President Biden’s Peloton raises cyber security concerns

Spies could use its camera and microphone to eavesdrop on confidential conversations

Peloton bike's wheels with a person's feet on the pedals

President Biden's fitness regime may be derailed by cyber security concerns, as reports indicate his Peloton bike could be a risk.

According to a Popular Mechanics report, Max Kilger, director of the data analytics program and associate professor in practice at the University of Texas at San Antonio, said spies could use the bike’s microphone and camera to eavesdrop on confidential discussions.

"Because you're connected to the internet, even though there are firewalls and intrusion detection software ... those things can be gotten around if you’re really good and skilled,” he said. "If you really want that Peloton to be secure, you yank out the camera, you yank out the microphone, and you yank out the networking equipment ... and you basically have a boring bike.”

Garrett Graff, director of the cyber security initiative at the Aspen Institute, told the New York Times: “The threat is real, but it is presumably a manageable risk given enough thought and preparation.”

Related Resource

Managing security risk and compliance in a challenging landscape

How key technology partners grow with your organisation

How to manage security risk and compliance - whitepaperDownload now

Tim Mackey, principal security strategist at the Synopsys CyRC (Cybersecurity Research Centre), told IT Pro we should assume all IoT devices have hardware that allows them to access information beyond their function. 

“That might be a microphone that the designers added in anticipation of a future feature, logging of Bluetooth targets for possible pairing, or interactions with third-party services,” he said.

According to Mackey, while this isn’t an overarching threat for most home users, IoT devices deployed in sensitive areas, like the White House or Congressional residences, should be inspected for any latent hardware and undergo a firmware analysis. 

“This can help to determine whether it has any unpatched security issues, but also to determine if it has any embedded phone home mechanisms or interacts with third-party APIs in an undisclosed manner," Mackey said.

"Since many IoT devices have some form of over the air (OTA) update mechanism for their firmware, understanding the conditions under which that update occurs, what data is sent with a request, and what the updated firmware’s security risks might be are all part of operating any network containing IoT devices.

"Such risks only increase when there are high-profile users of the IoT device where the user might be a target for a well-funded attacker."

Featured Resources

Shining light on new 'cool' cloud technologies and their drawbacks

IONOS Cloud Up! Summit, Cloud Technology Session with Russell Barley

Watch now

Build mobile and web apps faster

Three proven tips to accelerate modern app development

Free download

Reduce the carbon footprint of IT operations up to 88%

A carbon reduction opportunity

Free Download

Comparing serverless and server-based technologies

Determining the total cost of ownership

Free download

Recommended

ID.me and Sterling Check partner on in-person identity verification
identity and access management (IAM)

ID.me and Sterling Check partner on in-person identity verification

19 Nov 2021
Podcast transcript: Can the US take on big tech?
Policy & legislation

Podcast transcript: Can the US take on big tech?

19 Nov 2021
The IT Pro Podcast: Can the US take on big tech?
Policy & legislation

The IT Pro Podcast: Can the US take on big tech?

19 Nov 2021
FTC raises concerns over Nvidia’s Arm purchase
mergers and acquisitions

FTC raises concerns over Nvidia’s Arm purchase

18 Nov 2021

Most Popular

How to move Microsoft's Windows 11 from a hard drive to an SSD
Microsoft Windows

How to move Microsoft's Windows 11 from a hard drive to an SSD

24 Nov 2021
What should you really be asking about your remote access software?
Sponsored

What should you really be asking about your remote access software?

17 Nov 2021
Nike to take customers into the metaverse with 'NIKELAND'
virtualisation

Nike to take customers into the metaverse with 'NIKELAND'

19 Nov 2021