Congress has cut federal funding for public media — a $3.4 million loss for LAist. We count on readers like you to protect our nonprofit newsroom. Become a monthly member and sustain local journalism.
An Experiment Shows How Quickly The Internet Of Things Can Be Hacked
The Internet can be a dangerous place. Hackers, bots and viruses are prowling the Web trying to turn your machines into zombies.
Last month, a massive network of hacked devices helped temporarily shut down Twitter and other websites. Hackers used a virus called Mirai to target Dyn, a major Internet infrastructure company, in a sophisticated denial-of-service attack — when insecure Internet-connected devices are directed to barrage a target with data until it shuts down.
Andrew McGill, a reporter at The Atlantic, devised an experiment to find out how vulnerable our devices are to hackers. He built a virtual Internet-connected toaster, put it online and waited to see how quickly it would take for hackers to attempt to breach it. They found him much faster than he expected.
"Well, I had talked to some experts, and I was fully expecting maybe a week, maybe never, certainly not less than a day," McGill told NPR's Ari Shapiro. "But it came a lot sooner. It was 41 minutes. [The second attempt was] within 10 or 15 minutes [and the third was] another 10 or 15."
Interview Highlights
On the toaster experiment
Well, I kind of wanted to see if I put something unsecured on the Internet — if I just plugged it in — how long would it take for a hacker to find it and hack into it?
So when this botnet took down all these computers a few weeks ago, there were thousands and thousands of devices that had been compromised, but I always had kind of thought, "You know, if I'm lax with security in my own personal life, it won't be a big deal because the Internet is huge." You know, there's millions, and actually billions, of IP addresses, each one with a computer behind it. Why would a hacker find me?
So I kind of devised this thing where I built a virtual Internet-connected toaster, as I called it, and I put it online and saw how quickly it took for someone to compromise it.
On how hackers found him so quickly
This is the thing: People probably think of a hacker as behind their keyboard and prowling for folks that are vulnerable. Really they write scripts and they write bots that do that prowling for them.
They will actually randomly scan ports, which are essentially ways into computers, across the entire Internet. And the thing is, you know, our technology has advanced to a degree that you can actually reasonably expect to scan the entire Internet in a few hours.
On why certain devices are more vulnerable than others
This is the thing that I always want to make clear to the readers is that if you are plugging in your Internet toaster into your home Wi-Fi or into your home router, you already have a layer of security and that's your router. It's essentially a device that makes sure that incoming connections don't get through to your devices that would be malicious.
This [device] was a little bit different. This mimicked more the simpler devices that were attacked in the Mirai botnet. They're more vulnerable because they don't have that layer of protection between them and the modem, which connects directly to the Internet. So your average consumer has that layer of protection, but that protection can be breached sometimes, too.
On identifying the location of hacking attempts
I could log the IP addresses, and you could actually geo-locate those to see where they're coming from. You know, I don't really trust those because you can easily spoof an IP or have a proxy server to make it look like you're coming from somewhere else, but they were all over the map. There actually was one as close as Ohio, which I thought was funny.
On how to protect your devices from hacking
For the average consumer, we've figured this out to some degree. We have basic security in place in modern devices that screen out the most obvious attacks. Really getting phished, if you will, is more of a problem where you are tricked in surrendering your password or username to a common service. If you plug in your webcam into your router or to your Wi-Fi, you're relatively safe.
I think the biggest security concern for folks at home would be if their router actually is old, it might have an easily guessed password that someone could gain control. Most modern devices don't have that problem, but that certainly is a concern for older devices.
Copyright 2023 NPR. To see more, visit https://www.npr.org.
As Editor-in-Chief of our newsroom, I’m extremely proud of the work our top-notch journalists are doing here at LAist. We’re doing more hard-hitting watchdog journalism than ever before — powerful reporting on the economy, elections, climate and the homelessness crisis that is making a difference in your lives. At the same time, it’s never been more difficult to maintain a paywall-free, independent news source that informs, inspires, and engages everyone.
Simply put, we cannot do this essential work without your help. Federal funding for public media has been clawed back by Congress and that means LAist has lost $3.4 million in federal funding over the next two years. So we’re asking for your help. LAist has been there for you and we’re asking you to be here for us.
We rely on donations from readers like you to stay independent, which keeps our nonprofit newsroom strong and accountable to you.
No matter where you stand on the political spectrum, press freedom is at the core of keeping our nation free and fair. And as the landscape of free press changes, LAist will remain a voice you know and trust, but the amount of reader support we receive will help determine how strong of a newsroom we are going forward to cover the important news from our community.
Please take action today to support your trusted source for local news with a donation that makes sense for your budget.
Thank you for your generous support and believing in independent news.

-
The new ordinance applies to certain grocers operating in the city and has led to some self-checkout lanes to shutter.
-
Children asked to waive right to see a judge in exchange for $2,500
-
There’s still a lot to be determined as the refinery, which supplies about one-fifth of Southern California's vehicle fuels, works to restore production and as data is collected.
-
The FCC voted to end E-Rate discounts for library hotspot lending and school bus Wi-Fi.
-
About half the Pacific Airshow’s 2025 lineup has been grounded because of the federal government shutdown.
-
USC says it’s reviewing the letter also sent to eight other prestigious schools nationwide. California's governor vowed that any California universities that sign will lose state funding.