Sony Pixel Power calrec Sony

HP Study Finds Alarming Vulnerabilities with Internet of ings (IoT) Home Security Systems

10/02/2015

HP Study Finds Alarming Vulnerabilities with Internet of Things (IoT) Home Security SystemsHP Fortify OnDemand finds that 100 percent of top security systems studied display significant security deficiencies

PALO ALTO, Calif., February 10, 2015 HP today released results of a security testingstudy revealing that owners of Internet-connected home security systems may not be the only ones monitoring their homes. The study found that 100 percent of the studied devices used in home security contain significant vulnerabilities, including password security, encryption and authentication issues.

Home security systems, such as video cameras and motion detectors, have gained popularity as they have joined the booming Internet of Things (IoT) market and have grown in convenience. Gartner, Inc. forecasts that 4.9 billion connected things will be in use in 2015, up 30 percent from 2014, and will reach 25 billion by 2020.(1) The new HP study reveals how ill-equipped the market is from a security standpoint for the magnitude of growth expected around IoT.

Manufacturers are quickly bringing to market connected security systems that deliver remote monitoring capabilities. The network connectivity and access necessary for remote monitoring presents new security concerns that did not exist for the previous generation of systems that have no internet connectivity.

The HP study questions whether connected security devices actually make our homes safer or put them at more risk by providing easier electronic access via insecure IoT products. HP leveraged HP Fortify on Demand to assess 10 home security IoT devices along with their cloud and mobile application components, uncovering that none of the systems required the use of a strong password and 100 percent of the systems failed to offer two-factor authentication.

The most common and easily addressable security issues reported include:

Insufficient authorization: All systems that included their cloud-based web interfaces and mobile interfaces failed to require passwords of sufficient complexity and length with most only requiring a six character alphanumeric password. All systems also lacked the ability to lock out accounts after a certain number of failed attempts.

Insecure Interfaces: All cloud-based web interfaces tested exhibited security concerns enabling a potential attacker to gain account access through account harvesting which uses three application flaws; account enumeration, weak password policy and lack of account lockout. Similarly five of the ten systems tested exhibited account harvesting concerns with their mobile application interface exposing consumers to similar risks.

Privacy Concerns: All systems collected some form of personal information such as name, address, date of birth, phone number and even credit card numbers. Exposure of this personal information is of concern given the account harvesting issues across all systems. It is also worth noting that the use of video is a key feature of many home security systems with viewing available via mobile applications and cloud-based web interfaces. The privacy of video images from inside the home becomes an added concern.

Lack of transport encryption: While all systems implemented transport encryption such as SSL/TLS, many of the cloud connections remain vulnerable to attacks (e.g. POODLE attack). The importance of properly configured transport encryption is especially important since security is a primary function of these systems.

As we continue to embrace the convenience and availability of connected devices, we must understand how vulnerable they could make our homes and families, said Jason Schmitt (@raidschmitt), vice president and general manager, Fortify, Enterprise Security Products (@HPsecurity), HP. With ten of the top security systems lacking fundamental security features, consumers must be diligent about adopting simple and practical security measures when they're available, and device manufacturers must take ownership in building security into their products to avoid exposing their customers unknowingly to serious threats.

As IoT product manufacturers work to incorporate much needed security measures, consumers are urged to consider security when choosing a monitoring system for their home. Implementing secure home networks before adding insecure IoT devices, instituting complex passwords, account lockouts and two-factor authentication are only a few measures consumers can take to make their IoT experience more secure. Legislators are also getting involved, with the U.S. Federal Trade Commission releasing a recent report analyzing the balance between security and privacy concerns with development of the IoT devices.

For more information, visit the first report in this IoT series, 2014 HP Internet of Things Research Study, which reviews the security of the top 10 most common IoT devices. Additionally, the most recent HP Security Briefing, Episode 20: The Internet of Things: A Security Overview looks at how the advent of millions of connected devices affects network security from a practical standpoint.

Methodology

Conducted by HP Fortify and leveraging HP Fortify on Demand, HP's Home Security Systems study tested 10 of the most commonly used home security IoT devices for vulnerabilities using standard security testing techniques that combined manual testing along with the use of automated tools. Devices and their components were assessed based on the OWASP Internet of Things Top 10 and the specific vulnerabilities associated with each top 10 category. The resulting data and percentages in this report were drawn from the 10 IoT systems tested. Given the popularity and similarity among the 10 devices, HP Fortify believes the results provide a good indicator of where the market currently stands as it relates to security and the Internet of Things.

Additio
LINK: http://www8.hp.com/us/en/hp-news/press-release.html?id=1909050...
See more stories from hp

Most recent headlines

04/09/2025

Monumental Sports & Entertainment and Dalet Win Prestigious 2025 NAB Show Project of the Year Award

Monumental Sports & Entertainment (MSE), in collaboration with Dalet, has been a...

19/04/2025

SDVI Earns Both Product and Project of the Year Awards at...

SDVI, the leading platform provider for cloud-native media supply chains, today announced that the company earned multiple awards at the 2025 NAB Show, with two...

19/04/2025

Ateliere Announces CEO Transition

Ateliere Creative Technologies, a leading GenAI media software solutions company, today announced that Dan Goman has stepped down as CEO and David Bortis, Ateli...

19/04/2025

Marshall CV574 Miniature 4K UHD Camera Revolutionizes Off...

As Director of Media and Aerial Production at Terrible Herbst Motorsports, Bryan Moore is setting new standards in off-road racing media coverage thanks to his ...

19/04/2025

Lightware Launches Dual Screen Extended Desktop Taurus

A next-generation collaboration device that redefines connectivity for meeting environments Lightware, an industry-leading manufacturer of signal management so...

19/04/2025

Calrec Wins 2025 NAB Show Product of the Year Award for N...

Calrec is today announcing that its True Control 2.0 is a Remote Production winner in the 2025 NAB Show Product of the Year Awards. This official awards program...

19/04/2025

Appear and NBCUniversal Win Project of the Year at NAB Sh...

Appear, a global leader in live production technology, proudly announces it has been recognised alongside NBCUniversal with the prestigious NAB Show Delivery Pr...

19/04/2025

Deity Microphones Announces The Deity THEOS DIFB at NAB 2...

Deity Microphones, a leader in innovative audio equipment, is proud to announce the expected release of our Ultra-Wide Band IFB to the market. The THEOS DIFB wi...

19/04/2025

LiveU IQ Technology Delivers Breakthrough Network Perform...

A world renowned broadcaster and long-standing LiveU customer has successfully completed a series of live connectivity tests using LiveU's revolutionary, aw...

19/04/2025

BitFire Wins 2025 NAB Show Project of the Year and Produc...

BitFire (bitfire.tv), a longtime leader in live video transport, today announced dual NAB Show award wins at the 2025 NAB Show in Las Vegas. The company's M...

19/04/2025

BitFire Wins Three Top Awards at 2025 NAB Show

BitFire (bitfire.tv), a longtime leader in live video transport, today announced three major award wins at the 2025 NAB Show, April 5-9, in Las Vegas. The compa...

19/04/2025

Moments Lab and Satisfaction Group Form Unique Strategic...

AI video discovery company Moments Lab and Satisfaction Group, a leading independent unscripted television production company, are proud to announce a unique st...

19/04/2025

The Infrastructure of Creative Flow DigitalGlues creative...

As the media industry navigates the triple challenge of AI-driven production, distributed teams, and skyrocketing content demand, DigitalGlue s creative.space h...

19/04/2025

Miri Technologies Wins Two Prestigious Awards for X510 Bo...

Network technology startup Miri Technologies Inc. capped off its tremendously successful NAB Show debut by winning two prestigious industry awards for its cutti...

19/04/2025

Tablo Adds 45 New FAST Channels From Warner Bros. Discovery

CINCINNATI Scripp's Nuvyyo USA has concluded a deal with Warner Bros. Discovery to bring 45 FAST channels to Nuvyyo's Tablo TV device....

19/04/2025

Court Overrules FCC's $57 Million Fine Against AT&T

In a ruling that could have broader implications on the legality of regulatory agencies levying fines through administrative proceedings, the 5th U.S. Circuit C...

19/04/2025

FCC Chair Carr Blasts Comcast Over MSNBC Coverage

WASHINGTON Federal Communications Commission chair Brendan Carr has blasted Comcast over MSNBC's coverage of the deportation of Kilmar Abrego Garcia in a so...

19/04/2025

Berklee NYC and NYC Media Launch Season 3 of Inside Power Station @BerkleeNYC

Berklee NYC and NYC Media Launch Season 3 of Inside Power Station @BerkleeNYC This season features faculty member Arun Pandian as the new host and interviews ...

18/04/2025

Everyone Is Cordially Invited to Celebrate Queer Joy in The Wedding Banquet

Director Andrew Ahn, alongside actors Youn Yuh-jung and Joan Chen, takes a photo of the audience after the premiere of his film The Wedding Banquet at Eccles ...

18/04/2025

U.S. Judge Rules Google Illegally Monopolized Ad Technologies

In a ruling that could have a major impact on the digital advertising market, a federal judge has ruled that Google has monopolized some types of advertising te...

18/04/2025

TV News Outlets See March Spike in Social Media Usage

Broadcast and cable TV news outlets saw strong social media growth in March, according to new data from the social video analytics company Tubular Labs ....

18/04/2025

Berklee Student Yukai Yang Named 2025 Yamaha Young Performing Artist

Berklee Student Yukai Yang Named 2025 Yamaha Young Performing Artist The drummer secured a spot among the elite winners in this years competition. By Maddie...

18/04/2025

Boston Conservatory Alums Bring Real Women Have Curves to Broadway

Boston Conservatory Alums Bring Real Women Have Curves to Broadway The Latin American immigrant community takes center stage in a new musical featuring Tatian...

18/04/2025

UPDATED: Broadcasters Urge FCC to Hit the Delete Button on Antiquated Regs

WASHINGTON The FCC's call for public comments and suggestions on outdated regulations that it should be eliminated, has prompted a slew of fillings from bro...

18/04/2025

Federal Judge Rules Google Illegally Monopolized Ad Technologies

In a ruling that could have a major impact on the digital advertising market, a federal judge has ruled that Google has monopolized some types of advertising te...

18/04/2025

AMS, VideoAmp Collaborate on Cross-Channel Targeting and Measurement

PEARL RIVER, N.Y. Global media solutions company Active Media Services (AMS) has formed a new relationship with VideoAmp, a measurement company for linear TV, c...

18/04/2025

Netflix Reports Strong Q1 Revenue, Operating Income

Netflix reported generally positive results for first-quarter 2025, with revenue up 13% year-over-year to $10.543 billion and operating income growing by 27% to...

18/04/2025

NHL Playoffs 2025: TNT Sports Hits the Road for Onsite Productions With Mobile Units from NEP Group, Game Creek Video

NHL Playoffs 2025: TNT Sports Hits the Road for Onsite Productions With Mobile U...

18/04/2025

EVS's Sbastien Verlaine on U.S. Expansion, Next-Generation Products

EVSs S bastien Verlaine on U.S. Expansion, Next-Generation Products Beyond replay, offerings also target asset management and media infrastructure By Ken Kersc...

18/04/2025

ESPN Unleashes 4DREPLAY as NCAA Women's Gymnastics Championships Hit ABC

ESPN Unleashes 4DREPLAY as NCAA Women's Gymnastics Championships Hit ABC Men's championships to follow Saturday night on ESPN2 By Brandon Costa, Direct...

18/04/2025

Visualizing Victory: The Latest in AR, XR, and Virtual Production in Live Sports

Visualizing Victory: The Latest in AR, XR, and Virtual Production in Live Sports This panel discussion featured leaders from ESPN, CBS Sports, Warner Bros. Disc...

18/04/2025

NHL Playoffs 2025: With 16 Games in First Six Days, ESPN Deploys Variety of Remote-Production Models in U.S., Canada

NHL Playoffs 2025: With 16 Games in First Six Days, ESPN Deploys Variety of Remo...

17/04/2025

The Ugly Stepsister: A Cinderella Body Horror Story That Will Leave a Crowd in Shambles

Emilie Blichfeldt attends the 2025 Sundance Film Festival premiere of The Ugly ...

17/04/2025

Why Resilient GPS (R-GPS) Matters for US Military Superiority: We Must Address GPS Vulnerabilities

R-GPS gives warfighters a decisive battlefield advantage by punching through adv...

17/04/2025

What NAB told us about the future of media tech

This year's NAB Show in Las Vegas marked a noticeable shift in the priorities of media and broadcast organisations. Gone are the days of chasing flashy, or ...

17/04/2025

Changing Sustainable Production in Wales and Beyond

class=attachment-thumbnail size-thumbnail f-align-center alt= decoding=async data-lazy-srcset=https://www.antonbauer.com/wp-content/uploads/2024/12/Amy-Daniel-1...

17/04/2025

Roku to Collaborate with Adobe on Real-Time Customer Data

SAN JOSE, Calif. Roku and Adobe have announced that they are collaborating on a real time data platform made possible by a a new integration of the Roku Data C...

17/04/2025

IAB: Digital Ad Revenue Surges 14.9% YoY to $259 Billion in 2024

NEW YORK Internet advertising revenues demonstrated strong growth in 2024, increasing 14.9% year-over-year to $258.6 billion, according to the IAB Internet Adv...

17/04/2025

SDVI Earns Both Product and Project of the Year Awards at 2025 NAB Show

SDVI Earns Both Product and Project of the Year Awards at 2025 NAB Show Brie Clayton April 17, 2025 0 Comments Left to right, Geoff Stedman, CMO, SDVI...

17/04/2025

Singapore Polytechnic Readies Aspiring AV Professionals for Live IP Productions with AJA

Singapore Polytechnic Readies Aspiring AV Professionals for Live IP Productions ...

17/04/2025

Calrec Wins 2025 NAB Show Product of the Year Award for True Control 2.0

Calrec Wins 2025 NAB Show Product of the Year Award for True Control 2.0 Brie Clayton April 17, 2025 0 Comments Image: The Calrec True Control 2.o on ...

17/04/2025

In Return to Berklee, Lucius Looks Back and Moves Forward

In Return to Berklee, Lucius Looks Back and Moves Forward From mood boards to live demos, the alumni band gave students an exclusive look at the process behin...

17/04/2025

MyFree DirecTV Adds 8 NBCU Channels

DirecTV's free streaming service MyFree DirecTV has just added another eight channels from NBCUniversal....

17/04/2025

GameChanger Launches in the U.S.

LOS ANGELES The virtual production company GameChanger has announced that it is expanding its global footprint by bringing its virtual production technology to ...

17/04/2025

IBCAP Launches Automated VOD Monitoring and Takedown System

DENVER The International Broadcaster Coalition Against Piracy (IBCAP) has announced that it has developed a proprietary, automated software-based system to iden...

17/04/2025

Pixalate: Roku Continues to Dominate U.S. CTV Device Market

Pixalate's new CTV Device Market Share report for Q1 2025 shows that Roku has the highest open programmatic CTV device market share in the United States, wi...

17/04/2025

Edward J. Lewis III Named Senior Vice President of Institutional Advancement

Edward J. Lewis III Named Senior Vice President of Institutional Advancement Lewis has more than 20 years of industry experience, leading fundraising initiati...

17/04/2025

The Curling Group Puts On Inaugural Curling All-Star Game in Nashville

The Curling Group Puts On Inaugural Curling All-Star Game in Nashville The location in Music City is intended to broaden the sport's appeal By Dan Daley, ...

17/04/2025

Tribeca Festival 2025 Announces TV and NOW Lineup

April 17th, 2025 Press Materials Available Here Tribeca Festival 2025 Announces TV & NOW Lineup World Premieres and Exclusive Cast Panels with Apple TV '...

17/04/2025

SVG Sit-Down: Cisco's Bryan Bedford on Providing End-to-End Support for Clients, How Industry Trends Impact Workflows

SVG Sit-Down: Cisco's Bryan Bedford on Providing End-to-End Support for Clie...