The Internet of Things (IoT) is the name for physical objects that have sensors, software and a network connection, so they can measure the real world, report it, and sometimes act on it. A smart bowl, a tracking collar and a cat flap that unlocks itself are all IoT devices, and so are the sensors in factories, farms and power grids.
What makes something an IoT device
Being 'on the internet' isn't enough: a laptop is on the internet but isn't usually called IoT. An IoT device is an everyday physical object with three extra parts:
- Sensors that measure something physical: movement, location, temperature, weight, light.
- Software, usually on a small, low-power chip, that reads the sensors and decides what to send or do.
- A network connection, such as Wi-Fi, Bluetooth, a mobile network, or a low-power radio protocol built for small devices.
Many devices also have actuators: parts that do something physical, like a motor that turns a feeder, a latch on a cat flap, or a relay that switches a fan on.
Sense, report, respond
IoT is less about the gadgets and more about the loop they make:
- Sense. A smart bowl's weight sensor notices the food level has dropped. A collar's GPS and motion sensor log that the cat is zooming at 3 AM.
- Report. The device sends that data to a server or an app, often as a small message every few seconds or minutes.
- Respond. Something acts on the data. Sometimes that is a person reading an alert. Often it is automatic: too hot, so the fan turns on; a known cat at the door, so the flap unlocks.
The most useful setups chain devices together. The bowl gets low, the app gets a message, and the feeder dispenses food, with no one pressing a button.
How devices talk: publish and subscribe
Small devices have little memory, little power and connections that come and go. Many IoT systems use a messaging protocol called MQTT because it was designed for exactly that. MQTT works on a publish-subscribe model:
- A central server called a broker passes messages around.
- Devices publish messages to named topics, such as
home/kitchen/bowl/level. - Anything that wants those messages subscribes to the topic, and the broker forwards each new message to every subscriber.
The publisher doesn't need to know who is listening. The bowl just reports its level; the app, a logging service and an automation rule can all subscribe without the bowl changing at all.
Here is the bowl-to-feeder chain from the video, running through a broker:
A smart bowl, an automation rule and a feeder working together
Step 1 of 6: The bowl's weight sensor reads 12 per cent, and the bowl publishes the reading to the broker.
A worked example with MQTT
You can try the same pattern on a laptop with Mosquitto, a popular open-source MQTT broker, and its command-line tools. In one terminal, subscribe to everything under the bowl's topics. # is a wildcard meaning 'any topic below this point':
mosquitto_sub -h localhost -t "home/kitchen/bowl/#"In another, play the part of the bowl and publish a reading:
mosquitto_pub -h localhost \
-t "home/kitchen/bowl/level" \
-m '{"percent": 12}'The first terminal prints {"percent": 12} straight away. A real bowl does the same thing from its firmware, and an automation rule is just another subscriber with a condition attached:
def on_level(reading):
if reading["percent"] < 20:
publish("home/kitchen/feeder/cmd",
{"action": "dispense"})Here publish stands for whichever MQTT client library the rule uses. The feeder subscribes to home/kitchen/feeder/cmd and runs its motor when a command arrives.
Why more devices means more risk
Every connected device is another way into your network, which is why IoT matters so much in conversations about attack surfaces. Small devices are often weaker than laptops and phones:
- Default passwords. Some devices ship with the same login on every unit, and owners never change it.
- No updates. A device that never receives firmware updates keeps every bug it was sold with.
- Plain-text traffic. A device that sends readings unencrypted lets anyone on the same network read or fake them.
- A foothold. A hacked smart plug is rarely the goal. It is a way in, from which an attacker can reach more valuable devices on the same network.
The script's three habits are the core of the fix:
- Updates. Install firmware updates, and prefer makers that ship them for years.
- Passwords. Change default logins, and use a unique password per device and account.
- Secure networks. Put IoT devices on their own network, such as a guest Wi-Fi or a separate VLAN, so a compromised bowl can't reach your laptop. It is the same idea as a DMZ: keep riskier devices apart from the ones you care about most. Where devices support it, use encrypted connections, such as MQTT over TLS.
Common mistakes
- Thinking 'it's only a light bulb'. Small devices still sit on your network. Attackers look for the weakest one.
- Relying on the cloud for everything. If the internet goes down or the maker shuts its service, some devices stop working. Prefer devices that keep basic functions working locally.
- Collecting data with no plan. Sensing is only useful if something reports or responds. Decide what each reading should trigger.
- Forgetting about privacy. A collar that logs location around the clock is also a record of where you go. Check what is collected and who can see it.
Key takeaways
- IoT devices are physical objects with sensors, software and a network connection.
- They sense the real world, report data to an app or server, and sometimes respond with an action.
- Devices can work together, often through a publish-subscribe protocol such as MQTT.
- More connected things means more ways for bugs and attackers to get in.
- Keep devices updated, change default passwords and put them on a separate network.