
    • Take a Tour
  • EMAG
    • eMagazine
    • Archive Issues
    • Monitoring Today
    • Advertise
  • SIGN UP!
ColumnsSecurity NetWorkings

Hey Alexa, Unlock My Back Door & Potential QR Vulnerabilities

By David Engebretson
Security Networkings
March 4, 2022

I am not a proponent of smart home devices such as Google’s Nest or Amazon’s Alexa. I suspect that part of my reluctance to install these devices is the numerous potential security problems to which such systems can be susceptible.

I will admit to a certain amount of paranoia; but I really don’t think that putting a smart device that listens to voices and conversations in my home is a great idea. Every day I read on the internet about different security problems that such systems can pose.

There are a number of DIY and installed alarm systems that support these voice-activated systems, including Simplisafe, Cove, Vivint, Ring and other major alarm suppliers. Connecting these systems to a smart home voice controller is simply asking for trouble.

“I will admit to a certain amount of paranoia; but I really don’t think that putting a smart device that listens to voices and conversations in my home is a great idea.”

Part of the problem is the DIY installation by the end users. These systems come pre-programmed to be as simple as possible for an uninitiated user to hook up and make operate. These simplified programming features can result in major security holes that can be easily and quickly exploited to allow the degrading or complete disarming of a connected alarm system.

Some of the common ways to hack into such systems include exploiting the universal plug and play Wi-Fi feature found in many residential-grade system routers. The hacker gets onto the target’s network and can access the smart systems to disable devices, open door locks, control PTZ cameras, and the like.

Another common path to hacking these systems is the creation of third-party apps that contain malware to assist the hacker in controlling the system. Once loaded into their smart phone, such apps can allow unauthorized users to take control of smart systems.

And perhaps the simplest attacking method is to simply yell, “Alexa, open the (garage, back, front) door” through a window.

Looking for quick answers on security topics? Try Ask SDM, our new smart AI search tool. Ask SDM →

And while the manufacturers issue patches and warnings to users, how many people will update their system when notified? I suspect that most system security upgrades are performed after the burglary has occurred

If a security system is connected to one of these systems and a successful attack occurs, I believe that the customer will likely blame the alarm company and not the mega-corporation that provided the porous “smart” gateway into their building. They have their alarm company’s phone number; who do they call at Google or Amazon?

This headlong dive into smart home system installations (millions are sold every year) can leave owners quite vulnerable to hacking attacks. Security dealers might carefully consider whether customers' vital security devices and functions are made controllable by one of these smart systems. In my world, the security system is separate from every other network in my houses, except for central station reporting. I guess I’m just old school.

Now, to the QR codes. During one of my last airplane trips this past year I was at Midway Airport and it was lunch time. I found an open bar/restaurant and asked the waiter for a menu. “We don’t have menus,” he said. “Just scan the QR code on this placard.” Because of COVID-19 many of the restaurants that are still open don’t want to provide a written menu and expect their customers to do the QR shuffle to get the listings of menu.

I don’t scan QR codes. When the waiter said that they had no menus I had to interrogate him regarding the lunch sandwich options available. I did get lunch, so I guess I dodged the QR problem temporarily.

QR codes were first developed in 1994 by a subsidiary of Toyota. The idea was to automate the manufacturing and assembly of cars and trucks. Now QR codes are everywhere, with everything from TV news to catalogs to programming smart home devices requiring that a QR code be scanned onto a user or technician’s smart phone.

What most all unsuspecting users don’t understand is that QR codes are easily manipulated to provide opportunities for bad guys to steal passwords and other information. QR codes often will connect users to particular websites, such as a restaurant. Often the hacker will dummy up a fake web page that looks exactly like the restaurant’s, and slip it into the plastic holders while no one is looking. If the user scans the rogue QR code and punches in his/her credit card info to buy lunch, that information is grabbed and exploited by the hacker(s).

This proliferation of QR codes and the trusting nature of the connected public is going to provide increasing opportunities for exploitation and invasive actions. Phones may be “smart,” but that doesn’t mean the user is.

Warning your technicians about not randomly scanning QR codes onto their smart phones which they also use for business functions is probably a good idea. The more “connected” we get, the more hacks will sprout to attack our digital worlds.

Bio: Dave Engebretson provides fiber optic and networking training for low-voltage technicians. He recommends the Little Richard version of the Rolling Stones’ “Brown Sugar,” available online. And if you have the time, binging “Ozark” provides a quality if convoluted story with money laundering being the central theme.

KEYWORDS: smart home devices

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Dave Engebretson is the president of Slayton Solutions Ltd., which provides fiber optic, IP networking, and cable termination and testing training for our industry. Catch his speeches at the ADI Expo in your area and win a prize if you can identify the 1970s era rock song that is his ringtone. See his work at slaytonsolutionsltd.com.

Recommended Content

JOIN TODAY
to unlock your recommendations.

Already have an account? Sign In

  • SDM 100

    SDM 100: Top 100 Security Dealers of 2026

    The top 100 security dealers navigated a complex...
    SDM 100 Report
    By: Karyn Hodgson
  • Security camera

    State of the Market: Video Surveillance

    As video surveillance shifts from siloed systems to...
    Exclusives
    By: Brianna Wilson
  • 2026 Industry Forecast

    SDM 2026 INDUSTRY FORECAST

    Rapid technology advances meet shifting economic...
    Trends & Industry Issues
    By: Karyn Hodgson
Manage My Account
  • SDM Newsletters
  • Online Registration
  • eMagazine Subscriptions
  • Subscription Customer Service
  • Manage My Preferences

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the SDM audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of SDM or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Doctor examining child patient with mother present in medical clinic
    Sponsored byHID

    The Human Side of Hospital Security: How Modern Visitor Management Protects People First

Popular Stories

Video surveillance camera

Why Video Health Monitoring Is a ‘No Brainer’

ESA Board of Directors Q2 26 Elections

Electronic Security Association Announces 2026 Board of Directors Election Results

TMA & SDM Logos

Becklar, Elite & Puget Win 2026 TMA/SDM Monitoring Center Excellence Awards

SDM Dealer of the Year 2026 Promotion

Poll

What’s the most promising trend in the industry?

What’s the most promising trend in the industry?
View Results Poll Archive

Products

Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

See More Products
SDM 100 2026 Rankings

Related Articles

  • Monster Burgers With Huge RMR Potential

    See More
  • What's Holding Back Security Dealers From Installing IP Cameras?

    See More
  • Security Networkings

    How POE+ Switch Can Make Outdoor Cameras Easy & Quick to Install

    See More

Related Products

See More Products
  • CASP.jpg

    CASP+ CompTIA Advanced Security Practitioner Certification All-In-One Exam Guide...

  • effective.jpg

    Effective Physical Security, 5th Edition

  • Physical Security and Safety: A Field Guide for the Practitioner

See More Products
×

Be in the forefront of security intelligence when you receive SDM.

Join over 10,000+ professionals when you subscribe today.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Directories
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing