How did researchers turn networked light bulbs into a self-spreading worm, and which assumption did the attack break?
By recovering the shared symmetric firmware-protection key shared by every lamp of one model, they could authenticate malicious over-the-air updates — and because lamps accept updates from nearby lamps over ZigBee, the infection spread by physical proximity alone, with no internet involved.
* Extracting a shared firmware key enables malicious updates; nearby infected lamps propagate the worm over Zigbee across controller boundaries, without an Internet path. *
The setup: Philips Hue smart lamps deployed across a city, each speaking ZigBee (a low-power mesh radio built on IEEE 802.15.4) to a bridge and to one another. Researchers built a worm that jumps from lamp to lamp using that radio and nothing else.
Three elements made it work:
- A correlation power analysis attack recovered the shared firmware key. A device's power consumption varies with the data it processes, so measuring the power trace while it performs cryptography leaks the key bits — this is differential and correlation power analysis, a side-channel attack. That broke the boot loader's protection and let the researchers encrypt, authenticate and upload firmware the lamps would accept. The fatal design decision was that a single key was shared between all lamps of a given model: recover it once, own the entire product line.
- Control from a distance without custom hardware, using the lamps' own unmonitored and unprotected ZigBee communication rather than any internet path.
- Spread by physical proximity alone, disregarding the established network structure of lamps and controllers. A lamp does not need to be on the attacker's network — it only needs to be near an already-infected lamp.
The assumption that broke was the perimeter itself. Defences here watch the internet-facing bridge, but the worm never used the internet: it propagated through an air gap of a few metres, across a city, as a chain reaction. (IoT Goes Nuclear: Creating a ZigBee Chain Reaction, Ronen et al., IEEE Security & Privacy 2017.)
Tip: two transferable lessons. Never share one key across a product line — per-device keys turn a catastrophe into an incident. And remember that in a dense deployment, proximity is a network, whether or not you modelled it as one.
Go deeper:
-
Wikipedia — Zigbee — the radio the worm travelled on: a 128-bit-keyed mesh with a trust centre, and the weaknesses later versions had to close.
-
Wikipedia — Power analysis — how measuring a device's current draw recovers key bits, from simple visual inspection to the differential and correlation variants, plus the countermeasures.
-
Ronen et al. — IoT Goes Nuclear — the original researchers explain proximity propagation and recovery of the shared firmware key.