Smart TVs, fridges and light bulbs may stop working next year: Here's why

A smart TV displaying the words "No Signal: Please check the input connection" with a disconnected cable nearby.
(Image credit: Rolandas Grigaitis/Shutterstock)

Your smart TV, set-top box or smart refrigerator might lose most of its internet connections in the next year or two, a digital-security expert warns. Even old Android phones might stop working. By the middle of the decade, we may be looking at a Y2K-scale mass failure of smart-home and Internet of Things devices.

"Within the next 12 months we're going to have lot of things breaking," security researcher and consultant Scott Helme told The Register in an interview yesterday (June 10).

This is because the Certificate Authority root security certificates built into many smart-home and Internet of Things devices are beginning to expire, Helme wrote on his blog. 

Such certificates make it possible for digital devices to establish secure online connections with servers, and almost all internet connections have to be secure these days.

The root certificates can be renewed with firmware updates, but such updates can be hard to find and hard to install by device owners, especially if a smart-home or IoT device has no associated mobile app or administrative interface.

"We're coming to a point in time now where there are lots of CA Root Certificates expiring in the next few years simply because it's been 20+ years since the encrypted Web really started up and that's the lifetime of a Root CA certificate," Helme wrote on his blog Monday (June 8).

No Netflix for you

Helme pointed out that two weeks ago, at 10:48 Universal Time (6:48 a.m. in New York) on May 30, many Roku devices suddenly could not connect to online services and streams because their root certificates had expired. 

Online-syncing service SugarSync, password manager RoboForm and payment-processors Stripe and Speedly were among more than a dozen other services that seemed to have similar issues, according to online reports.

Roku had already made a certificate-updating patch available, but many devices had not installed it. So on May 30, Roku put up a web page instructing owners on how to manually install the necessary system update. 

At least Roku had such an update ready for its users whose devices were affected. Owners of smart-home devices that don't constantly connect to the internet, or whose manufacturers are not aware of the problem, may not be so lucky. 

"Are manufacturers going to release an update?" Helme wondered aloud to The Register in an interview. "Then how is the consumer going to know that they need to install it? Is the TV going to prompt them?"

Beware September 2021

The next big date to watch is Sept. 30, 2021, Helme said, when the root certificates used by many widely used Let's Encrypt certificates are set to expire. If the makers of the affected devices don't push out updates, and the owners of those devices don't install the updates, then the devices will be reduced to old-fashioned "dumb" appliances.

Root certificates are the most basic level of the worldwide "web of trust" system of digital certificates that make secure internet communications, include all online shopping, possible. We're not going to get into the details, but when a root certificate expires, the devices using those certificates will no longer be trusted by other devices on the internet.

So, bingo: A device whose root certificate has expired won't be able to connect to Netflix to stream a movie, or to Amazon to make an online purchase, or to Gmail to view the user's messages. 

The most vulnerable devices

Helme said users of Windows computers won't need to worry, as Microsoft has built in constant updating of certificates. Web browsers on most platforms get certificate updates regularly. And because iPhones get system updates so frequently, "I wouldn't be too concerned about this problem if I was an iOS user (I am)."

"But it looks like Android users might have some concerns in the not too distant future," Helme added. 

That's because as of April 2020, nearly 40% of all Android devices visible to Google were using now-unsupported Android versions such as Nougat or earlier. (These statistics don't include Amazon Fire tablets, Xiaomi Mi phones or other devices that run non-Google versions of Android.) Many of those older devices may soon lose the ability to connect to most app servers and websites.

[UPDATE: Thanks to Android's lax enforcement of certificate expiration dates, Let's Encrypt has crafted a workaround that will keep all devices running Android 2.3.6 or later in business until September 2024.]

"Now, mobile apps and browsers aren't generally too much of a problem," Helme wrote on his blog, "but Smart TVs, well, they're a whole different game."

Helme said smart TVs rarely get updates once they're out of the box, and usually only to remove old features. Many models use root certificates that are so old, he said, that even new models had trouble connecting to the BBC's iPlayer service, which needs to verify that the receiving TV is indeed in the U.K. 

Missing the update window and getting locked out

Because some smart-home devices -- for example, a smart light bulb or wall-outlet plug -- can go for months without connecting to the internet, Helme fears that many devices will miss the window between when an update that installs a new root certificate is made available and when the old certificates expire. 

After the windows passes, those devices that are still using the old root certificates won't even be able to connect to their own manufacturer's servers to install the firmware updates that would fix the problem.

"I thought I should start highlighting this now in that we do have a little bit of time," Helme told The Register. "This is going to be a problem; we are not on top of this."

TOPICS
Paul Wagenseil

Paul Wagenseil is a senior editor at Tom's Guide focused on security and privacy. He has also been a dishwasher, fry cook, long-haul driver, code monkey and video editor. He's been rooting around in the information-security space for more than 15 years at FoxNews.com, SecurityNewsDaily, TechNewsDaily and Tom's Guide, has presented talks at the ShmooCon, DerbyCon and BSides Las Vegas hacker conferences, shown up in random TV news spots and even moderated a panel discussion at the CEDIA home-technology conference. You can follow his rants on Twitter at @snd_wagenseil.

Read more
Windows
240 million Windows 10 users are vulnerable to six different hacker exploits — protect yourself now
Roast turkey on dining table, with Christmas decorations in background
Your roast turkey might be stealing your data
Graphic of fibre optic cables attacking code
An estimated 46,000 VPN servers are vulnerable to being hijacked
A laptop on a windowsill in the middle of a Windows update
Microsoft is ending support for Windows 10 soon — 5 ways to make sure your PC is secure
Malware
The top cyber threats to watch out for in 2025
An Android bot next to an Android TV remote
Millions of Android TVs hijacked in massive botnet — how to see if yours is at risk
Latest in Tech
Casetify Bounce Suitcase
I ditched my Away Carry-On for a bright red suitcase made by a phone case brand, and I was shocked by how much I liked it
Columbia Sportswear and Intuitive Machines partnership
Columbia Sportswear’s UV-blocking technology just landed on the moon, and I spoke to the materials scientist who designed it
iPhone 16e review.
What Tom’s Guide tested this week — the iPhone 16e is the most polarizing phone of the year
A split screen photo showing a coffee grinder on one side and a smart watch on the other
What Tom’s Guide tested this week: Sony, OnePlus, Corsair and more
A split screen image showing an instant camera on the left and a Dyson vacuum on the right
What Tom’s Guide tested this week: Expert reviews of Dyson, Insta360 and more
A composite of Soundcore Space One Pro headphones and Sony ZV-1F vlogging camera
What Tom’s Guide tested this week: 5 products that won our expert reviewers’ hearts
Latest in News
AirPods Max in various colors
AirPods Max is getting a big update with lossless audio and ultra-low latency — here's how it works
A mosquito resting on a plant
Experts predict a spring surge in these 9 pest populations — here's what's forecast for your area
Apple Watch SE (2022) shown on wrist
Apple Watch SE 3 reportedly in ’serious jeopardy’ — here’s why
Galaxy S25 Plus held in the hand.
Samsung could delay One UI 7’s release in the US — here’s what we know
Claude AI on phone sitting on keyboard
Claude 3.7 Sonnet now supports real-time web searching — but there's a catch
Nintendo Switch 2
Nintendo Switch 2 pre-order date just tipped — here's when you might be able to buy