Why Pre-Owned IoT Devices Are a Security Blind Spot
A factory reset on a returned router clears the Wi-Fi password. It does not touch the firmware. That gap is what Josephs tested.
He illustrated how IoT failures chain at a conference, he escaped a kiosk, grabbed the Wi-Fi password, scanned the network, and found badge printers on ports 80 and 443. The credentials?
“the username was admin and the password was admin, of course” — Matei Josephs
Four failures: broken kiosk mode, flat network, default credentials, a volunteer who handed over the badge anyway. Pre-owned IoT devices sold through major retailers run the same risk. A device returned by one buyer reaches the next with no firmware inspection between them.
Research Hypothesis and Device Selection
“retailers do not implement enough checks to prevent reselling backdoor devices” — Matei Josephs
That hypothesis drove a four-step test: identify devices with writable firmware, order them, modify the firmware, return them, then see if they reappear as pre-owned. Josephs picked TP-Link routers because the OpenWRT reflash process is public and the hardware is cheap enough to break. He ordered 15 units across five retailers, three per retailer, to test whether inspection practices varied. The payload was a curl to an IP he controlled, not a full backdoor. He built a Web scraper monitors retailer listings for re-listed devices (10:33) to buy the devices back before they reached anyone else.
Firmware Modification Methodology
Josephs pulled firmware off the SPI chip, ran binwalk to map the file system, then planted a service that beaconed every 10 minutes to an IP he controlled with a per-device identifier. A self-destruct counter cleared it after 3,000 requests, about 21 days. The web UI rejected unsigned images. SPI reflash failed on unsteady hands. He showed TFTP recovery mode used to flash modified firmware (16:48) as the workaround: on boot the router queries a predefined local IP, fetches whatever it finds, and writes it without a signature check. A factory reset afterward cleared only configuration files, leaving the backdoor intact.
Return, Resale, and Callback Results
All five retailers accepted the returns without inspection. No questions, no firmware checks. One device had a broken seal; the courier still took it. None of the routers called back during that window, which Josephs read as confirmation the retailers only verified that LEDs turned on.
Once the web scraper flagged re-listings, he bought back what he could. He showed 13 of 15 modified routers recovered after resale (19:08) on screen. The two he missed kept calling back from live networks for nearly a month before the self-restore timer fired and wiped the implant.
“There is just an added feature, my little back door.” — Matei Josephs
Attack Impact and Scaled Threat Models
Routers were the test case, not the ceiling. A modified vacuum robot ships a live camera feed to an attacker’s server. A surveillance camera gets firmware that forces the feed public regardless of user settings. A botnet builds from tens of residential IPs. Josephs’s 15 devices tripped retailer fraud teams, but a threat actor who opens a legitimate-looking online store, buys thousands of units from reputable vendors, and prices them just below market never triggers those alarms. The attack scales, and it targets by name: the buyer’s address, employer, and order history all come with the purchase.
Mitigations and Responsible Disclosure
Vendor-side fixes exist on paper: locked bootloaders, secure boot, encrypted firmware, tamper-evident seals. Fewer than half the security professionals in the room had ever updated firmware on a device. End users won’t.
“if you are targeted, you will be targeted anyway” — Matei Josephs
The NSA’s TAO group has intercepted deliveries and modified hardware before forwarding them. No consumer habit stops that. Josephs’s advice: buy from reputable vendors, and push bug bounty programs to bring physical-access attacks in scope. Most programs exclude them today. This research proves they shouldn’t.
Q&A
How did you come up with the idea, and why didn’t you leave your own logo in the setup process to see if retailers would notice? The idea grew organically from conference videos; he deliberately omitted his logo from the final devices, partly to avoid tipping off retailers and partly for legal reasons (he never contacted any of the retailers he tested). ▶ 27:40
Would this concept apply to Android phones, and could retailers show a bootloader-unlocked warning the way Android does? He had no firm answer and said the real gap is person-to-person resale (Facebook Marketplace), where almost no buyer would spot a tampered device regardless of any retailer-side warning. ▶ 29:17
Notable Quotes
the username was admin and the password was admin, of course Matei Josephs · ▶ 3:55
retailers do not implement enough checks to prevent reselling backdoor devices Matei Josephs · ▶ 9:23
There is just an added feature, my little back door. Matei Josephs · ▶ 20:56
if you are targeted, you will be targeted anyway Matei Josephs · ▶ 26:02
Key Takeaways
- Never trust a factory reset to sanitize IoT firmware — it only clears configuration, not the file system.
- Push vendors to include physical-access attacks in bug bounty scope; this talk proves the threat is real.
- Any open-firmware IoT device sold on the second-hand market can be a persistent, targeted implant.
About the Speaker
Matei Josephs
Matei is a cybersecurity researcher with experience in Penetration Testing, Threat Hunting and Vulnerability Management. Matei discovered several CVEs across the past 2 years and recently built HiveHack alongside his wife, Alexa.