And another anniversary: The BOSCH Smart Home Controller together with the associated mobile application BOSCH Smart Home have been in our laboratories for the 5th time in a row this year for certification. And as in previous years, the system successfully passed all tests without any notable points of criticism, and will thus receive the “Approved Smart Home Product” certificate for 2021 as well.
The Smart Home Controller (tested in firmware version 10.2.2164-20551) itself is still adequately secured in the current version and has no weak points worth mentioning. Our static analysis of the device did not reveal any potentially exploitable information for a possible attacker: The device does not have any undocumented interfaces or ports, and access is also otherwise secured in the best manner. The communication has always been encrypted, and all our attempts to trick the device’s communication via man-in-the-middle attacks or similar were not successful in the test. The device reliably detects such attempts and then denies communication.
As for the mobile apps on Android (v10.1.2061) and iOS (v10.1.1), they have even further improved in the current version. For example, one of the previously included Google trackers (AdMob) has been removed, thus limiting the app’s data collection capabilities. Only the Google Firebase Analytics tracker is still included. However, this tracker can be found in practically every app nowadays and is used to collect anonymous data for usage statistics. With the BOSCH Smart Home system, however, the user is informed in detail about the presence and function of the tracker and has the option of opting out of the data collection – exemplary!
Overall, the BOSCH Smart Home System passes all tests, as in previous years, without any significant problems and accordingly receives for the 5th time in a row highly deserved our certificate “Tested Smart Home Product”. Congratulations and good luck for the next 5 years!