Comprehensive Security Assessment of a Smart Home IoT Platform

End-to-end IoT penetration testing covering devices, firmware, cloud infrastructure, applications and source code ahead of an acquisition.

Location

USA

Background

The company under assessment develops a connected smart home platform.  The connected smart home platform includes:

  • IoT sensors collecting data in users’ homes
  • Cloud services collecting and processing sensor readings
  • Mobile applications for end users
  • Web interface for managing the installed device base

The components work as one connected system, so effective IoT penetration testing had to cover the wider ecosystem rather than assess each component in isolation.

Our client was preparing to acquire this company and opened a technical due diligence process before closing the deal. Financial and legal checks cover only a part of what matters in a technology business, so the client asked for an independent security assessment of the platform to understand what they were actually purchasing, what risks it would inherit and how much remediation work would follow the integration.

An assessment of this kind is performed outside the company by design. The team that built a system knows it best, and an external review looks at the same system differently and finds additional issues. For the client the independence of the assessment was part of its value, because the findings would go to its own advisors and inform decisions about the acquisition rather than an internal remediation plan.

Challenge

The vendor does not control every part of an IoT platform, because the sensors belong to the customers who bought them. Anyone who owns a sensor can open the case, connect to the board and read out the firmware and the keys stored inside, and no setting on the cloud side prevents that. For this reason, the IoT penetration testing scope had to include the physical devices themselves, not only the services they communicate with.

Testing the components separately would not have produced a reliable answer. The device, the cloud, and the mobile application exchange requests continuously, and only an assessment that covers all three shows whether each of them verifies who the request came from.

Solution overview

End-to-End IoT Penetration Testing

Our IoT penetration testing covered the platform as one connected ecosystem: physical devices, firmware, source code, AWS infrastructure, web and mobile applications, and personal data processes. Ten physical devices were tested hands-on.

The project ran for three months. A standard penetration test of a web or mobile application takes about a month, and a scope like this one takes two to three. Hardware analysis, source code review and the cloud audit ran in parallel, and the findings of each showed the others where to look.

Why Hardware Matters in IoT Penetration Testing

The IoT penetration testing started with the hardware itself and followed the principles of the UL 2900-1 standard for software cybersecurity in network-connectable products. Our engineers inspected the devices for tamper resistance, located and tested debug interfaces such as UART, JTAG, SPI and I2C, and extracted the contents of the accessible memory. We then recovered the firmware, reverse engineered it and searched for hardcoded credentials, cryptographic keys and certificates, and we assessed how the device verifies firmware integrity and how it accepts updates.

We gave the same attention to how the device behaves on the network. We identified the exposed services and open ports, tested the supported protocols including MQTT, CoAP and HTTP, and analysed the traffic for sensitive information transmitted in clear text, and we validated how a device proves its identity to the cloud and how the cloud proves its identity to the device.

Secure code review as a separate deliverable

Alongside the testing, our engineers reviewed approximately 70,000 lines of application and firmware source code, combining manual analysis with automated scanning. Code review finds a different class of problem than testing does, because a penetration test discovers what an attacker can exploit today and a code review discovers what will become exploitable after the next release.

We looked for insecure coding practices and memory safety issues, hardcoded credentials, API keys and secrets, weaknesses in authentication, authorization and session management, gaps in input validation, outdated third party libraries with known vulnerabilities, and cryptographic implementations that store or generate keys incorrectly. For the client this part of the work gave more than the vulnerability list, because the state of the code shows how the engineering team works and how much effort the platform will require after the acquisition.

Cloud, applications and data handling

The AWS environment audit covered identity and access management, network architecture, data storage and the serverless components. We reviewed IAM users, roles and policies against the principle of least privilege, examined VPC design, security groups and network segmentation, checked S3 buckets and RDS databases for public exposure and encryption settings, and simulated cloud attack scenarios to establish whether an attacker who compromises one identity can escalate privileges and move laterally across the environment.

The web platform was assessed using a white box approach aligned with the OWASP testing methodology, which gave deeper coverage and more accurate validation of exploitability than black box testing produces. Mobile applications for Android and iOS were reviewed for local storage security and for the way they handle credentials, tokens and cryptographic material. The GDPR assessment examined personal data handling processes, retention and access control practices, and identified the compliance gaps together with the business risk attached to each.

Standards and qualification requirements

We work primarily to the OWASP standards, which cover web applications, mobile applications and, in recent years, IoT systems, and we supplement them with additional checks where the architecture requires it. The client set a formal requirement for this project and asked that the assessment be performed by a specialist holding the Certified Ethical Hacker certification, because its own advisors would review the report.

Results

3monthsof assessment covering devices, cloud, applications and code
10devicestested on the bench, from physical inspection to firmware analysis
70,000linesof source code reviewed manually and with automated tooling

The client received a prioritized list of findings across the whole platform in time to use it in the transaction, and the acquisition proceeded as planned.

The findings in this case covered every part of the platform and included excessive privileges in AWS IAM policies that opened privilege escalation paths, weaknesses in web application authentication and access control, firmware issues affecting device integrity, hardcoded secrets found during code review, and personal data handling practices that fell short of GDPR requirements.

Each finding was ranked by risk and potential business impact rather than by technical severity alone, so the client could make acquisition and remediation decisions on the basis of what the findings meant for the business.

OutcomeWhat it gave the client
Independent security validationThe assessment came from outside the target company, so the client could rely on it in the acquisition process
Technical and compliance risks identified before closingThe client knew about the technical and GDPR risks before the deal closed
Visibility into development practices and code qualityThe code review showed how the development team writes and maintains the platform, which a vulnerability list alone does not reveal
Remediation and integration requirementsThe client could estimate the work the platform would need after the acquisition, both to fix the findings and to integrate the system

About IBA Group

IBA Group has been delivering custom projects since 1993 for clients in over 50 countries. Our security practice covers penetration testing across web, mobile, network, cloud, infrastructure, LLM and IoT environments, as well as source code and architecture reviews, red team and social engineering assessments, phishing simulations, OSINT, and digital forensics and incident investigations.

Want to hear it from the client?

Request a reference and we will send you what the company said about our work.