• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

After forcing workers back to the office, Goldman Sachs and JPMorgan Chase are now letting their staff work remotely—but only for the World Cup

2

The Pentagon said Iran War costs $29 billion,but the real cost is closer to $200 billion—and counting

3

Markets tumble worldwide as Fed resets expectations: $400 billion wiped off SpaceX stock

1

After forcing workers back to the office, Goldman Sachs and JPMorgan Chase are now letting their staff work remotely—but only for the World Cup

2

The Pentagon said Iran War costs $29 billion,but the real cost is closer to $200 billion—and counting

3

Markets tumble worldwide as Fed resets expectations: $400 billion wiped off SpaceX stock
Nest

Why Are Security Cameras Getting Hacked? Your Sloppy Password Management, Nest Says

By
John Patrick Pullen
John Patrick Pullen
Down Arrow Button Icon
By
John Patrick Pullen
John Patrick Pullen
Down Arrow Button Icon
February 6, 2019, 4:29 PM ET
Add Fortune on Google for similar content.

Over the past few weeks, a pair of horrifying headlines have turned unwarranted fears about smart homes into reality:

  • “‘5 minutes of sheer terror’: Hackers infiltrate East Bay family’s Nest surveillance camera, send warning of incoming North Korea missile attack,” reported the Mercury News.
  • “Homeowner’s Blood ‘Ran Cold’ as Smart Cameras, Thermostat Hacked, He Says,” wrote Chicago’s NBC5.

But today, Nest released its counter—an email to customers saying definitively, “Nest security has not been breached or compromised.”

So what’s going on with these terrifying intrusions of privacy? Plainly stated, Nest is placing the blame on owners of its products who have been reckless with their passwords. But that shouldn’t be the end of the issue. The smart home company also deserves a slice of the blame pie.

According to the email from Rishi Chandra, the company’s vice president and general manager, Nest users may have been targeted because the Internet is overflowing with email addresses and passwords that have been sucked up in countless data breaches of other, less tech-savvy companies.

“For example, if you use your Nest password for a shopping site account and the site is breached, your login information could end up in the wrong hands,” writes Chandra. “From there, people with access to your credentials can cause the kind of issues we’ve seen recently.”

Faceless Dark Web hackers selling login info online makes for a convenient scapegoat—even if there is an abundance of truth to Nest’s claims. But a vulnerability that large and obvious shouldn’t stop the one of world’s tech-savviest companies from buttoning up that hole as tightly as possible.

In the email, Chandra says Nest, a part of Google and one of the world’s largest tech conglomerates, Alphabet, proactively scours the web for accounts compromised by breaches and prevents passwords that appear on known lists, a proactive step that sounds similar to Google’s new Password Checkup tool. It also recommends that users enable two-step verification (also known as two-factor authentication, or 2FA) and use strong passwords to block unauthorized users from accessing their camera, thermostats, smoke detectors, and other smart home devices.

These are smart tactics, to be sure, but they aren’t best practices. As a long-time Nest user, I cannot recall ever being prompted by the app or website to sign up for 2FA. And until I started writing this piece, I have never changed my password, dating back to at least 2016. In fact, though Nest currently requires a string of “at least 8 characters, including upper and lowercase letters, numbers, and symbols,” my now-defunct password didn’t meet those requirements. A better suggestion would be for Nest to require its customers to employ 2FA. In addition, it could issue a mass-password reset, prompting old users like me to get up-to-date on the company’s requirements.

Taking the security a step further, the company also could integrate support for password management apps like 1Password or LastPass into the Nest app. These kinds of password vaults make and store passwords so complex that they’re nearly impossible to crack (or remember). I used one myself to make my Nest hacker-proof, just now.

But in my defense, the reason I originally recycled the password for my Nest account wasn’t just because I’m lazy. It’s because oftentimes Nest camera feeds fail, and the only thing you can do to reboot them is to log out of the app. When it’s 3 a.m. and I want to check in on my sleeping children, plugging in a string of random characters to reset the app is untenable. But, that’s the state of Nest’s security today, I guess.

Nest did not reply to a request for comment about its email customers, so it’s unclear if the company has ever prompted users to sign up for 2FA, beyond announcing the security feature in 2017. What is clear is that the increasingly popular security measure is not required by an app that can allow hackers to peer into a house, crank up (or lower) its heat, and test its smoke alarms. In plain terms, that’s dangerous.

In recent years, Nest has had its share of growing pains, but it has grown nonetheless. Adding products, services, and features has been necessary to keep it at the top of the smart home category. So in the face of such horror stories, why doesn’t Nest require something as simple as a password reset for all its users, have its app push 2FA security at login, or—even bolder—just require that users implement it?

Perhaps because it’s easier and cheaper simply to blame users.

About the Author
By John Patrick Pullen
See full bioRight Arrow Button Icon
Add Fortune on Google for similar content.

Latest in

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in

Taktile cofounders Maik Taro Wehmeyer (left) and Maximilian Eber (right) stand side by side, smiling at the camera.
Startups & VentureVenture Capital
Exclusive: Taktile raises $110 million from Goldman Sachs, Tiger Global to automate high-stakes financial decisions 
By Camila Grigera NaónJune 24, 2026
1 hour ago
price-of-oil-06-23-2026
Personal FinanceOil
Current price of oil as of June 24, 2026
By Joseph HostetlerJune 24, 2026
1 hour ago
Sarah Youngwood, EVP and CFO at Nasdaq.
AICFO Daily
Nasdaq’s CFO says leaders must learn AI—not just their teams
By Sheryl EstradaJune 24, 2026
1 hour ago
Current price of silver as of Wednesday, June 24, 2026
Personal Financesilver
Current price of silver as of Wednesday, June 24, 2026
By Joseph HostetlerJune 24, 2026
1 hour ago
steve
Commentary250 Years of Innovation
Steve Case: America was built by entrepreneurs. Here’s how we keep that edge for the next 250 years
By Steve CaseJune 24, 2026
2 hours ago
(left to right) Andrew Berman, Tal Peretz, and Vitor Balocco
AIVenture Capital
Exclusive: Vinod Khosla wanted ‘every available dollar’ of Runlayer’s funding round. It just raised $30 million to govern the agent workforce
By Lily Mae LazarusJune 24, 2026
2 hours ago

Most Popular

After forcing workers back to the office, Goldman Sachs and JPMorgan Chase are now letting their staff work remotely—but only for the World Cup
Success
After forcing workers back to the office, Goldman Sachs and JPMorgan Chase are now letting their staff work remotely—but only for the World Cup
By Orianna Rosa RoyleJune 23, 2026
1 day ago
The Pentagon said Iran War costs $29 billion,but the real cost is closer to $200 billion—and counting
Economy
The Pentagon said Iran War costs $29 billion,but the real cost is closer to $200 billion—and counting
By Jacqueline MunisJune 24, 2026
7 hours ago
Markets tumble worldwide as Fed resets expectations: $400 billion wiped off SpaceX stock
Banking
Markets tumble worldwide as Fed resets expectations: $400 billion wiped off SpaceX stock
By Jim EdwardsJune 23, 2026
1 day ago
Current price of oil as of June 23, 2026
Personal Finance
Current price of oil as of June 23, 2026
By Joseph HostetlerJune 23, 2026
1 day ago
Texas and Charlotte used to build huge McMansions—now they're copying the California design tricks they once mocked
Real Estate
Texas and Charlotte used to build huge McMansions—now they're copying the California design tricks they once mocked
By Sydney LakeJune 22, 2026
2 days ago
Current price of gold as of June 23, 2026
Personal Finance
Current price of gold as of June 23, 2026
By Danny BakstJune 23, 2026
1 day ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.